Public-sector assurance

Current position for schools, councils and commissioning organisations.

This page shows what is in place, what evidence can be discussed and what still requires completion or delivery-specific verification. It should be read with the relevant contract, programme scope and data arrangement.

Status
Published current-position summary
Owner
The Hwb Collective CIC board
Version
1.0 · 22 July 2026
Review
Before each commissioned delivery
AreaStatusCurrent evidence or positionNext action
Legal entityCurrentThe Hwb Collective CIC, company number 16467677.Verify Companies House details during due diligence.
Governance manualCurrentVersion 1 approved unanimously by the board on 14 February 2026; review scheduled for February 2027.Record any amendment through the board process.
Safeguarding rolesCurrentGrant Parry is Safeguarding Lead; Claudia Niamh Evan-Jones is Deputy; dedicated mailbox in place.Confirm delivery-specific escalation and partner responsibilities.
Data Protection LeadCurrentGrant Parry is named Data Protection Lead under the approved manual.Maintain request, breach and processing records.
Website privacy informationPublished; service checks in progressPublished notices distinguish service communication from optional updates, and the website uses email routes instead of unconnected forms.Complete the CV Builder data-flow, retention and supplier-role verification before organised institutional rollout.
CV Builder DPIAIn progressA structured assessment process has been prepared but is not presented as complete.Complete, approve and review before organised school or council rollout.
Processing recordIn progressProcessing, lawful-basis, supplier and retention records are being verified against the real service.Complete and maintain the records from verified system information.
AccessibilityIn progressKeyboard structure, scalable text, colour themes and reduced-motion support are built into the website.Complete automated and manual WCAG 2.2 AA testing and publish verified results.
Cyber EssentialsNot certifiedNo certification is claimed. Readiness work covers devices, accounts, cloud services and the scheme's core control areas.Complete the readiness review, remediate gaps and decide when to certify.
Independent security testingNot completedNo penetration-test or independent security-audit claim is made.Commission proportionate testing before higher-risk scale-up.
Insurance and DBS evidenceVerify before deliveryNo blanket public claim is made. Currency, scope and suitability requirements depend on the activity and roles.Verify and supply relevant evidence through a controlled due-diligence route.
Risk and health and safetyDelivery-specificThe governance framework assigns health-and-safety implementation responsibility. Each practical activity still requires proportionate risk controls.Approve venue, equipment, supervision and emergency arrangements before delivery.
ComplaintsPublished route; procedure review in progressA dedicated complaints address and conflict-aware escalation principle exist.Approve and record acknowledgement, response and review times.
Business continuityNot publicly evidencedNo completed continuity-plan claim is made on this website.Document essential services, backups, recovery, communications and responsible roles.
Welsh-language provisionDevelopingA complete bilingual service is not currently claimed.Agree language requirements and resource status for each partnership.

What should be agreed before delivery

The written scope should identify participants, intended outcomes, timetable, venue, staffing, supervision, equipment, risk controls, accessibility, safeguarding, complaints, data roles, retention, communications and evidence requirements.

Data sharing and processing

A partner should not assume the correct data role from the service name alone. The actual flow determines whether an organisation is a controller, joint controller or processor and whether a data-sharing agreement, controller to processor contract or another arrangement is required.

Children and young people

Privacy information should be age appropriate, collection should be limited to what is necessary, and high-risk processing should be assessed before it starts. Safeguarding and data protection are connected but remain distinct responsibilities.

Evidence requests

Detailed internal records, security information or personal documents should be shared through a controlled due-diligence route, not published openly on the website.

Privacy controls

Cookie, storage and statistics status

Essential preferences

Language, colour theme, text size and your acknowledgement of this notice. These choices are stored in your browser only.

Active
Aggregate site statistics

IONOS SiteAnalytics may create aggregate statistics through hosting logs or a pixel without analytics cookies. This page can record your objection to any optional analytics controlled by HWB; essential hosting and security logs may still be created by IONOS.

Aggregate only

Objecting stops any optional statistics script that HWB may control now or introduce later. The current website does not load Google Analytics, Meta Pixel or advertising trackers.

Advertising and profiling

No advertising cookies, Meta Pixel, Google Analytics, behavioural profiling or cross-site tracking are used.

Not in use
External media

No YouTube, map, social-media or other third-party embeds load automatically. External services are contacted only after you choose to follow a link.

Not loaded