ABRSM Shop Privacy Policy

We collect and use your personal data so you can buy music and resources from shop.abrsm.org. We need details such as your name, contact information, payment method and what you’ve ordered. We use this data to deliver your items, provide customer support, keep our website secure, and, if you allow it, send you news and offers.

We share data only with trusted service providers (e.g. Shopify, payment processors and couriers). We share order information with our trusted print partner Page Bros Norwich Ltd. to produce and deliver your items.

We comply with UK/EU privacy laws.

You are in control: you can access, correct or delete your data, opt out of marketing, and complain to the UK ICO or your local authority if you’re unhappy.

We never sell your data, we protect it with strong security, and we keep it only as long as necessary.

1. Who we are

1. Who we are

shop.abrsm.org (the “Shop”) is operated by The Associated Board of the Royal Schools of Music (Publishing) Ltd, a limited liability company registered in England & Wales No. 01910047 whose registered office is 4 London Wall Place, London EC2Y 5AU, UK.

In this privacy policy we use the terms “ABRSM”, “we”, “us”, “our” to mean both the Associated Board of the Royal Schools of Music (Publishing) Ltd and its parent company, the Associated Board of the Royal Schools of Music (Reg No.1926395).

Both companies are registered with the UK Information Commissioner's Office as data controllers (Z6618494) and (Z6329415).

For UK and EU data-protection law, ABRSM is the data controller for personal data collected through this Shop.

2. Scope of this Policy

2. Scope of this Policy

This policy applies only to the Shop and any related emails, SMS, fulfilment and customer-service activities arising from purchases made at shop.abrsm.org. It supplements the main ABRSM Privacy Policy. Where the two overlap, this Shop Policy governs.

3. What personal data we collect

3. What personal data we collect

The categories below describe what we collect and why.

Category
Examples
Why we need it
Account & contact details
Name, email address, postal address, telephone number, (optional) ABRSM Candidate/Contact ID
Create and manage your Store account; communicate with you; fulfil orders
Transaction information
Products purchased, payment method, billing & delivery address, VAT number, order history
Process payments; deliver goods; handle returns; maintain accounting records
Device & usage data
IP address, browser type, device identifiers, timezone settings, clickstream data
Improve site performance; prevent fraud; personalise content
Marketing preferences
Opt-in/opt-out status for email, SMS, social advertising
Send relevant news, offers and updates (with consent or where permitted)
Cookies & similar tech
Functional, performance, analytics and advertising cookies, local storage, server-side tags
Enable basket, remember preferences, analyse traffic, personalise ads
Support correspondence
Emails, live chat transcripts, call recordings
Provide customer service; resolve issues; train staff

4. Children

4. Children

The Store is not intended for children under 14. We do not knowingly collect their data without parental consent. If we learn we have done so, we will delete it.

Purpose
Legal basis
Legitimate interests (if applicable)
Fulfilment of orders, delivery, returns, warranty
Contract (Art 6 (1)(b))
Account administration & customer support
Contract; Legitimate interests
Efficient service; accurate records
Fraud prevention, site security, record keeping
Legitimate interests; Legal obligation
Protect business, customers and charity funds
Direct marketing (email & SMS)
Consent; Legitimate interests ("soft opt-in" for existing customers under PECR)
Promoting publications and resources relevant to our customers
Personalised advertising, analytics cookies
Consent
Compliance with tax and other laws
Legal obligation

6. Automated decision-making & profiling

6. Automated decision-making & profiling

We use automated tools to:

  • Score transactions for fraud risk (e.g. mismatched IP and payment country)
  • Show personalised product recommendations and ads based on browsing and purchase history. These processes have no legal or significant effect on you. You may object by contacting us (see Section 16).

7. Cookies and other tracking technologies

7. Cookies and other tracking technologies

We use first and third-party cookies, local storage and server-side tags to remember your basket and keep you logged in, analyse traffic and performance, and show ABRSM ads on social media and other websites. You can manage these via our cookie-consent banner or your browser/device settings. Full details are in our Cookie Policy.

8. How we share your data

8. How we share your data

We disclose personal data only with appropriate safeguards:

  • Service providers: Shopify Inc. (ecommerce & hosting; servers in Canada, USA, EU), payment processors (Shopify Payments, PayPal, Apple Pay, Google Pay), fulfilment partners & couriers (Royal Mail, UPS), IT support, email, analytics (Google Analytics, Meta Pixel), and trusted partner Page Bros Norwich Ltd for fulfillment of your order.
  • Within ABRSM: Relevant abrsm.org teams to support your order or improve services.
  • Legal & compliance: HMRC, regulators, law-enforcement bodies and courts where required.

We never sell your personal data.

9. International transfers

9. International transfers

Some providers operate outside the UK/EEA. When transferring data we rely on:

  • UK adequacy regulations;
  • UK/EU Standard Contractual Clauses (SCCs) or International Data Transfer Agreements (IDTAs)
  • Additional safeguards such as TLS encryption, at-rest encryption and access controls.

10. Data retention

10. Data retention

We keep data only as long as necessary or required by law, as detailed below.

Data type
Typical retention period
Order & financial records
7 years after the end of the relevant financial year
Account data
Life of your account + 2 years
Marketing consents/preferences & suppression list
Until you withdraw consent + 2 years
Device logs & analytics data
26 months (Google Analytics default)
Customer service correspondence
3 years from last contact
Fraud-screening data
Up to 6 months unless linked to a disputed transaction

11. Security and data-breach procedure

11. Security and data-breach procedure

We follow industry best practice, including:

  • HTTPS across the Store
  • PCI-DSS Level 1 compliant payment processing.
  • Encryption at rest and in transit.
  • Role-based access controls and MFA for staff.
  • ISO 27001-certified hosting.
  • 24/7 security monitoring and annual penetration testing.

If we discover a personal-data breach likely to risk your rights, we will notify the ICO within 72 hours and inform affected users without undue delay.

12. Your rights

12. Your rights

Your rights are set out in the main ABRSM Privacy Policy

Under the UK GDPR and (where applicable) EU GDPR you may: access the personal data we hold about you; request correction; request erasure (\"right to be forgotten\"); object to or restrict processing; withdraw consent at any time (e.g. via the unsubscribe link); and request data portability in a structured, machine-readable format.

You can exercise these rights by submitting a request via our online privacy webform, emailing privacy@abrsm.ac.uk, or writing to the address in Section 16. You also have the right to lodge a complaint with the UK ICO or your local supervisory authority.

13. Marketing communications

13. Marketing communications

If you opt-in, we may send you emails or SMS about new publications, exam resources, events and special offers. You can opt-out at any time by:

  • Clicking unsubscribe in any marketing email.
  • Replying STOP to an SMS.
  • Updating your preferences in your Shop account.
  • Contacting us at dataprotection@abrsm.ac.uk

15. Accessibility

15. Accessibility

We want everyone to be able to use the Shop easily. The site integrates accessiBe, an automated accessibility solution that:

  • Continuously scans the Shop and applies adjustments required by WCAG 2.1 AA and the UK Accessibility Regulations 2018.
  • Provides an on-screen Accessibility Interface (look for the circular icon in the bottom left) that lets you choose profiles such as “Seizure-Safe”, “Vision-Impaired”, “Keyboard-Only”, or fine-tune text size, contrast and spacing in real time.
  • Optimises pages for popular screen readers (JAWS, NVDA, VoiceOver, TalkBack) through AI-generated alt-text, correct ARIA roles and skip-links.
  • Ensures full keyboard navigation, pause/stop controls for moving content and colour ratios that meet or exceed WCAG AA.

AccessiBe’s AI re-scans the Shop every 24 hours to incorporate new or updated content. If any part of the site remains inaccessible, or if you need this policy in large-print, braille or another format, please email accesscoordinator@abrsm.ac.uk or use the contact details in Section 17. We will provide an alternative within five working days.

16. Changes to this policy (version control)

16. Changes to this policy (version control)

We may update this policy to reflect legal, regulatory or operational changes. Significant changes will be announced on the Store or via email. Previous versions are archived and available if requested.

17. Contact us & EU representative

17. Contact us & EU representative

Data Protection Officer
Please email: dataprotection@abrsm.ac.uk

If we cannot resolve your concern, you may escalate to the UK Information Commissioner’s Office (ICO) or, if you are in the EU/EEA, to your local data-protection authority.

Need help with your data?

If you have a privacy question or would like to make a rights request, we’re here to help.

Email our Privacy team