Learning 1 – Understanding UK Data Protection Law

1. Section 1: Understanding UK data protection law

1.4. 1.4 Applied activity: map the data flow

UK data protection learning

1.4 Applied activity: map the data flow

Use the legal definitions to analyse a realistic organisational process.

Scenario

A training provider collects applications through an online form. The data is saved in a cloud system, reviewed by admissions staff and shared with a placement employer when the applicant reaches the placement stage.

Your task

  1. Identify at least five items of personal data that might be collected.
  2. Identify any information that could be special category or criminal offence data.
  3. Identify the likely controller.
  4. Identify one possible processor.
  5. List each processing action taking place from collection to deletion.
  6. Write two questions the provider should answer before sharing data with the employer.
Open the model discussion

The provider is likely to be a controller because it decides why applicant data is collected and used. The cloud supplier may be a processor if it acts only on the provider's documented instructions.

Possible data includes name, contact details, qualifications, application statement and placement preferences. Health adjustments may be special category data. DBS information may be criminal offence data. Processing includes collection, transmission, storage, access, review, sharing, updating, restriction and deletion.

Before sharing, the provider should identify its lawful basis, confirm necessity and fairness, give suitable privacy information, minimise the data, check security and clarify the employer's role.

Section completion evidence: Keep your completed data-flow map or upload it to the activity chosen by your tutor.

Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.