Processing of Personal Data for Virtual Work Experience and Subject Spotlights

Edited

For Springpod to deliver its services, it must use certain information. Read together with Springpod's Privacy Notice, this guidance gives clients more detailed information about what data is processed, on what lawful basis, who is responsible for it and how it is secured. It is practical guidance for clients and is not legal advice.

What information is processed?

Student data

To hold an account on springpod.com, a student provides:

  • Name.

  • Email address, validated by two step verification.

  • Username.

  • Password, created by the user.

  • Confirmation that they are aged 13 or over.

  • Their activity on the platform, and their education and work activity.

  • Agreement to the Springpod Terms of Use.

Students are also invited, optionally, to provide school, year group, gender and ethnicity, and other programme-specific demographic information. Providing this information is optional and a student can decline without any effect on their use of the platform.

Parent data

To hold an account on springpod.com, a parent provides name, validated email address, username, password, information relating to their child, their activity on the platform, and agreement to the Terms of Use. Parent data is shared with their child only, so that the child knows who provided their information.

Education provider data

An employee of an education provider provides name, validated email address, username, password, the education provider that employs them, their data protection and safeguarding contacts, their activity on the platform, and agreement to the Terms of Use.

Employer data

An employee of a business hosting work experience provides name, validated email address, username, password, the business that employs them, their activity on the platform, and agreement to the Terms of Use.

What is the lawful basis for processing?

Mandatory account information. Springpod is the controller for the personal data needed to create, host, maintain and administer a user's Springpod account. It is processed under Article 6(1)(b) of the UK GDPR, because it is necessary to provide the account and the platform service the user has asked for.

Platform security and other Springpod legitimate interests. Springpod also carries out processing that is not necessary to perform the user contract, such as protecting the platform and its users, preventing misuse and fraud, maintaining service integrity, and proportionate platform analytics. Springpod is the controller for that processing and relies on Article 6(1)(f), subject to a documented legitimate interests assessment and the user's right to object.

Optional information that is not special category data. Where a user chooses to provide optional information such as school or year group, and Springpod uses it for its own purposes of tailoring the opportunities shown to the user and understanding how the platform is used, Springpod is the controller and relies on Article 6(1)(f). This is separate from the account processing described above.

Special category equality information. Ethnicity, disability information and other special category equality information are not used for Springpod's own platform purposes and are not covered by the legitimate interests described above.

Where this information is collected for a client's equality monitoring, the client is the controller, Springpod is the client's processor, and Springpod hosts and processes the information only under the client's documented instructions.

Springpod's technical hosting of the information does not create a separate Springpod controller purpose.

Where optional information is collected to support a client's own equality monitoring, the client is the controller for that processing and Springpod acts as the client's processor. The client determines and documents its Article 6 lawful basis and, where the information includes special category data such as ethnicity or disability status, its Article 9 condition. Where relevant, that condition is Article 9(2)(g) of the UK GDPR together with paragraph 8 of Part 2 of Schedule 1 to the Data Protection Act 2018, concerning equality of opportunity or treatment.

That condition does not extend to measures or decisions about a particular data subject. Information processed for equality monitoring is not used to provide personalised careers advice and is not used to make individual employment, recruitment or selection decisions.

Explicit consent is not relied on for equality monitoring. Article 9(2)(b) is not relied on, because students taking part in virtual work experience are not employees for this purpose.

Students may give consent for Springpod to use their information for marketing. Consent can be withdrawn at any time.

Who is the controller and who is the processor?

Springpod may be a controller and a processor at the same time, for different processing activities. The distinction is determined by the purpose of the processing, not by where the information was collected. There is no joint controller relationship.

Processing activity

Roles

Creating, maintaining and administering a springpod.com

account, and Springpod's own platform purposes

Springpod is the controller.

Delivering a virtual work experience programme commissioned by a client

The client is the controller. Springpod is the client's processor and acts only on the client's documented instructions.

Monitoring, reporting, evaluation and equality monitoring for a client's programme

The client is the controller. Springpod is the client's processor.

Springpod does not become the controller for a client's programme processing merely because the information was collected through springpod.com. Equally, a client's lawful basis does not become Springpod's lawful basis. The client determines and documents the lawful basis and any Article 9 condition for processing carried out on its behalf.

NHS England Widening Access Demonstrator and Partner Portal reporting

WAD and NHS England

SPR13.3 – Processing of Personal Data for Virtual Work Experience v1.3 30.07.26 Page 2 of 5The Widening Access Demonstrator (WAD) is an internal reporting framework managed and used by NHS England (NHSE). It is not a Springpod product or service and is not provided, operated or managed by Springpod. Participants do not access WAD through Springpod.

Where an applicable programme is reported through WAD, relevant participant and programme information is supplied or made available to NHS England for monitoring, equality monitoring and programme-reporting purposes for use within that framework. This applies only to participants in applicable programmes and not to Springpod users generally.

NHS England's use of that information is limited to monitoring, equality monitoring and programme reporting within WAD. NHS England does not access WAD through the Springpod platform or Partner Portal.

Partner Portal

The Springpod Partner Portal is a Springpod reporting facility and is separate from WAD. Authorised users of the client commissioning a programme, and any authorised participating employer organisation responsible for that programme, may access relevant programme information through the Partner Portal.

The Programme Client may use relevant information to deliver and administer its programme, monitor participation, engagement and completion, evaluate delivery and outcomes, carry out equality monitoring, support widening access and participation objectives, complete programme reporting and meet applicable governance and accountability requirements.

Where a participating employer organisation is separate from the Programme Client, it may access or use relevant information only where it is authorised and responsible for the programme concerned. The purposes of the Programme Client and NHS England must not automatically be attributed to every participating employer.

Information accessed through the Partner Portal is not used to provide personalised careers advice and is not used to make individual employment, recruitment or selection decisions.

Access restrictions

Access to the Springpod platform and Partner Portal will be limited:

  • to authorised users at the Programme Client and any participating employer organisation responsible for the programme concerned;

  • to the programme or programmes for which that organisation is responsible;

  • according to the user's role; and

  • to the information necessary for the permitted programme, monitoring, equality-monitoring and programme-reporting purposes.

No client or participating employer organisation will be given access to information belonging to another client's programme.

Why do we need a Data Processing Agreement?

Where Springpod processes personal data on a client's behalf, the relationship is controller to processor and is governed by a Data Processing Agreement. This is set out in the data protection section of the Springpod Terms of Business Agreement. It is not controller-to-controller sharing.

Before processing begins, Springpod also records the name and contact details of the client's data protection contact and safeguarding responsible person, so that data subject requests and safeguarding concerns can be handled promptly.

How does Springpod manage its data integrity?

Springpod maintains a suite of policies and procedures covering data protection and wider risk, overseen through its Risk Management Framework. Springpod's Data Protection Officer monitors compliance and advises the business. The Framework allows Springpod to manage regulatory compliance, incidents and third parties centrally.

How does Springpod tell people about the processing?

Springpod publishes a Privacy Notice at www.springpod.com/privacy-policy. Throughout the collection process, people are told what information is needed and why, which information is optional, that they do not have to provide optional information, and how to exercise their rights.

How is information shared?

Most of the information Springpod makes available to employers and education providers is given to Springpod directly by students. Occasionally Springpod receives information from education providers and employers where it is appropriate and lawful to do so. All information is shared securely and data in transit is encrypted.

Springpod's key third party suppliers

Springpod uses a number of cloud based services to run its business and deliver its services. Where it does, Springpod takes care to ensure those third parties meet relevant data protection and security requirements. Current suppliers are listed in the Privacy Notice, and details of subprocessors relevant to a client's services are provided on request under the Terms of Business Agreement.

Google Workspace

Multi-factor authentication is enforced for all users and data in transit is secured using TLS. Google undergoes regular

independent third party audits, including SOC 1, SOC 2, SOC 3, ISO 27001 and ISO 27018. Customer data is encrypted at

rest using 128 bit or stronger AES, and encrypted in transit using HTTPS with forward secrecy.

Amazon Web Services

Users access the platform through a front end application which reaches data via an authenticated API over a secure TLS connection. Users are authenticated on the platform rather than through a directory. Authentication and authorisation on the back end ensure users can only access the data that concerns them. All access to the system is logged, both at network level and through the logging of authentication requests.

What does a client need to do?

  • Add Springpod to your list of third parties.

  • Sign the Springpod Terms of Business Agreement, which contains the Data Processing Agreement.

  • Add the processing to your record of processing activities.

  • Undertake a Data Protection Impact Assessment. Springpod can supply a template on request.

  • Check that your privacy information tells data subjects that their data may be shared with other organisations, and identifies your role as controller.

  • Review your data subject request processes so that you can respond to requests received via Springpod.

  • Review your data breach procedure to reflect that notifications may come from Springpod, and to notify Springpod of anything that happens at your end.

  • Where you request optional or special category information for equality monitoring, document your Article 6 lawful basis and Article 9 condition, and hold an appropriate policy document where one is required.

What if I have more questions?

Contact Springpod's Data Protection Officer, Kieran Morgan-McGeehan:

Telephone: 0203 637 8665

Email: dpo@springpod.com

Post: Springpod, Arch 6, Maltings Place, 169 Tower Bridge Road, London, SE1 3LJ

Further guidance on your own responsibilities is available from the Information Commissioner's Office at

www.ico.org.uk.

Was this article helpful?

Sorry about that! Care to tell us more?

Thanks for the feedback!

There was an issue submitting your feedback
Please check your connection and try again.