Coaching Professional Qualification Ltd – United Kingdom
CPQ-DATA-2026-v1.0 · CPQ™ INSTITUTIONAL STANDARD

CPQ Data Protection & Records Retention Policy

Retention and deletion periods and access rights for credentialing, complaint and research records.

External Review Draftv1.0Issued 2026-08-16Review 2026-11-16
External Review DraftNumeric or procedural requirements not fixed in the original source materials remain proposed CPQ™ policy until formally adopted.

1. Purpose & Data Minimisation

CPQ collects only data necessary to deliver services, evidence entitlement or meet legal compliance, and separates identity data from aggregated research data where practicable.

2. Retention Periods

RecordPeriodAction
Approved credential applicationCredential term + 7 yearsArchive then remove detailed evidence while retaining core registry record
Declined application3 yearsDelete unless an appeal is active
Complaint/ethical review10 yearsRestricted archive then delete sensitive personal data
Assessment recordings2 yearsDelete unless linked to appeal/investigation
Raw research data5 yearsFully anonymise before further use

3. Access & Deletion

Individuals may request access, correction or deletion. Deletion may be partly declined for legal obligations, audit or active appeals/complaints, with reasons documented. The operational target for access requests is 30 days.

4. Security & v111 Pre-Activation Addendum

  • Encryption and role-based access.
  • Access logs for complaint and assessment files.
  • Annual security review of registry-linked databases.

Proposed pre-activation addendum: appoint a privacy contact, maintain a data-incident/breach procedure, and document cross-border transfer controls according to applicable law. Legal review by jurisdiction remains required.

CPQ™ · Institutional Review Centre

Review the complete pack or return to the organization hub