UWC
UWC International, Integrated Application Manager

Data Protection Impact Assessment

This system processes the personal data of applicants (mostly minors) and their families — names, dates of birth, contact details, academic records, references, essays, financial and family circumstances, identity documents and photographs — for the legitimate interest of operating UWC school admissions and National Committee nominations. Because it involves special-category data about children, on a large scale, across many jurisdictions, a Data Protection Impact Assessment (GDPR Art. 35) is indicated. This page is the computed, living assessment.

Status — template assessment. The jurisdiction risk bands below are computed heuristics to focus review, not legal advice or a completed DPIA. This document must be reviewed, completed and adopted by UWC's Data Protection Officer and legal counsel before production use, and kept under review as adequacy decisions and local laws change.

1. Purpose & lawful basis

The sole purpose is to help National Committees and UWC schools review, discuss and decide on student applications and nominations. The lawful bases relied on are:

2. Controllers & conditions — UWC International Office

The International Office acts as controller from two establishments, each under its own regime and supervisory authority:

Controller (UK establishment)

UWC International — London

Regime: UK GDPR + Data Protection Act 2018

Supervisory authority: Information Commissioner's Office (ICO) — data-protection fee payable; ICO Age-Appropriate Design (Children's) Code applies to services likely accessed by children.

  • Lawful basis: legitimate interests (Art. 6(1)(f)) for admissions and nominations, supported by a documented Legitimate Interests Assessment (LIA).
  • Special-category data (Art. 9): processed on explicit consent (Art. 9(2)(a)) and/or substantial public interest, with an Appropriate Policy Document.
  • International transfers: UK adequacy regulations, or the IDTA / UK Addendum to the EU SCCs plus a Transfer Risk Assessment for restricted transfers.
  • Records of processing (Art. 30), DPIA (Art. 35), and a designated contact / DPO.
Controller (EU establishment)

UWC International — Berlin

Regime: EU GDPR + Federal Data Protection Act (BDSG) + Berlin State Act (BlnDSG)

Supervisory authority: Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit, BlnBDI).

  • Lawful basis: legitimate interests (Art. 6(1)(f)) for admissions and nominations, with an LIA; balancing test documented.
  • Children's consent age is 16 in Germany (§ not lowered under BDSG); verifiable parental/guardian consent for applicants below that age.
  • Special-category data (Art. 9): explicit consent (Art. 9(2)(a)); § 22 BDSG safeguards.
  • International transfers: Chapter V GDPR — adequacy or EU SCCs + Transfer Impact Assessment; Art. 26 joint-controller and Art. 28 processor agreements in place.

3. Jurisdiction impact — the 18 UWC schools (data destinations)

Each nominated applicant's data flows to the host country of the school. The band is a cross-border transfer & compliance risk relative to the UK and EU controllers; the inherent processing risk (minors' special-category data) is High system-wide and is mitigated by the technical measures in §6.

18 school jurisdictions Low 7 Medium 7 High 4
SchoolCountryApplicable lawTransfer basis requiredTransfer risk
Li Po Chun UWC Hong Kong SAR (HK) PDPO (Cap. 486) SCCs / IDTA + transfer risk assessment; supplementary measures as needed Medium
Pearson College UWC Canada (CA) PIPEDA (EU/UK adequacy — commercial) Adequacy / EEA — no additional transfer tool required Low
UWC Adriatic Italy (IT) EU GDPR + Italian Codice Privacy Adequacy / EEA — no additional transfer tool required Low
UWC Atlantic United Kingdom (GB) UK GDPR + Data Protection Act 2018 Adequacy / EEA — no additional transfer tool required Low
UWC Changshu China China (CN) PIPL 2021 (data-export controls) Local data-export control regime + SCCs/IDTA + supplementary measures High
UWC Costa Rica Costa Rica (CR) Law No. 8968 on Protection of the Person SCCs / IDTA + transfer risk assessment; supplementary measures as needed Medium
UWC Dilijan Armenia (AM) Law on Protection of Personal Data + Conv. 108 SCCs / IDTA + transfer risk assessment (Convention 108 signatory) Medium
UWC East Africa Tanzania (TZ) Personal Data Protection Act 2022 SCCs / IDTA + transfer risk assessment; supplementary measures as needed High
UWC ISAK Japan Japan (JP) APPI (EU/UK mutual adequacy) Adequacy / EEA — no additional transfer tool required Low
UWC Maastricht Netherlands (NL) EU GDPR + Dutch UAVG Adequacy / EEA — no additional transfer tool required Low
UWC Mahindra College India (IN) Digital Personal Data Protection Act 2023 SCCs / IDTA + transfer risk assessment; supplementary measures as needed High
UWC Mostar Bosnia and Herzegovina (BA) Law on Protection of Personal Data + Conv. 108 SCCs / IDTA + transfer risk assessment (Convention 108 signatory) Medium
UWC Red Cross Nordic Norway (NO) EU GDPR (EEA) + Norwegian PDA Adequacy / EEA — no additional transfer tool required Low
UWC Robert Bosch College Germany (DE) EU GDPR + BDSG + state law Adequacy / EEA — no additional transfer tool required Low
UWC South East Asia Singapore (SG) PDPA 2012 SCCs / IDTA + transfer risk assessment; supplementary measures as needed Medium
UWC Thailand Thailand (TH) PDPA 2019 SCCs / IDTA + transfer risk assessment; supplementary measures as needed Medium
UWC USA United States (US) EU-US/UK Data Privacy Framework + state laws SCCs / IDTA + transfer risk assessment; supplementary measures as needed Medium
Waterford Kamhlaba UWC Eswatini (SZ) Data Protection Act 2022 SCCs / IDTA + transfer risk assessment; supplementary measures as needed High

4. Jurisdiction impact — National Committees (data sources)

Applications originate from National Committees in 150+ countries. Rather than enumerate each, they are grouped by the data-protection regime that governs the transfer to the controllers:

GroupRegimeTransfer to controllersRisk
EU / EEA National Committees
e.g. Germany, France, Italy, Spain, Netherlands, Poland, Sweden, Ireland
EU GDPR + national implementing law Free flow to the Berlin (EU) controller; UK adequacy decision covers the London controller. Low
United Kingdom National Committee
UWC Great Britain
UK GDPR + Data Protection Act 2018 EU adequacy decision for the UK covers flow to the Berlin controller (subject to periodic review). Low
Adequacy-covered third countries
e.g. Switzerland, Norway/Iceland/Liechtenstein (EEA), Japan, Canada, New Zealand, South Korea, Israel, Argentina, Uruguay
Local law recognised as adequate by the EU and/or UK Adequacy decision — no additional transfer tool required, verify scope. Low
Convention 108/108+ third countries
e.g. Armenia, Bosnia and Herzegovina, Georgia, Morocco, Tunisia, Mexico
Council of Europe data-protection convention; no adequacy decision Standard Contractual Clauses / IDTA + a transfer risk assessment. Medium
Other third countries (no adequacy)
e.g. India, China, most of Sub-Saharan Africa, much of the Middle East and Latin America
Emerging or sectoral local law, or none in force SCCs / IDTA + transfer risk assessment; supplementary measures where the assessment shows a gap. Data-export-controlled regimes (e.g. China PIPL) need separate local compliance. High

5. Consent, processing agreements & data-subject rights

Consent & agreements

Consent is captured at the point of application (through the SurveyMonkey Apply intake), including explicit consent for special-category data and verifiable parental/guardian consent for minors. The movement operates on Article 28 data-processing agreements (DPAs) between the controllers and each school / National Committee that processes the data, and Article 26 joint-controller arrangements between the International Office establishments. The system supports these by enforcing scope, recording processing activity, and confining data to the admissions purpose; the agreements themselves are executed by the organisation.

Full GDPR data-subject rights

The system is built to support the full set of data-subject rights — to be informed, of access, rectification, erasure, restriction, portability, and objection. In particular:

6. Technical & organisational measures (mitigations)

See the technical detail in docs/SECURITY-HARDENING.md.

Not legal advice. This computed assessment is provided with the software to structure UWC's own DPIA. It does not replace UWC's official privacy policy or the judgement of its Data Protection Officer and legal counsel, who must verify the jurisdiction facts, adequacy status and risk bands for the live deployment.
← Privacy & Data Use  ·  Sign in A UWC Constellation Application · v 0.3 · Constellation ID CONSTIO271828