DATA PROTECTION POLICY AND PRIVACY NOTICE
Date: 1st March 2026
1. Data Controller Information
Lisa Marsh trading as Peak Assessment, is the Data Controller. Contact details: Email: lisaelene12@gmail.com Telephone: 07734391532 Address: Douglas House, The Stones, Castleton, Derbyshire S33 8WX
ICO Registration Number: C1891169
2. Legal Framework
This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It reflects professional guidance issued by the SpLD Assessment Standards Committee (SASC) and the Information Commissioner's Office (ICO).
3. Lawful Basis for Processing
Most personal data is processed under Article 6(1)(b) – performance of a contract.
Special Category Data (e.g., health or neurodevelopmental information) is processed under Article 9(2)(a) – explicit consent.
4. Special Category Data (Consent)
Clients will need to give explicit written consent for Special Category Data to be included in the report at the start of the assessment process. Consent may be withdrawn in writing at any time. Withdrawal does not affect processing already completed but may affect future storage or use.
5. Safeguarding Exception
If information suggests a risk of harm to a child or vulnerable adult, relevant information may be shared with statutory bodies without consent.
6. Digital Scoring Platforms
Recognised test publisher platforms (e.g., Pearson Q‑interactive, GL Assessment Testwise, or other equivalent GDPR‑compliant systems) may be used. Data Processing Agreements are in place where required. Only necessary data is entered. A Data Protection Impact Assessment (DPIA) has been conducted.
7. Use of Artificial Intelligence
No personal or confidential client data is entered into public AI systems. If AI tools are used, they are limited to non‑identifiable wording support. All reports are professionally reviewed by the assessor.
8. Data Retention
Adults: Records retained for 7 years from date of report.
Children/Young People: Retained until age 25 or 7 years after report (whichever is later), in line with professional indemnity insurance requirements. After this period, records are securely destroyed/deleted
9. Data Subject Rights
Clients have the right to access, rectify, erase, restrict processing, object, and lodge a complaint with the ICO. Requests must be made in writing and should be responded to within one month.