Privacy Policy

How we use and protect personal data when you visit the website, contact us, apply for accreditation or submit a course for review.

Effective 22 August 2026 · Version 1.2

1. Who we are

CPD Ireland is operated by IACT, 32 Fitzwilliam Street Upper, Dublin 2, Ireland. IACT is the controller of personal data processed through the CPD Ireland service unless we tell you otherwise.

General enquiries: info@cpd-ireland.com. Data-protection enquiries: dpo@cpd-ireland.com.

2. Personal data we collect

Depending on how you use CPD Ireland, we may collect:

  • provider/organisation name, address, website and provider identifier;
  • contact names, business email addresses, phone numbers, enquiry details, communication preferences/suppression choices and correspondence;
  • course titles, audiences, sectors, delivery information, version details and proposed CPD hours;
  • course-pack files such as outlines, learning outcomes, materials, trainer biographies, assessment/evaluation documents and supporting evidence;
  • assessment notes, assigned reviewer information, decisions, decision dates, accreditation status and validity dates;
  • learner certificate information supplied by accredited providers, including learner name, learner email, completion date, course details and certificate status;
  • MyCPD account information, including learner name, Identity account linkage, primary and additional verified email addresses, email-verification status, account status and security/audit events;
  • Self-recorded CPD activity entered in MyCPD, including activity details, CPD hours, notes/reflections and optional private supporting evidence;
  • complaint or appeal correspondence and evidence;
  • technical and security information needed to operate, protect and troubleshoot the website and admin services.

Learner certificate verification pages expose only the minimum details needed to verify the certificate and do not publish learner email addresses. MyCPD accounts, annual totals, self-recorded CPD, verified email lists and supporting evidence are private and are not exposed through a public learner directory or arbitrary email search. Verification links are unguessable, are not included in the sitemap or a public learner directory, and are marked noindex.

Please avoid including unnecessary personal or sensitive information in course materials. Providers submitting information about trainers or other people are responsible for having an appropriate basis to share it for accreditation review.

3. Why we use personal data

We use personal data to respond to enquiries; record and manage lead follow-up; respect communication preferences and suppression requests; take steps at your request before entering an accreditation arrangement; administer provider and course accreditation; assess course packs; communicate actions and decisions; maintain the public CPD Register; generate and verify provider-issued learner CPD completion certificates; provide the private MyCPD record-keeping service, match certificates to verified learner emails, generate learner annual CPD records and protect MyCPD accounts; manage renewals, complaints and appeals; protect the service; keep appropriate accreditation/audit records; and meet legal obligations.

Our main legal bases are performance of a contract or steps taken at your request before a contract, our legitimate interests in operating a credible accreditation service and maintaining defensible records, and compliance with legal obligations where applicable. Where a different basis is required for a particular activity, we will use that basis.

4. Sharing and service providers

We limit access to people who need information for accreditation or service administration. This may include CPD Ireland/IACT staff, appropriately matched assessors, and suppliers that host or support the website, forms, uploaded files, database, email or security services.

Our current website uses Netlify for hosting, serverless functions and form/file submission services, and a hosted Postgres/Neon database for structured accreditation, lead and communication-preference workflow data. Transactional email is delivered through our configured email service provider and delivery identifiers/status are retained for audit and troubleshooting. Those providers process information on our behalf subject to their applicable data-processing arrangements. We may also disclose information where required by law, to protect legal rights, or with your direction.

We do not sell personal data.

5. International transfers

Some technology suppliers may process or support data from locations outside the European Economic Area. Where data is transferred internationally, we require an appropriate lawful transfer mechanism or safeguard as required by applicable data-protection law.

6. How long we keep information

We use purpose-specific retention periods rather than keeping every record for the same length of time:

RecordNormal retention
Successful accreditation file, assessment record and substantive course-pack evidence7 years after the accreditation finally expires, is withdrawn or otherwise ends
Complaints and appeals7 years after the matter is closed
Rejected or withdrawn applications that never become accredited2 years after closure
General enquiries that do not progress12 months after the last substantive contact
MyCPD account/profile and verified-email relationshipWhile the account is active and then only as long as needed to process closure, legal/security obligations and applicable rights requests
Self-recorded MyCPD activity and supporting evidenceWhile retained by the learner in MyCPD; deleted/anonymised through the account-deletion process subject to limited legal/security requirements
Provider-issued learner certificate evidenceRetained separately from the MyCPD account lifecycle for as long as reasonably required to preserve the integrity and verifiability of the historical certificate/accreditation record
Financial/tax recordsFor the period required by applicable accounting and tax law

MyCPD account closure does not automatically destroy an independently retained Provider-issued certificate verification record. These are normal policy periods, not a statement that the GDPR requires a fixed seven-year period. We may keep specific records longer where reasonably necessary for an active dispute, legal claim or legal obligation, and may delete them earlier where the purpose no longer justifies retention. Retention periods are reviewed periodically.

7. Security

We use technical and organisational measures appropriate to the nature of the information, including controlled administrative access, server-side validation, secure hosting controls, access restrictions and measures designed to reduce accidental loss, misuse or unauthorised access. No internet service can guarantee absolute security.

8. Your data-protection rights

Subject to the GDPR and applicable law, you may have rights to access, correct, erase or restrict personal data, object to certain processing, receive certain data in portable form, and complain to a supervisory authority. Some rights are subject to conditions and exemptions.

To exercise a right, email dpo@cpd-ireland.com. We may need to verify your identity before acting on a request.

9. Cookies and browser storage

CPD Ireland does not currently use advertising or behavioural-tracking cookies on the public website. The service may use essential technical browser storage where needed for a requested function or restricted administration. If we introduce non-essential cookies or comparable tracking technologies, we will update this notice and obtain consent where required.

10. Contact and complaints

Questions about this policy or our use of personal data should be sent to dpo@cpd-ireland.com. You also have the right to complain to the Irish Data Protection Commission or another competent supervisory authority.

We may update this policy as the service, suppliers or legal requirements change. The effective date and version above identify the current published version.