NIHR Learn Privacy Notice

How we protect your data

We are committed to ensuring that your data is secure. We use leading technologies and encryption software to safeguard your data, and maintain strict security standards to prevent any unauthorised access to it. However, given that transmitting information over the internet cannot be completely secure, we can’t guarantee the security of your data in transit.

NIHR Learn may contain links to other websites of interest outside the CRNCC. This privacy policy only applies to our websites, systems and services, and doesn’t cover other websites and services that we may link to. You should exercise caution and look at the privacy notice applicable to the website/service in question.

NIHR Learn is hosted on the Amazon Web Services (AWS) platform, a cloud-based software platform which provides for disaster recovery processes across its servers, which are all located within the European Economic Area (EEA). None of the data contained within NIHR Learn will go outside the UK or the EEA. The Amazon Web Services (AWS) platform is accredited to ISO 27001 security standards.

We will not sell your personal data. We will not disclose your personal data to third parties outside of the CRN, unless we have your explicit permission, or are required by law to do so.

We will hold the data for as long as we are providing you services and for as long as you agree to this. We will retain your data for 7 years after the end of the CRNCC’s current contract with the Department of Health and Social Care in order to provide ongoing access to learning certificates previously awarded. Archived training records from before 2015 are also retained and certificates attained between 2012 and 2015 are available through a request process.


  • We only store data that is necessary for a specific purposes

  • We will not store your data for longer than is necessary

  • Your data will be securely deleted when no longer needed for the purpose(s)