UK GDPR statement
Last updated 24 August 2026. This statement is C&G Education’s transparency notice for C&G Nest under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It sits alongside our privacy policy.
1. Controller
The data controller is C&G Education. C&G Nest is the platform we use to manage student education, staff records, and family communication. We determine the purposes and means of the processing described here.
2. Lawful bases (UK GDPR Article 6)
| Purpose | Typical lawful basis |
|---|---|
| Delivering education, session planning and logging, attendance, targets, and destinations | Public task (education functions) and/or legitimate interests in supporting placed students |
| Safeguarding, KCSIE duties, and sharing with statutory partners where required | Legal obligation; vital interests where a child is at immediate risk |
| Staff employment, safer recruitment, DBS, training, payroll, and expenses | Contract with the staff member; legal obligation (tax, right to work, safeguarding) |
| Family portal access and parent/carer change requests | Legitimate interests in keeping families informed; public task in working with those with parental responsibility |
| Account security, audit logs, and essential cookies | Legitimate interests in securing the service; legal obligation to keep education and safeguarding records auditable |
We do not rely on consent for core education, employment, or safeguarding processing. Where we ever ask for consent (for example an optional communication preference), you can withdraw it without affecting processing that rests on another basis.
3. Special category and criminal-offence data (Articles 9 and 10)
Student records may include health, SEND, and wellbeing information. Safeguarding records may include information about alleged or actual harm. Staff records may include DBS and other safer-recruitment checks. We process this data only where a UK GDPR Article 9 condition applies, typically:
- substantial public interest (safeguarding of children and individuals at risk; statutory and government purposes connected with education);
- employment, social security, and social protection law (staff);
- health or social care where a qualified professional is involved and the processing is necessary;
- vital interests if a student cannot consent and a life is at risk.
Article 10 processing (criminal offence data, including DBS) is limited to safer recruitment and safeguarding and is accessible only to authorised roles.
4. Recipients and processors
- Authorised C&G Education staff, according to role (least privilege).
- Parents and carers, only for their linked child and only the categories exposed in the family portal.
- Local authorities, commissioning schools, and safeguarding partners where necessary for the placement or a statutory duty.
- Google Cloud (UK region, London / europe-west2) as processor for hosting, storage, and anonymised AI drafting.
- Email delivery and similar subprocessors bound by contract and UK GDPR Article 28 terms.
5. International transfers
We host C&G Nest in the United Kingdom. If a processor ever stores or accesses data outside the UK, we will do so only with a UK-approved transfer mechanism (for example the UK International Data Transfer Agreement or UK Addendum to the EU SCCs) and appropriate safeguards.
6. Retention
Retention follows C&G Education’s schedule and statutory education, safeguarding, employment, and tax requirements. Safeguarding records are retained in line with KCSIE and local safeguarding partnership expectations. When a period expires, records are deleted or anonymised unless a longer legal hold applies (for example an ongoing investigation).
7. Automated decision-making
We do not make solely automated decisions that produce legal or similarly significant effects on students, parents, or staff. Optional AI features produce drafts only after on-platform anonymisation; a member of staff must accept or reject the draft. That is not Article 22 automated decision-making. The safe AI usage policy describes what the helpers may and may not be used for.
8. Source of data
We collect data from you (staff onboarding, family profile requests, session logs), from colleagues in C&G Education, and from placing authorities or previous settings where a student is referred to us. If we receive personal data from someone other than you, this notice still applies; we will tell you unless an exemption applies (for example a safeguarding investigation).
9. Your rights
You have the right to:
- be informed (this statement and the privacy policy);
- access your personal data (subject access);
- have inaccurate data corrected;
- erasure, restriction, and objection, where the UK GDPR allows — these rights are limited where we must keep education, safeguarding, or employment records;
- data portability, where we process data by automated means on the basis of consent or contract;
- complain to the Information Commissioner’s Office at ico.org.uk.
To exercise a right, email office@cgeducation.co.uk. We may need to verify your identity. We will respond within one month, or explain if we need extra time (up to two further months for complex requests).
How to contact us
For privacy questions, subject-access requests, or to exercise your UK GDPR rights, email office@cgeducation.co.uk.
You can also complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection.