Last updated August 2026
Controller and processor roles
GLS is the controller for accreditation records, reviewer decisions, published verification data and its own account data. Where a provider uploads learner or staff personal data inside evidence, the provider remains the controller for that content and GLS acts as processor for the purpose of assessment and monitoring.
Principles we apply
- Lawfulness, fairness and transparency — published notices, no hidden processing.
- Purpose limitation — evidence is used for assessment, monitoring and audit only.
- Data minimisation — providers are asked to anonymise learner data before upload.
- Accuracy — providers can correct records; published verification data can be corrected on request.
- Storage limitation — defined retention tied to the accreditation cycle.
- Integrity and confidentiality — role-based access, encryption and audit logging.
- Accountability — documented decisions, reviewer trails and administrative audit logs.
Data subject rights
Individuals may request access, rectification, erasure, restriction, portability, or object to processing, and may withdraw consent where consent is the basis. Requests are acknowledged promptly and answered within one month, extendable by two months for complex cases with notice. Where erasure would undermine the integrity of an issued accreditation, we will explain what must be retained and why.
Automated decision-making
GLS does not make accreditation decisions by automated means alone. AI produces advisory mapping, gap analysis and readiness scores; a qualified human reviewer decides every outcome and their rationale is recorded.
Sub-processors
We use contracted providers for hosting and database services, file storage, transactional email and AI evidence analysis. All are bound by data processing terms with confidentiality, security and sub-processor controls. Providers may request the current sub-processor list through the contact page.
International transfers
Where personal data leaves the UK or EEA we rely on adequacy decisions or the UK International Data Transfer Addendum and EU standard contractual clauses, supported by encryption in transit and at rest and access controls.
Security and breach handling
We operate role-based access enforced at the database layer, least-privilege administrative accounts and audit logging. If a personal data breach occurs and is likely to result in a risk to individuals, we notify the relevant supervisory authority within 72 hours of becoming aware, and notify affected controllers and individuals without undue delay.
Data processing agreements
Providers acting as controllers may request a data processing agreement covering subject matter, duration, purpose, categories of data, security measures, sub-processor terms, assistance with data subject requests and deletion on termination.
Contact and complaints
Contact the GLS data protection contact through the contact page. You also have the right to complain to your supervisory authority, such as the Information Commissioner's Office in the UK. GLS is registered with the UK ICO — registration number 00014816084.
This page sets out the policies of Global Learning Standards (GLS). GLS is an independent accreditation body. GLS is not a certification body and is not ISO. If anything here is unclear, contact us and we will explain it in plain language.

