Data Protection Impact Assessment (DPIA)

Last updated: 23 March 2026

This Data Protection Impact Assessment has been prepared by Chapter Technologies Ltd in accordance with UK GDPR Article 35. It assesses the data protection risks associated with the Chapter Schools platform and the measures taken to mitigate those risks. Schools may use this document as supporting evidence for their own DPIA processes and Ofsted readiness.

1. Description of the processing

1.1 Purpose

Chapter Schools is a careers education management platform for UK secondary schools and multi-academy trusts. It enables schools to track student career engagement against the Gatsby Benchmarks, manage employer encounters and events, deliver careers lessons, provide guidance sessions, and report to Ofsted.

1.2 Nature of processing

  • Collection and storage of student records imported from school MIS systems (via Wonde API or CSV upload)
  • Tracking of student career activities, encounters, and guidance sessions
  • AI-assisted generation of lesson plans, worksheets, and guidance summaries (using Anthropic Claude)
  • Communication with parents via email digests
  • Integration with the Chapter student-facing app to receive activity data via webhooks
  • Reporting and analytics for careers leaders and school leadership

1.3 Scope

The platform processes data for students in Years 7-13 (ages 11-18), school staff (careers leaders, teachers, administrators), and parents/guardians. Data processing covers the academic year cycle and continues for the duration of the school's subscription.

1.4 Data processed

  • Student identifiers: Name, email, date of birth, UPN (Unique Pupil Number), year group, form group
  • Career activity data: Gatsby evidence records, event attendance, guidance session notes, lesson participation
  • App engagement data: Chapter app activity (zones visited, quests completed, XP earned) - linked via student ID
  • Staff data: Name, email, role, school affiliation
  • Parent data: Name, email, linked child relationships, digest preferences
  • Provider data: Employer/university contact names, emails, interaction history

Special category data (as defined in UK GDPR Article 9) is not intentionally processed. Schools are advised not to include sensitive personal data in free-text fields (e.g., guidance notes, lesson content).

2. Necessity and proportionality

2.1 Lawful basis

Schools (as data controllers) process student personal data under Article 6(1)(e) - public task (delivery of statutory careers education under the Education Act 1997 and Careers guidance statutory guidance). The school's contract with Chapter Technologies Ltd provides the basis for data sharing with the processor.

2.2 Data minimisation

  • Only data necessary for careers education tracking is imported from MIS systems
  • AI API calls use contextual prompts without transmitting student names or identifiers to Anthropic
  • Parent access is limited to their own child's career activity summary
  • Teacher access is restricted to their assigned form group students

2.3 Accuracy

Student data is synchronised from MIS systems (daily for Wonde-connected schools), ensuring the platform reflects the school's authoritative records. Manual corrections are available to careers leaders.

2.4 Storage limitation

See Section 5 (Data Retention Schedule) for specific retention periods.

3. Risk assessment

3.1 Risks to data subjects

Risk 1: Unauthorised access to student data

Likelihood: Low | Impact: High

  • Mitigation: Row-level security (RLS) policies enforce school-level data isolation
  • Mitigation: Role-based access control (careers lead, teacher, parent) limits data visibility
  • Mitigation: All API endpoints require authenticated sessions
  • Mitigation: HMAC signature verification on all webhook endpoints

Risk 2: Data breach via third-party sub-processor

Likelihood: Low | Impact: High

  • Mitigation: Sub-processors selected for SOC 2 / ISO 27001 compliance
  • Mitigation: Data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Mitigation: 72-hour breach notification commitment in DPA
  • Mitigation: Sub-processor list is documented and schools are notified of changes

Risk 3: AI processing revealing or exposing personal data

Likelihood: Very Low | Impact: Medium

  • Mitigation: Student identifiers (names, UPN, email) are not sent to the Anthropic API
  • Mitigation: Only contextual information (year group, career interests, activity types) is used in prompts
  • Mitigation: Anthropic does not use API inputs for model training (per their data usage policy)
  • Mitigation: AI-generated content is always reviewed by staff before being shared with students/parents

Risk 4: Inappropriate data visible to parents

Likelihood: Low | Impact: Medium

  • Mitigation: Parent accounts only see their linked child's career activity summary
  • Mitigation: Guidance session notes (which may contain sensitive context) are not visible to parents
  • Mitigation: Parent-student links require school admin approval

Risk 5: Data retained beyond necessity

Likelihood: Medium | Impact: Low

  • Mitigation: Data retention schedule (Section 5) defines clear retention periods
  • Mitigation: 90-day export window after subscription termination, followed by deletion
  • Mitigation: Schools can request immediate deletion at any time

4. Technical and organisational measures

4.1 Access controls

  • Supabase Auth with short-lived JWT tokens (1-hour access, 7-day refresh)
  • Row-level security (RLS) on all database tables enforcing school-level isolation
  • Five-tier role system: super_admin, trust_admin, careers_lead, teacher, parent
  • Principle of least privilege: teachers see only their form group; parents see only their child

4.2 Encryption

  • All data in transit: TLS 1.2 or higher (enforced via HSTS)
  • All data at rest: AES-256 encryption (Supabase managed)
  • Webhook payloads: HMAC-SHA256 signature verification

4.3 Infrastructure security

  • Application hosted on Cloudflare Workers (edge computing, DDoS protection)
  • Database hosted on Supabase (AWS eu-west-2, London, United Kingdom)
  • Content Security Policy (CSP) headers restricting script/resource origins
  • Strict security headers: X-Frame-Options, X-Content-Type-Options, Referrer-Policy

4.4 Monitoring and incident response

  • Application error monitoring via Axiom
  • Database query performance monitoring via Supabase Dashboard
  • Breach notification: Controller notified within 72 hours
  • Audit log tracking staff actions within the platform

5. Data retention schedule

The following retention periods apply to data processed within Chapter Schools:

  • Student records: Retained for the duration of the subscription. Deleted within 90 days of subscription termination (or immediately upon school request).
  • Career activity and Gatsby evidence: Retained for the duration of the subscription. Available for export before deletion.
  • Guidance session notes: Retained for the academic year + 1 year (to support transition planning). Deleted on subscription termination.
  • Event and provider records: Retained for the duration of the subscription.
  • Email delivery logs: Retained for 12 months for deliverability monitoring, then deleted.
  • AI chat sessions (Chappy): Retained for 90 days, then automatically purged.
  • Audit logs: Retained for 2 years for compliance purposes.
  • Account data (staff, parents): Retained for the duration of the subscription + 30 days.
  • Payment records: Retained for 7 years as required by UK financial regulations.

Schools may request data export or deletion at any time by contacting luke@chapterapp.co.uk.

6. Sub-processors and international transfers

Full details of sub-processors and international transfer safeguards are documented in our Data Processing Agreement.

Summary of data locations:

  • Supabase: eu-west-2 (London, United Kingdom) - primary data storage
  • Cloudflare: Global edge network (application hosting, no persistent student data)
  • Anthropic: United States - AI processing only, no student identifiers transmitted, no data retention by Anthropic
  • Resend: United States - transactional email delivery, email addresses only
  • Stripe: United States/Ireland - payment processing for school subscriptions only, no student data

7. Consultation

This DPIA has been prepared by Chapter Technologies Ltd. Schools are encouraged to share this document with their Data Protection Officer (DPO) and use it as the basis for their own institutional DPIA where required.

If your school or trust requires a tailored version of this DPIA or additional information for your DPO, please contact us at luke@chapterapp.co.uk.

8. Review schedule

This DPIA is reviewed annually or when significant changes are made to the platform's data processing activities. The next scheduled review is September 2026 (aligned with the academic year).