Data Handling Policy
SystemShift Leadership Development Platform
GDPR Compliant
| Version | 1.0 |
|---|---|
| Issue Date | 01 June 2026 |
| Review Date | Annually or upon material change |
| Document Owner | Data Protection Officer |
| Classification | Internal / Participant-facing |
1. Introduction and Scope
This Data Handling Policy (“Policy”) sets out how SystemShift Ltd (“we”, “us”, “the Organisation”) collects, uses, stores, shares, and protects personal data in connection with our Learning Management System (“LMS”) and the four bespoke training programmes delivered through it.
This Policy is issued in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) and reflects the principles of the EU GDPR where applicable. It applies to all staff, trainers, administrators, and third-party processors who handle personal data as part of LMS operations.
The LMS delivers the following four training programmes:
- Programme 1: Leading Strategic Change: The Step Up, Step Back Approach
- Programme 2: How to develop your Strategy and set up your Organisation to Deliver
- Programme 3: How to get More out of your People
- Programme 4: How to have ‘Difficult’ Conversations More Effectively
The LMS also has two public-facing portals:
- The “L&D Manager” portal, used by the individual responsible for managing participants within an organisation (“L&D manager portal”).
- The “Participant” portal, used by those who are enrolled on one or more of SystemShift's four training programmes to complete their programme (“participant portal”).
2. Data Controller Details
For the purposes of the UK GDPR, SystemShift Ltd is the Data Controller in respect of all personal data processed through the LMS.
| Field | Detail |
|---|---|
| Organisation | SystemShift LTD |
| Registered Address | 6th Floor Kings House, 9-10 Haymarket, London, United Kingdom, SW1Y 4BP |
| ICO Registration Number | ZC171745 |
| Data Protection Officer (DPO) | Elsbeth Johnson, Managing Director |
| DPO Contact Email | Enquiries@SystemShift.com |
Where a client organisation procures licences to SystemShift's programmes and is granted access to the LMS, that organisation may act as a joint controller or separate controller for certain processing activities. A Data Processing Agreement (“DPA”) will be entered into with all such organisations.
3. Personal Data We Collect
3.1 Account Registration Data
When participants or L&D managers register for and use the LMS, we collect the following personal data directly from them:
| Data Element | Data Subject | Source | Purpose |
|---|---|---|---|
| Full Name | Participant / L&D Manager | Account registration | Identity and programme administration |
| Job Role / Title | Participant / L&D Manager | Account registration | Allocating appropriate training programmes |
| Work Email Address | Participant / L&D Manager | Account registration | Authentication, notifications, correspondence |
| Password (hashed) | Participant / L&D Manager | Account creation | Secure authentication |
| Organisation / Department | Participant / L&D Manager | Account registration | Cohort management and reporting |
3.2 Calendar Integration Data
Calendar integration is a requirement of onboarding to the SystemShift LMS platform. Where participant or L&D Manager users connect their Microsoft Outlook or Google Calendar accounts to the LMS, we access the following calendar data via secure OAuth 2.0 authorisation:
- Calendar event titles and descriptions (to schedule and surface training sessions)
- Meeting availability and free/busy status (to recommend optimal scheduling)
- Event dates and times (to create and update LMS-generated calendar entries)
Important – Scope of Calendar Access
We access only the minimum calendar data necessary for scheduling purposes. We do not read, store, or process personal or confidential content from calendar events unrelated to LMS training activities.
Calendar integration is a requirement of onboarding and access to the programme and is not optional. If a participant does not wish to connect their calendar, they will not be able to access any training programme.
Calendar access tokens are revocable by the participant at any time through their Microsoft or Google account settings. Participants should contact their L&D manager to understand how revoking their tokens will impact progress through their programme.
3.3 Programme Participation Data
While delivering the four training programmes, we collect the following data generated by participant activity:
- Written responses to course questions, exercises, and reflective activities
- Module and session progress and timestamps
- Feedback and evaluation responses
- Certificates of completion
We may, from time to time, wish to publish quotes based on participant feedback. We will not do this without the explicit consent of the participant.
3.4 Technical and Log Data
Our systems automatically collect limited technical data when participants access the LMS:
- IP address and browser/device type (for security and audit purposes)
- Login timestamps and session durations
- System error and access logs
4. Lawful Basis for Processing
We rely on the following lawful bases under Article 6 UK GDPR for each category of processing:
| Processing Activity | Lawful Basis |
|---|---|
| Account registration and authentication | Contract (Art. 6(1)(b)) – necessary to provide access to the LMS |
| Programme delivery and progress tracking | Contract (Art. 6(1)(b)) – necessary to deliver the agreed training |
| Written responses to course questions | Contract (Art. 6(1)(b)) – integral to programme delivery; Legitimate Interests (Art. 6(1)(f)) – improving programme quality |
| Calendar integration | Consent (Art. 6(1)(a)) – participants expressly authorise access via OAuth |
| Management reporting and oversight | Legitimate Interests (Art. 6(1)(f)) – lawful employer oversight of training; balanced against participant privacy |
| Security logging and fraud prevention | Legal Obligation (Art. 6(1)(c)) / Legitimate Interests (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal Obligation (Art. 6(1)(c)) |
Where we rely on Legitimate Interests, a Legitimate Interests Assessment (LIA) has been carried out and is available upon request from the DPO.
5. Special Category and Sensitive Data
The LMS is not designed to collect special category personal data as defined by Article 9 UK GDPR (e.g. health data, race/ethnicity, political opinions, religious beliefs).
However, participants should be aware that written responses submitted to course questions are free-form in nature. Participants are advised not to include sensitive personal information about themselves or third parties in their course responses beyond what is required to answer the questions set.
If a participant inadvertently discloses special category data within a course response, such data will be handled with heightened care and restricted access controls, and the participant will be notified.
6. How We Use Personal Data
We use the personal data collected through the LMS for the following purposes:
- Registering and managing participant and L&D manager accounts
- Authenticating users and maintaining platform security
- Delivering the four training programmes and tracking progress
- Scheduling and sending programme-related calendar invitations and reminders
- Providing L&D managers with progress reports on their team members' participation and completion
- Generating anonymised aggregate analytics to evaluate and improve programme effectiveness
- Complying with legal and regulatory obligations
- Responding to data subject rights requests
We will not use personal data for automated decision-making or profiling that produces legal or similarly significant effects without explicit consent.
7. Data Sharing and Recipients
7.1 Internal Access
Access to personal data within the Organisation is restricted on a strict need-to-know basis:
| Role | Access Scope |
|---|---|
| Programme Administrators | Account management, scheduling, and reporting |
| Training Facilitators / Coaches | Programme delivery; access to participant responses relevant to their programme only |
| IT / Platform Team | System maintenance and security; no routine access to content data |
| Data Protection Officer | Compliance oversight, rights request handling |
| Senior Management | Anonymised aggregate programme reports only |
7.2 Third-Party Processors
We engage the following categories of third-party data processors who act under our written instructions and are bound by a Data Processing Agreement:
- LMS Platform Provider – hosting and software infrastructure
- Cloud hosting and storage provider (e.g. AWS / Azure / GCP)
- Microsoft and Google – solely in connection with calendar integration (OAuth access governed by their respective privacy policies and terms)
- Email delivery provider – for system notifications
- Analytics provider – receives only anonymised or aggregated data
A register of all third-party processors is maintained by the DPO and is reviewed annually. All processors are assessed for adequacy of their technical and organisational security measures prior to engagement.
7.3 Disclosure to Client Organisations
Where the LMS is deployed on behalf of a client organisation, we may share participant progress and completion data with designated managers or HR administrators within that organisation. The extent of such sharing is governed by the Data Processing Agreement between us and the client and participants are informed of this sharing at registration.
7.4 Legal Disclosure
We may disclose personal data to law enforcement, regulatory authorities, or courts where required by law, or where necessary to protect the rights, property, or safety of the Organisation, its participants, or others.
8. International Data Transfers
We endeavour to process and store all personal data within the UK or European Economic Area (EEA). Where any transfer to a third country outside the UK/EEA is necessary (for example, through the use of global cloud infrastructure), we ensure that an appropriate safeguard is in place, including:
- An adequacy decision by the UK Secretary of State or European Commission
- UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs) where applicable
Details of any international transfers and the safeguards applied are available from the DPO upon request.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The following retention periods apply:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account data (name, role, email) | Duration of active enrolment + 2 years | Legitimate interests; post-programme support |
| Programme completion records and certificates | 6 years from completion date | Legal obligation; potential employment/audit reference |
| Written course responses | 2 years from programme completion | Programme quality assurance; dispute resolution |
| Management reports | 3 years from issue date | Legitimate interests; HR audit trail |
| Calendar integration tokens | Until revoked by participant or account deletion | Consent-based; revocable at any time |
| Security and access logs | 12 months | Security monitoring; incident investigation |
| Technical log data | 90 days (rolling) | System stability and fraud prevention |
At the end of the applicable retention period, data is securely deleted or anonymised in accordance with our Data Destruction Procedure.
10. Security Measures
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration, including:
10.1 Technical Controls
- One-Time Password is used for all participant and L&D manager accounts.
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of data at rest using industry-standard AES-256
- OAuth 2.0 protocol for calendar integrations (no passwords stored for Microsoft or Google)
- Secure access controls and role-based permissions limiting access to personal data
- Regular automated security patching and vulnerability scanning
- Penetration testing conducted at least annually
10.2 Organisational Controls
- Data protection and information security training for all staff with access to the LMS
- Data protection impact assessments (DPIAs) conducted for high-risk processing activities
- Confidentiality obligations for all staff and processors
- An incident response and breach notification procedure
- Regular audits of access controls and data holdings
11. Data Subject Rights
As a data subject, participants and managers have the following rights under the UK GDPR, which can be exercised free of charge:
| Right | Description |
|---|---|
| Right of Access (SAR) | Request a copy of the personal data we hold about you and information about how it is used. |
| Right to Rectification | Request correction of inaccurate or incomplete personal data. |
| Right to Erasure ('Right to be Forgotten') | Request deletion of your personal data where there is no overriding legal basis for retention. |
| Right to Restrict Processing | Request that we limit how we use your data in certain circumstances. |
| Right to Data Portability | Receive your data in a structured, commonly used, machine-readable format (applies to consent or contract-based processing). |
| Right to Object | Object to processing based on legitimate interests or for direct marketing purposes. |
| Right to Withdraw Consent | Where processing is based on consent (e.g. calendar integration), withdraw consent at any time without affecting prior processing. |
| Rights re Automated Decisions | Not be subject to solely automated decisions that produce significant effects, without human review. |
To exercise any of these rights, please contact the DPO at Enquiries@SystemShift.com. We will respond within one calendar month of receiving a valid request. We may request proof of identity before processing a rights request.
If you are dissatisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at www.ico.org.uk or by telephone on 0303 123 1113.
12. Consent and Withdrawal
Where we rely on consent as the lawful basis for processing (currently limited to calendar integration), participants are informed at the point of connection of exactly what data will be accessed and for what purpose.
Consent is obtained separately from acceptance of general terms and conditions and is granular – participants can connect their calendar without accepting any unrelated data use.
Participants may withdraw consent for calendar integration at any time by:
- Disconnecting the integration within their LMS account settings, or
- Revoking access directly through their Microsoft or Google account settings
Withdrawal of consent will not affect the lawfulness of any processing that took place prior to withdrawal, nor will it affect participation in any training programme.
13. Data Protection Impact Assessment
We have conducted a Data Protection Impact Assessment (DPIA) covering the LMS and its core processing activities, including the collection of written participant responses and integration with third-party calendar services. The DPIA is reviewed annually and following any material change to the system or processing activities.
Copies of DPIAs are maintained by the DPO. Participants or client organisations may request a summary upon reasonable request.
14. Children's Data
The LMS is intended solely for use by adults (individuals aged 18 years or over) in a professional capacity. We do not knowingly collect or process personal data relating to children. If we become aware that a child has registered for the LMS, we will promptly delete their account and associated personal data.
15. Cookies and Tracking Technologies
The LMS uses cookies and similar technologies to maintain session authentication, remember user preferences, and support platform security. A separate Cookie Policy is available within the LMS interface. Non-essential cookies require prior consent, which may be managed through the cookie preference centre.
16. Changes to This Policy
We review this Policy at least annually and following any significant change to our processing activities, applicable law, or ICO guidance. Material changes will be communicated to participants and client organisations by email and via a notice on the LMS platform. The version history below records all substantive amendments.
| Version | Date | Approved By | Summary of Changes |
|---|---|---|---|
| 1.0 | 29 April 2026 | Data Protection Officer | Initial issue |
17. Contact and Further Information
If you have any questions about this Policy, how we handle your personal data, or wish to exercise your data subject rights, please contact:
Data Protection Officer Contact
For complaints about the handling of your personal data, you may also contact the UK Information Commissioner's Office:
- Website: www.ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF