PRIVACY • SECURITY • ACCOUNTABILITY
Data Protection and Online Privacy Policy
How The Association for IEMT Practitioners Ltd uses and protects personal information, and the standards members must apply in their own independent practices.
Effective: 3 August 2026 Review: 3 August 2027 Version: 2.0
Who controls which information?
The Association for IEMT Practitioners Ltd, company number 09689977, is the controller for personal information it collects through this website, membership, directories, training administration, events, enquiries, complaints and governance. An individual practitioner normally acts as a separate controller for records created in their own practice. The Association does not control or routinely receive members’ client files.
1. Contact
Questions, rights requests and data-protection complaints may be sent to AssociationforIEMT@gmail.com. Please write “Data protection” in the subject line. We may need proportionate information to verify identity before releasing personal data.
2. Information the Association may collect
- name, contact details, country and account identifiers;
- membership status, qualifications, training, CPD and directory information;
- membership, event and transaction records, including payment status but not complete card details;
- enquiries, correspondence, feedback, complaints, safeguarding reports and adverse-event information;
- marketing preferences and communication history;
- website security, login and technical information needed to operate and protect the service; and
- other information a person chooses to provide for a stated purpose.
3. Why information is used
The Association uses personal information to administer membership and certification, maintain directories, provide member services, deliver or list training and events, process enquiries and payments, communicate relevant updates, protect website security, meet legal and accounting duties, investigate complaints or safety concerns, uphold standards and establish, exercise or defend legal rights.
The applicable lawful basis may be contract, legal obligation, legitimate interests, consent or vital interests, depending on the activity. Health, safeguarding and other special-category information requires both an Article 6 lawful basis and an Article 9 condition under UK GDPR. These are identified and documented before processing rather than assumed from the sensitivity of the matter.
4. Sharing
Information may be shared, where necessary and lawful, with contracted providers supporting website hosting, membership, email, forms, events or payments; professional, insurance or legal advisers; authorised Association personnel; and public, safeguarding, police, court or regulatory bodies. Providers may process information only for the agreed service and subject to appropriate contractual and security controls.
The Association does not sell personal information. Confidential or identifying client information is not shared with health professionals or peers without express written client permission, except where a limited disclosure is necessary and lawful because of serious harm, safeguarding a child or adult at risk, or a legal requirement or valid court order. See Breaking Confidentiality Without Consent.
5. International services
Some technology providers may process information outside the United Kingdom. Where UK data-protection law applies, the Association will use an adequacy regulation, recognised transfer mechanism or other lawful safeguard and assess the protection provided. Members working internationally must comply with the law applying to their clients and processing locations.
6. Retention
UK GDPR does not impose one universal five-year or seven-year period. The Association uses category-based retention and keeps information only for as long as necessary for its purpose, legal duties, safeguarding, public protection, accounting, insurance and the establishment or defence of claims.
- Membership, certification and transaction records: for the membership or certification relationship and the additional period required for accounting, audit, insurance or legal claims.
- Directory information: while publication is authorised and relevant, then removed or archived as appropriate.
- Routine enquiries: until the matter is complete and no continuing operational or legal need remains.
- Complaints, disciplinary, safeguarding and adverse-event records: according to seriousness, statutory requirements, limitation periods and the continuing need to protect the public or demonstrate fair process.
- Marketing records: until consent is withdrawn, an objection is made or the record is removed following review.
- Security logs: for a proportionate operational period, or longer where required to investigate an incident.
Retention is reviewed periodically. Information that is no longer needed is securely deleted, anonymised or archived where a continuing lawful purpose applies.
7. Individual rights
Depending on the circumstances, people may have rights to be informed, access their information, correct inaccurate data, request erasure or restriction, receive portable data, object to processing, withdraw consent and challenge solely automated decisions. These rights are not all absolute.
A valid subject access request will normally be answered without undue delay and within one month. The period may be extended where the law permits, including for complex or multiple requests, and the requester will be told. Requests should receive a reasonable and proportionate search.
8. Security and data breaches
- access is limited according to role and need;
- accounts and devices must use suitable passwords, updates and access controls;
- sensitive material must use secure storage and transmission appropriate to the risk;
- providers and new systems must be assessed before confidential information is entered; and
- suspected loss, misdirection, unauthorised access or disclosure must be contained, recorded and assessed promptly.
A notifiable UK personal-data breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of awareness. Affected people must also be informed without undue delay where the breach is likely to create a high risk to their rights and freedoms. Not every incident meets the reporting threshold, but every suspected breach should be documented and assessed.
9. Cookies and similar technology
The Association’s policy is to use only technology that is strictly necessary to provide requested website functions, including security, authentication, member access and essential service operation. Strictly necessary storage does not require consent, so the site does not use a consent banner merely to obtain agreement for essential functions.
Non-essential advertising or tracking technology must not be enabled unless users first receive clear information and a valid choice where consent is required. If the site’s technology changes, this notice and the consent mechanism will be reviewed before deployment.
10. Standards for independent practitioners
Members are responsible for the information they collect in their own practices. They must determine whether they are a controller, joint controller or processor; issue an accurate privacy notice; identify lawful bases and special-category conditions; collect only necessary information; set justified retention periods; protect records; respond to rights requests; manage processors; and maintain an incident process.
Client information must not be entered into generative AI, transcription, recording, cloud or messaging systems merely because they are convenient. The practitioner must first understand the system’s use, retention, training, transfer and security arrangements and have a lawful and ethical basis. Anonymisation must prevent reasonable re-identification, not simply remove a name.
11. Complaints and the ICO
Send a data-protection complaint to AssociationforIEMT@gmail.com. The Association will provide a clear route, acknowledge the complaint within 30 days, investigate appropriately and communicate an outcome without undue delay. A person may also complain to the Information Commissioner’s Office. Using the Association route first is helpful but does not remove external rights.
Authoritative guidance
Controllers and processors | Storage limitation | Personal-data breaches | Cookies and storage technologies






