Information Security Policy

PLEASE READ THE TERMS OF THIS POLICY CAREFULLY BEFORE USING THIS SITE

1. Introduction

Teens in AI is committed to protecting the confidentiality, integrity and availability of the information we hold and process. We apply proportionate technical and organisational measures to protect personal, organisational and programme data from unauthorised access, loss, misuse, alteration or disclosure.

2. Scope

This policy applies to all personal, organisational and programme data held or processed by Teens in AI, across our online and in-person activities, and to all staff, contractors, volunteers and partners who access that data.

3. Principles

3.1 Access to information is granted according to role and business need, not by default.
3.2 Security measures must be proportionate to the risk and sensitivity of the data involved.
3.3 We collect and retain only what is reasonably required.
3.4 Everyone who handles our data understands their confidentiality and security responsibilities.

4. Our Security Measures

To protect our information, we:

  • Restrict access to information according to role and business need.
  • Use secure, reputable cloud-based systems and service providers.
  • Apply appropriate password, authentication and account-access controls.
  • Protect personal data in accordance with our Privacy Policy and applicable data protection legislation.
  • Limit the collection and retention of information to what is reasonably required.
  • Take reasonable steps to ensure staff, contractors and relevant partners understand their confidentiality and security responsibilities.
  • Assess information security and digital risks as part of our wider risk-management processes.
  • Maintain appropriate safeguards when sharing information with third-party processors and service providers.
  • Report, investigate and respond to suspected information security incidents or data breaches.
  • Review security practices where systems, risks or regulatory requirements change.

5. Reporting an Incident

Any suspected loss, unauthorised disclosure, cyber-security incident or personal data breach must be reported promptly to the appropriate member of the leadership team, so that the issue can be assessed, contained and, where necessary, escalated or reported. Incidents are then handled under our Non-Conformance and Corrective Action Procedure.

6. Monitoring and Review

6.1 Security incidents and near-misses are logged and reviewed to identify trends.
6.2 This policy is reviewed at least annually, and following any significant security incident, system change or regulatory change.

7. Related Policies

This policy should be read alongside our 🔗 Privacy Policy, 🔗Children’s Privacy Policy,  🔗Risk Assessment Policy, 🔗Responsible AI Statement and 🔗Non-Conformance and Corrective Action Procedure.


Updated: September 2026

Teens In AI Courses Icon Pink

AI Adventures

Build core skills in AI, coding, and ethics through guided teen-friendly learning.

AI4Good Incubator icon

AI4Good Incubator

Develop impact-driven projects using AI to tackle real global challenges.

Teens In AI Global Techathon Icon Green

Global AI Techathon

Work in global teams to design AI solutions that support equity and inclusion.

Teens-In-AI-Action-Forum-Icon-White

Teens in Action Forum

Explore AI ethics and leadership with peers through live discussions.