Policy owner: Data Protection Officer / Designated Data Protection Lead
Jokings International Business College ("the College" or "JIBC") is committed to protecting the privacy, dignity, and personal information of its students, applicants, parents, guardians, employees, volunteers, contractors, visitors, alumni, suppliers, and other members of the College community.
The College will collect, use, store, disclose, transfer, archive, and dispose of personal data fairly, lawfully, transparently, and securely. Personal data will be used only for legitimate educational, administrative, safeguarding, employment, legal, and operational purposes.
The College recognises that children and young people may require additional protection. Their personal data will be handled with particular care, and their best interests will be a primary consideration where appropriate.
This policy establishes the principles, responsibilities, and procedures governing the College's handling of personal data.
Its purposes are to:
The College will process personal data in accordance with applicable data-protection and privacy legislation, regulatory guidance, contractual obligations, and recognised good practice.
This may include, where applicable:
Where different legal requirements apply, the College will follow the requirement applicable to the relevant processing activity and individual.
This policy applies to:
It applies to personal data processed:
All persons who handle personal data for or on behalf of the College must comply with this policy.
Personal data is any information relating to an identified or identifiable individual. It may include:
Sensitive personal data requires additional protection. Depending on applicable law, it may include information about:
Processing includes any operation performed on personal data, including collecting, recording, organising, storing, viewing, changing, sharing, transferring, analysing, archiving, or destroying it.
A data subject is the individual to whom personal data relates.
The data controller determines why and how personal data is processed. JIBC will normally act as the data controller for personal data it collects for its own institutional purposes.
A data processor is a person or organisation that processes personal data on behalf of the College and according to its documented instructions.
A personal data breach is a security incident resulting in the accidental or unlawful loss, destruction, alteration, unauthorised disclosure of, or access to personal data.
The College is accountable for ensuring that personal data is:
Personal data will be processed on a valid legal basis and in a manner individuals can reasonably understand.
The College will identify why information is required and will not use it for an incompatible purpose without an appropriate legal basis and, where necessary, further notice.
The College will collect only the personal data reasonably necessary for the intended purpose.
Reasonable steps will be taken to ensure personal data is accurate. Incorrect or incomplete information will be corrected or updated when identified.
Personal data will not be kept for longer than required for its original purpose or an applicable legal, safeguarding, regulatory, academic, financial, or contractual reason.
Appropriate technical and organisational measures will protect personal data from loss, misuse, unauthorised access, disclosure, alteration, or destruction.
The College will maintain appropriate policies, records, contracts, training, and controls to demonstrate compliance.
The College may collect and process:
The College will not request personal data that is excessive or unrelated to a legitimate purpose.
Personal data may be collected directly from the individual or from:
Where required, individuals will be informed of the source and purpose of the information.
The College may process personal data to:
The College will identify and document an appropriate lawful basis before processing personal data.
Depending on the circumstances, processing may be necessary:
Sensitive or special-category data will be processed only where an additional lawful condition applies.
Consent will not be used where another lawful basis is more appropriate or where the individual cannot freely refuse without disadvantage.
Where processing is based on consent, the College will ensure that consent is:
Where the individual is a child or young person, the College will assess whether the student can provide valid consent or whether consent from a parent or guardian is required.
An individual may withdraw consent at any time by contacting the Data Protection Officer or designated lead. It must be as easy to withdraw consent as it was to give it.
Withdrawal will not affect processing lawfully undertaken before consent was withdrawn. It may also not prevent processing that is required or permitted under another lawful basis.
The College will give particular attention to the privacy rights and interests of students who are children or young people.
The College will:
Information will not automatically be disclosed to a parent, guardian, or sponsor merely because they pay fees. The College will consider the student's age, capacity, consent, safety, and the applicable legal basis before making a disclosure.
The College will provide appropriate privacy notices explaining:
Privacy notices may be provided through application forms, enrolment documents, employment materials, the College website, student portals, or other appropriate channels.
Students, parents, guardians, employees, and other individuals should notify the College promptly if their personal information changes.
The College will provide reasonable methods for individuals to update details such as:
Staff must record information accurately, distinguish facts from opinions, and correct verified errors promptly.
Access to personal data will be granted only to authorised individuals who require it for legitimate duties.
The College will:
Employees must not access personal data out of curiosity or for personal purposes.
The College will implement proportionate technical and organisational safeguards, which may include:
Personal data must not be stored in unauthorised personal email accounts, devices, cloud services, messaging applications, or removable storage.
Paper records containing personal data must:
Before sending personal data electronically, staff must:
Personal data must not be communicated through informal or unauthorised channels.
The College may share personal data with:
Before sharing personal data, the College will consider:
Consent is not required where disclosure is authorised or required by law, necessary to protect a person from serious harm, or supported by another valid lawful basis.
The College may share personal data without consent where necessary to:
Only relevant information will be shared, and the reason for the disclosure will be recorded where appropriate.
Data protection must not be used as a reason to delay necessary safeguarding action.
Third parties that process personal data on behalf of the College must:
The College will conduct proportionate checks before appointing a processor and will use written contracts containing appropriate data-protection terms.
Personal data will not be transferred outside the country in which it was collected unless:
Individuals will be informed of relevant international transfers through appropriate privacy notices.
The College may use photographs, recordings, or student work for educational, administrative, security, or promotional purposes where a valid lawful basis exists.
For promotional use, the College will normally:
Withdrawal of consent will not normally require the College to recall materials already lawfully printed, published, or distributed, but the College will stop future use where reasonably practicable.
The College may operate CCTV, access-control systems, network monitoring, or other security measures for legitimate purposes such as:
Monitoring will be proportionate, appropriately communicated, securely managed, and retained only as long as necessary.
Covert monitoring will be used only in exceptional circumstances where lawful, necessary, and authorised.
The College will maintain a records-retention schedule specifying how long different categories of personal data should be kept.
Retention periods will reflect:
At the end of the applicable retention period, records will be securely deleted, anonymised, or destroyed unless there is a lawful reason to retain them longer.
The College will suspend routine destruction where records are relevant to an active complaint, investigation, safeguarding matter, audit, or legal proceeding.
Subject to applicable law and any valid limitations, individuals may have the right to:
These rights are not absolute. The College may refuse or limit a request where permitted or required by law and will explain the reason where appropriate.
A request concerning personal data should be submitted to the Data Protection Officer or designated lead.
The College may request sufficient information to:
The College will respond within the period required by applicable law. Requests will normally be handled without charge, although a lawful fee may be applied where a request is manifestly unfounded, excessive, or repetitive.
Information relating to another person may be withheld or redacted where necessary to protect that person's rights or comply with confidentiality obligations.
The College will not make a decision producing a significant legal or similar effect solely through automated processing unless:
The College will explain the general basis and likely consequences of qualifying automated decisions.
All suspected or confirmed personal data breaches must be reported immediately to the Data Protection Officer or designated lead.
Examples include:
The College will:
Staff must not conceal, delete evidence of, or attempt to investigate a breach without authorisation.
Management is responsible for:
The Data Protection Officer or designated lead is responsible for:
Managers must ensure that:
All individuals handling personal data must:
The College will conduct a data-protection impact assessment before beginning processing that is likely to create a high risk to individuals.
This may include:
The assessment will identify the purpose, necessity, risks, safeguards, and approval requirements associated with the proposed activity.
The College will provide appropriate data-protection and information-security training to staff, volunteers, and relevant contractors.
Training will cover:
Training will be provided during induction and refreshed periodically.
Failure to comply with this policy may result in:
Any action taken will be proportionate and handled under the relevant College procedure.
An individual who is concerned about how the College has handled personal data should first contact the Data Protection Officer or designated lead.
If the matter is not resolved, the individual may use the College's Complaints Policy and may also have the right to complain to the relevant data-protection authority.
No person will be penalised for raising a genuine data-protection concern in good faith.
This policy will be reviewed regularly and whenever there is:
Updated versions will be communicated through appropriate College channels.
Questions, concerns, rights requests, and data-breach reports should be directed to:
Officer: Data Protection Officer / Designated Data Protection Lead
Institution: Jokings International Business College
Address: No. 5 Kazuare Street, Area 2, Section 1, Garki, Abuja, Nigeria
Email: admin@jibcnigeria.co.uk
Telephone: +234 707 509 8790
Office hours: Monday to Friday, 10:00 a.m. – 4:00 p.m., excluding public holidays
Approved by: Kingsley Ibeji
Position: President
Signature: Kingsley
Date: 10 September 2026