1. Who we are
CPD Ireland is operated by IACT, 32 Fitzwilliam Street Upper, Dublin 2, Ireland. IACT is the controller of personal data processed through the CPD Ireland service unless we tell you otherwise.
General enquiries: info@cpd-ireland.com. Data-protection enquiries: dpo@cpd-ireland.com.
2. Personal data we collect
Depending on how you use CPD Ireland, we may collect:
- provider/organisation name, address, website and provider identifier;
- contact names, business email addresses, phone numbers, enquiry details, communication preferences/suppression choices and correspondence;
- course titles, audiences, sectors, delivery information, version details and proposed CPD hours;
- course-pack files such as outlines, learning outcomes, materials, trainer biographies, assessment/evaluation documents and supporting evidence;
- assessment notes, assigned reviewer information, decisions, decision dates, accreditation status and validity dates;
- learner certificate information supplied by accredited providers, including learner name, learner email, completion date, course details and certificate status;
- MyCPD account information, including learner name, Identity account linkage, primary and additional verified email addresses, email-verification status, account status and security/audit events;
- Self-recorded CPD activity entered in MyCPD, including activity details, CPD hours, notes/reflections and optional private supporting evidence;
- complaint or appeal correspondence and evidence;
- technical and security information needed to operate, protect and troubleshoot the website and admin services.
Learner certificate verification pages expose only the minimum details needed to verify the certificate and do not publish learner email addresses. MyCPD accounts, annual totals, self-recorded CPD, verified email lists and supporting evidence are private and are not exposed through a public learner directory or arbitrary email search. Verification links are unguessable, are not included in the sitemap or a public learner directory, and are marked noindex.
Please avoid including unnecessary personal or sensitive information in course materials. Providers submitting information about trainers or other people are responsible for having an appropriate basis to share it for accreditation review.
3. Why we use personal data
We use personal data to respond to enquiries; record and manage lead follow-up; respect communication preferences and suppression requests; take steps at your request before entering an accreditation arrangement; administer provider and course accreditation; assess course packs; communicate actions and decisions; maintain the public CPD Register; generate and verify provider-issued learner CPD completion certificates; provide the private MyCPD record-keeping service, match certificates to verified learner emails, generate learner annual CPD records and protect MyCPD accounts; manage renewals, complaints and appeals; protect the service; keep appropriate accreditation/audit records; and meet legal obligations.
Our main legal bases are performance of a contract or steps taken at your request before a contract, our legitimate interests in operating a credible accreditation service and maintaining defensible records, and compliance with legal obligations where applicable. Where a different basis is required for a particular activity, we will use that basis.
5. International transfers
Some technology suppliers may process or support data from locations outside the European Economic Area. Where data is transferred internationally, we require an appropriate lawful transfer mechanism or safeguard as required by applicable data-protection law.
6. How long we keep information
We use purpose-specific retention periods rather than keeping every record for the same length of time:
MyCPD account closure does not automatically destroy an independently retained Provider-issued certificate verification record. These are normal policy periods, not a statement that the GDPR requires a fixed seven-year period. We may keep specific records longer where reasonably necessary for an active dispute, legal claim or legal obligation, and may delete them earlier where the purpose no longer justifies retention. Retention periods are reviewed periodically.
7. Security
We use technical and organisational measures appropriate to the nature of the information, including controlled administrative access, server-side validation, secure hosting controls, access restrictions and measures designed to reduce accidental loss, misuse or unauthorised access. No internet service can guarantee absolute security.
8. Your data-protection rights
Subject to the GDPR and applicable law, you may have rights to access, correct, erase or restrict personal data, object to certain processing, receive certain data in portable form, and complain to a supervisory authority. Some rights are subject to conditions and exemptions.
To exercise a right, email dpo@cpd-ireland.com. We may need to verify your identity before acting on a request.
10. Contact and complaints
Questions about this policy or our use of personal data should be sent to dpo@cpd-ireland.com. You also have the right to complain to the Irish Data Protection Commission or another competent supervisory authority.
We may update this policy as the service, suppliers or legal requirements change. The effective date and version above identify the current published version.