Legal

Data protection

How records are kept safe on StadiNet, and who is responsible for them.

Last updated 7 October 2026

Who is responsible

An institution decides what it collects from its learners and staff, who may see it and how long it is needed. StadiNet runs the system on the institution's behalf and follows those choices.

For someone who joined on their own, with no institution, StadiNet is responsible.

Kept apart

  • Each institution's records are kept apart from every other's, and the separation is enforced in the database itself, not only on the screens.
  • A person signed in to one institution cannot reach another's records.
  • Inside an institution, staff see the cases they are allocated or the programmes they are responsible for.

Signing in

  • Passwords are held by a dedicated sign-in service and never by an institution's staff.
  • A new password is chosen through a link sent to your own email address.
  • Connections to StadiNet are encrypted.

A record of what happened

  • Each decision on a case records who made it and when.
  • Changes made by StadiNet's own staff are recorded with who made them.

When an institution leaves

An institution can be switched off, which stops its people signing in, and its records can then be removed. Records of payments received are kept.

What next?