Reporting & Analytics Policy
Last updated: 13 August 2026
Malta Red Cross – First Aid Training & Education
This policy supplements our training data protection notice and general Privacy Policy. It applies to data collected through individual and group training bookings and used for internal reporting, quality assurance, and external reporting obligations.
9.1 Purpose
This policy defines how the Malta Red Cross collects, processes, and uses data relating to training participants for reporting, analytics, and organisational improvement purposes, while ensuring full compliance with the General Data Protection Regulation (GDPR) and applicable national legislation.
9.2 Scope
This policy applies to:
- All data collected through training bookings (individual and group)
- Data recorded during training delivery (attendance, assessments)
- Data used for internal reporting, quality assurance, and external reporting obligations
9.3 Categories of Data Used for Reporting
The following participant data may be used:
Core identification data (operational use)
- Name and surname
- ID card number
- Date of birth
- Attendance and assessment outcomes
Additional data (reporting & analytics use only)
- Gender (optional)
9.4 Purpose of Reporting & Analytics
Participant data may be used for:
- Internal performance monitoring (course completion, pass rates)
- Quality assurance and training improvement
- Planning and resource allocation
- Statistical reporting to stakeholders, funders, or regulators (e.g. MFHEA where applicable)
- Monitoring demographic participation trends
9.5 Principles of Data Use
All reporting and analytics activities shall adhere to the following principles:
Data minimisation
- Only data necessary for clearly defined reporting purposes shall be used.
Purpose limitation
- Data collected for training and certification shall not be used for unrelated purposes
- Gender data is used exclusively for reporting and statistical analysis
Accuracy
- Data used for reporting must be accurate and based on validated attendance and assessment records.
Security
- All reporting data shall be stored securely, accessed only by authorised personnel, and protected against unauthorised disclosure.
9.6 Use of Gender Data (Important)
Collection of gender data is optional. It shall be used only in aggregated form for statistical and reporting purposes.
It shall not:
- Affect training access or eligibility
- Be used in decision-making
- Be included on certificates or official participant records
Where reported, gender data shall be anonymised and presented without identifying individuals.
9.7 Age & Eligibility Data
Date of birth is collected to ensure compliance with the minimum age requirement (14 years).
Age data may also be used in aggregated form for reporting (e.g. age group distribution). Individual age data shall not be disclosed in reporting outputs.
9.8 Reporting Outputs
Reports generated may include:
- Number of participants
- Course completion rates
- Assessment performance
- Demographic trends (e.g. age groups, gender distribution)
All reports must
- Be anonymised where possible
- Avoid identifying individual participants
- Comply with GDPR and internal data protection policies
9.9 Access & Responsibilities
Access is limited to
- Training Coordinator
- Authorised administrative personnel
- Management (for reporting and oversight purposes)
Responsibilities
- Ensure reporting data is accurate and up to date
- Ensure data is processed lawfully and securely
- Ensure confidentiality is maintained at all times
9.10 Data Retention
Reporting data shall be retained only for the duration necessary to meet operational, audit, and regulatory requirements.
Thereafter, data shall be anonymised for long-term statistical use, or securely deleted.
9.11 Compliance
All reporting activities must comply with:
- Malta Red Cross Data Protection & GDPR Policy
- Training Data Protection Notice
- Applicable GDPR requirements and national legislation
Non-compliance may result in disciplinary or legal action.