Child Data Notice
This Child Data Notice explains how child learner information may be collected, used, protected, shared, retained, and accessed when children, students, schools, parents, guardians, caregivers, or organizations use the Child Protect Training Portal.
Child Data Protection Notice
This notice is provided for transparency and general platform guidance about child learner data. It does not replace a school privacy notice, child protection policy, emergency reporting process, legal advice, medical care, or official safeguarding procedure. Parents, guardians, schools, and organizations should review their own legal, safeguarding, data protection, and Ministry of Education related responsibilities before enrolling child learners or using learner data.
Why child data needs special care
Child data is more sensitive because children may not fully understand how information is collected, stored, shared, or used. Safeguarding training may involve learners, school communities, trusted adults, completion records, and child safety topics. For that reason, child learner information should be collected only when needed, used only for clear purposes, and protected carefully.
Child-aware privacy
Children should receive privacy information in a way that is clear, age-aware, and understandable where possible.
Parent and guardian involvement
Parents, guardians, schools, or authorized organizations may need to provide notice, consent, or lawful authority before a child is enrolled.
Protected learner records
Course progress, learner accounts, completion status, and certificates should be accessed only by authorized people with a valid reason.
Thai education and privacy context
Child Protect is designed for safeguarding training that may be used by schools, parents, caregivers, child-facing organizations, and learners in Thailand. Schools and organizations should consider Thai data protection expectations, Ministry of Education or education authority requirements, child protection duties, and their own safeguarding policies before assigning child learners to training.
- Thailand’s Personal Data Protection Act B.E. 2562 may apply when personal data is collected, used, disclosed, stored, transferred, or protected.
- Where children are involved, parents, guardians, schools, or authorized organizations may need to confirm the lawful basis, consent, authority, or notice for enrollment.
- Schools and organizations should use child learner data only for appropriate education, safeguarding, training, support, administration, and completion record purposes.
- Child data should not be used for unrelated marketing, unrelated profiling, or unnecessary disclosure.
- Schools and organizations should follow their own child protection, data retention, incident response, access control, reporting, and parent communication procedures.
What child learner data may be collected
The exact information collected depends on the course, account setup, school or organization arrangement, learner age, certificate settings, and training features enabled.
| Data type | Examples | Why it may be needed |
|---|---|---|
| Basic learner identity | Name, email address, username, learner role, school or organization group. | To create the learner account, assign training, identify the learner, and manage access. |
| Training participation | Courses assigned, course access, lesson progress, activity completion, knowledge checks. | To allow the learner to complete safeguarding training and show what learning steps remain. |
| Completion records | Completed training, completion date, certificate status, certificate details where enabled. | To confirm completion and support school, organization, parent, guardian, or learner records. |
| Support information | Help requests, access issues, account questions, certificate questions, support messages. | To resolve learner, parent, school, or organization support requests. |
| Technical information | Login records, device/browser details, IP address, security logs, session information. | To protect the platform, troubleshoot issues, prevent misuse, and maintain safe access. |
| Organization records | Class, group, department, school, organization, administrator assignment. | To help authorized schools or organizations manage assigned training and completion records. |
How child learner data should be used
Child learner data should be used only for the training and support purposes that learners, parents, guardians, schools, or organizations would reasonably expect.
Appropriate uses
- Creating and managing learner accounts.
- Assigning safeguarding training to a child learner.
- Showing learner progress and completion status.
- Providing completion certificates where enabled.
- Supporting school or organization training administration.
- Helping parents, guardians, or authorized adults understand training completion.
- Protecting platform security and preventing unauthorized access.
Uses that should be avoided
- Using child learner data for unrelated marketing.
- Sharing child data with people who do not need access.
- Collecting more child data than is needed for training.
- Keeping child data longer than necessary without a clear reason.
- Using learner records to embarrass, shame, label, or unfairly treat a child.
- Publishing training records, certificate details, or learner information without proper authority.
- Combining child data with unrelated profiling or advertising data.
Consent, authority, and parent or guardian involvement
Before a child learner is enrolled, the person or organization providing the child’s data should confirm that they have the proper authority, consent, legal basis, or responsibility to do so.
Confirm who is responsible
A parent, guardian, school, or organization should clearly understand who is responsible for assigning the training and managing the child learner record.
Provide clear notice
Parents, guardians, and learners should be told what information is collected, why it is used, who may access it, and how long it may be kept.
Use the minimum data needed
Child learner records should contain only the information needed for account access, training assignment, progress tracking, support, and completion records.
Respect parent, guardian, and learner rights
Requests to access, correct, restrict, or delete child data should be handled carefully, with identity and authority verified before action is taken.
Plain-language message for children
We use your training information to help you take the course, see your progress, and show when you finish. Your information should only be seen by people who are allowed to help with your training, such as your parent, guardian, school, organization, or support team. If something does not feel right, ask a trusted adult for help.
Who may see child learner data?
Child learner data should be limited to people and service providers who need access for training, support, security, administration, or legal reasons.
Parents and guardians
May receive or request information about learner access, progress, completion, or certificate status where they have appropriate authority.
Schools and organizations
Authorized administrators may see learner progress and completion records where they assigned or manage the training.
Child Protect support
Limited support or technical staff may access data only when needed to operate the platform, resolve problems, or protect security.
Service providers
Hosting, email, security, analytics, payment, or platform service providers may process data only as needed to provide the service.
Authorities or safety contacts
Information may be shared where required by law, official request, child protection need, emergency, or serious safety concern.
Legal or compliance advisors
Information may be shared with advisors, auditors, insurers, or legal representatives where necessary for compliance or dispute handling.
Child safety information and reporting limits
Child Protect provides safeguarding training and awareness. The portal is not an emergency reporting service. If a child is in danger or a serious concern exists, the correct school, parent, guardian, child protection, emergency, or legal pathway should be used.
If a child may be at risk
Do not rely on a training account, contact form, certificate record, or general support message as an emergency channel. Contact the appropriate local emergency service, child protection service, school safeguarding contact, parent or guardian, or trusted authority right away when immediate safety is at risk.
How child learner data is protected
Child learner information should be protected through reasonable technical, administrative, and organizational safeguards.
- Account access controls for learners, administrators, and support users.
- Password protection and authentication tools.
- Role-based access where supported by the platform.
- Limiting access to authorized users with a valid reason.
- Secure platform hosting and server-side protections appropriate for the service.
- Security monitoring, backups, maintenance, and audit support where appropriate.
- Responsible handling of learner progress, certificate records, support messages, and organization records.
- Review of access when learners leave a school, organization, course, or program.
How long child data may be kept
Child learner data should be kept only for as long as reasonably needed for training, certificates, support, security, organization administration, legal compliance, or legitimate record purposes.
During active training
Data may be kept while the learner is actively using the portal or enrolled in assigned training.
After completion
Progress and certificate records may be kept to confirm completed training where enabled.
For school or organization records
Schools or organizations may need records for onboarding, refresher training, safeguarding awareness, or audit purposes.
Deletion, restriction, or anonymization
When data is no longer needed, it may be deleted, restricted, archived, or anonymized according to legal, technical, and operational requirements.
Parent, guardian, learner, and school requests
Subject to applicable law, identity checks, authority checks, school or organization responsibility, and legal exceptions, requests may be made about child learner data.
Requests may include
- Access to child learner data.
- Correction of inaccurate learner information.
- Deletion where legally and operationally available.
- Restriction of access or processing in appropriate circumstances.
- Withdrawal of consent where processing is based on consent.
- Questions about course progress or certificate records.
- Questions about who can see the child learner record.
- Concerns about misuse or unauthorized access.
Before action is taken
- We may need to verify the identity of the person making the request.
- For child data, we may need to verify parent, guardian, school, or organization authority.
- Some requests may need to be handled by the school or organization that assigned the training.
- Some records may need to be retained for training, certificate, security, legal, or compliance reasons.
- We may explain if a request cannot be fully completed or must be directed to another responsible party.
Responsibilities of schools and organizations
When a school or organization enrolls child learners, assigns training, or receives progress information, it should treat learner data as protected information and manage it according to its own safeguarding and privacy responsibilities.
- Provide clear privacy notice to parents, guardians, learners, staff, and participants where required.
- Confirm consent, lawful basis, or authority before uploading or assigning child learner data.
- Limit administrator access to authorized people with a valid training or safeguarding need.
- Keep learner information accurate and update or remove outdated records where appropriate.
- Use learner progress and certificates only for proper training, education, safeguarding, or organization purposes.
- Maintain internal safeguarding, child protection, reporting, access control, and retention procedures.
- Respond properly to parent, guardian, learner, staff, or authority questions about child data.
- Report suspected data misuse, unauthorized access, or security incidents through the appropriate process.
How children can be supported with privacy
Children should not be expected to understand privacy systems alone. Adults should help children understand what information is used, why training matters, and who can help if they have a concern.
Explain simply
Use age-aware language to explain that training records help show progress and completion.
Limit pressure
Do not use training records to shame, label, or unfairly treat a child.
Encourage questions
Let children ask who can see their training and who can help if something feels wrong.
Protect access
Help children keep login details private and tell a trusted adult if account access seems unsafe.
Related privacy and training pages
This notice should be read together with the full Privacy Policy, training guide, certificates page, and safeguarding support pages.
Privacy Policy
Read the broader privacy policy for all users, accounts, organizations, and platform services.
Open privacy policyTraining Portal Guide
Understand how learners use the portal, complete training, track progress, and access certificates.
Open guideCertificates
Learn how completion certificates support training records and confidence after completion.
View certificatesUpdates to this Child Data Notice
This notice may be updated when training features change, legal requirements change, privacy practices improve, or additional child data protections are added.
Recommended review: Parents, guardians, schools, organizations, and trusted adults should review this notice periodically and confirm that their own child protection and privacy procedures remain aligned with their responsibilities.
Effective date: July 2026
Questions about child learner data?
Contact Child Protect for questions about learner accounts, child data, privacy requests, training progress, certificate records, school access, or organization setup.
Contact Child Protect Privacy Policy