DPIA - pre-completed for your school
Last updated: 2 August 2026
Your school is the data controller for pupil data processed in Chapter Schools, so the Data Protection Impact Assessment is your school's document - but there is no reason your DPO should start from a blank page. Everything describing Chapter's processing, security measures and risks is already written and kept accurate by us. Fill in the handful of fields below and the document completes itself as you type, then send it to your DPO to sign in the browser. No downloading, no manual editing, no DocuSign account.
Complete your DPIA
Fill these in and the document below completes itself. Everything else is already written for you.
Who you consulted (Step 3)
Optional, but the ICO expects to see it. Usually your DPO, careers lead and DSL.
Confirm your school-side actions
How to use this template
Under UK GDPR your school is the data controller for pupil data processed in Chapter Schools, and a DPIA is your school's document - it must be completed and signed off on your side. To make that a review job rather than a research project, Chapter Technologies Ltd (your data processor) has pre-completed every section that describes our processing, security measures and risks. Sections marked ✎ School to complete are yours: your context, your consultation, your DPO's advice and sign-off. Verify our pre-filled statements against the linked source documents, amend anything to fit your school's circumstances, and keep the completed document with your records of processing.
- Companion documents: Data Processing Agreement (chapterschools.com/dpa) · Security overview & sub-processor register (chapterschools.com/security) · Chapter's own DPIA (chapterschools.com/dpia) · Safeguarding statement (chapterschools.com/safeguarding-statement)
- Questions while completing it: luke@chapterapp.co.uk - we answer DPO queries directly.
Document control
| School / trust | ____________________________ |
|---|---|
| Completed by (name, role) | ____________________________ |
| Data Protection Officer | ____________________________ |
| Date completed | ____________________________ |
| Review date | ____________________________ |
| Processor | Chapter Technologies Ltd (company no. 14743161, ICO registration ZC143219) |
Step 1: Identify the need for a DPIA
A DPIA is required. The processing involves children's personal data at scale, delivered through new technology including generative AI features, and includes data about potentially vulnerable data subjects - each an ICO trigger criterion for a mandatory DPIA.
The project: adoption of Chapter Schools, a careers education management platform, to deliver and evidence the school's statutory careers programme (Education Act 1997 s.42A; Gatsby Benchmarks), including MIS roster sync, careers activity tracking, employer encounter management, an optional linked student app, and parent engagement digests.
Step 2: Describe the processing
2.1 Nature
- Pupil roster imported from the school's MIS via Wonde (school-approved, read-only sync) or CSV upload; synchronised daily.
- Recording of careers activities, employer encounters, guidance sessions and Gatsby Benchmark evidence by school staff.
- Optional: pupils link a Chapter student account; engagement summaries flow back to the school dashboard.
- Optional: parents/carers receive email digests of their own child's careers activity.
- AI-assisted generation of lesson plans, worksheets and summaries. Prompts use contextual data (year group, activity type); pupil identifiers are not transmitted to AI providers and provider terms exclude use of inputs for model training.
2.2 Data categories
- Pupils: name, date of birth, UPN, year and form group, careers activity records, guidance notes, work-experience records.
- Staff: name, email, role.
- Parents/carers: name, email, link to child (from MIS parental-responsibility data).
- Employers/providers: business contact details.
Special category data is not intentionally processed. Staff are instructed not to record sensitive personal data in free-text fields (see risk R8).
2.3 Storage, location and retention
- Primary data storage: Supabase (PostgreSQL), hosted in the United Kingdom (London, AWS eu-west-2). Encrypted in transit and at rest.
- Limited flows to sub-processors including AI providers (US) under appropriate transfer safeguards - see the sub-processor register at chapterschools.com/security.
- Retention: pupil data retained for the duration of the subscription and deleted within 90 days of termination (or immediately on request), with export available first. A nightly automated retention engine flags expired pupil data during the subscription. Full schedule: chapterschools.com/dpia.
✎ School to complete: note where this processing appears in your record of processing activities (ROPA), and confirm your privacy notice covers careers education processing and the categories above.
Step 3: Consultation
✎ School to complete: record who you consulted (DPO, careers lead, DSL, IT lead; pupil/parent voice where proportionate) and what they said. Chapter will answer any technical or data protection query from your DPO during this step: luke@chapterapp.co.uk.
| Consultee | Date | Summary of views |
|---|---|---|
| ____________________________ | ____________________________ | ____________________________ |
| ____________________________ | ____________________________ | ____________________________ |
Step 4: Necessity and proportionality
- Lawful basis: Article 6(1)(e) public task - delivery of statutory careers education under the Education Act 1997 and the DfE's careers statutory guidance. The school's contract and DPA with Chapter govern the processor relationship (Article 28).
- Data minimisation: only roster fields needed for careers tracking are synced; teacher access is scoped to assigned groups; parents see only their own child's summary.
- Accuracy: daily MIS synchronisation keeps records aligned to the school's authoritative source; manual correction available.
- Data subject rights: export and deletion are supported at any time; subject access, rectification and erasure requests are actioned with the school as controller.
- Alternatives considered: spreadsheet-based tracking (weaker security, no access control, no automated retention) or no dedicated system (statutory duty harder to evidence).
Step 5: Identify and assess risks
| # | Risk to individuals | Likelihood | Severity | Overall |
|---|---|---|---|---|
| R1 | Unauthorised external access to pupil data (attack, credential theft) | Remote | Significant | Medium |
| R2 | Staff accessing more pupil data than their role requires | Possible | Some impact | Medium |
| R3 | Pupil identifiers exposed to third-party AI providers | Remote | Significant | Medium |
| R4 | Parent digest sent to a wrong or non-authorised contact (e.g. estranged parent without parental responsibility) | Possible | Significant | High |
| R5 | Pupil data retained longer than necessary | Possible | Some impact | Medium |
| R6 | International transfer risk for limited flows to US sub-processors | Possible | Some impact | Medium |
| R7 | Personal data breach without timely notification to the school | Remote | Significant | Medium |
| R8 | Special category data recorded in free-text guidance notes | Possible | Significant | High |
Step 6: Measures to reduce risk
| # | Measures (in place unless marked as school action) | Residual risk |
|---|---|---|
| R1 | Row-level security isolating each school's data; passwordless email-code sign-in with TOTP multi-factor authentication for staff; encryption in transit and at rest; security headers and rate limiting; UK data hosting. | Low |
| R2 | Role-based access (careers lead / teacher / governor / parent tiers); teacher visibility scoped to assigned groups; audit logging of staff actions. | Low |
| R3 | No pupil identifiers in AI prompts; provider commercial terms exclude training on inputs; no persistent storage by providers. | Low |
| R4 | Parent contacts come from the school's MIS with parental-responsibility flags; parent access is by school-issued, single-use, time-limited invites; each parent sees only their own child. School action: keep MIS contact records and contact-restriction flags current. | Low |
| R5 | Automated nightly retention engine flags expired pupil data; full deletion within 90 days of subscription end, export offered first. | Low |
| R6 | Primary data rests in the UK; only limited, minimised flows reach US sub-processors under recognised transfer safeguards (see sub-processor register). | Low |
| R7 | Processor breach notification to the school without undue delay (target 24-48 hours) with Article 33(3) information, supporting the school's 72-hour ICO deadline. | Low |
| R8 | Product guidance instructs staff not to record sensitive data in free text; guidance notes access-restricted to authorised roles. School action: brief staff who record guidance notes on what belongs in them. | Medium → Low once staff briefed |
Step 7: Sign-off and outcomes
| Item | Name / date | Notes |
|---|---|---|
| Measures and residual risks approved by | ____________________________ | Integrate actions back into the project plan. If accepting any high residual risk, consult the ICO before going ahead. |
| DPO advice provided by | ____________________________ | ____________________________ — advises on compliance, the Step 6 measures and whether processing can proceed |
| Summary of DPO advice | ____________________________ | |
| This DPIA will be kept under review by | ____________________________ | Next review ____________. The DPO should also review ongoing compliance. |