UWC
UWC International, Integrated Application Manager

Privacy & Data Use Notice

This system holds sensitive personal information about young people applying to UWC schools, and about their families. Everyone who uses it shares responsibility for protecting that information. This notice explains what the data is for and the rules for handling it.

In one line: use this data only to review and process applications, share it only with people who genuinely need it, and never disclose it to anyone outside that purpose.

1. Purpose & lawful basis

The UWC International, Integrated Application Manager exists for a single purpose: to help National Committees and UWC schools review, discuss, and decide on student applications and nominations. The data in it may be used only for that admissions purpose. It must not be used for marketing, research, profiling, or any unrelated activity.

The system processes the private data of applicants (mostly minors) and their families under the lawful basis of legitimate interest (GDPR Art. 6(1)(f)) — operating a fair and secure UWC school admissions and National Committee nominations process — supported by a documented Legitimate Interests Assessment. Consent is relied on where appropriate, including explicit consent for special-category data and verifiable parental/guardian consent for minors.

Data Protection Impact Assessment. Because this involves children's special-category data across the many countries of the UWC movement, a computed, per-country impact assessment is maintained separately, together with the International Office controller conditions (London & Berlin). See the Data Protection Impact Assessment →

2. What personal data it contains

The system contains information supplied through the application process, which may include applicants' names, contact details, dates of birth, academic records, references, essays, financial or family circumstances, identity documents, photographs, and similar material — including information about applicants' parents, guardians and family members. Much of this concerns minors and is treated as sensitive.

3. Who can see what — access on a need-to-know basis

Access is strictly scoped by role, and enforced by the system, not left to discretion:

You must not attempt to access, copy, or share data outside your own scope, and you must only share an applicant's information with colleagues who genuinely need it to do their admissions work.

4. Confidentiality & non-disclosure

Applicant and family information is confidential. It must not be disclosed to anyone who does not need to know — this includes other applicants, other schools or committees, unrelated staff, external parties, or the public. Do not forward, post, print, or store this data outside the approved system without authorisation, and do not discuss identifiable applicants in public or insecure settings.

5. Safeguarding & security

The system enforces individual logins, role-based scoping, and an access audit trail; documents are downloaded only by authorised, scoped users. You are responsible for keeping your credentials secret, signing out on shared devices, and reporting any suspected loss or misuse of data immediately. Downloaded documents remain confidential and must be stored and disposed of securely.

6. Retention

Personal data is kept only for as long as it is needed for the admissions cycle and any legitimate follow-up, and is then deleted or anonymised in line with the organisation's data-retention policy and applicable law.

7. Consent & data-processing agreements

Consent is captured at the point of application, including explicit consent for special-category data and verifiable parental/guardian consent for minors. Data flows between the International Office, National Committees, and schools are governed by Article 28 data-processing agreements (DPAs) and, between the International Office establishments, Article 26 joint-controller arrangements. The system supports these by enforcing scope, recording processing activity in an audit trail, and confining the data to the admissions purpose.

8. Rights of individuals — including the right to be forgotten

Applicants and their families have the full set of GDPR rights over their personal data — to be informed, and to request access, rectification, restriction, portability, objection, and erasure. The system is built to support them: an applicant's record can be exported on request, and their personal data erased — the "right to be forgotten".

Erasure is honoured subject to the mandatory archival and legal-retention requirements that GDPR Art. 17(3) expressly preserves (compliance with a legal obligation; the establishment or defence of legal claims; and archiving in the public interest). Where those apply, identifying data is removed while the minimal record required for integrity and audit is retained. Requests should be directed to the relevant National Committee, school, or the UWC International Office (London or Berlin) as data controller.

9. AI assistance

Where an AI assistant is enabled, it operates within the same access scope as the signed-in user and is read-only. Depending on how the deployment is configured, applicant data may or may not be sent to an external model provider; operators should prefer a self-hosted model when applicant data is involved, so that data remains within the organisation's control.

10. UWC AI policy compliance & the Constellation framework

This application and its use of data have been checked for compliance with the UWC AI policy. That review examined each use of personal data in the application within a complete Data Protection Impact Assessment (DPIA), covering applicants, their families, and the special-category and children's data the system handles.

The person responsible for this at UWC is the Head of External Relations, who can be contacted as needed at external_relations@uwcio.org.

The data usage in this application is consistent with the United Kingdom's data protection regime (ICO directives) and with all the other local data-usage directives of the different jurisdictions of the UWC schools and National Committees. The per-jurisdiction assessment is maintained on the Data Protection Impact Assessment page.

The data is fully secured in flight and in storage: transport is encrypted with modern TLS including a post-quantum-safe key exchange, and data at rest is protected with strong, quantum-resistant encryption. These measures are applied so that minors' personal data stays protected against both present and anticipated future threats.

Part of the UWC Constellation. This application is a member (“star”) of the UWC Constellation — the UWC framework for auditing and managing AI-enabled applications that handle UWC data. It carries a permanent Constellation ID (CONSTIO271828) and maintains a Constellation log of data movement for independent oversight of how personal data flows through the system.
Please note: this notice is a plain-language summary provided with the software. It is not legal advice and does not replace UWC's official privacy policy. It should be reviewed and adapted by UWC's data-protection officer / legal counsel to reflect the applicable laws (e.g. GDPR) and the organisation's own policies before production use.
← Back to sign in  ·  Data Protection Impact Assessment  ·  Admissions Calendar  ·  Contact & About A UWC Constellation Application · v 0.3 · Constellation ID CONSTIO271828