Secure Scholarship Management for UK Universities
![]() |
Dean Murphy Growth Marketing Specialist, Submit.com |
Secure scholarship management means running every step of a university scholarship or bursary scheme, from application to award to deletion, in one controlled system where each person sees only the data their role needs. For UK universities, that means handling special category data under UK General Data Protection Regulation (GDPR), evidencing decisions and limiting what reviewers can see.
A disabled students’ bursary looks like a small scheme on paper. Forty applicants, one panel, a modest pot. It is also, very often, the most sensitive dataset a student funding team holds: medical letters, diagnostic reports, household income evidence, and sometimes a personal statement about a crisis the student has told almost no one about.
That is the first problem university scholarship management software has to solve. Not the form, and not the scoring. The question of who can see that file at each stage, and whether you could prove it to an auditor next spring.
This guide follows that question through the whole scholarship lifecycle, for scholarship and bursary managers who have to satisfy their data protection officer and IT team as well as their applicants. If you are still building the wider case, start with why UK universities are moving scholarship administration off spreadsheets.
What makes scholarship data riskier than ordinary student records?
Two things: what applicants are asked to prove, and how many people handle the proof.
UK GDPR treats some personal data as special category data because misusing it creates significant risks to people’s rights and freedoms. The categories include health, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, and genetic and biometric data (Information Commissioner’s Office, what is special category data). Scholarship schemes collect several of these as a matter of routine: health and disability evidence for support funds, and ethnicity or religion wherever equality monitoring sits inside the application form.
Financial evidence is a different case. Bank statements, payslips and household income are not special category data, and nor is care-experienced or estranged status. They can still do real harm if exposed, and they tend to travel furthest, because finance, student services and panel members all ask to see them.
Then there is headcount. One named scholarship can involve a funding officer, an academic lead, a donor’s representative, a finance colleague and an external panel member. Every extra login is another route out for the data.
Where does the risk actually come from?
Mostly from inside, and mostly from ordinary behaviour.
The Information Commisioner Office (ICO) analysed 215 personal data breach reports caused by insider attacks in the education sector between January 2022 and August 2024. It found 30 per cent were caused by stolen login details, and 23 per cent by poor data protection practices, including staff accessing data without a legitimate need (Information Commissioner’s Office, insider threat in education). That analysis covers education settings broadly rather than universities alone, but the pattern will be familiar to anyone who has shared a scholarship workbook with a colleague for one round and never taken it back.
So the threat model for most scholarship teams is a folder that twelve people can open, a panel member from two cycles ago who still has access, or a committee sharing one login. Firewalls and encryption matter, and your supplier should evidence both. The controls that fix the everyday exposure are about access design.
Does a scholarship scheme need a DPIA?
Often, yes. Check before the scheme opens, not after.
The ICO publishes a list of processing that requires a data protection impact assessment. One item covers decisions about a person’s access to a product, service, opportunity or benefit where special category data is processed (Information Commissioner’s Office, when do we need to do a DPIA). A bursary awarded partly on medical or disability evidence fits that description closely.
Inferring from that list: treat any fund where health evidence informs the award as Data Protection Impact Assessment (DPIA) territory, and expect your data protection officer to ask three things about the platform. How is access limited? How are decisions recorded? When is the data deleted? Having those answers ready before the questionnaire arrives is the quickest route to sign-off.
How do you secure each stage of the scholarship lifecycle?
Follow one application from submission to deletion and ask the same question at every step: who can see this now, and do they need to?
Application: keep evidence out of inboxes
The first control is the simplest. Applicants upload evidence to a portal rather than emailing it. In Submit.com, documents and form uploads sit in encrypted storage, and data is encrypted in transit and at rest (Submit.com security and compliance).
Form design is a security measure as well. With smart online forms and conditional logic, a student only sees the medical evidence question if they are applying under the criterion that needs it, so you stop collecting sensitive documents nobody asked for. Autosave and save-and-resume help for a quieter reason: an applicant who loses a half-finished form is the one most likely to email the documents instead.
Applicants can register through Google, Microsoft, LinkedIn or Facebook accounts, and enterprise single sign-on is available for institutional logins, depending on plan (based on Project knowledge). Fewer separate passwords means fewer weak ones.
Screening: route applications, not spreadsheets
Eligibility screening is where access quietly sprawls. One officer checks fee status, another checks residency, and both end up holding the whole portfolio. Submit.com tags and routes applications by criteria, and granular permissions and roles restrict what each person sees by programme, department, category or role. The administrator of a hardship fund has no reason to open the named postgraduate scholarships, and in a well-configured system cannot.
Review: give the panel the rubric, not the payslip
This is the stage most schemes get wrong. A panel scoring academic merit or a personal statement rarely needs bank statements or a consultant’s letter. In a shared folder, it gets them anyway.
Blind review removes identifying details from what reviewers see, and role-based visibility limits panel members to the sections they are scoring. Conflict-of-interest controls record declarations. Weighted rubrics keep every reviewer marking against the same published criteria, which is also what you point to when a student appeals.
Reviewer experience and security pull in the same direction here. A reviewer who opens a focused dashboard of assigned applications, with the scoring form beside each one, has no reason to download anything.
Decision: make every award reconstructable
Audit trails in Submit.com record submissions, reviews, decisions and admin actions. When a student asks why they were unsuccessful, or internal audit asks who changed a score in March, the answer comes from the record rather than from memory. Bulk decisions and automated decision letters mean outcomes leave from the system, consistently, and not from someone’s personal mailbox.
Award and renewal: report without rebuilding
After the award, data tends to drift back into spreadsheets because finance and development colleagues need figures. Renewable award tracking and fund-level reporting from the same record remove most of the reasons for side copies. Where data genuinely has to move to student records or finance systems, exports and the Submit.com API and integrations give it a controlled route.
End of cycle: delete on purpose
Scholarship evidence is rarely deleted on a schedule. It is simply forgotten. Configurable retention and deletion policies let you set how long each scheme’s data is kept, in line with your institution’s retention schedule, with export options for anything that must be archived first.
What will your DPO and IT team ask?
Security review is where scholarship software projects usually slow down. Taking these questions to data protection and IT early, with answers attached, is faster than waiting for their questionnaire. For the wider feature shortlist, see nine features to look for in university scholarship software.
| Question | Why it matters for scholarships | What to ask the supplier for |
|---|---|---|
| Who can see each applicant’s evidence? | Panels, finance and donors need different parts of the same file | Permissions by programme, category and role, plus blind review |
| Can we evidence every decision? | Appeals and audits arrive months after the panel meets | Audit logs covering submissions, scores, decisions and admin actions |
| How are logins protected? | Stolen login details are a leading cause of insider breaches in education | Single sign-on, multi-factor authentication support, password policy and session timeouts |
| How long is data kept? | Bursary evidence should not outlive its purpose | Retention and deletion rules you can set per scheme |
| What independent assurance is there? | IT and procurement need evidence rather than claims | Current certifications and support with your own security questionnaire |
| Who owns the data? | The university stays responsible for how applicant data is used | Written data ownership terms and no secondary use |
How Submit.com supports secure scholarship management
Submit.com runs the full scholarship management lifecycle in one platform, with the controls above built in: encryption in transit and at rest, least-privilege role-based access with separation of duties, multi-factor authentication support, single sign-on options, immutable audit trails, optional blind review and configurable retention.
Independent assurance includes SOC 2 Type 1 and Type 2, Cyber Essentials, GDPR compliance and a G-Cloud supplier listing, and Submit.com is an AWS Technology Partner, as set out on the security and compliance page. Cyber Essentials is the UK government-backed certification scheme that the National Cyber Security Centre recommends as the minimum standard of cyber security for all organisations (National Cyber Security Centre, Cyber Essentials).
Applicant data stays the university’s. Submit.com does not access it without explicit authorisation and makes no secondary use of it. Security is still shared work: the platform supplies the controls, and your team decides who holds which role.
Universities including the University of Oxford run programmes on Submit.com, and more than 50,000 scholarship applications have been processed across higher education and foundations.
Frequently asked questions
What is secure scholarship management?
Secure scholarship management is the practice of running scholarship and bursary schemes in one controlled system, where applicant evidence is encrypted, access is limited by role, every score and decision is recorded, and data is deleted on a set schedule. It covers the whole lifecycle, not only the application form.
Is bursary evidence special category data under UK GDPR?
Some of it is. Health and disability evidence, and ethnicity or religion collected for equality monitoring, are special category data. Bank statements, household income and care-experienced status are not on the Article 9 list, but they are still sensitive and should be restricted to the people who need them.
Do we need a DPIA before launching a scholarship scheme?
Often, yes. The ICO requires a data protection impact assessment where special category data is used in decisions about a person’s access to an opportunity or benefit, which describes many bursaries that consider medical or disability evidence. Confirm the position for each scheme with your data protection officer before it opens.
Should scholarship reviewers see applicants’ financial evidence?
Usually not. A panel scoring merit or a personal statement needs the parts of the application its rubric assesses, not bank statements or medical letters. Blind review and role-based visibility let you show reviewers only those sections, while eligibility and financial checks stay with the funding team.
What security certifications does Submit.com hold?
Submit.com is SOC 2 Type 1 and Type 2 certified, Cyber Essentials certified, GDPR compliant and a G-Cloud listed supplier, and it is an AWS Technology Partner. Its security and compliance team also works with university IT and data protection staff to complete security questionnaires and assessments.
Bring your security questionnaire
Share the questions your data protection and IT colleagues will ask. We will work through them with you and scope a quote around the schemes you actually run.











0 Comments