Data Management Approach
Updated 11 August 2026
Introduction
Student Loans Company (SLC) is committed to protecting the confidentiality of personal information and ensuring that the official statistics we publish do not identify individuals or disclose personal information about them. All data is collected, stored, processed and used in accordance with relevant legislative and regulatory requirements, including the UK General Data Protection Regulation (GDPR)
For more information on SLC’s general approach to handling personal data, please refer to our Personal Information Charter
How we define personal information
Personal information is information that:
- Relates to an identified or identifiable natural person
- Is not publicly available or widely known
- Could cause damage, harm or distress to an individual if disclosed.
A natural person refers to an individual member of the public. Throughout our statistical publications, references to students or borrowers include natural persons, whether living or deceased.
Protecting Confidentiality
SLC has a responsibility to protect confidential information and maintain public trust in the statistics we produce. To ensure confidentiality, we:
- Store confidential information securely and restrict access to authorised staff who are trained in their responsibilities under data protection legislation.
- Clearly communicate our confidentiality protections and data handling practices to customers.
- Share data with partner organisations, including the Department for Education (DfE), only where there is a lawful basis and a clearly defined purpose. Data sharing arrangements are governed by formal agreements that set out the intended use of the data and the safeguards required to protect it.
- Maintain appropriate records of data sharing activities and transfers.
- Apply statistical disclosure control methods, such as suppression, redaction or rounding, where necessary to prevent the identification of individuals or the disclosure of personal information.
Data security
SLC takes the protection of personal information seriously and has robust controls in place to ensure data is handled securely throughout its lifecycle.
To support the secure processing and storage of data:
- Information is stored and processed on secure IT systems and platforms.
- Access to data is restricted to authorised members of staff who require it for their role.
- Security controls and monitoring processes are in place to protect information from unauthorised access, loss, misuse or disclosure.
- Personal information is only processed for specified and legitimate purposes.
All authorised staff receive regular training on data protection, information security and the standards expected under the Civil Service Code. Data is handled in accordance with the requirements of the UK GDPR, the Data Protection Act 2018 and SLC’s internal information governance policies.
Transparency and Accountability
SLC is committed to maintaining transparency about how it manages and protects personal information. Our statistical publications are produced in a way that protects confidentiality while ensuring that valuable information remains available to support public understanding and decision-making.
Further information can be found in our ‘Statement on Data Confidentiality’ within our Policies and Procedures section on GOV.UK.