This system processes the personal data of applicants (mostly minors) and their families — names, dates of birth, contact details, academic records, references, essays, financial and family circumstances, identity documents and photographs — for the legitimate interest of operating UWC school admissions and National Committee nominations. Because it involves special-category data about children, on a large scale, across many jurisdictions, a Data Protection Impact Assessment (GDPR Art. 35) is indicated. This page is the computed, living assessment.
The sole purpose is to help National Committees and UWC schools review, discuss and decide on student applications and nominations. The lawful bases relied on are:
The International Office acts as controller from two establishments, each under its own regime and supervisory authority:
Regime: UK GDPR + Data Protection Act 2018
Supervisory authority: Information Commissioner's Office (ICO) — data-protection fee payable; ICO Age-Appropriate Design (Children's) Code applies to services likely accessed by children.
Regime: EU GDPR + Federal Data Protection Act (BDSG) + Berlin State Act (BlnDSG)
Supervisory authority: Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit, BlnBDI).
Each nominated applicant's data flows to the host country of the school. The band is a cross-border transfer & compliance risk relative to the UK and EU controllers; the inherent processing risk (minors' special-category data) is High system-wide and is mitigated by the technical measures in §6.
| School | Country | Applicable law | Transfer basis required | Transfer risk |
|---|---|---|---|---|
| Li Po Chun UWC | Hong Kong SAR (HK) | PDPO (Cap. 486) | SCCs / IDTA + transfer risk assessment; supplementary measures as needed | Medium |
| Pearson College UWC | Canada (CA) | PIPEDA (EU/UK adequacy — commercial) | Adequacy / EEA — no additional transfer tool required | Low |
| UWC Adriatic | Italy (IT) | EU GDPR + Italian Codice Privacy | Adequacy / EEA — no additional transfer tool required | Low |
| UWC Atlantic | United Kingdom (GB) | UK GDPR + Data Protection Act 2018 | Adequacy / EEA — no additional transfer tool required | Low |
| UWC Changshu China | China (CN) | PIPL 2021 (data-export controls) | Local data-export control regime + SCCs/IDTA + supplementary measures | High |
| UWC Costa Rica | Costa Rica (CR) | Law No. 8968 on Protection of the Person | SCCs / IDTA + transfer risk assessment; supplementary measures as needed | Medium |
| UWC Dilijan | Armenia (AM) | Law on Protection of Personal Data + Conv. 108 | SCCs / IDTA + transfer risk assessment (Convention 108 signatory) | Medium |
| UWC East Africa | Tanzania (TZ) | Personal Data Protection Act 2022 | SCCs / IDTA + transfer risk assessment; supplementary measures as needed | High |
| UWC ISAK Japan | Japan (JP) | APPI (EU/UK mutual adequacy) | Adequacy / EEA — no additional transfer tool required | Low |
| UWC Maastricht | Netherlands (NL) | EU GDPR + Dutch UAVG | Adequacy / EEA — no additional transfer tool required | Low |
| UWC Mahindra College | India (IN) | Digital Personal Data Protection Act 2023 | SCCs / IDTA + transfer risk assessment; supplementary measures as needed | High |
| UWC Mostar | Bosnia and Herzegovina (BA) | Law on Protection of Personal Data + Conv. 108 | SCCs / IDTA + transfer risk assessment (Convention 108 signatory) | Medium |
| UWC Red Cross Nordic | Norway (NO) | EU GDPR (EEA) + Norwegian PDA | Adequacy / EEA — no additional transfer tool required | Low |
| UWC Robert Bosch College | Germany (DE) | EU GDPR + BDSG + state law | Adequacy / EEA — no additional transfer tool required | Low |
| UWC South East Asia | Singapore (SG) | PDPA 2012 | SCCs / IDTA + transfer risk assessment; supplementary measures as needed | Medium |
| UWC Thailand | Thailand (TH) | PDPA 2019 | SCCs / IDTA + transfer risk assessment; supplementary measures as needed | Medium |
| UWC USA | United States (US) | EU-US/UK Data Privacy Framework + state laws | SCCs / IDTA + transfer risk assessment; supplementary measures as needed | Medium |
| Waterford Kamhlaba UWC | Eswatini (SZ) | Data Protection Act 2022 | SCCs / IDTA + transfer risk assessment; supplementary measures as needed | High |
Applications originate from National Committees in 150+ countries. Rather than enumerate each, they are grouped by the data-protection regime that governs the transfer to the controllers:
| Group | Regime | Transfer to controllers | Risk |
|---|---|---|---|
| EU / EEA National Committees e.g. Germany, France, Italy, Spain, Netherlands, Poland, Sweden, Ireland |
EU GDPR + national implementing law | Free flow to the Berlin (EU) controller; UK adequacy decision covers the London controller. | Low |
| United Kingdom National Committee UWC Great Britain |
UK GDPR + Data Protection Act 2018 | EU adequacy decision for the UK covers flow to the Berlin controller (subject to periodic review). | Low |
| Adequacy-covered third countries e.g. Switzerland, Norway/Iceland/Liechtenstein (EEA), Japan, Canada, New Zealand, South Korea, Israel, Argentina, Uruguay |
Local law recognised as adequate by the EU and/or UK | Adequacy decision — no additional transfer tool required, verify scope. | Low |
| Convention 108/108+ third countries e.g. Armenia, Bosnia and Herzegovina, Georgia, Morocco, Tunisia, Mexico |
Council of Europe data-protection convention; no adequacy decision | Standard Contractual Clauses / IDTA + a transfer risk assessment. | Medium |
| Other third countries (no adequacy) e.g. India, China, most of Sub-Saharan Africa, much of the Middle East and Latin America |
Emerging or sectoral local law, or none in force | SCCs / IDTA + transfer risk assessment; supplementary measures where the assessment shows a gap. Data-export-controlled regimes (e.g. China PIPL) need separate local compliance. | High |
Consent is captured at the point of application (through the SurveyMonkey Apply intake), including explicit consent for special-category data and verifiable parental/guardian consent for minors. The movement operates on Article 28 data-processing agreements (DPAs) between the controllers and each school / National Committee that processes the data, and Article 26 joint-controller arrangements between the International Office establishments. The system supports these by enforcing scope, recording processing activity, and confining data to the admissions purpose; the agreements themselves are executed by the organisation.
The system is built to support the full set of data-subject rights — to be informed, of access, rectification, erasure, restriction, portability, and objection. In particular:
See the technical detail in docs/SECURITY-HARDENING.md.