policy
IT and Information Security Policy
Version 2.14 · Published 7 October 2026
Information Security Policy sets guidelines and procedures for how RCG secures, protects, and manages the information it needs to conduct business. This policy applies to all employees, contractors, and partners of RCG, as well as any third-party vendors or service providers that may have access to assessment materials or any data that falls under GDPR and the Data Protection Act of 2018.
Railway Competence Group is fully committed to complying with the Data Protection Act 2018 and the General Data Protection Regulation (GDPR). Document management principles are outlined in this policy to ensure consistency across all formats.
Data Locations
ACE360
Apprentice contact details and results are hosted on ACE360.
Testinvite
Online test questions and answers linked to individual apprentices are hosted on Testinvite.
Documents
Physical security measures are in place to protect data at RCG offices. RCG offices can only be accessed via lockable doors, and only authorised staff receive keys. Outside of office hours, both the offices and building are locked and secured with key code burglar alarms.
Email servers
Email stored on OFFICE 365.
Email servers are compliant with all UK and EU data protection regulations.
Hard-drive memory on PCs and Laptops
Employees of the RCG will have access to additional storage options, such as hard-drive memory on PCs and laptops. This information is unsecured and as such should not contain any confidential or personal information. Employees are responsible for following these guidelines.
Password policy
All RCG passwords are covered by the same password policy. Meaning, all passwords must be:
Private
Unique
Never written down
Be at least 8 characters in length
Contain a combination of letters and numbers
Replaced when compromised
Passwords may need to be shared with line managers in certain circumstances, such as sickness or holidays. Passwords should never be shared with anyone else.
Acceptable Personal Use
RCG provides all its employees with systems, data and equipment for the purposes of the company's activities only.
There is a security filter on the company's internet connection, so inappropriate sites will be blocked.
These facilities/equipment should not be used for personal financial gain, to solicit others for unrelated activities, or to engage in political campaigns or lobbying. Tools provided by the organisation can never be used to publish defamatory or obscene material, infringe on someone's intellectual property, or violate any law.
RCG may monitor electronic correspondence (including email, voice and text messages) so as to ensure the integrity of its information technology, or to prevent or detect criminal activity, or to comply with employment laws and policies.
Social Media
RCG uses several social media accounts and encourages employees to promote the company through social media.
RCG employees should be aware that their personal social media accounts should always reflect the company's values, ethics, and codes of conduct, and should never be used to transfer personal information.
All social media accounts mentioning RCG are subject to this policy.
Software Downloads
Internet downloaded software is an essential part of any business, but it is also a risk. Software downloads must be approved by IT provider.
Leaving desk
Whenever an employee is away from their desk for an extended period, all paperwork containing personal information should be locked away. All employees will have lockable cabinets.
If an employee is not actively using a device it must be locked and must not be left unattended whilst unlocked.
Data Breach
Any suspected or actual breaches of security or confidentiality will be reported to the appropriate authorities immediately. RCG will conduct an internal investigation and take appropriate actions to prevent further breaches and to protect the confidentiality of candidate details and assessment materials.
If you suspect a data breach you must report this immediately to Managing Partner-Delivery or alternatively the compliance manager.
Security and Confidentiality of Materials
RCG (End-Point Assessment Organisation) will ensure the security and confidentiality of all materials related to the assessment process, including but not limited to candidate information, assessment results, and any other sensitive or confidential data.
The accuracy and reliability of assessments rely on the safeguarding and confidentiality of sensitive information. For RCG, confidential information pertains to data that is not commonly known outside the organisation or is legally protected. Such information includes, but is not limited to:
Grading
Intellectual property
Answer sheets or question banks
Business plans, financial information and forecasts
Information obtained regarding RCG’s EPA processes and materials used.
Confidentiality
All employees, contractors, and partners of RCG, as well as any third-party vendors or service providers, will be required to sign a non-disclosure agreement before being granted access to assessment materials. This agreement prohibits the sharing, copying, or distribution of any assessment materials to any unauthorized parties.
In case of emergencies, health or safety concerns, or audits, disclosure of confidential information may be necessary and agreed with RCG. All confidential materials, property, and information remain the property of the RCG.
Procedure
RCG mandates that all employees/representatives/contractors and service providers uphold the trust and confidentiality of confidential information, and:
Comply with data protection laws and GDPR.
Follow RCG's IT and Information Security Policy and Procedure to maintain the security of materials/data and property.
Access, use, store, or disclose confidential information solely for the agreed purposes/duties within their agreed upon role/contract with RCG.
Only remove confidential materials or property from the organization's offices when agreed upon with management, in line with their agreed upon role responsibilities.
Securely return or destroy any confidential materials, property, or copies of confidential information in their possession upon request by RCG management team.
All RCG employees/representatives/contractors and service providers are accountable for maintaining the confidentiality of such data.
Data Retention
Procedure
Railway Competence Group applies the following principles when handling apprentices' personal data:
We will only use personal data with the candidate's permission and in association with delivery of End Point Assessments.
Unless required by law, Railway Competence Group will never share a candidates' personal information with any other organisation.
We only collect the information we need for the delivery of End-point Assessments and subsequent certification.
Candidates' personal information is only seen by those who require it to provide the service.
Candidate personal data is retained only as long as necessary.
If changes are made to personal information, Railway Competence Group will update our records.
Immediately correct inaccuracies or misleading information.
Information about candidates is protected from accidental or unauthorised disclosure.
Railway Competence Group will make personal data that we have stored available to the individual upon request and comply with all relevant legislation.
Third parties working for Railway Competence Group must comply with this policy.
Staff members are responsible for managing, storing appropriately, and disposing of the information they produce and receive on a day-to-day basis.
Electronic data is held securely and is only accessed by authorised personnel. The server and all computers are firewall protected.
Railway Competence Group must review and dispose of the information gathered and generated throughout the course of its business.
Disposal Schedules
A long retention period carries additional risks, costs, and potential non-compliance with the Data Protection Act 2018.
According to the Data Protection Act 2018, Railway Competence Group must not hold personal data for longer than is necessary.
Please see table below regarding data types, retention periods, storage methods, review dates, and when to destroy documents safely.
Type of Record | Retention Period | Reason for Length of Period |
Learner registration | 3 years after the qualification is completed | Processing any queries; requirement to maintain contact details in the case of any legacy malpractice. |
Learner achievements/certification record | In perpetuity | Replacement certificates; authenticating achievement. |
RCG staff records | 3 years after data subject ceases to be on staff | May be required for professional reference. |
5 years for data relating to proven malpractice | Potential litigation | |
Data may be held in perpetuity in cases of proven serious malpractice | Potential litigation | |
Personnel files, including training records, notes of disciplinary and grievance hearings, and appraisal forms | 6 years from end of employment | References and potential litigation |
Some data relating to proven serious malpractice may be held in perpetuity | Selected material may form part of the Institute Archive | |
Letters of reference | 6 years from end of employment, by the author of the reference letter | References and potential litigation |
Application forms / interview notes | At least 6 months from the date of the interviews | Time limits on litigation |
Facts relating to redundancies where fewer than 20 redundancies | 6 years from the date of redundancy | As above |
Facts relating to redundancies where more than 20 redundancies | 12 years from the date of redundancies | Limitation Act 1980 |
Income Tax and NI returns including correspondence with tax office | At least 3 years after the end of the financial year the records relate to | Income Tax Employment Regulations 1993 |
Statutory Maternity pay records and calculations | As above | Statutory Maternity Pay (General) Regulations 1986 |
Statutory sick pay records and calculations | As above | Statutory Sick Pay (General) Regulations 1982 |
Wages and salary records | 6 years from end of employment | Taxes Management Act 1970 |
Accident books and records and reports of accidents | 3 years after the date of the last entry | Social Security (Claims and Payments) Regulations 1979, RIDDOR 1985 |
Health Records | During period of employment | Management of Health and Safety at Work Regulations |
Health records where reason of termination of employment is connected with health including stress related illnesses | 3 years | Limitation Period for personal injury claims |
Medical records kept by reasons of the Substances Hazardous to Health Regulations 1999 | 40 years | The Control of Substances Hazardous to Health Regulations 1999 |
Anonymised data does not have retention periods. We will not destroy data records pending audits, litigation, or investigations.
Managing Partner - Delivery is responsible for securely disposing of data, including backups, and maintaining an audit trail.
When challenging the retention of personal data, GDPR Article 17 (Right to erasure) or the equivalent sections in the DPA 2018 should be applied. When Railway Competence Group is legally obliged to process personal data or processing is necessary for us to perform our functions, the right to erasure does not apply.
Breaches and Reporting
Any suspected or actual breaches of security or confidentiality will be reported to the appropriate authorities immediately. RCG will conduct an internal investigation and take appropriate actions to prevent further breaches and to protect the confidentiality of assessment materials.
Training
All employees and contractors of RCG will receive regular training on data protection and retention, including the importance of maintaining data security and compliance with this policy. This training will cover topics such as data protection legislation, data access controls, data disposal procedures, and incident response procedures.
Compliance
Failure to comply with this policy may result in non-compliance with Ofqual's conditions of recognition. RCG will conduct regular compliance audits to ensure that this policy is being followed and that all data is being retained, processed, and disposed of in compliance with relevant legislation and regulations. Annual compliance audit will be undertaken by the Managing Partner-Delivery.
Penalties for Non-Compliance
Violations of this policy may result in disciplinary action, including but not limited to termination of employment or contract, and/or legal action. In addition, any third-party vendors or service providers found to be in violation of this policy may be terminated from their contract with RCG.