Privacy Statement for Participants on Programmes Leading to UCC awards, click here
Privacy Statement for Participants on Programmes Leading to IMI electronic certification, click here
About IMI and This Statement
IMI Leadership Limited (company number 714739) is a private limited company incorporated in Ireland, registered at Sandyford Road, Dundrum, Dublin 14. IMI is a subsidiary of Business Post Group (Business Post Group). IMI does not systematically share personal data with Business Post Group but may on a case-by-case basis share personal data where there is a legitimate reason and/or your consent has been obtained.
IMI’s Primary Privacy Statement
This is IMI’s primary Integrated Privacy Statement, covering IMI’s own independent processing activities across all audience groups. A separate, jointly approved Privacy Statement also exists for learners on IMI programmes leading to an award of UCC: “IMI Privacy Statement for Learners undertaking Executive Development Programmes leading to Awards of University College Cork.” That document is maintained jointly with UCC as required by the Joint Controller Agreement dated 24 February 2026 and governs the jointly controlled processing for those programmes. Learners on programmes leading to a UCC award should read both documents — this Statement for IMI’s independent processing, and the jointly approved statement for the jointly controlled processing. Where the two address the same matter in respect of UCC-award programme processing, the jointly approved statement prevails. This Statement replaces and supersedes all previous separate IMI privacy notices for audiences other than learners on programmes leading to UCC awards.
This Statement is issued in compliance with the EU General Data Protection Regulation (GDPR) 2016/679, the Data Protection Act 2018 (Ireland), the Irish ePrivacy Regulations 2011 (S.I. 336/2011), and, where relevant, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). IMI has regard to guidance issued by the Data Protection Commission (DPC).
This Statement is made available to each audience group as follows: to programme learners at or before enrolment; to staff and faculty at the start of employment or engagement and as part of induction; to associate faculty with their Associate Framework Agreement; to suppliers at or before contracting; and to members of the public at imi.ie. Where IMI obtains personal data indirectly, you will be informed within one month of IMI obtaining that data (see ‘Data Obtained Indirectly’ below).
IMI is not required to appoint a Data Protection Officer. IMI has appointed a Data Advisor who oversees compliance with data protection law and is the primary point of contact for all data protection queries, rights requests and breach reports:
| Data Advisor | Dr. Mark Glynn |
| [email protected] | |
| Post | IMI Leadership Limited, Sandyford Road, Dundrum, Dublin 14 |
| Supervisory Authority | Data Protection Commission │ www.dataprotection.ie │ 21–25 Canal Road, Dublin 6, D06 F46E │ +353 57 868 4800 |
IMI is the data controller for all personal data described in this Statement. For programmes leading to an award of UCC, IMI and UCC act as joint controllers for defined academic purposes only — the scope is described in Section A and in the jointly approved statement.
This Statement is structured in sections, one for each audience group. Please go directly to the section that applies to you. The IMI Knowledge Centre library service (library.imi.ie) does not have a separate privacy notice — it is fully covered by this Statement. Learner and staff library data is covered by the relevant audience section. Members of the public requesting access to controlled-access theses are covered by Section F. For Knowledge Centre queries contact [email protected].
Contents
Section A: Learners on IMI Programmes Leading to an Award of UCC
- IMI’s Independent Processing
- Thesis and Dissertation Deposit
- Virtual Learning Environment
- Assignments and Examination Scripts
- Recording of Sessions
- Group Work
- Ethics and Research
- Employer and Corporate Sponsorship
Section B: Learners on Programmes Leading to IMI Electronic Certification
- What Data We Collect and Why
- Other Provisions
- Virtual Learning Environment
- Assignments
- Recording of Sessions
- Group Work
- Ethics and Research
- Employer and Corporate Sponsorship
Section D: Recruitment Applicants
- When You Will Receive This Statement
- What Data We Collect and Why
- Health Data
- Building Access and IT Monitoring
- Data Security Responsibilities
- Remote Working and Personal Devices
Section F: Website Visitors, Members of the Public and Visitors to IMI Premises
- Your Dual Role: Data Subject and Data Processor
- What Data IMI Holds About You
- Your Obligations as a Data Processor
- Sharing of Your Data
- Mandatory Policies
- Updating Your Details
Section H: Suppliers and Contractors
- What Data We Collect and Why
- Data We Do Not Collect
- Data Processing Agreements
- Updating Your Details
9. Your Rights
- Right to Be Informed (Articles 13 and 14)
- Right of Access (Article 15)
- Right to Rectification (Article 16)
- Right to Erasure (Article 17)
- Right to Restrict Processing (Article 18)
- Right to Data Portability (Article 20)
- Right to Object — General (Article 21(1))
- Right to Object — Direct Marketing (Article 21(2))
- Rights in Relation to Automated Decision-Making (Article 22)
- Right to Withdraw Consent
- Right to Know Named Recipients (Article 15 — Categories Edition)
10. Data Security
11. Personal Data Breaches
12. How to Make a Complaint
13. Review of This Statement
14. Governing Law
How IMI Uses Your Data — the Data Protection Principles
IMI is legally bound by all seven data protection principles in Article 5 GDPR and is accountable for demonstrating compliance with each of them:
-
-
- Lawfulness, fairness and transparency: IMI processes your data lawfully, fairly and transparently. This Statement is how IMI meets its transparency obligation.
-
- Purpose limitation: IMI collects data for specific, explicit and legitimate purposes and will not use it for any incompatible purpose. If IMI wishes to use your data for a new purpose it will inform you and, where required, seek a fresh lawful basis or your consent.
-
- Data minimisation: IMI collects only data that is adequate, relevant and strictly necessary for each purpose.
-
- Accuracy: IMI takes reasonable steps to ensure data is accurate and up to date. If your details change, please notify IMI promptly using the contact in your relevant section below.
-
- Storage limitation: IMI retains data only for as long as necessary or as required by law or accreditation obligations. Retention periods are in the IMI Data Retention Schedule, available from [email protected].
-
- Integrity and confidentiality: IMI implements appropriate technical and organisational security measures. This is a legal obligation under Article 5(1)(f) GDPR, not merely good practice.
-
- Accountability: IMI takes responsibility for compliance with all the above principles and maintains records, policies, procedures and data protection impact assessments to demonstrate that compliance. The Data Advisor oversees accountability.
-
The Lawful Basis for Processing
IMI only processes personal data where there is a lawful basis under Article 6 GDPR:
-
-
- Contract (Article 6(1)(b)): processing is necessary to perform a contract with you or to take steps at your request before entering one.
-
- Legal obligation (Article 6(1)(c)): processing is required by EU or Irish law — for example, payroll tax reporting, employment law compliance, or regulatory reporting to QQI or HEA.
-
- Legitimate interests (Article 6(1)(f)): processing is necessary for IMI’s legitimate interests, provided those interests are not overridden by your rights. Where IMI relies on this basis, a record of the balancing test is maintained by the Data Advisor and available on request from [email protected].
-
- Consent (Article 6(1)(a)): you have given freely given, specific, informed and unambiguous consent — for example, for direct marketing or for the recording of sessions. You may withdraw consent at any time without affecting the lawfulness of prior processing. To withdraw consent, contact [email protected].
-
For special category data (such as health information), IMI relies on additional conditions under Article 9 GDPR. The most common condition is Article 9(2)(b) GDPR read with Schedule 2(1) of the Data Protection Act 2018 — processing necessary to carry out obligations under employment law, including the Organisation of Working Time Act 1997, the Safety, Health and Welfare at Work Act 2005, and the Workplace Relations Act 2015. Where no employment law condition applies, explicit consent under Article 9(2)(a) GDPR will be sought.
Automated Decision-Making, Profiling and AI — Article 13(2)(f) / 14(2)(g) GDPR
IMI does not engage in any automated decision-making or profiling in relation to learners, staff, applicants or any other individuals. No decision producing a legal or similarly significant effect on you is made solely by automated means — all decisions are made by trained human staff. IMI does not currently use artificial intelligence tools in any processing activity involving your personal data. If this changes, this Statement will be updated, a DPIA completed, and you will be informed before any such system is deployed. Your right under Article 22 GDPR not to be subject to solely automated decisions is set out in the Your Rights section below.
Direct Marketing and ePrivacy
IMI may send you information about programmes, events, research and other IMI activities by email or other electronic means where you have given your consent to receive such communications.
You have an absolute and unconditional right under Article 21(2) GDPR and the Irish ePrivacy Regulations 2011 to object to processing of your personal data for direct marketing at any time. IMI will stop sending marketing communications immediately upon receiving your objection — there is no balancing test. To opt out, click the unsubscribe link in any marketing email or contact [email protected].
IMI’s use of cookies and similar technologies on imi.ie is governed by the Cookie Policy at imi.ie, which sets out which cookies require consent and how to manage preferences. The Cookie Policy is updated whenever IMI’s use of cookies changes — refer to the live version at imi.ie.
Children and Young Persons
IMI’s programmes and services are directed at senior professionals and adult learners. IMI does not knowingly collect or process personal data of individuals under the age of 18. If you believe IMI has inadvertently collected data relating to a person under 18, contact [email protected] immediately.
How Long IMI Keeps Your Data
Retention periods are set out in the IMI Data Retention Schedule, which reflects applicable legal, regulatory and accreditation requirements including AACSB accreditation, Revenue and tax law, employment law, and QQI quality assurance requirements. The Schedule is maintained by the Data Advisor and available on request from [email protected]. When data is no longer required it is securely deleted or anonymised.
Data Obtained Indirectly
In some circumstances IMI receives personal data about you from a third party rather than directly from you. This occurs in the following contexts:
-
-
- References: where you apply for a role at IMI and provide the names of referees, IMI will obtain a reference. You will be asked to confirm that referees are aware their details are being provided.
-
- Employer or sponsor nomination: where your employer or a sponsoring organisation enrols you on an IMI programme or provides information about you as part of a commissioning or sponsorship arrangement.
-
- External Examiner nomination: where an academic or professional body nominates you as External Examiner, your details will be provided to IMI by that body.
-
- Supplier contact details: where a supplier organisation provides the contact details of its staff as part of a contracting or procurement process.
-
In each case, IMI will inform you that it holds your data, the source from which it was obtained, and the purposes for which it will be used within one month of first obtaining it, or at the point of first contact with you, whichever is sooner. Contact [email protected] with any queries.
Third Parties and Data Sharing
IMI shares personal data only where necessary. The principal categories of organisations with whom IMI shares data are set out below. All processors are engaged under written data processing agreements and are required to process data only on IMI’s instructions, implement appropriate security measures, and not transfer data outside the EEA without IMI’s prior written consent. The full list of named processors is available on request from [email protected].
| Category of Recipient | Location / Transfer Mechanism |
| HR and workforce management system provider | EEA and UK (adequacy decision) |
| Outsourced payroll and tax administration provider | EEA (Ireland) |
| Pension scheme administrator | EEA (Ireland) |
| Group health insurance and employee assistance provider | EEA (Ireland) |
| IT security and compliance training platform provider | EEA |
| Digital credentialing and certification platform | Outside EEA — EU Standard Contractual Clauses |
| Virtual Learning Environment provider | Outside EEA — EU Standard Contractual Clauses |
| Online session recording and storage providers | Outside EEA — EU Standard Contractual Clauses |
| Website analytics provider | See Cookie Policy at imi.ie |
| Regulatory and statutory authorities (Revenue, QQI, HEA) | EEA (Ireland) — statutory recipients, not processors |
| Programme delivery partners (selected programmes) | EEA (Ireland) — programme logistics only |
| Thesis/dissertation repository platform provider | Location/transfer mechanism to be confirmed — contact [email protected] |
| Corporate parent group | EEA (Ireland) — case-by-case only |
| Joint controller for programmes leading to UCC awards | EEA (Ireland) — UCC, for defined academic purposes under JCA dated 24 February 2026. Contact [email protected]. |
Note on Recipients
Under Articles 13(1)(e) and 14(1)(e) GDPR, IMI may lawfully provide categories of recipients rather than named recipients. The full list of named processors is maintained internally and available on request from [email protected]. Where a named recipient is required to exercise a data subject right, IMI will provide names upon request per Article 15 GDPR.
IMI does not sell personal data or share it for commercial or marketing purposes with any organisation outside those required to administer its activities.
Section A: Learners on IMI Programmes Leading to an Award of UCC
A dedicated privacy policy is in place for learners on programmes leading to awards of UCC. Please refer to that statement. This section solely indicates matters over which IMI has obligations in the context of its relationship with University College Cork (UCC).
Read the jointly approved statement
The jointly controlled processing of your personal data by IMI and UCC is governed by the separately issued and jointly approved “IMI Privacy Statement for Learners undertaking Executive Development Programmes leading to Awards of University College Cork.” That document sets out the scope of joint control, the data collected for jointly controlled purposes, and your data subject rights in respect of that processing. It is available from your Programme Director and at imi.ie. This section of the Integrated Statement covers only IMI’s independent processing activities in relation to you as a learner. For jointly controlled processing, please refer to the jointly approved statement.
Accreditation Transition
IMI was acquired by the Business Post Group in April 2025. UCC continues to make awards in respect of IMI programmes and remains a joint controller for those programmes. Under the Joint Controller Agreement (24 February 2026), joint control continues for any learner enrolled prior to any cessation of collaboration, solely for completing their programme, assessment, certification and academic record retention. Joint control does not extend to new enrolments following any such cessation. IMI will communicate any material change to IMI’s own processing that affects enrolled learners before it takes effect. For changes to UCC’s processing, refer to UCC’s Privacy Statement at ucc.ie/en/ocla/comp/data/dataprotection/.
IMI’s Independent Processing
The following table sets out the personal data IMI processes in its capacity as independent data controller for learners on IMI programmes leading to an award of UCC. This processing is separate from, and in addition to, the jointly controlled processing described in the jointly approved statement.
| Purpose | Data Collected | Lawful Basis | Retention | Recipients |
| Enrolment administration (IMI systems) | Name, contact details, date of birth, previous qualifications, employer details where relevant to sponsorship | Contract | See Retention Schedule | IMI staff only — data shared with UCC only to extent required under the joint controller agreement; see jointly approved statement |
| VLE access and management | Login credentials, access logs, submitted materials | Contract | See Retention Schedule | Programme Director; IMI IT; Canvas LMS |
| Session recordings | Audio/video recordings of workshops, assessments and reflection sessions | Consent | See Retention Schedule | Programme team; External Examiner (assessment only); Zoom; Vimeo |
| Thesis/dissertation deposit | Name, email, course, dissertation title, supervisor name; chosen access level; thesis content (may include third-party personal data) | Contract; Legitimate interests (research preservation) | Duration of repository holding — see Retention Schedule | Knowledge Centre staff; researchers granted controlled access; repository platform provider |
| Payment of programme fees | Payment details (EFT, card or cheque); invoicing and instalment records | Contract; Legal obligation | See Retention Schedule | IMI finance; payment card processor; Revenue Commissioners |
| Alumni engagement | Name, email, programme, graduation date | Consent | See Retention Schedule | IMI communications team |
| Employer/corporate sponsorship | Name, programme, attendance and engagement data | Contract; Consent where personal data shared with sponsor | See Retention Schedule | Sponsoring employer only where written agreement in place |
For academic records held by UCC in its capacity as awarding body — including the official UCC academic record, conferring records and regulatory reporting — contact UCC directly at [email protected] or consult UCC’s Privacy Statement.
Thesis and Dissertation Deposit
Where your programme requires the submission of a thesis or dissertation, you will be asked to sign a Thesis and Dissertation Deposit Agreement before submitting your work to the IMI Knowledge Centre repository. The personal data collected includes your name, email address, course, dissertation title, and supervisor name. This data is collected on the basis of contract and retained for as long as your thesis remains in the IMI repository.
You must select an access level at deposit: Open Access, Controlled Access, Restricted Access, Embargoed or Redaction. Where you select Controlled Access, researchers requesting access will receive citation information only and must agree to a copyright declaration. A citation remains visible even where access to the full text is restricted.
Your thesis may contain personal data about third parties — for example research learners or individuals featured in recordings or photographs. You are responsible for ensuring appropriate consents are in place. By signing the Deposit Agreement you warrant that written consents from persons featured in recordings or photographs are held and available for inspection. IMI processes any such third-party data only in accordance with the access level you have selected.
You retain copyright in your thesis. The licence granted to IMI is non-exclusive and royalty-free. IMI may reformat or migrate your thesis for preservation purposes without changing its content. To exercise any data subject right in connection with your thesis deposit, contact [email protected] or [email protected].
Virtual Learning Environment
You do not retain perpetual access to the VLE after your programme ends. Once your last assignment is submitted, download any materials you wish to keep. The VLE is not a permanent storage facility.
Assignments and Examination Scripts
All submitted assignments and examination scripts are stored on the password-protected VLE. Access is restricted to the Programme Director, grading faculty, associate faculty in a grading role, and the appointed External Examiner. You are advised to retain electronic copies of your own work. Assignments and examination scripts are retained in accordance with the IMI Data Retention Schedule, which reflects AACSB accreditation requirements. Any psychometric reports used on the programme will be stored only for the duration of the programme and destroyed thereafter.
In line with GDPR, please anonymise any third parties referenced in written assignments — do not use actual names of individuals without their consent. Job titles and organisational roles do not need to be anonymised.
Recording of Sessions
Presentations, workshops and assessments may be recorded for quality, research, distribution or assessment purposes. IMI’s Recording of Sessions Policy (available on the VLE and from your Programme Director) governs how recordings are made, stored, accessed and deleted. Key points:
-
-
- Online workshops: The session invitation will state that recording will take place. By joining you give consent. You will be reminded at the start. Recordings are held on the Zoom server then stored on Vimeo.
-
- In-person workshops: All learners must be advised in advance and provide written permission. If you object, notify the Programme Director before the session. Recording pauses for commercially sensitive content. Recordings are uploaded to a secure server and deleted from the device immediately after.
-
- Assessment recordings: Access is limited to the Programme Director, Programme Co-ordinator, relevant External Examiner or moderator, and the delivering Associate Faculty member. Not published on the VLE.
-
- Reflection recordings: Access is restricted to those present, the Programme Director and Programme Co-ordinator only. Must not be shared with anyone else.
-
You must not copy, download or further distribute any recording of a session. Recordings are personal data and must be treated accordingly.
Group Work
Where your programme requires group work, the Programme Co-ordinator may share the email addresses of your study group with each other to facilitate group assignments. If you object, notify the Programme Co-ordinator before or on the first day of your programme.
Ethics and Research
If your programme requires you to collect personal data from individuals as part of research or an assignment, you must comply with IMI’s Ethics Policy and Procedure. Details are available via the VLE or from your Programme Director.
Employer and Corporate Sponsorship
If your employer is funding your participation and you have agreed that your employer may access some or all of your personal data, you must provide a copy of the relevant approval letter and details of the data sharing arrangement before your programme commences. Where IMI is delivering a corporate or custom programme commissioned by your employer, your employer may receive programme-level attendance and engagement data as set out in the programme agreement — you will be informed of this at enrolment.
Section B: Learners on Programmes Leading to IMI Electronic Certification
This section applies to you if you are an applicant to, or learner on, an executive development programme leading to IMI electronic certification. IMI is the sole data controller for these programmes. Your data is not shared with UCC and UCC has no role in the processing of your personal data.
What Data We Collect and Why
| Purpose | Data Collected | Lawful Basis | Retention | Recipients |
| Enrolment and administration | Name, contact details, date of birth, previous qualifications, employer details where relevant | Contract; Legal obligation | See Retention Schedule | IMI staff only |
| Assessment and grading | Assignments, grades, attendance, moderation records | Contract | See Retention Schedule | Programme Director; External Examiner; Associate Faculty (grading) |
| Reasonable accommodation | Health or disability information, medical certificates | Legal obligation; Explicit consent | See Retention Schedule | Occupational health provider where applicable |
| Session recordings | Audio/video recordings of workshops, assessments and reflection sessions | Consent | See Retention Schedule | Programme team; External Examiner (assessment only); Zoom; Vimeo |
| Payment of programme fees | Payment details (EFT, card or cheque); invoicing and instalment records | Contract; Legal obligation | See Retention Schedule | IMI finance; payment card processor; Revenue Commissioners |
| Alumni engagement | Name, email, programme completed, completion date | Consent | See Retention Schedule | IMI communications team |
| Certification | Name, programme, completion date | Contract | See Retention Schedule | Parchment (digital credentials) |
| Employer/corporate sponsorship | Name, programme, attendance and engagement data | Contract; Consent where personal data shared with sponsor | See Retention Schedule | Sponsoring employer only where written agreement in place |
Other Provisions
The provisions set out below — Virtual Learning Environment, Assignments and Examination Scripts, Recording of Sessions, Group Work, Ethics and Research, and Employer and Corporate Sponsorship — apply equally to learners on IMI-certified programmes.
Virtual Learning Environment
You do not retain perpetual access to the VLE after your programme ends. Once your last assignment is submitted, download any materials you wish to keep. The VLE is not a permanent storage facility.
Assignments
All submitted assignments are stored on the password-protected VLE. Access is restricted to the Programme Director, grading faculty, associate faculty in a grading role, and the appointed External Examiner. You are advised to retain electronic copies of your own work. Assignments and examination scripts are retained in accordance with the IMI Data Retention Schedule. Any psychometric reports used on the programme will be stored only for the duration of the programme and destroyed thereafter.
In line with GDPR, please anonymise any third parties referenced in written assignments — do not use actual names of individuals without their consent. Job titles and organisational roles do not need to be anonymised.
Recording of Sessions
Presentations, workshops and assessments may be recorded for quality, research, distribution or assessment purposes. IMI’s Recording of Sessions Policy (available on the VLE and from your Programme Director) governs how recordings are made, stored, accessed and deleted. Key points:
-
-
- Online workshops: The session invitation will state that recording will take place. By joining you give consent. You will be reminded at the start. Recordings are held on the Zoom server then stored on Vimeo.
-
- In-person workshops: All learners must be advised in advance and provide written permission. If you object, notify the Programme Director before the session. Recording pauses for commercially sensitive content. Recordings are uploaded to a secure server and deleted from the device immediately after.
-
- Assessment recordings: Access is limited to the Programme Director, Programme Co-ordinator, relevant External Examiner or moderator, and the delivering Associate Faculty member. Not published on the VLE.
-
- Reflection recordings: Access is restricted to those present, the Programme Director and Programme Co-ordinator only. Must not be shared with anyone else.
-
You must not copy, download or further distribute any recording of a session. Recordings are personal data and must be treated accordingly.
Group Work
Where your programme requires group work, the Programme Co-ordinator may share the email addresses of your study group with each other to facilitate group assignments. If you object, notify the Programme Co-ordinator before or on the first day of your programme.
Ethics and Research
If your programme requires you to collect personal data from individuals as part of research or an assignment, you must comply with IMI’s Ethics Policy and Procedure. Details are available via the VLE or from your Programme Director.
Employer and Corporate Sponsorship
If your employer is funding your participation and you have agreed that your employer may access some or all of your personal data, you must provide a copy of the relevant approval letter and details of the data sharing arrangement before your programme commences. Where IMI is delivering a corporate or custom programme commissioned by your employer, your employer may receive programme-level attendance and engagement data as set out in the programme agreement — you will be informed of this at enrolment.
Section C: External Examiners
This section applies to you if you have been nominated or appointed as an External Examiner at IMI.
What Data We Collect and Why
| Purpose | Data Collected | Lawful Basis | Retention | Recipients |
| Appointment and engagement | Name, CV, current employer, qualifications, expertise, residency and citizenship status | Contract; Legal obligation (QA requirements) | See Retention Schedule | QQI; UCC (programmes leading to UCC awards only); Programme Director |
| Payment of fees and expenses | Bank account details, tax reference | Contract; Legal obligation | See Retention Schedule | IMI’s bank; Revenue Commissioners |
| QA transparency | Name, qualifications, institution — disclosed to learners | Legal obligation (QA transparency) | See Retention Schedule | Programme learners (name, qualifications and institution only) |
| External Examiner Reports | Report contents (may reference learner performance) | Legal obligation | See Retention Schedule | Internal academic staff; QQI; learners where QA frameworks require |
A Note on External Examiner Reports
External Examiner Reports are quality assurance documents. They may be shared by IMI with internal academic committees, and awarding bodies in accordance with quality assurance requirements. They are shared with learners only to the extent required by applicable QA frameworks.
Updating Your Details
Contact [email protected] at any time to update your details.
Section D: Recruitment Applicants
This section applies to you if you have applied, or are applying, for a role at IMI. If appointed, Section E will apply from the date of your appointment.
What Data We Collect and Why
| Purpose | Data Collected | Lawful Basis | Retention | Recipients |
| Processing your application | Name, address, CV, cover letter, application form responses, interview notes and scoring sheets | Legitimate interests | See Retention Schedule | Recruiting panel; HR |
| Right-to-work verification | Passport or travel document, visa or permit details | Legal obligation — collected at conditional offer stage only | See Retention Schedule | HR; immigration authorities if required |
| References | Content provided by named referees | Legitimate interests; Consent | See Retention Schedule | Recruiting panel; HR |
IMI does not use automated screening tools or artificial intelligence at any stage of its recruitment or selection process. All decisions are made by trained human staff.
Retention
If your application is unsuccessful, your recruitment file is securely deleted one year after the conclusion of the process. If you are appointed, your file is retained as part of your personnel record in accordance with the Data Retention Schedule.
References
IMI will seek your written consent before approaching any referee. We do not ask you to include references on application forms.
Your Right to Withdraw
You may withdraw your application at any time by contacting [email protected]. Your data will be deleted promptly unless IMI has a legal obligation to retain it.
Section E: Staff and Faculty
This section applies to all current and former IMI staff and faculty, including permanent and fixed-term employees, placement students and volunteers. This Statement is the complete privacy notice for staff and faculty — no separate staff privacy policy is issued.
When You Will Receive This Statement
-
-
- On commencement of employment — provided as part of your induction.
-
- When new categories of personal data are collected — you will be informed at the time.
-
What Data We Collect and Why
| Purpose | Data Collected | Lawful Basis | Retention | Recipients |
| Employment contracts and workforce administration | Name, address, contact details, next of kin, job title, contract terms, salary, qualifications | Contract; Legal obligation | See Retention Schedule | Revenue; Department of Social Protection; pension provider |
| Payroll and tax | PPS number, bank account details, tax codes, salary, statutory payments | Legal obligation | See Retention Schedule | Payroll provider; Revenue; Department of Social Protection |
| Pensions and employee benefits | Name, salary, pension contributions, health insurance enrolment | Contract; Legal obligation | See Retention Schedule | Pension administrator; health insurance provider |
| Right-to-work verification | Passport or travel document, visa or permit details | Legal obligation | See Retention Schedule | Immigration authorities if required |
| Sickness absence and health | Medical certificates, self-certification, occupational health referrals | Legal obligation — Article 9(2)(b) GDPR and Schedule 2(1) Data Protection Act 2018 | See Retention Schedule | Occupational health provider; HR |
| Disciplinary, grievance and performance | Records of proceedings, correspondence, outcomes | Legal obligation; Legitimate interests | See Retention Schedule | Legal advisors (if claim arises); WRC or Labour Court (if required) |
| Annual and statutory leave | Leave taken, types, dates | Legal obligation (Organisation of Working Time Act 1997) | See Retention Schedule | HR management system provider |
| Training records | Training completed, dates, outcomes | Legal obligation; Contract | See Retention Schedule | IT security training platform provider; HR |
| Building access and IT monitoring | Door swipe card logs, IT system access logs — security purposes only | Legitimate interests (security and system integrity) | See Retention Schedule | IT department; Data Advisor (on investigation only) |
| Health and safety | Accident reports, risk assessments, occupational health records | Legal obligation | See Retention Schedule | Health and Safety Authority (if required); insurers |
Health Data
Health information is processed only where necessary for sickness absence management or to determine and implement reasonable adjustments. The lawful basis is Article 9(2)(b) GDPR read with Schedule 2(1) of the Data Protection Act 2018, which permits processing necessary to carry out obligations under employment law, including the Organisation of Working Time Act 1997, the Safety, Health and Welfare at Work Act 2005, and the Workplace Relations Act 2015. Where no employment law condition applies, explicit consent under Article 9(2)(a) GDPR will be sought.
Building Access and IT Monitoring
IMI collects building access card logs and IT system access logs for the purpose of physical and information security only. The lawful basis is legitimate interests (Article 6(1)(f) GDPR). This data will not be repurposed — for example, it will not be used routinely to monitor attendance or performance. Access is restricted to the IT department and, where a formal investigation requires it, the Data Advisor and relevant management.
Data Security Responsibilities
All staff and faculty who handle personal data must:
-
-
- Store confidential files securely and not leave them accessible to unauthorised persons;
-
- Use strong passwords and not share them;
-
- Lock computers when away from their desks;
-
- Not transfer personal data to personal email accounts or unauthorised devices;
-
- Password-protect confidential email attachments and send the password by a separate means;
-
- Use the Bcc field when emailing groups where recipients do not know each other; and
-
- Report any actual or suspected data breach to [email protected] immediately.
-
Full obligations are set out in the Acceptable Use Policy. Failure to comply may result in disciplinary action up to and including dismissal.
Remote Working and Personal Devices
When working remotely you must lock your device, ensure screens cannot be overlooked, and save work to IMI systems promptly. Personal devices may not be used to access, process or store IMI personal data without prior written authorisation from your line manager and the IT department. Staff working outside the EEA will have no access to IMI personal data for the duration of that period.
Section F: Website Visitors, Members of the Public and Visitors to IMI Premises
This section applies to you if you visit imi.ie, contact IMI as a member of the public, or visit IMI’s premises at Sandyford Road, Dundrum, Dublin 14.
Website and Online Enquiries
| Purpose | Data Collected | Lawful Basis | Retention | Recipients |
| Website operation and analytics | IP address, browser type, OS, clickstream data, session duration, cookie identifiers | Legitimate interests (functionality); Consent (non-essential cookies) | See Retention Schedule | Analytics provider — see Cookie Policy at imi.ie |
| Responding to enquiries | Name, email, telephone, content of enquiry | Legitimate interests; Consent (where marketing follow-up agreed) | See Retention Schedule | Relevant IMI team |
| Event registration | Name, email, employer, role, dietary or access requirements | Contract; Consent (marketing) | See Retention Schedule | Event management team; venue (dietary and access needs only) |
| Content download and podcast forms | Name, email, employer role where submitted via imi.ie | Consent | See Retention Schedule | Relevant IMI team; CRM platform provider |
| Controlled-access thesis requests | Name and copyright declaration agreement of researchers requesting access to restricted theses | Legitimate interests (administration of controlled access) | See Retention Schedule | Knowledge Centre staff only |
IMI does not use website data to make automated decisions about you. The Cookie Policy at imi.ie provides full details on cookies IMI uses, the analytics and third-party services employed, and how to manage your preferences. Please refer to the live version at imi.ie rather than any saved copy.
By using imi.ie you accept IMI’s Terms and Conditions of Website Use.
CCTV
IMI operates CCTV at its premises at Sandyford Road, Dundrum, Dublin 14, for the purposes of the security of persons and property and the prevention and detection of crime. The lawful basis is legitimate interests (Article 6(1)(f) GDPR). CCTV footage is retained for a period set out in the Data Retention Schedule. Access is restricted to the Head of Facilities and, where a security incident or formal investigation requires it, the Data Advisor and relevant management. CCTV footage will not be used for any other purpose, including performance monitoring. To exercise a data subject right in respect of CCTV footage, contact [email protected] with proof of identity and details of the date, time and location of your visit.
Section G: Associate Faculty
This section applies to you if you are engaged by IMI as an associate faculty member under an Associate Framework Agreement. It covers both the personal data IMI holds about you, and your obligations as a data processor when you access learner data in the course of your services.
Your Dual Role: Data Subject and Data Processor
-
-
- As a data subject: IMI holds personal data about you to administer your engagement, make payments and manage programme quality. Your data subject rights apply in full to this data.
-
- As a data processor: When you access personal data relating to IMI’s programme learners in the course of your services — for example reviewing assignments, recording grades or facilitating recorded sessions — you act as a data processor on IMI’s behalf. You process that data only on IMI’s instructions, as set out in Schedule 2 of your Associate Framework Agreement.
-
What Data IMI Holds About You
| Purpose | Data Collected | Lawful Basis | Retention | Recipients |
| Engagement, contracting and onboarding | Name, address, contact details, photographic identification, right-to-work documentation | Contract; Legal obligation | See Retention Schedule | HR; legal advisors if required |
| Payment of fees and payroll taxes | Bank account details, tax reference, PAYE/PRSI/USC records | Contract; Legal obligation | See Retention Schedule | Payroll provider; Revenue Commissioners |
| Programme delivery and quality assurance | Qualifications, expertise, VLE access records, delivery feedback, learner evaluation scores | Contract; Legitimate interests (quality) | See Retention Schedule | Programme Directors; UCC (programmes leading to UCC awards only — name, qualifications and role for QA purposes); learners (name and bio only) |
| Mandatory policy compliance | Policy acknowledgements, training completion records | Contract; Legal obligation | See Retention Schedule | Data Advisor; HR |
Your Obligations as a Data Processor
When you access learner data in the course of your services you are legally bound by Schedule 2 (Data Processing Agreement) of your Associate Framework Agreement. Key obligations:
-
-
- Process learner data only on IMI’s documented instructions and only to the minimum extent necessary for your services;
-
- Not transfer or process learner data outside the EEA without IMI’s prior written consent;
-
- Implement appropriate security measures to prevent unauthorised access to or loss of learner data;
-
- Not sub-contract any processing of learner data without IMI’s prior written approval;
-
- Notify IMI at [email protected] within 48 hours of becoming aware of any actual or suspected data breach involving learner data;
-
- Notify IMI at [email protected] within 48 hours of receiving any data subject rights request relating to learner data — take no action without IMI’s written instructions; and
-
- On termination of engagement, immediately destroy all learner data in your possession and certify that destruction in writing to IMI.
-
You must not retain learner assignments, grades, scripts or any other personal data beyond what is strictly necessary for an active assignment. Retaining learner data after your engagement ends is a breach of your Associate Framework Agreement and of data protection law.
Sharing of Your Data
Your name and professional biography may be shared with programme learners in connection with the programmes you deliver. Where you are engaged on a programme leading to an award of UCC, your name, qualifications and role will be shared with UCC in its capacity as awarding body for quality assurance and accreditation purposes. Your bank details and tax information are shared with the payroll provider and Revenue solely for payment purposes. Your data is not shared for commercial or marketing purposes.
Mandatory Policies
You are required under your Associate Framework Agreement to comply with IMI’s Mandatory Policies, including the Acceptable Use Policy. Current versions are available on the Canvas Associate Portal and at imi.ie.
Updating Your Details
Contact [email protected] or [email protected] at any time to update your personal details.
Section H: Suppliers and Contractors
This section applies to you if you, or the organisation you represent, supply goods or services to IMI under a contract or purchase order and are not covered by Section G. This includes facilities contractors, IT vendors, professional advisors, consultants, event management suppliers, and other third-party service providers.
What Data We Collect and Why
| Purpose | Data Collected | Lawful Basis | Retention | Recipients |
| Supplier and contract management | Name, job title, employer, business address, email, telephone, contract and purchase order records | Contract; Legitimate interests | See Retention Schedule | Relevant IMI department; legal advisors if required |
| Payment processing | Bank account details, payment records, invoices | Contract; Legal obligation | See Retention Schedule | IMI finance; payroll provider where applicable; Revenue Commissioners |
| Tax and regulatory compliance | Tax reference, VAT number, relevant statutory information | Legal obligation | See Retention Schedule | Revenue Commissioners |
| Due diligence and security | Identity verification, insurance certificates, accreditations | Legal obligation; Legitimate interests | See Retention Schedule | Relevant IMI department; insurers if required |
Data We Do Not Collect
IMI collects only the personal data of individual contacts within supplier organisations that is strictly necessary for managing the commercial relationship. IMI does not collect personal data about a supplier’s wider workforce unless directly relevant to the services being provided.
Data Processing Agreements
Where a supplier handles personal data belonging to IMI or its staff, learners or other stakeholders in the course of providing services, a written data processing agreement must be in place before any processing commences. If you are unsure whether this applies to your organisation, contact [email protected].
Updating Your Details
To update your contact or payment details held by IMI, contact the relevant IMI department or email [email protected].
Your Rights
All individuals whose personal data is processed by IMI have the following rights under GDPR and the Data Protection Act 2018, regardless of which section of this Statement covers your relationship with IMI. To exercise any right, contact the Data Advisor at [email protected] or write to IMI Leadership Limited, Sandyford Road, Dundrum, Dublin 14, with proof of your identity. IMI will respond within one calendar month. Where a request is complex or numerous, this may be extended by a further two months and you will be notified within the first month.
Right to Be Informed (Articles 13 and 14)
You have the right to clear, transparent information about how your personal data is processed. This Statement, together with the jointly approved UCC statement where applicable, fulfils that obligation.
Right of Access (Article 15)
You may request a copy of the personal data IMI holds about you, together with information about how it is used, who it is shared with, and how long it will be kept. Submit a written request to [email protected] with proof of identity. There is no charge for a first request. If you wish to know the names of specific organisations to whom your data has been disclosed, you may request this and IMI will provide it.
Right to Rectification (Article 16)
You may request correction of inaccurate or completion of incomplete personal data without undue delay. IMI will also inform any third parties to whom the data has been disclosed, unless this is impossible or involves disproportionate effort.
Right to Erasure (Article 17)
You may request deletion of your personal data where it is no longer necessary for the purpose collected, where you have withdrawn consent and no other basis applies, where you have objected and IMI has no overriding grounds, where processing has been unlawful, or where erasure is required by law. IMI will assess each request individually and explain where erasure is not possible.
Right to Restrict Processing (Article 18)
You may request that IMI restricts processing of your data in certain circumstances — for example while IMI verifies accuracy you have contested. IMI will inform you before any restriction is lifted.
Right to Data Portability (Article 20)
Where processing is based on consent or contract and carried out by automated means, you may request your data in a structured, machine-readable format, or ask that it be transmitted to another controller where technically feasible.
Right to Object — General (Article 21(1))
You may object to processing based on legitimate interests. IMI will cease that processing unless it can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or that the processing is necessary for a legal claim.
Right to Object — Direct Marketing (Article 21(2))
You have an absolute and unconditional right to object to processing of your personal data for direct marketing at any time. IMI must stop immediately upon receipt of your objection — there is no balancing test. To object, click unsubscribe in any marketing email or contact [email protected].
Rights in Relation to Automated Decision-Making (Article 22)
You have the right not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect on you. IMI does not engage in any such processing. If this changes, IMI will update this Statement, complete a DPIA, and ensure this right is fully protected before deployment.
Right to Withdraw Consent
Where IMI processes your data on the basis of consent, you may withdraw it at any time without affecting the lawfulness of prior processing. Contact [email protected] or use the unsubscribe mechanism in any consent-based communication.
Right to Know Named Recipients (Article 15 — Categories Edition)
This version lists categories of recipients rather than named organisations, permitted under Articles 13(1)(e) and 14(1)(e) GDPR. You have the right under Article 15 to request the identities of specific organisations to whom your personal data has been disclosed. Contact [email protected] with proof of identity.
Data Security
IMI implements appropriate technical and organisational measures to protect personal data against accidental loss, destruction, alteration, unauthorised disclosure or access. These include password protection and encryption of systems and devices, multi-factor authentication on key systems, restricted access on a need-to-know basis, secure physical disposal of documents, and written data processing agreements with all third-party processors.
All staff, faculty, associate faculty and relevant contractors are subject to data security obligations set out in their relevant section above and in the Acceptable Use Policy. Failure to comply may result in disciplinary action up to and including dismissal or termination of engagement.
Personal Data Breaches
A personal data breach is any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. All staff, faculty and associate faculty must report any actual or suspected breach to [email protected] immediately. Associate faculty must do so within 48 hours as required by their Data Processing Agreement. The full procedure is set out in IMI’s Personal Data Breach Management Procedure.
If you become aware of any actual or suspected data breach — including loss or theft of a device, an email sent to the wrong person, or any unauthorised access to personal data — report it to [email protected] immediately. Do not wait. Do not attempt to resolve it yourself.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, IMI will notify the Data Protection Commission within 72 hours of becoming aware. Where there is a high risk to individuals, IMI will also notify those individuals without undue delay.
How to Make a Complaint
If you believe your data protection rights have been infringed, contact the Data Advisor at [email protected] in the first instance. IMI will acknowledge your concern promptly and work to resolve it.
If you remain unsatisfied, you have the right — without prejudice to any other administrative or judicial remedy — to lodge a complaint with the Data Protection Commission (DPC):
| Data Protection Commission | |
| Address | 21–25 Canal Road, Dublin 6, D06 F46E |
| Website | www.dataprotection.ie |
| Phone | +353 57 868 4800 |
You also have the right to an effective judicial remedy against IMI as controller, or against the DPC if you consider it has failed to handle a complaint properly, without prejudice to any other administrative or judicial remedy available to you under Article 79 GDPR.
Review of This Statement
This Statement is reviewed annually by the Data Advisor and updated as required to reflect changes in law, regulatory guidance, or IMI’s operations. Material changes — including any change to the identity of the controller, processing purposes, or how data subject rights can be exercised — will be communicated to data subjects before taking effect. Printed or locally saved copies are uncontrolled. Always refer to imi.ie for the latest version.
Governing Law
This Statement is governed by the laws of Ireland. Any dispute arising from or in connection with IMI’s processing of personal data shall be subject to the exclusive jurisdiction of the Irish courts, without prejudice to your right to lodge a complaint with the Data Protection Commission or to seek any other administrative or judicial remedy available under GDPR.