Privacy policy

 

  1. Introduction

This privacy notice sets out what personal data we hold about you and how we collect, use and share it. It also contains important information about your rights in relation to your personal data, and how to contact us or supervisory authorities in the event you have a complaint.

The Wine and Spirit Education Trust (WSET) is a data controller as it determines and purposes and means of the processing of your personal data. WSET is a UK company registered with the Information Commissioner’s Office (ICO) under reference Z8972470.

If you have any questions about this Privacy Notice, please contact our Data Protection Lead by emailing us at dpc@wsetglobal.com.

The purposes for processing personal data, the types of personal data collected and the lawful basis for processing this data are set out below, grouped into the categories of data subject that we interact with.

  1. Exam participants

Purpose

Categories of personal data

Lawful basis

Online exams

Candidate number

Exam data

Legitimate interest

Remote invigilation

Candidate number

Exam data

Video footage

Legitimate interest

Marking exam papers

Candidate number

Exam data

Legitimate interest

Issuing results

Candidate number

Exam data

Legitimate interest

Issuing replacement certificates

Candidate number

Exam data

Legitimate interest

Dealing with candidate complaints

Contact details

Complaint details

Legitimate interest

Enquiry and feedback

Candidate number
Exam data
Health data
Reasonable adjustments
Special considerations

Legitimate interest

Collecting payment

Candidate number

Contact details

Bank details

Course details

Contract

Payment by instalments

Candidate number

Contact details

Bank details

Course details

Contract

Refunds

Candidate number

Contact details

Bank details

Course details

Contract

Exam related invoices

Candidate number

Contract

 

If you do not provide personal data when requested, we may not be able to carry out the exam process and you may not be able to exercise your statutory or contractual rights.

Retention periods

Category of data

Retention period

Candidate number

Exam data

Video footage

Contact details

Health data
Reasonable adjustments
Special considerations

10 years

Bank details

6 years

 

 

  1. WSET School students

Purpose

Categories of personal data

Lawful basis

Reviewing applications

Contact details

Application information

Consent

Onboarding new students

Contact details

Application information

Legitimate interest

Conducting training courses

Contact details

Course details

Contract

Facilitating exams

Candidate number

Contact details

Exam data

Legitimate interest

Student surveys

Contact details

Course details

Ethnicity

Legitimate interest

 

If you do not provide personal data when requested, we may not be able to enrol you onto a course or take an exam, and you may not be able to exercise your statutory or contractual rights.

Retention periods

Category of data

Retention period

Contact details

Application information

Candidate number

10 years

Course details

Exam Data

Ethnicity

10 years

 

  1. Event attendees

Purpose

Categories of personal data

Lawful basis

Event sign up

Contact details

Event details

Consent

Conducting events

Contact details

Event details

Consent

Quiz activations

Contact information

Consent

 

If you do not provide personal data when requested, we may not be able to allow you to attend an event and you may not be able to exercise your statutory or contractual rights.

Retention periods

Category of data

Retention period

Contact details

Event details

Contact information

10 years

 

 

  1. Shop customers

Purpose

Categories of personal data

Lawful basis

Online Shop Payments 

Contact details

Payment information

Order details

Contract

 

If you do not provide personal data when requested, we may not be able to fulfil your order and you may not be able to exercise your statutory or contractual rights.

Retention periods

Category of data

Retention period

Order details

Contact details

10 years

Payment information

6 years

 

  1. Visitors to our physical sites

When you visit our physical sites, we will process personal data about you. The personal data we collect, the purposes for processing and the lawful bases are set out below.

Purpose

Personal data used

Lawful basis

Building access management

Identification details

Access logs

Legitimate interest

CCTV management

Images

Legitimate interest

 

If you do not provide personal data when requested we may not be able to provide access to our physical sites and offices.

Retention periods

Category of data

Retention period

Identification details

Access logs

6 months

Images

30 days/as long as necessary for investigations

 

  1. Recipients of marketing communication

When you subscribe to our newsletter, we will process personal data about you. We may also send you marketing communication where you are a professional contact.

Purpose

Personal data used

Lawful basis

Sending marketing communication

Contact details

Consent

Sending marketing communication

Professional contact details

Legitimate interest

 

If you do not provide personal data when requested we may not be able to send you relevant marketing communication.

Retention periods

Category of data

Retention period

Contact details

5 years from last contact

Professional contact details

5 years from last contact

 

  1. Visitors to our website

When you visit and interact with our website, we will process your personal data. The below table sets out the purposes for processing, the personal data used and the lawful basis. This applies to the website www.wsetglobal.com.  

Purpose

Personal data used

Lawful basis

Managing website enquiries

Name

Contact details

Details of enquiry

Consent

Website analytics

Set out in ‘Cookie’ section below.

Consent and legitimate interests

 

Cookies

Cookies are small text files that are storied on your device when you visit our website. They allow the website to function properly, personalise some functions and analyse how people use our website.

Necessary cookies

These cookies are crucial to the functioning of our website and cannot be turned off in our cookie settings.

We do not ask for consent for these cookies and rely on the legitimate interest lawful basis to install them. You can block these cookies using your browser settings, but the website may not function as intended and some parts of the website may not work.

Analytic and Advertisement cookies

These cookies allow us to track the behaviour of users when using the website and optimise the performance of the website. We rely on the lawful basis of consent to install these cookies. Consent is switched off by default, and you have the opportunity to opt-in to these cookies by using the banner at the bottom of the page.

Cookie name

Purpose

Expiry

.ASPXAUTH

These cookies collect information about how visitors use our website, for instance which pages visitors go to most often, and if they get error messages from web pages. These cookies do not collect information that identifies a visitor.

Session

ARRAffinity

These cookies set by Azure app service, and allows the service to choose the right instance established by a user to deliver subsequent requests made by that user

Session

ARRAffinitySameSite

These cookies are set by websites run on the Microsoft Azure cloud platform (which hosts our website). It is used for load balancing to make sure the visitor page requests are routed to the same server in any browsing session.

Session

ASP.NET_SessionId

These cookies used to identify the users' session on the server. The session used to store data in between off HTTP requests on server.

Session

CookieConsent

Stores the user's cookie consent state for the current domain

1 year

MUID

Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronising the ID across many Microsoft domains.

1 year

__RequestVerificationToken

This cookie is an anti-forgery token designed to stop unauthorised posting of content to a website.

Session

_ce.s

These cookies are used to track a recording visitor session unique ID, tracking host and start time. cebs is used to track the current user session internally.

1 year

_fbp

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers.

3 months

_ga

Registers a unique ID that is used to generate statistical data on how the visitor uses the website.

399 days

_ga_7KZQBR9ZJ3

Used by Google Analytics to collect data on the number of times a user has visited the website as well as dates for the first and most recent visit.

399 days

_ga_FG6QBJYZYB

Used by Google Analytics to collect data on the number of times a user has visited the website as well as dates for the first and most recent visit.

399 days

_ga_K87WKE25HV

Used by Google Analytics to collect data on the number of times a user has visited the website as well as dates for the first and most recent visit.

399 days

_gid

Registers a unique ID that is used to generate statistical data on how the visitor uses the website.

Session

_hjSessionUser_1013636

Collects anonymous statistical data related to the user's website visits, such as the number of visits, average time spent on the website and what pages have been loaded.

Session

_shopify_m

These cookies are to manage user browsing preferences. The purpose of Shopify cookies can range from creating an order cart or tracking users for analytics data.

Session

_shopify_y

These cookies are to manage user browsing preferences. The purpose of Shopify cookies can range from creating an order cart or tracking users for analytics data.

Session

cebs

These cookies are used to track a recording visitor session unique ID, tracking host and start time. cebs is used to track the current user session internally.

1 year

ln_or

Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator.

Session

 

  1. Our legitimate interests

We process personal data for the following legitimate interests:

  • Meeting obligations in our contracts with Approved Programme Providers.
  • Protecting our staff, premises, physical property and information assets.
  • Establishing, exercising and defending against legal claims.
  • Effective internal administration.
  • Promoting our products, services and business.

 

  1. Recipients of personal data

Your personal data is accessed internally by the individuals and teams that need it to carry out the purposes set out above.  

We use systems and products provided by third party companies to assist us in conducting our business. This includes using data processors such as Microsoft.

We may share your data with the following categories of recipients:

  • Approved Programme Providers
  • Public service providers such as the police or social services
  • IT service providers
  • Professional advisers, such as solicitors.

We will only share your personal data when we are allowed to do so under data protection law.

  1. International transfers of personal data

If any personal data is transferred internationally, we ensure appropriate transfer mechanisms are in place depending on the jurisdiction. The types of mechanisms we may employ include ensuring:

  • The country has been deemed to provide an adequate level of protection for personal data
  • Specific contracts approved by the relevant authorities are used which ensure data subjects can exercise their data protection rights in third-countries.

We may transfer personal data to other WSET Group companies to enable us to carry out services to you or for effective internal administration.

  1. Your rights

You have the following rights under data protection law in relation to your personal data.

  • The right to be informed- this Privacy Notice is our way of informing you how your data is used. 
  • The right of access- you can request a copy of all the information we hold about you to check that we are lawfully processing it. 
  • The right to rectification- you can request that we rectify information about you that is incorrect. 
  • The right to erasure- also known as the right to be forgotten. You can request that information about you is deleted. 
  • The right to restrict processing- you can request that we pause processing your data so we can verify the lawfulness of processing. 
  • The right to object- you can request that we stop processing your information if you feel that the processing is not lawful. 
  • The right to data portability- you can request that data is transferred to another party so it can be reused across services. 

Where you have given consent for us to use your personal data for specific purposes, you have the right to withdraw this consent at any time. If you would like to exercise any of the above rights, please contact our Data Protection Officer on the contact details above. 

If you would like to exercise any of those rights, please contact our Data Protection Officer by emailing dpc@wsetglobal.com.

We will respond to any request within the statutory deadline of one calendar month. This deadline may be extended where applicable under data protection law. We will inform you if your request meets the extension criteria.

  1. How to complain

We hope that we can resolve any query or concern you raise about our use of your information. If you have any questions or queries about how we are processing your data, please contact our Data Protection Officer by emailing dpc@wsetglobal.com.

The Information Commissioner’s Office (ICO) is the UK’s regulator for data protection. Under data protection law you have the right to make a complaint to the ICO if you feel we have not complied with our data protection obligations. You can contact the ICO by:

 

  1. Changes to this privacy notice

This privacy notice was last updated on 21st July 2023.

Where there are substantial changes to this Privacy Notice, we will inform you.

Website privacy and cookie policy

What is this policy for?

This privacy policy is for this website www.wsetglobal.com and served by Wine & Spirit Education Trust (WSET) and governs the privacy of its users who choose to use it.

The policy sets out the different areas where user privacy is concerned and outlines the obligations & requirements of the users, the website and website owners. Furthermore, the way this website processes, stores and protects user data and information will also be detailed within this policy.

The Website

This website and its owners take a proactive approach to user privacy and ensure the necessary steps are taken to protect the privacy of its users throughout their visiting experience. This website complies to all UK national laws and requirements for user privacy.

Use of Cookies

This website uses cookies to better the users experience while visiting the website. Where applicable this website uses a cookie control system allowing the user on their first visit to the website to allow or disallow the use of cookies on their computer / device. This complies with recent legislation requirements for websites to obtain explicit consent from users before leaving behind or reading files such as cookies on a user's computer / device.

Cookies are small files saved to the user's computer’s hard drive that track, save and store information about the user's interactions and usage of the website. This allows the website, through its server to provide the users with a tailored experience within this website.

Users are advised that if they wish to deny the use and saving of cookies from this website on to their computers hard drive they should take necessary steps within their web browsers security settings to block all cookies from this website and its external serving vendors.

This website uses tracking software to monitor its visitors to better understand how they use it. This software is provided by Google Analytics which uses cookies to track visitor usage. The software will save a cookie to your computer’s hard drive in order to track and monitor your engagement and usage of the website, but will not store, save or collect personal information. You can read Google's privacy policy here for further information [http://www.google.com/privacy.html].

Other cookies may be stored to your computer’s hard drive by external vendors when this website uses referral programs, sponsored links or adverts. Such cookies are used for conversion and referral tracking and typically expire after 30 days, though some may take longer. No personal information is stored, saved or collected.

Contact & Communication

WSET complies with its obligations under current data protection legislation, the Data Protection Act 2018. We will only use your personal information for the purposes we clearly state at the point at which you provide it to us – for example, when you register for one of our events, submit an enquiry, subscribe to our newsletter, or order any of our products or services.

We will only share your personal information with our employees, contractors, agents or professional advisors where it is necessary to fulfil a valid, stated purpose, as above. Each marketing message we send you, whatever medium, will also include an appropriate and easy way for you to opt out of receiving further communications of that type.

For more details on how and why we store your personal data and your rights please see our full  Privacy Policy.

Email Newsletter

This website operates an email newsletter program, used to inform subscribers about products and services supplied by this website. Users can subscribe through an online automated process should they wish to do so but do so at their own discretion. Some subscriptions may be manually processed through prior written agreement with the user.

Subscriptions are taken in compliance with UK Spam Laws detailed in the Privacy and Electronic Communications Regulations 2003. All personal details relating to subscriptions are held securely and in accordance with the Data Protection Act 2018. No personal details are passed on to third parties nor shared with companies / people outside of the company that operates this website. Under the Data Protection Act 2018 you may request a copy of personal information held about you by this website's email newsletter program by emailing our data protection officer at dpo@wsetglobal.com. Please see our full  Privacy Policy for more details.

Email marketing campaigns published by this website or its owners may contain tracking facilities within the actual email. Subscriber activity is tracked and stored in a database for future analysis and evaluation. Such tracked activity may include; the opening of emails, forwarding of emails, the clicking of links within the email content, times, dates and frequency of activity [this is by no far a comprehensive list].

This information is used to refine future email campaigns and supply the user with more relevant content based around their activity.

In compliance with UK Spam Laws and the Privacy and Electronic Communications Regulations 2003 subscribers are given the opportunity to un-subscribe at any time through an automated system. This process is detailed at the footer of each email campaign. If an automated un-subscription system is unavailable clear instructions on how to un-subscribe will be detailed instead.

External Links

Although this website only looks to include quality, safe and relevant external links, users are advised to adopt a policy of caution before clicking any external web links mentioned throughout this website. (External links are clickable text / banner / image links to other websites.)

The owners of this website cannot guarantee or verify the contents of any externally linked website despite their best efforts. Users should therefore note they click on external links at their own risk and this website and its owners cannot be held liable for any damages or implications caused by visiting any external links mentioned.

Adverts and Sponsored Links

This website may contain sponsored links and adverts. These will typically be served through our advertising partners, who may have detailed privacy policies relating directly to the adverts they serve.

Clicking on any such adverts will send you to the advertisers’ website through a referral program which may use cookies and will track the number of referrals sent from this website. This may include the use of cookies which may in turn be saved on your computer’s hard drive. Users should therefore note that they click on sponsored external links at their own risk and this website and its owners cannot be held liable for any damages or implications caused by visiting any external links mentioned.

Social Media Platforms

Communication, engagement and actions taken through external social media platforms that this website and its owners participate on are governed by the terms and conditions as well as the privacy policies held with each social media platform respectively.

Users are advised to use social media platforms wisely and communicate / engage upon them with due care and caution regarding their own privacy and personal details. Neither this website nor its owners will ever ask for personal or sensitive information through social media platforms and encourage users wishing to discuss sensitive details to contact them through primary communication channels such as by telephone or email.

This website may use social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised before using such social sharing buttons that they do so at their own discretion and note that the social media platform may track and save your request to share a web page respectively through your social media platform account.

Shortened Links in Social Media

This website and its owners through their social media platform accounts may share web links to relevant web pages. By default, some social media platforms shorten lengthy URLs [web addresses]. Users are advised to take caution and good judgement before clicking any shortened URLs published on social media platforms by this website and its owners. Despite the best efforts to ensure only genuine URLs are published many social media platforms are prone to spam and hacking and therefore this website and its owners cannot be held liable for any damages or implications caused by visiting any shortened links.

Policy Update

We may update this policy from time to time to take account of any new business activity or to reflect any changes in law or best practice in relation to data protection. We will seek to make you aware of any significant changes to this policy by placing an update notice on our website.

This policy was last updated on August 1, 2018