Data processing information
Last updated: 9 August 2026
This page describes Journey's intended data-processing approach for controlled pilot evaluation. It is not itself a data processing agreement (DPA). Before a provider workspace is activated, the contracting entity, controller/processor roles, processing scope, retention and applicable DPA are confirmed in writing.
Roles and instructions
The provider and Journey's contracting entity will identify the controller and processor roles in the written pilot or commercial agreement. The intended model for provider-held apprenticeship data is that the provider acts as controller and Journey processes data only on documented instructions.
Scope and security
The approved agreement defines the exact categories of data, processing instructions, purpose, duration and applicable technical and organisational measures. Journey documents relevant controls during provider due diligence, including encryption in transit and at rest, server-derived tenant context, role-based access control and audit logging. Do not provide learner or special-category data through the public enquiry form.
Sub-processors and transfers
Current disclosed sub-processors are listed on the sub-processors page. The signed agreement identifies the processors, processing locations, international-transfer safeguards and notice process relevant to the approved provider arrangement.
Data subject requests, incidents and exit
The applicable agreement sets out support for data-subject requests, security incidents, data-protection impact assessments, data export, return, deletion and retention. Any lawful funding-rule retention requirement is considered in that agreement.
Contact
To request pilot data-processing information, use the Journey contact page.