policy
Privacy Policy
Version 2.02 · Published 7 October 2026
This privacy notice applies to all activities and services provided by Railway Competence Group ("RCG", "we", "us"). These include delivering qualifications, end-point assessments, and psychometric tests; collecting and storing personal data; and operating our websites and online platforms. That includes the RCG website, online booking and candidate portal.
RCG is the data controller for the personal data described in this notice. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Contact details
Railway Competence Group,
Albion Wharf,
19 Albion Street,
Manchester
M1 5LN
Email: contact@rcg.org.uk
Phone: 0330 1332470
ICO registration number: ZA763665
Personal data we collect
Name and contact details (address, email, telephone number)
Date of birth
Qualification, assessment and test information (bookings, attendance, results, grades, progress)
Booking and payment records. Card details are handled directly by our payment provider and are never seen or stored by RCG.
Account information for our candidate portal (login email, account activity)
Messages you send us through contact, waiting list or reschedule forms
Technical data when you use our website (IP address, browser, device, and cookies)
Special category data: we may collect demographic information (e.g. ethnicity) and information about special educational needs, disabilities or health conditions. We only collect it where you choose to give it to us, for example to arrange reasonable adjustments or for equality monitoring required by regulators.
How we use your data and our lawful basis
Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
Booking, delivering and recording assessments and tests | Contract |
Taking payments and keeping financial records | Contract; Legal obligation |
Sending booking confirmations, joining instructions and reminders | Contract |
Reporting to awarding bodies, Ofqual, Skills England / ESFA, and employers or providers who funded your assessment | Legal obligation; Legitimate interests |
Making reasonable adjustments | Legal obligation (Equality Act 2010); Article 9(2)(b) and (g) |
Equality and diversity monitoring | Article 9(2)(g) with DPA 2018 Schedule 1 conditions; Consent where requested |
Responding to enquiries | Legitimate interests |
Keeping our systems secure and preventing fraud | Legitimate interests |
Non-essential cookies and marketing | Consent |
We only use personal data for the purposes it was collected for, or as the law allows.
Who we share your data with
We do not sell your personal data. We share it only where necessary:
Regulators and awarding/funding bodies (e.g. Ofqual, Skills England / ESFA, awarding organisations), as the law or regulations require
Your employer or training provider, where they arranged or paid for your assessment
Service providers who process data for us under written contracts (data processors):
Website hosting, database and file storage provider
Payment provider (Stripe) for card payments
Email delivery provider for booking and account emails
ACE360 End-point Assessment Management System
Law enforcement or other authorities where the law requires it
Where your data is stored (international transfers)
The personal data collected through our website, booking system and candidate portal is stored on secure servers in Ireland (European Union). That includes your account details, bookings and the documents we provide to you.
The UK Government has issued an adequacy regulation for the European Economic Area under the Data Protection Act 2018. This means the UK recognises Ireland as providing an adequate level of data protection. Transfers to Ireland therefore do not need extra safeguards.
Some of our service providers (for example, payment and email providers) may process data outside the UK and EEA, including in the United States. Where this happens, we make sure appropriate safeguards are in place. These include the UK Extension to the EU–US Data Privacy Framework, or the ICO's International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses. You can ask us for details of these safeguards.
How we keep your data secure
We take appropriate technical and organisational measures to protect personal data from unauthorised access, alteration, disclosure or destruction. These include:
Encryption of data in transit (HTTPS) and at rest
Access controls, so candidates can see only their own records and staff can access only what their role requires
Multi-factor authentication for administrator accounts
Private document storage, with download links that expire after a short period
Audit logs of sensitive actions such as bookings, refunds and document access
How long we keep your data
We keep personal data only for as long as needed for the purposes it was collected for, or as the law, regulators or awarding bodies require. Online booking and candidate account data is deleted automatically 24 months after it is no longer needed, unless we must keep it longer. Assessment records and financial records may be kept for longer periods as set out in our Data Retention Policy. After that, data is securely destroyed.
Your rights
Under UK data protection law you have the right to:
Access – ask for copies of your personal information
Rectification – ask us to correct inaccurate or incomplete information
Erasure – ask us to delete your personal information in certain circumstances
Restriction – ask us to limit how we use your information
Object – object to processing based on legitimate interests or to direct marketing
Data portability – ask us to transfer information you gave us to you or another organisation
Withdraw consent – where we rely on consent, at any time, without affecting earlier processing
Which rights apply depends on the lawful basis we rely on. Some exemptions may apply. See the ICO's website for more information.
You can make a request verbally or in writing using the contact details in section 1. You do not usually need to pay a fee. We will respond without undue delay and within one month. We may extend this by up to two further months for complex requests and will tell you if we do. We will take reasonable steps to verify your identity first.
You can also view and update some of your details yourself in our candidate portal and in ACE360.,
Automated decision-making
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
Cookies
Our website uses essential cookies and similar storage to keep you signed in and make booking work. These do not need your consent. We will only use non-essential cookies, such as analytics or advertising cookies, with your consent, and you can change your choice at any time. You can also control cookies through your browser settings.
Data breaches
If a personal data breach happens, we will contain and investigate it. We will report it to the ICO within 72 hours where required. Where there is a high risk to you, we will tell you without undue delay.
Changes to this policy
The policy will be reviewed annually.
How to complain
If you have concerns about how we use your personal data, please contact us first using the details in section 1. If you are still unhappy, you can complain to the Information Commissioner's Office (ICO):
Information Commissioner's Office,
Wycliffe House,
Water Lane,
Wilmslow,
Cheshire
SK9 5AF
Helpline: 0303 123 1113 ·
Website: https://ico.org.uk/make-a-complaint