Learning 4 - Security, breaches and complaints

1. Section 4: Security, breaches and complaints

1.4. 4.4 Capstone case study and course summary

UK data protection learning

4.4 Capstone case study and course summary

Apply all four sections to one complex organisational scenario.

Case study: Northbridge Training

Northbridge Training introduces an online learner-support platform. It collects identity data, attendance, device identifiers, welfare notes and predicted risk scores. All tutors can see every record. Data is retained indefinitely. The supplier uses subcontractors outside the UK. A learner asks for copies of their data and complains that an inaccurate risk score affected a placement decision. During the investigation, a tutor sends welfare notes to the wrong employer.

Your task

  1. Identify the categories of personal data, including any special category data.
  2. Identify the controller, processor and possible sub-processors.
  3. Apply all seven principles and identify weaknesses.
  4. Identify the lawful-basis and Article 9 questions that must be answered.
  5. Explain why a DPIA is likely to be required.
  6. Plan the response to the learner's access request and rectification concern.
  7. Plan the response to the complaint under the current complaints requirements.
  8. Plan the response to the email breach, including risk assessment and notifications.
  9. Recommend at least eight corrective controls.
Open the model analysis

Data and roles: Identity, attendance and device data are personal data. Welfare notes and health-related information may be special category data. Northbridge is likely a controller; the platform supplier may be a processor, with overseas sub-processors.

Principles: Risks include excessive access, indefinite retention, possible inaccuracy, opaque profiling, weak transparency, insufficient security and poor accountability.

Lawfulness and risk: Northbridge must document an Article 6 basis for each purpose and an Article 9 condition for relevant welfare or health data. Profiling, vulnerable learners, special category data and significant decisions make a DPIA likely.

Rights and complaint: The learner's message may contain access, rectification, objection or automated-decision issues as well as a complaint. Each should be logged, investigated and handled under the relevant process.

Breach: The welfare-note disclosure requires immediate containment, evidence preservation and a documented risk assessment. ICO and individual notification thresholds must be considered promptly.

Controls: Role-based access, minimum fields, retention limits, privacy notices, human review, accuracy challenge routes, processor and sub-processor controls, transfer safeguards, staff training, incident playbooks, audit logs and periodic review.

Course summary

  • Use personal data for clear and justified purposes.
  • Apply all seven principles and select an appropriate lawful basis.
  • Add Article 9 or criminal-offence safeguards where required.
  • Make rights easy to exercise and maintain a reliable response process.
  • Build privacy, security and retention into systems from the start.
  • Escalate breaches immediately and document decisions.
  • Acknowledge complaints within 30 days and respond without undue delay.
Next activity: Complete the separate Moodle mini test. A score of 70% or more is recommended as the pass threshold.

Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.