Privacy and Data Protection Policy
The International Institute of Leadership and Management respects the privacy of members, applicants, delegates, programme participants, institutional contacts, website visitors and others, and handles information responsibly and in accordance with applicable data protection law.
Information We May Hold
- Name, contact and account information.
- Membership and Fellowship application information.
- Professional and educational information.
- Supporting information provided with an application.
- Grade and membership status.
- Programme and event registrations.
- Attendance, completion and professional development records.
- Payment and transaction information.
- Communications with the Institute.
- Credential and certificate information.
- Other information reasonably required to provide our services.
Identity Verification
Where identity verification is required, the Institute uses an appropriate specialist third party provider wherever reasonably practicable.
Our preferred approach is not to collect or retain copies of passports, driving licences, national identity documents or similar documents directly where third party verification can reasonably be used instead.
Where verification takes place, the Institute may retain minimum verification result information such as the verification status, the date, the provider and a reference.
How Information Is Used
- Account administration.
- Applications and eligibility assessment.
- Identity verification.
- Membership administration and renewals.
- Delegate and programme administration.
- Payments.
- Attendance and professional development records.
- Certificates, badges and credentials.
- Programme delivery.
- Communications with members, applicants and contacts.
- Handling enquiries and complaints.
- Maintaining appropriate records.
- Fraud prevention and security.
- Legal, regulatory and safeguarding responsibilities.
- Improving our services.
Lawful Basis
The Institute processes personal information only where an appropriate lawful basis applies. This may include performance of a contract or delivery of a service, compliance with a legal obligation, legitimate interests, consent where appropriate, or other lawful grounds.
Payments
Payments may be handled by specialist third party payment providers. The Institute does not need to receive or store full card details where those details are processed securely by the provider.
Automation and Artificial Intelligence
Automated tools may support completeness checking, organisation of information, identification of missing information and preliminary assessment against criteria approved by the Institute.
Automated systems cannot invent criteria. Human oversight is maintained for significant professional judgement, and final admission to Fellow requires human approval.
Children and Young People
The Institute recognises that some Student Members are under 18. Additional care is taken with their information, including age appropriate privacy, safeguarding and communication practices.
Only information that is reasonably necessary is collected, and parent or guardian involvement and consent is used where appropriate or legally required. Privacy information provided to children is written in an age appropriate way.
Sharing Information
The Institute does not sell personal information.
Appropriate service providers may support hosting and technology, payments, identity verification, email and communications, learning and programme delivery, credential services and administration.
Information may also be shared where required by law or safeguarding responsibilities, or where reasonably necessary to protect people or the Institute. Where an organisation sponsors a delegate, appropriate registration, attendance and completion information may be shared with that organisation where necessary and lawful.
International Processing
The Institute works internationally, and information may be processed in more than one country. Where information is transferred internationally, appropriate safeguards are applied.
Retention and Security
Information is retained for a proportionate period, taking account of membership records, professional status, legal obligations and legitimate business needs.
Appropriate security measures and access controls are applied to protect personal information.
Your Rights
Depending on applicable law, individuals may have rights to access their information, request correction or erasure, restrict or object to processing, request portability and withdraw consent where processing is based on consent.
Where United Kingdom data protection law applies, individuals also have the right to complain to the Information Commissioner's Office.
The Institute may carry out reasonable identity checks before responding to a data request.
Data Protection Lead and Contact
C. Titilola Aboyade-Cole is President of the Institute and Data Protection Lead.
Privacy enquiries may be sent through the Institute contact details published on the Contact page.
Updates
This policy is reviewed periodically and may be updated to reflect changes in our services, technology or legal obligations.
Questions About This Document
Enquiries relating to this document, including privacy and data protection enquiries, may be sent through the Institute contact details.
Contact the Institute