Home

Data processing information

Last updated: 9 August 2026

This page describes Journey's intended data-processing approach for controlled pilot evaluation. It is not itself a data processing agreement (DPA). Before a provider workspace is activated, the contracting entity, controller/processor roles, processing scope, retention and applicable DPA are confirmed in writing.

Roles and instructions

The provider and Journey's contracting entity will identify the controller and processor roles in the written pilot or commercial agreement. The intended model for provider-held apprenticeship data is that the provider acts as controller and Journey processes data only on documented instructions.

Scope and security

The approved agreement defines the exact categories of data, processing instructions, purpose, duration and applicable technical and organisational measures. Journey documents relevant controls during provider due diligence, including encryption in transit and at rest, server-derived tenant context, role-based access control and audit logging. Do not provide learner or special-category data through the public enquiry form.

Sub-processors and transfers

Current disclosed sub-processors are listed on the sub-processors page. The signed agreement identifies the processors, processing locations, international-transfer safeguards and notice process relevant to the approved provider arrangement.

Data subject requests, incidents and exit

The applicable agreement sets out support for data-subject requests, security incidents, data-protection impact assessments, data export, return, deletion and retention. Any lawful funding-rule retention requirement is considered in that agreement.

Contact

To request pilot data-processing information, use the Journey contact page.