EdiWay connects the information schools, families, learners and authorised professionals need across education, while ensuring that connection never means everyone can see every record or use information for every purpose. Privacy is built around context: who is acting, which organisation they represent, their relationship with the learner, why they need the information, which records are relevant and how sensitive that information is.
EdiWay's architecture is designed to help answer those questions before access or sharing is treated as appropriate. Discover how EdiWay supports purposeful access, responsible information sharing and stronger privacy boundaries across the learner journey.
Schools need personal information to educate learners, communicate with families, provide support, manage staff, operate services and meet responsibilities. Privacy does not mean preventing legitimate use. It means ensuring that personal information is handled appropriately for the reason it is needed.
EdiWay's governance model supports that through connected controls around:
The objective is a platform where information can support the work it was collected for without becoming available simply because it exists.
EdiWay is designed for UK education environments. The current UK data-protection framework includes the UK GDPR, the Data Protection Act 2018, and amendments introduced through the Data (Use and Access) Act 2025.
Those responsibilities apply to organisations using personal information - not simply to the software holding it. Schools and other responsible organisations still need to determine matters such as:
A person's ability to access information should relate to the work they are authorised to perform. For example:
This is why EdiWay goes beyond a simple: “Staff member = learner access” model. Access can consider role, organisation, relationship, case, purpose and sensitivity together.
A connected platform can hold substantial information about a learner. That does not mean every workflow needs all of it. EdiWay's direction is to expose the information appropriate to the task rather than treating a complete learner profile as the default response. For example:
May need learning and support context.
May need minimum necessary emergency information.
May require transaction and buyer context.
May require selected learner information for a defined purpose.
May use a selected Transition Pack.
Uses a separately restricted information boundary.
EdiWay can enforce platform permissions. But a permission toggle does not, by itself, determine whether an organisation has a lawful basis to process or disclose information.
Likewise, consent is not the only possible basis for processing personal information and should not be treated as a universal answer to every education-data workflow. The responsible organisation must establish the appropriate legal basis and governance for the particular processing activity.
EdiWay can then help implement the relevant access, relationship and sharing controls.
EdiWay handles education journeys where information may concern children and young people for many years. That requires particular care around:
A learner’s ability to access or contribute information can therefore depend on age, configuration and sensitivity.
As learners grow, their relationship to their own information can also change. The platform should support that development rather than assuming the same family-access model applies indefinitely.
Parents and carers can play a central role in the learner journey. But different family relationships may have different legal and operational significance. EdiWay's relationship model can distinguish contexts such as:
Access should follow the relevant relationship and information purpose rather than assuming that every family-linked account should receive identical visibility.
This becomes particularly important for sensitive learner voice, safeguarding, medical information and complex family circumstances.
Education platforms can contain information relating to areas such as:
EdiWay is designed to apply stronger boundaries around sensitive domains rather than making them ordinary learner-profile fields.
Safeguarding information requires additional restrictions. EdiWay treats safeguarding as a separate governed domain with more limited access, controlled chronology and purpose-specific sharing. Ordinary family, teaching, pastoral or professional access should not silently extend into safeguarding information.
The platform also avoids promising absolute confidentiality where safeguarding or legal obligations may require information to be acted upon or disclosed.
Learners and families may contribute information that gives important context to the education journey. EdiWay can preserve those contributions as attributable evidence. That means:
Keeping those sources visible helps prevent information from changing meaning simply because it appears in a connected record. Sensitive contributions can also require narrower visibility than ordinary learner information.
A tutor, therapist, adviser or other authorised professional does not necessarily need access to the entire learner history. EdiWay's collaboration model can scope participation according to:
Who does the work concern?
Why is the professional involved?
What are they helping with?
Which information is relevant?
How long does the relationship apply?
What information may they add?
A professional relationship should therefore create purposeful access, not permanent visibility across the learner record.
Preserve Material History.
The aim is to make collaboration possible without treating every recipient as another unrestricted platform user.
When a learner changes school or education pathway, continuity can matter. But privacy matters too.
EdiWay's Transition Pack model supports selected, purpose-bound information rather than assuming the next setting should inherit every historical record.
A controlled transition can consider:
A receiving setting can gain useful context without automatically receiving permanent access to the family’s, school’s or professional’s complete record.
Schools moving to EdiWay may import information from previous systems. Privacy and data quality both depend on maintaining appropriate context around that information.
Migration should distinguish matters such as:
An old record should not silently become a new current conclusion just because it has been migrated.
This is particularly important for safeguarding, SEND, assessments, family relationships and other high-risk records.
Personal information may change.
EdiWay is designed so material lifecycle and record changes can preserve source and history where the workflow requires it rather than simply overwriting everything without trace.
That supports both accuracy and accountability.
Correcting an error should not require losing the evidence of what was previously recorded where that history remains legitimately necessary.
Different education records have different purposes and retention considerations. There is no single appropriate retention period for every piece of information within EdiWay. Retention may depend on factors such as:
Responsible organisations should maintain appropriate retention policies and review the information they continue to hold. EdiWay’s learner-continuity model does not override those responsibilities.
Depending on the circumstances and applicable law, individuals may have rights concerning personal information held about them.
These can include rights relating to:
Not every right applies in every situation, and lawful restrictions or exemptions may sometimes apply.
EdiWay can support governed processes around information access and lifecycle.
The responsible organisation remains accountable for deciding how a particular request should be handled.
A child's record can involve parents and carers while the learner is young. But the learner does not remain a child forever.
EdiWay's wider continuity model recognises an eventual move towards the learner becoming the adult rights-holder.
From age 18, an eligible learner can move into the Adult Learner Record pathway, with access and responsibility reviewed for the adult context. Parent stewardship should not simply continue indefinitely because it existed during childhood.
Where EdiWay AI is enabled, personal information remains subject to the wider permission and purpose model. AI should not receive sensitive information merely because a user enters a prompt. Governance must still consider:
Safeguarding information is excluded from broad AI retrieval by default. Consequential AI outputs remain human-reviewed.
External services should not become an invisible way of widening the use of learner or school information.
Data-protection responsibilities depend on the actual processing activity and the decisions being made about that information. The relevant contracts, processing arrangements and privacy notices should make clear the roles of EdiWay, the school or organisation, and any other providers involved.
EdiWay should not use website marketing copy to imply that every processing activity has the same controller/processor arrangement.
Different services and relationships may require different analysis.
Privacy and security are closely connected, but they are not the same thing. Privacy asks:
A secure system can still use information inappropriately. A good privacy policy is also ineffective without strong security. EdiWay therefore treats both as part of the wider Trust and Governance model.
Schools and other responsible organisations need appropriate privacy information for the people whose data they handle. That information should explain matters such as:
EdiWay’s platform controls can support the organisation’s privacy approach. The organisation’s actual privacy notices must reflect its real use of the platform.
Current UK data-protection expectations place importance on clear processes for people to raise concerns about how their personal information is handled.
Schools and other organisations should maintain an accessible privacy or data-protection contact route and deal appropriately with requests and complaints.
EdiWay can provide platform evidence and records relevant to the organisation's investigation.
It does not replace the organisation's DPO, data-protection lead or complaints process.
Why is the information needed?
Which organisation or authorised person is acting?
What permits the processing?
Avoid unnecessary information.
Limit visibility by role, relationship, purpose and sensitivity.
Keep information attributable.
Use selected and governed disclosure where needed.
Retain appropriate evidence of significant access and sharing.
Do not keep information simply because it can be stored.
Provide appropriate processes for access, correction and other applicable requests.
EdiWay is designed with privacy, permission, governance and security controls for UK education.
However, EdiWay should not claim that using the platform alone makes an organisation compliant with data-protection law.
Compliance also depends on the organisation’s purposes, lawful bases, policies, configuration, notices, contracts and practices.
The framework includes the UK GDPR and Data Protection Act 2018, as amended by later legislation including the Data (Use and Access) Act 2025.
Organisations should use current ICO and applicable government guidance.
No.
Access can depend on role, organisation, learner relationship, purpose, case and information sensitivity.
No.
Family access remains subject to relationship, purpose, sensitivity and other applicable restrictions.
No.
Professional participation is designed to be scoped to the relevant learner, relationship and purpose.
No single lawful basis applies to every education workflow.
The responsible organisation needs to identify the appropriate basis for each processing purpose.
No.
Platform permissions and legal authority are related but separate matters.
Appropriate information can be shared where the relevant authority and purpose exist.
EdiWay supports controlled transition and information-sharing approaches rather than unrestricted access.
Where enabled, AI should only use information available to the authorised user for the permitted purpose.
AI does not create new permissions.
Data-protection law provides rights relating to accuracy and correction.
The exact handling of a request depends on the information and circumstances.
Erasure rights are not absolute.
Some records may need to remain for legal, safeguarding, contractual or other legitimate reasons.
No.
Different record types have different requirements, and responsible organisations need appropriate retention schedules.
EdiWay’s Adult Learner Record pathway is designed to support a change in responsibility and access as the learner becomes the adult rights-holder.
No.
Schools and other responsible organisations still need their own appropriate privacy information, policies and governance arrangements.
Understand the wider EdiWay governance model.
See how access and disclosure are scoped.
Explore the security and audit controls that protect information.
Understand stronger controls for restricted safeguarding information.
See how personal information remains permission-aware when AI is used.
Explore information lifecycle and individual-rights processes in more detail.
Understand how historic information is migrated and reconciled.