Privacy Statement for Participants on Programmes Leading to UCC awards, click here

Privacy Statement for Participants on Programmes Leading to IMI electronic certification, click here

 

About IMI and This Statement

IMI Leadership Limited (company number 714739) is a private limited company incorporated in Ireland, registered at Sandyford Road, Dundrum, Dublin 14. IMI is a subsidiary of Business Post Group (Business Post Group). IMI does not systematically share personal data with Business Post Group but may on a case-by-case basis share personal data where there is a legitimate reason and/or your consent has been obtained.

 

IMI’s Primary Privacy Statement

This is IMI’s primary Integrated Privacy Statement, covering IMI’s own independent processing activities across all audience groups. A separate, jointly approved Privacy Statement also exists for learners on IMI programmes leading to an award of UCC: “IMI Privacy Statement for Learners undertaking Executive Development Programmes leading to Awards of University College Cork.” That document is maintained jointly with UCC as required by the Joint Controller Agreement dated 24 February 2026 and governs the jointly controlled processing for those programmes. Learners on programmes leading to a UCC award should read both documents — this Statement for IMI’s independent processing, and the jointly approved statement for the jointly controlled processing. Where the two address the same matter in respect of UCC-award programme processing, the jointly approved statement prevails. This Statement replaces and supersedes all previous separate IMI privacy notices for audiences other than learners on programmes leading to UCC awards.

 

This Statement is issued in compliance with the EU General Data Protection Regulation (GDPR) 2016/679, the Data Protection Act 2018 (Ireland), the Irish ePrivacy Regulations 2011 (S.I. 336/2011), and, where relevant, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). IMI has regard to guidance issued by the Data Protection Commission (DPC).

This Statement is made available to each audience group as follows: to programme learners at or before enrolment; to staff and faculty at the start of employment or engagement and as part of induction; to associate faculty with their Associate Framework Agreement; to suppliers at or before contracting; and to members of the public at imi.ie. Where IMI obtains personal data indirectly, you will be informed within one month of IMI obtaining that data (see ‘Data Obtained Indirectly’ below).

IMI is not required to appoint a Data Protection Officer. IMI has appointed a Data Advisor who oversees compliance with data protection law and is the primary point of contact for all data protection queries, rights requests and breach reports:

 

Data Advisor  Dr. Mark Glynn 
Email  [email protected] 
Post  IMI Leadership Limited, Sandyford Road, Dundrum, Dublin 14 
Supervisory Authority  Data Protection Commission │ www.dataprotection.ie │ 21–25 Canal Road, Dublin 6, D06 F46E │ +353 57 868 4800 

 

IMI is the data controller for all personal data described in this Statement. For programmes leading to an award of UCC, IMI and UCC act as joint controllers for defined academic purposes only — the scope is described in Section A and in the jointly approved statement. 

This Statement is structured in sections, one for each audience group. Please go directly to the section that applies to you. The IMI Knowledge Centre library service (library.imi.ie) does not have a separate privacy notice — it is fully covered by this Statement. Learner and staff library data is covered by the relevant audience section. Members of the public requesting access to controlled-access theses are covered by Section F. For Knowledge Centre queries contact [email protected]. 

 

Contents

    1. About IMI and This Statement
    2. How IMI Uses Your Data – The Data Protection Principles
    3. The Lawful Basis for Processing
    4. Direct Marketing and ePrivacy
    5. Children and Young Persons
    6. How Long IMI Keeps Your Data
    7. Data Obtained Indirectly
    8. Third Parties and Data Sharing

Section A: Learners on IMI Programmes Leading to an Award of UCC

Section B: Learners on Programmes Leading to IMI Electronic Certification

Section C: External Examiners

Section D: Recruitment Applicants

Section E: Staff and Faculty

Section F: Website Visitors, Members of the Public and Visitors to IMI Premises

Section G: Associate Faculty

Section H: Suppliers and Contractors

9. Your Rights

10. Data Security
11. Personal Data Breaches
12. How to Make a Complaint
13. Review of This Statement
14. Governing Law

 

How IMI Uses Your Data — the Data Protection Principles

IMI is legally bound by all seven data protection principles in Article 5 GDPR and is accountable for demonstrating compliance with each of them: 

 

      • Lawfulness, fairness and transparency: IMI processes your data lawfully, fairly and transparently. This Statement is how IMI meets its transparency obligation. 
      • Purpose limitation: IMI collects data for specific, explicit and legitimate purposes and will not use it for any incompatible purpose. If IMI wishes to use your data for a new purpose it will inform you and, where required, seek a fresh lawful basis or your consent. 
      • Data minimisation: IMI collects only data that is adequate, relevant and strictly necessary for each purpose. 
      • Accuracy: IMI takes reasonable steps to ensure data is accurate and up to date. If your details change, please notify IMI promptly using the contact in your relevant section below. 
      • Storage limitation: IMI retains data only for as long as necessary or as required by law or accreditation obligations. Retention periods are in the IMI Data Retention Schedule, available from [email protected]. 
      • Integrity and confidentiality: IMI implements appropriate technical and organisational security measures. This is a legal obligation under Article 5(1)(f) GDPR, not merely good practice. 
      • Accountability: IMI takes responsibility for compliance with all the above principles and maintains records, policies, procedures and data protection impact assessments to demonstrate that compliance. The Data Advisor oversees accountability. 

 

The Lawful Basis for Processing

IMI only processes personal data where there is a lawful basis under Article 6 GDPR: 

 

      • Contract (Article 6(1)(b)): processing is necessary to perform a contract with you or to take steps at your request before entering one. 
      • Legal obligation (Article 6(1)(c)): processing is required by EU or Irish law — for example, payroll tax reporting, employment law compliance, or regulatory reporting to QQI or HEA. 
      • Legitimate interests (Article 6(1)(f)): processing is necessary for IMI’s legitimate interests, provided those interests are not overridden by your rights. Where IMI relies on this basis, a record of the balancing test is maintained by the Data Advisor and available on request from [email protected]. 
      • Consent (Article 6(1)(a)): you have given freely given, specific, informed and unambiguous consent — for example, for direct marketing or for the recording of sessions. You may withdraw consent at any time without affecting the lawfulness of prior processing. To withdraw consent, contact [email protected]. 

 

For special category data (such as health information), IMI relies on additional conditions under Article 9 GDPR. The most common condition is Article 9(2)(b) GDPR read with Schedule 2(1) of the Data Protection Act 2018 — processing necessary to carry out obligations under employment law, including the Organisation of Working Time Act 1997, the Safety, Health and Welfare at Work Act 2005, and the Workplace Relations Act 2015. Where no employment law condition applies, explicit consent under Article 9(2)(a) GDPR will be sought. 

 

Automated Decision-Making, Profiling and AI — Article 13(2)(f) / 14(2)(g) GDPR 

IMI does not engage in any automated decision-making or profiling in relation to learners, staff, applicants or any other individuals. No decision producing a legal or similarly significant effect on you is made solely by automated means — all decisions are made by trained human staff. IMI does not currently use artificial intelligence tools in any processing activity involving your personal data. If this changes, this Statement will be updated, a DPIA completed, and you will be informed before any such system is deployed. Your right under Article 22 GDPR not to be subject to solely automated decisions is set out in the Your Rights section below. 

 

Direct Marketing and ePrivacy 

IMI may send you information about programmes, events, research and other IMI activities by email or other electronic means where you have given your consent to receive such communications. 

 

You have an absolute and unconditional right under Article 21(2) GDPR and the Irish ePrivacy Regulations 2011 to object to processing of your personal data for direct marketing at any time. IMI will stop sending marketing communications immediately upon receiving your objection — there is no balancing test. To opt out, click the unsubscribe link in any marketing email or contact [email protected]. 

 

IMI’s use of cookies and similar technologies on imi.ie is governed by the Cookie Policy at imi.ie, which sets out which cookies require consent and how to manage preferences. The Cookie Policy is updated whenever IMI’s use of cookies changes — refer to the live version at imi.ie. 

 

Children and Young Persons 

IMI’s programmes and services are directed at senior professionals and adult learners. IMI does not knowingly collect or process personal data of individuals under the age of 18. If you believe IMI has inadvertently collected data relating to a person under 18, contact [email protected] immediately. 

 

How Long IMI Keeps Your Data 

Retention periods are set out in the IMI Data Retention Schedule, which reflects applicable legal, regulatory and accreditation requirements including AACSB accreditation, Revenue and tax law, employment law, and QQI quality assurance requirements. The Schedule is maintained by the Data Advisor and available on request from [email protected]. When data is no longer required it is securely deleted or anonymised. 

 

Data Obtained Indirectly 

In some circumstances IMI receives personal data about you from a third party rather than directly from you. This occurs in the following contexts: 

 

      • References: where you apply for a role at IMI and provide the names of referees, IMI will obtain a reference. You will be asked to confirm that referees are aware their details are being provided. 
      • Employer or sponsor nomination: where your employer or a sponsoring organisation enrols you on an IMI programme or provides information about you as part of a commissioning or sponsorship arrangement. 
      • External Examiner nomination: where an academic or professional body nominates you as External Examiner, your details will be provided to IMI by that body. 
      • Supplier contact details: where a supplier organisation provides the contact details of its staff as part of a contracting or procurement process. 

 

In each case, IMI will inform you that it holds your data, the source from which it was obtained, and the purposes for which it will be used within one month of first obtaining it, or at the point of first contact with you, whichever is sooner. Contact [email protected] with any queries. 

 

Third Parties and Data Sharing 

IMI shares personal data only where necessary. The principal categories of organisations with whom IMI shares data are set out below. All processors are engaged under written data processing agreements and are required to process data only on IMI’s instructions, implement appropriate security measures, and not transfer data outside the EEA without IMI’s prior written consent. The full list of named processors is available on request from [email protected]. 

 

Category of Recipient  Location / Transfer Mechanism 
HR and workforce management system provider  EEA and UK (adequacy decision) 
Outsourced payroll and tax administration provider  EEA (Ireland) 
Pension scheme administrator  EEA (Ireland) 
Group health insurance and employee assistance provider  EEA (Ireland) 
IT security and compliance training platform provider  EEA 
Digital credentialing and certification platform  Outside EEA — EU Standard Contractual Clauses 
Virtual Learning Environment provider  Outside EEA — EU Standard Contractual Clauses 
Online session recording and storage providers  Outside EEA — EU Standard Contractual Clauses 
Website analytics provider  See Cookie Policy at imi.ie 
Regulatory and statutory authorities (Revenue, QQI, HEA)  EEA (Ireland) — statutory recipients, not processors 
Programme delivery partners (selected programmes)  EEA (Ireland) — programme logistics only 
Thesis/dissertation repository platform provider  Location/transfer mechanism to be confirmed — contact [email protected] 
Corporate parent group  EEA (Ireland) — case-by-case only 
Joint controller for programmes leading to UCC awards  EEA (Ireland) — UCC, for defined academic purposes under JCA dated 24 February 2026. Contact [email protected]. 

 

Note on Recipients 

Under Articles 13(1)(e) and 14(1)(e) GDPR, IMI may lawfully provide categories of recipients rather than named recipients. The full list of named processors is maintained internally and available on request from [email protected]. Where a named recipient is required to exercise a data subject right, IMI will provide names upon request per Article 15 GDPR. 

 

IMI does not sell personal data or share it for commercial or marketing purposes with any organisation outside those required to administer its activities. 

 

Section A: Learners on IMI Programmes Leading to an Award of UCC

A dedicated privacy policy is in place for learners on programmes leading to awards of UCC.  Please refer to that statement.  This section solely indicates matters over which IMI has obligations in the context of its relationship with University College Cork (UCC). 

 

Read the jointly approved statement 

The jointly controlled processing of your personal data by IMI and UCC is governed by the separately issued and jointly approved “IMI Privacy Statement for Learners undertaking Executive Development Programmes leading to Awards of University College Cork.” That document sets out the scope of joint control, the data collected for jointly controlled purposes, and your data subject rights in respect of that processing. It is available from your Programme Director and at imi.ie.  This section of the Integrated Statement covers only IMI’s independent processing activities in relation to you as a learner. For jointly controlled processing, please refer to the jointly approved statement. 

 

Accreditation Transition 

IMI was acquired by the Business Post Group in April 2025. UCC continues to make awards in respect of IMI programmes and remains a joint controller for those programmes. Under the Joint Controller Agreement (24 February 2026), joint control continues for any learner enrolled prior to any cessation of collaboration, solely for completing their programme, assessment, certification and academic record retention. Joint control does not extend to new enrolments following any such cessation. IMI will communicate any material change to IMI’s own processing that affects enrolled learners before it takes effect. For changes to UCC’s processing, refer to UCC’s Privacy Statement at ucc.ie/en/ocla/comp/data/dataprotection/. 

 

IMI’s Independent Processing 

The following table sets out the personal data IMI processes in its capacity as independent data controller for learners on IMI programmes leading to an award of UCC. This processing is separate from, and in addition to, the jointly controlled processing described in the jointly approved statement. 

 

Purpose  Data Collected  Lawful Basis  Retention  Recipients 
Enrolment administration (IMI systems)  Name, contact details, date of birth, previous qualifications, employer details where relevant to sponsorship  Contract  See Retention Schedule  IMI staff only — data shared with UCC only to extent required under the joint controller agreement; see jointly approved statement 
VLE access and management  Login credentials, access logs, submitted materials  Contract  See Retention Schedule  Programme Director; IMI IT; Canvas LMS 
Session recordings  Audio/video recordings of workshops, assessments and reflection sessions  Consent  See Retention Schedule  Programme team; External Examiner (assessment only); Zoom; Vimeo 
Thesis/dissertation deposit  Name, email, course, dissertation title, supervisor name; chosen access level; thesis content (may include third-party personal data)  Contract; Legitimate interests (research preservation)  Duration of repository holding — see Retention Schedule  Knowledge Centre staff; researchers granted controlled access; repository platform provider 
Payment of programme fees  Payment details (EFT, card or cheque); invoicing and instalment records  Contract; Legal obligation  See Retention Schedule  IMI finance; payment card processor; Revenue Commissioners 
Alumni engagement  Name, email, programme, graduation date  Consent  See Retention Schedule  IMI communications team 
Employer/corporate sponsorship  Name, programme, attendance and engagement data  Contract; Consent where personal data shared with sponsor  See Retention Schedule  Sponsoring employer only where written agreement in place 

 

For academic records held by UCC in its capacity as awarding body — including the official UCC academic record, conferring records and regulatory reporting — contact UCC directly at [email protected] or consult UCC’s Privacy Statement. 

 

Thesis and Dissertation Deposit 

Where your programme requires the submission of a thesis or dissertation, you will be asked to sign a Thesis and Dissertation Deposit Agreement before submitting your work to the IMI Knowledge Centre repository. The personal data collected includes your name, email address, course, dissertation title, and supervisor name. This data is collected on the basis of contract and retained for as long as your thesis remains in the IMI repository. 

 You must select an access level at deposit: Open Access, Controlled Access, Restricted Access, Embargoed or Redaction. Where you select Controlled Access, researchers requesting access will receive citation information only and must agree to a copyright declaration. A citation remains visible even where access to the full text is restricted. 

 Your thesis may contain personal data about third parties — for example research learners or individuals featured in recordings or photographs. You are responsible for ensuring appropriate consents are in place. By signing the Deposit Agreement you warrant that written consents from persons featured in recordings or photographs are held and available for inspection. IMI processes any such third-party data only in accordance with the access level you have selected.  

You retain copyright in your thesis. The licence granted to IMI is non-exclusive and royalty-free. IMI may reformat or migrate your thesis for preservation purposes without changing its content. To exercise any data subject right in connection with your thesis deposit, contact [email protected] or [email protected]. 

 

Virtual Learning Environment 

You do not retain perpetual access to the VLE after your programme ends. Once your last assignment is submitted, download any materials you wish to keep. The VLE is not a permanent storage facility. 

 

Assignments and Examination Scripts 

All submitted assignments and examination scripts are stored on the password-protected VLE. Access is restricted to the Programme Director, grading faculty, associate faculty in a grading role, and the appointed External Examiner. You are advised to retain electronic copies of your own work. Assignments and examination scripts are retained in accordance with the IMI Data Retention Schedule, which reflects AACSB accreditation requirements. Any psychometric reports used on the programme will be stored only for the duration of the programme and destroyed thereafter. 

In line with GDPR, please anonymise any third parties referenced in written assignments — do not use actual names of individuals without their consent. Job titles and organisational roles do not need to be anonymised. 

 

Recording of Sessions 

Presentations, workshops and assessments may be recorded for quality, research, distribution or assessment purposes. IMI’s Recording of Sessions Policy (available on the VLE and from your Programme Director) governs how recordings are made, stored, accessed and deleted. Key points: 

 

      • Online workshops: The session invitation will state that recording will take place. By joining you give consent. You will be reminded at the start. Recordings are held on the Zoom server then stored on Vimeo. 
      • In-person workshops: All learners must be advised in advance and provide written permission. If you object, notify the Programme Director before the session. Recording pauses for commercially sensitive content. Recordings are uploaded to a secure server and deleted from the device immediately after. 
      • Assessment recordings: Access is limited to the Programme Director, Programme Co-ordinator, relevant External Examiner or moderator, and the delivering Associate Faculty member. Not published on the VLE. 
      • Reflection recordings: Access is restricted to those present, the Programme Director and Programme Co-ordinator only. Must not be shared with anyone else. 

 

You must not copy, download or further distribute any recording of a session. Recordings are personal data and must be treated accordingly. 

 

Group Work 

Where your programme requires group work, the Programme Co-ordinator may share the email addresses of your study group with each other to facilitate group assignments. If you object, notify the Programme Co-ordinator before or on the first day of your programme. 

 

Ethics and Research 

If your programme requires you to collect personal data from individuals as part of research or an assignment, you must comply with IMI’s Ethics Policy and Procedure. Details are available via the VLE or from your Programme Director. 

 

Employer and Corporate Sponsorship 

If your employer is funding your participation and you have agreed that your employer may access some or all of your personal data, you must provide a copy of the relevant approval letter and details of the data sharing arrangement before your programme commences. Where IMI is delivering a corporate or custom programme commissioned by your employer, your employer may receive programme-level attendance and engagement data as set out in the programme agreement — you will be informed of this at enrolment. 

 

 

Section B: Learners on Programmes Leading to IMI Electronic Certification 

This section applies to you if you are an applicant to, or learner on, an executive development programme leading to IMI electronic certification. IMI is the sole data controller for these programmes. Your data is not shared with UCC and UCC has no role in the processing of your personal data. 

 

What Data We Collect and Why 

Purpose  Data Collected  Lawful Basis  Retention  Recipients 
Enrolment and administration  Name, contact details, date of birth, previous qualifications, employer details where relevant  Contract; Legal obligation  See Retention Schedule  IMI staff only 
Assessment and grading  Assignments, grades, attendance, moderation records  Contract  See Retention Schedule  Programme Director; External Examiner; Associate Faculty (grading) 
Reasonable accommodation  Health or disability information, medical certificates  Legal obligation; Explicit consent  See Retention Schedule  Occupational health provider where applicable 
Session recordings  Audio/video recordings of workshops, assessments and reflection sessions  Consent  See Retention Schedule  Programme team; External Examiner (assessment only); Zoom; Vimeo 
Payment of programme fees  Payment details (EFT, card or cheque); invoicing and instalment records  Contract; Legal obligation  See Retention Schedule  IMI finance; payment card processor; Revenue Commissioners 
Alumni engagement  Name, email, programme completed, completion date  Consent  See Retention Schedule  IMI communications team 
Certification  Name, programme, completion date  Contract  See Retention Schedule  Parchment (digital credentials) 
Employer/corporate sponsorship  Name, programme, attendance and engagement data  Contract; Consent where personal data shared with sponsor  See Retention Schedule  Sponsoring employer only where written agreement in place 

 

Other Provisions 

The provisions set out below — Virtual Learning Environment, Assignments and Examination Scripts, Recording of Sessions, Group Work, Ethics and Research, and Employer and Corporate Sponsorship — apply equally to learners on IMI-certified programmes. 

 

Virtual Learning Environment

You do not retain perpetual access to the VLE after your programme ends. Once your last assignment is submitted, download any materials you wish to keep. The VLE is not a permanent storage facility. 

 

Assignments

All submitted assignments are stored on the password-protected VLE. Access is restricted to the Programme Director, grading faculty, associate faculty in a grading role, and the appointed External Examiner. You are advised to retain electronic copies of your own work. Assignments and examination scripts are retained in accordance with the IMI Data Retention Schedule.  Any psychometric reports used on the programme will be stored only for the duration of the programme and destroyed thereafter. 

In line with GDPR, please anonymise any third parties referenced in written assignments — do not use actual names of individuals without their consent. Job titles and organisational roles do not need to be anonymised. 

 

Recording of Sessions 

Presentations, workshops and assessments may be recorded for quality, research, distribution or assessment purposes. IMI’s Recording of Sessions Policy (available on the VLE and from your Programme Director) governs how recordings are made, stored, accessed and deleted. Key points: 

 

      • Online workshops: The session invitation will state that recording will take place. By joining you give consent. You will be reminded at the start. Recordings are held on the Zoom server then stored on Vimeo. 
      • In-person workshops: All learners must be advised in advance and provide written permission. If you object, notify the Programme Director before the session. Recording pauses for commercially sensitive content. Recordings are uploaded to a secure server and deleted from the device immediately after. 
      • Assessment recordings: Access is limited to the Programme Director, Programme Co-ordinator, relevant External Examiner or moderator, and the delivering Associate Faculty member. Not published on the VLE. 
      • Reflection recordings: Access is restricted to those present, the Programme Director and Programme Co-ordinator only. Must not be shared with anyone else. 

 

You must not copy, download or further distribute any recording of a session. Recordings are personal data and must be treated accordingly. 

 

Group Work 

Where your programme requires group work, the Programme Co-ordinator may share the email addresses of your study group with each other to facilitate group assignments. If you object, notify the Programme Co-ordinator before or on the first day of your programme. 

 

Ethics and Research 

If your programme requires you to collect personal data from individuals as part of research or an assignment, you must comply with IMI’s Ethics Policy and Procedure. Details are available via the VLE or from your Programme Director. 

 

Employer and Corporate Sponsorship 

If your employer is funding your participation and you have agreed that your employer may access some or all of your personal data, you must provide a copy of the relevant approval letter and details of the data sharing arrangement before your programme commences. Where IMI is delivering a corporate or custom programme commissioned by your employer, your employer may receive programme-level attendance and engagement data as set out in the programme agreement — you will be informed of this at enrolment. 

 

 

Section C: External Examiners 

This section applies to you if you have been nominated or appointed as an External Examiner at IMI. 

 

What Data We Collect and Why 

Purpose  Data Collected  Lawful Basis  Retention  Recipients 
Appointment and engagement  Name, CV, current employer, qualifications, expertise, residency and citizenship status  Contract; Legal obligation (QA requirements)  See Retention Schedule  QQI; UCC (programmes leading to UCC awards only); Programme Director 
Payment of fees and expenses  Bank account details, tax reference  Contract; Legal obligation  See Retention Schedule  IMI’s bank; Revenue Commissioners 
QA transparency  Name, qualifications, institution — disclosed to learners  Legal obligation (QA transparency)  See Retention Schedule  Programme learners (name, qualifications and institution only) 
External Examiner Reports  Report contents (may reference learner performance)  Legal obligation  See Retention Schedule  Internal academic staff; QQI; learners where QA frameworks require 

 

A Note on External Examiner Reports 

External Examiner Reports are quality assurance documents. They may be shared by IMI with internal academic committees, and awarding bodies in accordance with quality assurance requirements. They are shared with learners only to the extent required by applicable QA frameworks. 

 

Updating Your Details 

Contact [email protected] at any time to update your details. 

 

 

Section D: Recruitment Applicants 

This section applies to you if you have applied, or are applying, for a role at IMI. If appointed, Section E will apply from the date of your appointment. 

 

What Data We Collect and Why 

Purpose  Data Collected  Lawful Basis  Retention  Recipients 
Processing your application  Name, address, CV, cover letter, application form responses, interview notes and scoring sheets  Legitimate interests  See Retention Schedule  Recruiting panel; HR 
Right-to-work verification  Passport or travel document, visa or permit details  Legal obligation — collected at conditional offer stage only  See Retention Schedule  HR; immigration authorities if required 
References  Content provided by named referees  Legitimate interests; Consent  See Retention Schedule  Recruiting panel; HR 

 

IMI does not use automated screening tools or artificial intelligence at any stage of its recruitment or selection process. All decisions are made by trained human staff. 

 

Retention 

If your application is unsuccessful, your recruitment file is securely deleted one year after the conclusion of the process. If you are appointed, your file is retained as part of your personnel record in accordance with the Data Retention Schedule. 

 

References 

IMI will seek your written consent before approaching any referee. We do not ask you to include references on application forms. 

 

Your Right to Withdraw 

You may withdraw your application at any time by contacting [email protected]. Your data will be deleted promptly unless IMI has a legal obligation to retain it. 

 

 

Section E: Staff and Faculty 

This section applies to all current and former IMI staff and faculty, including permanent and fixed-term employees, placement students and volunteers. This Statement is the complete privacy notice for staff and faculty — no separate staff privacy policy is issued. 

 

When You Will Receive This Statement 

      • On commencement of employment — provided as part of your induction. 
      • When new categories of personal data are collected — you will be informed at the time. 

 

What Data We Collect and Why 

Purpose  Data Collected  Lawful Basis  Retention  Recipients 
Employment contracts and workforce administration  Name, address, contact details, next of kin, job title, contract terms, salary, qualifications  Contract; Legal obligation  See Retention Schedule  Revenue; Department of Social Protection; pension provider 
Payroll and tax  PPS number, bank account details, tax codes, salary, statutory payments  Legal obligation  See Retention Schedule  Payroll provider; Revenue; Department of Social Protection 
Pensions and employee benefits  Name, salary, pension contributions, health insurance enrolment  Contract; Legal obligation  See Retention Schedule  Pension administrator; health insurance provider 
Right-to-work verification  Passport or travel document, visa or permit details  Legal obligation  See Retention Schedule  Immigration authorities if required 
Sickness absence and health  Medical certificates, self-certification, occupational health referrals  Legal obligation — Article 9(2)(b) GDPR and Schedule 2(1) Data Protection Act 2018  See Retention Schedule  Occupational health provider; HR 
Disciplinary, grievance and performance  Records of proceedings, correspondence, outcomes  Legal obligation; Legitimate interests  See Retention Schedule  Legal advisors (if claim arises); WRC or Labour Court (if required) 
Annual and statutory leave  Leave taken, types, dates  Legal obligation (Organisation of Working Time Act 1997)  See Retention Schedule  HR management system provider 
Training records  Training completed, dates, outcomes  Legal obligation; Contract  See Retention Schedule  IT security training platform provider; HR 
Building access and IT monitoring  Door swipe card logs, IT system access logs — security purposes only  Legitimate interests (security and system integrity)  See Retention Schedule  IT department; Data Advisor (on investigation only) 
Health and safety  Accident reports, risk assessments, occupational health records  Legal obligation  See Retention Schedule  Health and Safety Authority (if required); insurers 

 

Health Data 

Health information is processed only where necessary for sickness absence management or to determine and implement reasonable adjustments. The lawful basis is Article 9(2)(b) GDPR read with Schedule 2(1) of the Data Protection Act 2018, which permits processing necessary to carry out obligations under employment law, including the Organisation of Working Time Act 1997, the Safety, Health and Welfare at Work Act 2005, and the Workplace Relations Act 2015. Where no employment law condition applies, explicit consent under Article 9(2)(a) GDPR will be sought. 

 

Building Access and IT Monitoring 

IMI collects building access card logs and IT system access logs for the purpose of physical and information security only. The lawful basis is legitimate interests (Article 6(1)(f) GDPR). This data will not be repurposed — for example, it will not be used routinely to monitor attendance or performance. Access is restricted to the IT department and, where a formal investigation requires it, the Data Advisor and relevant management. 

 

Data Security Responsibilities 

All staff and faculty who handle personal data must: 

 

      • Store confidential files securely and not leave them accessible to unauthorised persons; 
      • Use strong passwords and not share them; 
      • Lock computers when away from their desks; 
      • Not transfer personal data to personal email accounts or unauthorised devices; 
      • Password-protect confidential email attachments and send the password by a separate means; 
      • Use the Bcc field when emailing groups where recipients do not know each other; and 

 

Full obligations are set out in the Acceptable Use Policy. Failure to comply may result in disciplinary action up to and including dismissal. 

 

Remote Working and Personal Devices 

When working remotely you must lock your device, ensure screens cannot be overlooked, and save work to IMI systems promptly. Personal devices may not be used to access, process or store IMI personal data without prior written authorisation from your line manager and the IT department. Staff working outside the EEA will have no access to IMI personal data for the duration of that period. 

 

 

Section F: Website Visitors, Members of the Public and Visitors to IMI Premises 

This section applies to you if you visit imi.ie, contact IMI as a member of the public, or visit IMI’s premises at Sandyford Road, Dundrum, Dublin 14. 

 

Website and Online Enquiries 

Purpose  Data Collected  Lawful Basis  Retention  Recipients 
Website operation and analytics  IP address, browser type, OS, clickstream data, session duration, cookie identifiers  Legitimate interests (functionality); Consent (non-essential cookies)  See Retention Schedule  Analytics provider — see Cookie Policy at imi.ie 
Responding to enquiries  Name, email, telephone, content of enquiry  Legitimate interests; Consent (where marketing follow-up agreed)  See Retention Schedule  Relevant IMI team 
Event registration  Name, email, employer, role, dietary or access requirements  Contract; Consent (marketing)  See Retention Schedule  Event management team; venue (dietary and access needs only) 
Content download and podcast forms  Name, email, employer role where submitted via imi.ie  Consent  See Retention Schedule  Relevant IMI team; CRM platform provider 
Controlled-access thesis requests  Name and copyright declaration agreement of researchers requesting access to restricted theses  Legitimate interests (administration of controlled access)  See Retention Schedule  Knowledge Centre staff only 

 

IMI does not use website data to make automated decisions about you. The Cookie Policy at imi.ie provides full details on cookies IMI uses, the analytics and third-party services employed, and how to manage your preferences. Please refer to the live version at imi.ie rather than any saved copy. 

 

By using imi.ie you accept IMI’s Terms and Conditions of Website Use. 

 

CCTV 

IMI operates CCTV at its premises at Sandyford Road, Dundrum, Dublin 14, for the purposes of the security of persons and property and the prevention and detection of crime. The lawful basis is legitimate interests (Article 6(1)(f) GDPR). CCTV footage is retained for a period set out in the Data Retention Schedule. Access is restricted to the Head of Facilities and, where a security incident or formal investigation requires it, the Data Advisor and relevant management. CCTV footage will not be used for any other purpose, including performance monitoring. To exercise a data subject right in respect of CCTV footage, contact [email protected] with proof of identity and details of the date, time and location of your visit. 

 

 

Section G: Associate Faculty 

This section applies to you if you are engaged by IMI as an associate faculty member under an Associate Framework Agreement. It covers both the personal data IMI holds about you, and your obligations as a data processor when you access learner data in the course of your services. 

 

Your Dual Role: Data Subject and Data Processor 

      • As a data subject: IMI holds personal data about you to administer your engagement, make payments and manage programme quality. Your data subject rights apply in full to this data. 
      • As a data processor: When you access personal data relating to IMI’s programme learners in the course of your services — for example reviewing assignments, recording grades or facilitating recorded sessions — you act as a data processor on IMI’s behalf. You process that data only on IMI’s instructions, as set out in Schedule 2 of your Associate Framework Agreement. 

 

What Data IMI Holds About You 

Purpose  Data Collected  Lawful Basis  Retention  Recipients 
Engagement, contracting and onboarding  Name, address, contact details, photographic identification, right-to-work documentation  Contract; Legal obligation  See Retention Schedule  HR; legal advisors if required 
Payment of fees and payroll taxes  Bank account details, tax reference, PAYE/PRSI/USC records  Contract; Legal obligation  See Retention Schedule  Payroll provider; Revenue Commissioners 
Programme delivery and quality assurance  Qualifications, expertise, VLE access records, delivery feedback, learner evaluation scores  Contract; Legitimate interests (quality)  See Retention Schedule  Programme Directors; UCC (programmes leading to UCC awards only — name, qualifications and role for QA purposes); learners (name and bio only) 
Mandatory policy compliance  Policy acknowledgements, training completion records  Contract; Legal obligation  See Retention Schedule  Data Advisor; HR 

 

Your Obligations as a Data Processor 

When you access learner data in the course of your services you are legally bound by Schedule 2 (Data Processing Agreement) of your Associate Framework Agreement. Key obligations: 

 

      • Process learner data only on IMI’s documented instructions and only to the minimum extent necessary for your services; 
      • Not transfer or process learner data outside the EEA without IMI’s prior written consent; 
      • Implement appropriate security measures to prevent unauthorised access to or loss of learner data; 
      • Not sub-contract any processing of learner data without IMI’s prior written approval; 
      • Notify IMI at [email protected] within 48 hours of becoming aware of any actual or suspected data breach involving learner data; 
      • Notify IMI at [email protected] within 48 hours of receiving any data subject rights request relating to learner data — take no action without IMI’s written instructions; and 
      • On termination of engagement, immediately destroy all learner data in your possession and certify that destruction in writing to IMI. 

 

You must not retain learner assignments, grades, scripts or any other personal data beyond what is strictly necessary for an active assignment. Retaining learner data after your engagement ends is a breach of your Associate Framework Agreement and of data protection law. 

 

Sharing of Your Data 

Your name and professional biography may be shared with programme learners in connection with the programmes you deliver. Where you are engaged on a programme leading to an award of UCC, your name, qualifications and role will be shared with UCC in its capacity as awarding body for quality assurance and accreditation purposes. Your bank details and tax information are shared with the payroll provider and Revenue solely for payment purposes. Your data is not shared for commercial or marketing purposes. 

 

Mandatory Policies 

You are required under your Associate Framework Agreement to comply with IMI’s Mandatory Policies, including the Acceptable Use Policy. Current versions are available on the Canvas Associate Portal and at imi.ie. 

 

Updating Your Details 

Contact [email protected] or [email protected] at any time to update your personal details. 

 

 

Section H: Suppliers and Contractors 

This section applies to you if you, or the organisation you represent, supply goods or services to IMI under a contract or purchase order and are not covered by Section G. This includes facilities contractors, IT vendors, professional advisors, consultants, event management suppliers, and other third-party service providers. 

 

What Data We Collect and Why 

Purpose  Data Collected  Lawful Basis  Retention  Recipients 
Supplier and contract management  Name, job title, employer, business address, email, telephone, contract and purchase order records  Contract; Legitimate interests  See Retention Schedule  Relevant IMI department; legal advisors if required 
Payment processing  Bank account details, payment records, invoices  Contract; Legal obligation  See Retention Schedule  IMI finance; payroll provider where applicable; Revenue Commissioners 
Tax and regulatory compliance  Tax reference, VAT number, relevant statutory information  Legal obligation  See Retention Schedule  Revenue Commissioners 
Due diligence and security  Identity verification, insurance certificates, accreditations  Legal obligation; Legitimate interests  See Retention Schedule  Relevant IMI department; insurers if required 

 

Data We Do Not Collect 

IMI collects only the personal data of individual contacts within supplier organisations that is strictly necessary for managing the commercial relationship. IMI does not collect personal data about a supplier’s wider workforce unless directly relevant to the services being provided. 

 

Data Processing Agreements 

Where a supplier handles personal data belonging to IMI or its staff, learners or other stakeholders in the course of providing services, a written data processing agreement must be in place before any processing commences. If you are unsure whether this applies to your organisation, contact [email protected]. 

 

Updating Your Details 

To update your contact or payment details held by IMI, contact the relevant IMI department or email [email protected]. 

 

 Your Rights 

All individuals whose personal data is processed by IMI have the following rights under GDPR and the Data Protection Act 2018, regardless of which section of this Statement covers your relationship with IMI. To exercise any right, contact the Data Advisor at [email protected] or write to IMI Leadership Limited, Sandyford Road, Dundrum, Dublin 14, with proof of your identity. IMI will respond within one calendar month. Where a request is complex or numerous, this may be extended by a further two months and you will be notified within the first month. 

 

Right to Be Informed (Articles 13 and 14) 

You have the right to clear, transparent information about how your personal data is processed. This Statement, together with the jointly approved UCC statement where applicable, fulfils that obligation. 

 

Right of Access (Article 15) 

You may request a copy of the personal data IMI holds about you, together with information about how it is used, who it is shared with, and how long it will be kept. Submit a written request to [email protected] with proof of identity. There is no charge for a first request. If you wish to know the names of specific organisations to whom your data has been disclosed, you may request this and IMI will provide it. 

 

Right to Rectification (Article 16) 

You may request correction of inaccurate or completion of incomplete personal data without undue delay. IMI will also inform any third parties to whom the data has been disclosed, unless this is impossible or involves disproportionate effort. 

 

Right to Erasure (Article 17) 

You may request deletion of your personal data where it is no longer necessary for the purpose collected, where you have withdrawn consent and no other basis applies, where you have objected and IMI has no overriding grounds, where processing has been unlawful, or where erasure is required by law. IMI will assess each request individually and explain where erasure is not possible. 

 

Right to Restrict Processing (Article 18) 

You may request that IMI restricts processing of your data in certain circumstances — for example while IMI verifies accuracy you have contested. IMI will inform you before any restriction is lifted. 

 

Right to Data Portability (Article 20) 

Where processing is based on consent or contract and carried out by automated means, you may request your data in a structured, machine-readable format, or ask that it be transmitted to another controller where technically feasible. 

 

Right to Object — General (Article 21(1))

You may object to processing based on legitimate interests. IMI will cease that processing unless it can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or that the processing is necessary for a legal claim. 

 

Right to Object — Direct Marketing (Article 21(2)) 

You have an absolute and unconditional right to object to processing of your personal data for direct marketing at any time. IMI must stop immediately upon receipt of your objection — there is no balancing test. To object, click unsubscribe in any marketing email or contact [email protected]. 

 

Rights in Relation to Automated Decision-Making (Article 22) 

You have the right not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect on you. IMI does not engage in any such processing. If this changes, IMI will update this Statement, complete a DPIA, and ensure this right is fully protected before deployment. 

 

Where IMI processes your data on the basis of consent, you may withdraw it at any time without affecting the lawfulness of prior processing. Contact [email protected] or use the unsubscribe mechanism in any consent-based communication. 

 

Right to Know Named Recipients (Article 15 — Categories Edition) 

This version lists categories of recipients rather than named organisations, permitted under Articles 13(1)(e) and 14(1)(e) GDPR. You have the right under Article 15 to request the identities of specific organisations to whom your personal data has been disclosed. Contact [email protected] with proof of identity. 

 

Data Security 

IMI implements appropriate technical and organisational measures to protect personal data against accidental loss, destruction, alteration, unauthorised disclosure or access. These include password protection and encryption of systems and devices, multi-factor authentication on key systems, restricted access on a need-to-know basis, secure physical disposal of documents, and written data processing agreements with all third-party processors. 

All staff, faculty, associate faculty and relevant contractors are subject to data security obligations set out in their relevant section above and in the Acceptable Use Policy. Failure to comply may result in disciplinary action up to and including dismissal or termination of engagement. 

 

Personal Data Breaches 

A personal data breach is any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. All staff, faculty and associate faculty must report any actual or suspected breach to [email protected] immediately. Associate faculty must do so within 48 hours as required by their Data Processing Agreement. The full procedure is set out in IMI’s Personal Data Breach Management Procedure. 

 

If you become aware of any actual or suspected data breach — including loss or theft of a device, an email sent to the wrong person, or any unauthorised access to personal data — report it to [email protected] immediately. Do not wait. Do not attempt to resolve it yourself. 

 

Where a breach is likely to result in a risk to the rights and freedoms of individuals, IMI will notify the Data Protection Commission within 72 hours of becoming aware. Where there is a high risk to individuals, IMI will also notify those individuals without undue delay. 

 

How to Make a Complaint 

If you believe your data protection rights have been infringed, contact the Data Advisor at [email protected] in the first instance. IMI will acknowledge your concern promptly and work to resolve it. 

 

If you remain unsatisfied, you have the right — without prejudice to any other administrative or judicial remedy — to lodge a complaint with the Data Protection Commission (DPC): 

 

Data Protection Commission   
Address  21–25 Canal Road, Dublin 6, D06 F46E 
Website  www.dataprotection.ie 
Phone  +353 57 868 4800 

 

You also have the right to an effective judicial remedy against IMI as controller, or against the DPC if you consider it has failed to handle a complaint properly, without prejudice to any other administrative or judicial remedy available to you under Article 79 GDPR. 

 

Review of This Statement 

This Statement is reviewed annually by the Data Advisor and updated as required to reflect changes in law, regulatory guidance, or IMI’s operations. Material changes — including any change to the identity of the controller, processing purposes, or how data subject rights can be exercised — will be communicated to data subjects before taking effect. Printed or locally saved copies are uncontrolled. Always refer to imi.ie for the latest version. 

 

Governing Law 

This Statement is governed by the laws of Ireland. Any dispute arising from or in connection with IMI’s processing of personal data shall be subject to the exclusive jurisdiction of the Irish courts, without prejudice to your right to lodge a complaint with the Data Protection Commission or to seek any other administrative or judicial remedy available under GDPR.