How we assess high-risk processing

Last updated: August 2026

SiteTicket Ltd runs identity checks, records some remote test sittings, and uses software to help assessors review evidence. That combination is the profile where UK data-protection law expects a Data Protection Impact Assessment, not a paragraph in a privacy policy. This page is the public summary.

SiteTicket is the delivery centre and the controller for your enrolment, identity evidence, assessment recordings, and qualification records. The SkillCertify platform companies run the software on the centre's instructions. GQA is a separate controller for the data it needs to register and certificate you.

1. What this covers

  • Identity verification at registration, so the person who enrols is the person who sits and is certificated.
  • Recorded remote sittings for official Level 1 knowledge tests and the CSCS HS&E test, when that sitting is invigilated live. See the recording notice.
  • Assessor-support screening of NVQ evidence (completeness checks and a draft note). A person still decides. See how assessment decisions are made.

2. What we do not do

  • We do not sell your data.
  • We do not run third-party analytics or tracking scripts on this site.
  • We do not let a model pass, fail, or certificate you.
  • We do not automatically report a concern to GQA. A person does that when it is required.

3. How long records are kept

Learner and course records, including assessment evidence, are kept for seven years after the course ends (ST-POL-08). That also meets GQA273’s three-year floor. Remote-invigilation recordings are kept for 1,096 days (three years — AOP-042 and the Cloudflare Stream maximum), which meets GQA’s twelve-month floor. A legal hold pauses deletion. After the clock, the files are deleted.

4. Your rights

You can ask for a copy of the data we hold, ask us to correct it, or ask us to delete it where the awarding-body rules do not require us to keep it. Contact privacy@siteticket.co.uk. The full privacy policy lists every right.

How we assess high-risk processing