GDPR Information

GDPR Information

This page explains how ATL Portfolio aligns with the UK GDPR, EU GDPR and the Swiss Federal Act on Data Protection (FADP). It is intended for school Data Protection Officers, IT managers and procurement teams reviewing our platform.

Last updated: August 2026

This page is a summary of our GDPR alignment. It works alongside our Privacy Policy, Data Processing Agreement and Security Overview.
Overview

ATL Portfolio is a digital portfolio platform for IB World Schools. We process personal data relating to students, teachers, coordinators and school administrators on behalf of subscribing schools.

We are committed to meeting our obligations as a data processor under the UK GDPR (as supplemented by the Data Protection Act 2018), the EU GDPR, and the Swiss FADP, recognising that many international schools operate across these jurisdictions.

Scope and applicable framework
UK GDPRApplies to schools and data subjects in the United Kingdom; regulated by the ICO.
EU GDPRApplies to schools and data subjects in the EEA; Articles 5–6 principles, 15–20 rights, 28 DPA.
Swiss FADPApplies to schools and data subjects in Switzerland; principles of proportionality and transparency.
Our roleATL Portfolio acts as a <strong>processor</strong>. The school is the <strong>controller</strong>.
Controller and processor

1. The School is the Controller

The School determines the purposes and means of processing personal data, establishes the lawful basis, and obtains any necessary consents (including parental consent for students under the age of digital consent in their jurisdiction).

2. ATL Portfolio is the Processor

We process personal data only on documented instructions from the School, as set out in our Data Processing Agreement and the Platform\u2019s Terms of Service. We do not process school data for our own purposes, for advertising, or for training public AI models.

Lawful basis for processing

The School, as controller, is responsible for establishing the lawful basis for processing. The typical lawful bases relied upon for ATL Portfolio are:

  • Article 6(1)(b) \u2014 performance of a contract (providing the portfolio and assessment service).
  • Article 6(1)(c) \u2014 compliance with a legal obligation (e.g. record-keeping).
  • Article 6(1)(f) \u2014 legitimate interests of the School in managing and assessing student learning.
We do not process special category data (Article 9) unless a School explicitly uploads such content. We advise Schools not to upload special category data to the Platform.
Data subject rights

We support the School in fulfilling data subject requests under Articles 15\u201320:

  • Right of access (Article 15) \u2014 we provide the School with the relevant data within 30 days.
  • Right to rectification (Article 16) \u2014 we action verified correction requests promptly.
  • Right to erasure (Article 17) \u2014 deletion or anonymisation within 30 days of a verified request.
  • Right to restriction (Article 18) \u2014 we can restrict processing on request.
  • Right to data portability (Article 20) \u2014 we provide data export in a portable format.
  • Right to object (Article 21) \u2014 we support objection requests routed through the School.
  • Right to withdraw consent \u2014 where consent is the basis, it can be withdrawn at any time.

Students and parents/guardians should direct requests through their school administrator, who liaises with us. Schools may also contact us directly at privacy@atlportfolio.com.

Children\u2019s data

The Platform is designed for students aged 5\u201318. We apply the principles of the UK Age Appropriate Design Code and applicable children\u2019s privacy laws (including COPPA and the Swiss FADP provisions on minors):

  • Data minimisation \u2014 only data necessary for educational use is collected.
  • Private by default \u2014 portfolios are never publicly visible or indexed.
  • No profiling or advertising \u2014 no advertising, no marketing tracking cookies, no sale of student data.
  • Parental consent \u2014 Schools are responsible for obtaining parental or guardian consent where required by law before student accounts are created.
Data retention and deletion
  • Active School data is retained for the duration of the subscription.
  • Deleted user data is anonymised or removed within 30 days of request.
  • Backups are retained for a limited technical recovery period (30 days).
  • Billing records are retained as required by applicable financial regulation.

On termination of the subscription, at the School\u2019s choice, we will either return the School\u2019s data in a portable format or delete it, with deletion completed within 30 days.

International transfers

Data is stored in the United Kingdom. The Platform is hosted on the Base44 platform using AWS-backed infrastructure (Supabase) in the UK.

Where any data is transferred outside the UK, EU or Switzerland (for example, to a sub-processor with operations in another region), appropriate safeguards are put in place, such as Standard Contractual Clauses (SCCs) and, where relevant, the UK International Data Transfer Agreement (IDTA).

Schools with specific residency requirements should contact us before onboarding to confirm the available options.
Security measures

Taking into account the state of the art and the risks, we implement appropriate technical and organisational measures:

  • Encryption in transit (HTTPS / TLS) and encryption at rest.
  • Role-based access control and row-level security at the database layer.
  • School data isolation \u2014 no cross-school access.
  • Domain-based authentication and session token expiry.
  • Principle of least privilege for platform staff access.
  • Regular dependency updates and security patching.

Full details are available in our Security Overview.

Data breach notification

If a Personal Data Breach affecting School data is confirmed, we will:

  • Notify the School without undue delay and within 72 hours.
  • Provide the nature of the breach, the data affected, the likely consequences and the measures taken.
  • Assist the School in meeting any obligation to notify the supervisory authority (e.g. the ICO) and affected data subjects.
  • Document the breach and the remediation steps.
Data Processing Agreement

A formal Data Processing Agreement (DPA), suitable for review by a school Data Protection Officer, is available on request and forms part of the agreement between ATL Portfolio and subscribing schools.

Read the full Data Processing Agreement or request a countersigned copy by contacting us.

Contact our Data Protection team

For GDPR, data protection or DPA enquiries, please contact:

ATL Portfolio \u2014 Data Protection

privacy@atlportfolio.com

We aim to respond within two business days.

Questions about compliance?

Our data protection team is ready to help IT managers, DPOs and procurement leads review ATL Portfolio for your school.