Data Protection Policy
How we handle personal information across Olive for Education
Effective from: 10 August 2026
Version: 1.0
Owner: Chief Executive Officer
Review: Annually, or sooner if the law, our systems or our services change.
Applies to: All directors, employees, contractors, agency staff, interns and third parties acting for Upskill Online Limited trading as Olive for Education.
1. Purpose
We handle personal information about parents, guardians, school staff, students, our own people and our suppliers. A large part of that relates to children, which means it deserves a higher standard of care than most business data.
This policy sets out how we meet our obligations under the General Data Protection Regulation and the Data Protection Acts 1988 to 2018. It tells everyone working for us what is expected of them and what to do when something goes wrong.
This is a mandatory policy. Failure to follow it may be treated as a disciplinary matter, and in serious cases may amount to gross misconduct.
2. Scope
This policy applies to all personal information we handle, in any format, whether held on our systems, on paper, on a device in for repair, or on a system operated by a supplier on our behalf. It applies wherever the work is carried out, including at our Dublin office, at the National Service and Support Centre at Carrick Business Campus, in schools, at home and by colleagues and suppliers based outside Ireland.
3. Our two roles
We act in two different roles and it is important that everyone understands which one applies.
| Role | When it applies | What it means in practice |
|---|---|---|
| Controller | Information about parents and guardians who buy from us, school staff we deal with, our own staff and applicants, and our suppliers. | We decide why and how the information is used. We are directly answerable for it and we must give people a privacy notice. |
| Processor | Student information supplied to us by a school so that we can provision, deploy, service and support devices under its programme. | We may only act on the school’s documented instructions. We may not use the information for our own purposes and we must have a written data processing agreement in place before we receive anything. |
If you are ever unsure which role applies to a piece of work, stop and ask before you process the information.
4. The principles we work to
Every use of personal information must satisfy all of the following:
- Lawfulness, fairness and transparency. We have a lawful basis, we act fairly and we tell people what we are doing.
- Purpose limitation. We use information only for the purpose it was collected for, or for something compatible with it.
- Data minimisation. We collect the least we need. If a field is not needed to fulfil an order or support a device, we do not ask for it.
- Accuracy. We keep information correct and up to date and correct errors promptly.
- Storage limitation. We keep information only for as long as we need it and then delete it.
- Integrity and confidentiality. We protect information with appropriate security.
- Accountability. We document our decisions and can demonstrate compliance.
5. Responsibilities
| Who | What they are responsible for |
|---|---|
| Board and CEO | Overall accountability for compliance, approving this policy, and making sure the resources are there to meet it. |
| Data Protection Lead | Day-to-day ownership of this policy. Maintains the record of processing, handles individual rights requests, coordinates breach response, runs impact assessments, and is the point of contact for the Data Protection Commission and for schools. |
| Group CTO and IT | Technical security controls, access management, logging, backup, secure device provisioning and secure disposal. |
| Heads of function | Making sure their teams follow this policy, that new systems and suppliers are assessed before use, and that retention is applied in their area. |
| Everyone | Completing training, handling information properly, reporting suspected breaches immediately, and not using personal information for anything other than a legitimate work purpose. |
We will keep the need for a formally designated Data Protection Officer under review. Because we handle children’s information on a regular basis and at scale, we will document that assessment and revisit it at least annually.
6. Record of processing
We maintain a record of processing activities under Article 30. It records, for each activity, the purpose, the categories of individuals and information, the lawful basis, who we share it with, any transfer outside the EEA and the safeguard relied on, the retention period and the security measures in place.
The record must be updated before any new processing activity begins, including any new system, new supplier, new form on the website or new use of information we already hold. The Data Protection Lead owns the record. Heads of function must notify changes in their area.
7. Student and children’s information
This is the highest-risk information we handle and the following rules are not optional:
- Collect the minimum. Name, class or year group, school and the device assigned. Nothing further unless the school has instructed it in writing.
- Never use student information for marketing, analytics, product development, testing, demonstrations or training data.
- Never copy student information to a personal device, personal email account, personal cloud storage or an unapproved application.
- Restrict access to the staff who need it for a specific task, and remove that access when the task is complete.
- Do not access the contents of a student’s device unless the school or the user has asked us to for a support or repair case, and record why access was needed.
- Return or securely delete student information at the end of a programme, in line with the school’s instruction.
- Where a school asks us to install classroom management or safeguarding software, configure it exactly as the school has instructed and record that instruction. The school decides how that software is used, not us.
8. Working with schools
No student information may be received from a school until a written data processing agreement is signed. The agreement must cover the subject matter and duration, the nature and purpose of the processing, the categories of information and individuals, our obligation to act only on documented instructions, confidentiality of staff, security measures, use of sub-processors, assistance with individual rights and breaches, audit rights, and return or deletion at the end.
Where the school asks us to use a sub-processor, or where we intend to add or change one, the school must be informed in advance and given the opportunity to object.
Any request from a school for assistance with an access request, a correction or a deletion must be passed to the Data Protection Lead on the day it is received.
9. Suppliers and processors
Before any supplier handles personal information for us, the following must be completed and recorded:
- Due diligence on their security and data protection arrangements, proportionate to the risk.
- A written contract containing Article 28 processor terms.
- Written confirmation that personal information will be stored and backed up within the EEA, and confirmation of where support and administration will be carried out from.
- Where the supplier would support the service from outside the EEA, the safeguards in section 10 must be in place before go-live.
- An entry in the record of processing and on the supplier register.
No one may sign up to a new cloud service, plugin, integration or artificial intelligence tool that will handle personal information without approval from the Data Protection Lead and IT. This includes free trials.
10. Data residency and remote access from outside the EEA
Our position is that personal information stays in the European Economic Area. All personal information must be stored, hosted and backed up within the EEA. Where a platform offers a choice of region, it must be configured for an EEA region before it is used, and that configuration must be recorded. No personal information may be exported, copied or migrated to storage outside the EEA.
Some of our technical and support functions are delivered by colleagues based outside the EEA, who need remote access to administer and support our systems. Everyone needs to understand one point clearly. Remote access from a third country is a restricted transfer under Chapter V, even where the information never leaves the EEA. Using a VPN, a remote desktop session or a jump host does not change that. What matters is that a person in a third country can see the information, not the route the connection takes.
Remote access from outside the EEA is permitted only where all of the following are in place and recorded:
- Standard contractual clauses executed with the relevant entity or individual, held on file by the Data Protection Lead.
- A completed transfer impact assessment covering the destination country, reviewed at least annually.
- Named individual accounts with multi-factor authentication. No shared or generic administrator accounts.
- Access limited to the systems and the level of privilege actually needed, granted for a defined purpose and removed when no longer required.
- Logging of session activity on any system holding personal information, retained and reviewed.
- A strict prohibition on downloading, copying, screenshotting or storing personal information on any device located outside the EEA.
Access to student information from outside the EEA requires the additional step of informing the school, and is only permitted where the data processing agreement with that school allows it. If the agreement is silent, assume it is not permitted and escalate to the Data Protection Lead.
Any new supplier, integration or support arrangement that would involve access from outside the EEA must be approved by the Data Protection Lead before it goes live.
11. Security
The following controls apply across the business:
- Multi-factor authentication on all business accounts, with no shared logins.
- Role-based access, reviewed at least every six months and whenever someone changes role.
- Immediate revocation of all access on the last day of employment or engagement, covering email, cloud platforms, service principals, application registrations, API keys and remote access, with the revocation logged.
- Full-disk encryption on all laptops and mobile devices, with remote wipe enabled.
- Regular patching of operating systems, firmware and applications.
- Logging and monitoring of administrative activity and of access to systems holding personal information.
- Backups that are tested, and a documented restore process.
- Clear desk and clear screen at both offices, with paper records holding personal information locked away.
- Personal information sent externally must be sent securely, and email addresses of unrelated recipients must never be exposed to each other.
12. Devices in our care
We hold physical devices at the National Service and Support Centre for provisioning, repair and refurbishment. Those devices may contain personal information belonging to a student, a parent or a school.
- Devices awaiting or undergoing service must be held in a secured area with controlled access.
- Access the contents of a device only to the extent needed to diagnose or fix the reported fault, and record what was accessed and why.
- Never copy data from a customer device except where it is needed to transfer to a replacement device at the owner’s request, and delete the copy once the transfer is confirmed.
- Wipe every device to a recognised standard before reuse, resale or disposal, and keep a certificate or log entry for each one.
- Use an approved disposal partner for end-of-life equipment and retain the disposal certificate.
13. Retention and deletion
We keep personal information only as long as we need it. Retention periods are set out in the privacy policy and in the retention schedule maintained by the Data Protection Lead. Heads of function are responsible for applying them in their area.
Where information is subject to a legal hold, for example because it is relevant to a claim, an investigation or a regulatory inspection, it must not be deleted. The Data Protection Lead will notify affected teams when a hold applies and when it is lifted.
14. Individual rights requests
A request can arrive in any form and does not need to mention data protection or the GDPR. Anyone who receives one must forward it to dataprotection@olivegroup.io on the day it is received. Do not attempt to deal with it yourself.
We must respond within one month. That can be extended by up to two further months for complex requests, but only if we tell the individual within the first month. The Data Protection Lead will verify identity, locate the information, apply any exemptions and issue the response.
Where the request relates to student information we hold for a school, it must be passed to the school without delay and we assist the school in responding.
15. Personal data breaches
A personal data breach is any incident that leads to personal information being lost, destroyed, altered, disclosed or accessed without authorisation. It includes a lost or stolen device, an email sent to the wrong person, a misconfigured permission, a ransomware infection and unauthorised access to an account by a current or former member of staff.
Report every suspected breach immediately to dataprotection@olivegroup.io and to your manager. Report it even if you are not certain, even if you think it is minor, and even if you caused it. Nobody will be penalised for reporting an incident promptly and honestly. Delay is what causes harm.
On receipt of a report the Data Protection Lead will:
- Contain the incident and preserve the evidence and logs.
- Assess the risk to the individuals affected.
- Notify the Data Protection Commission within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals.
- Notify the individuals affected without undue delay where the risk to them is high.
- Notify any school that is the controller of the information affected, without undue delay, so that it can meet its own obligations.
- Record the incident in the breach register, including the facts, the effects and the action taken, whether or not it was notifiable.
Where a breach may involve criminal conduct, the matter will also be reported to An Garda Síochána and handled with our legal advisers.
16. Data protection by design and impact assessments
Data protection must be considered at the start of any new project, not once it is built. A data protection impact assessment must be completed before we proceed where the processing is likely to result in a high risk, and in particular where it involves:
- Children’s information on a significant scale.
- New technology, including any use of artificial intelligence on personal information.
- Systematic monitoring, tracking or profiling.
- A new supplier or platform holding significant volumes of personal information.
- A transfer of personal information to a new country outside the EEA.
The Data Protection Lead owns the assessment process. Where an assessment shows a high residual risk that we cannot mitigate, we must consult the Data Protection Commission before proceeding.
17. Marketing and CRM
Marketing to parents and guardians requires consent, or must fall within the existing customer exemption for similar products and services. Every marketing message must carry an unsubscribe option and unsubscribes must be actioned immediately.
Consent and opt-out status must be recorded in HubSpot and must be respected across every list and campaign. Marketing lists must never be built from student information, from a school’s contact list supplied for another purpose, or from information scraped or bought without a lawful basis.
18. Training
Everyone must complete data protection training on induction and at least annually after that. Staff in roles with greater exposure, including sales, helpdesk, service centre and IT, must complete additional role-specific training. Completion is recorded and reported to the Board.
19. Monitoring and review
The Data Protection Lead will report to the Board at least annually on compliance with this policy, covering the record of processing, rights requests, breaches, training completion, supplier assessments and any outstanding risks.
This policy will be reviewed at least once a year and following any significant incident, regulatory development or change to our services.
20. Related documents
- Privacy Policy, published on the Olive for Education website.
- Cookie Notice, published on the Olive for Education website.
- Website Terms and Conditions of Sale.
- Record of Processing Activities.
- Retention Schedule.
- Data Breach Register and Breach Response Procedure.
- Template Data Processing Agreement for schools.
- Acceptable Use and IT Security Policy.
Approved by the Board of Upskill Online Limited.
Signed: ______________________________
Date: 10 August 2026
Simon Cosgrove
Chief Executive Officer
