DPIA - pre-completed for your school

Last updated: 24 September 2026

Your school is the data controller for pupil data processed in Chapter Schools, so the Data Protection Impact Assessment is your school's document - but there is no reason your DPO should start from a blank page. Everything describing Chapter's processing, security measures and risks is already written and kept accurate by us. Fill in the handful of fields below and the document completes itself as you type, then send it to your DPO to sign in the browser. No downloading, no manual editing, no DocuSign account.

Complete your DPIA

Fill these in and the document below completes itself. Everything else is already written for you.

0/6
required fields

Still to fill in (6):

Who you consulted (Step 3)

Optional, but the ICO expects to see it. Usually your DPO, careers lead and DSL.

Who approves it

Usually your headteacher or bursar. They approve the measures and remaining risks, and get their own signing link alongside your DPO's. Optional, but most schools need it.

Three things your school does

Tick each one that's already done. They don't stop you sending - anything left unticked shows in the DPIA as a to-do for your school, and your DPO will know how to do them.

Signing happens here - no DocuSign account needed.

How to use this template

Under UK GDPR your school is the data controller for pupil data processed in Chapter Schools, and a DPIA is your school's document - it must be completed and signed off on your side. To make that a review job rather than a research project, Chapter Technologies Ltd (your data processor) has pre-completed every section that describes our processing, security measures and risks. Sections marked ✎ School to complete are yours: your context, your consultation, your DPO's advice and sign-off. Verify our pre-filled statements against the linked source documents, amend anything to fit your school's circumstances, and keep the completed document with your records of processing.

  • Companion documents: Data Processing Agreement (chapterschools.com/dpa) · Security overview & sub-processor register (chapterschools.com/security) · Chapter's own DPIA (chapterschools.com/dpia) · Safeguarding statement (chapterschools.com/safeguarding-statement)
  • Questions while completing it: luke@chapterapp.co.uk - we answer DPO queries directly.

Document control

School / trust____________________________
Completed by (name, role)____________________________
Data Protection Officer____________________________
Date completed____________________________
Review date____________________________
ProcessorChapter Technologies Ltd (company no. 14743161, ICO registration ZC143219)

Step 1: Identify the need for a DPIA

A DPIA is required. The processing involves children's personal data at scale, delivered through new technology including generative AI features, and includes data about potentially vulnerable data subjects - each an ICO trigger criterion for a mandatory DPIA.

The project: adoption of Chapter Schools, a careers education management platform, to deliver and evidence the school's careers programme(the statutory duty at Education Act 1997 s.42A; the Gatsby Benchmarks), including MIS roster sync, careers activity tracking, employer encounter management, an optional linked student app, and parent engagement digests.

Step 2: Describe the processing

2.1 Nature

  • Pupil roster imported from the school's MIS via Wonde (school-approved, read-only sync) or CSV upload; synchronised daily. Where the school connects through Wonde and its MIS holds them, the sync also brings yes/no support indicators - free school meals or Pupil Premium eligibility, SEND and looked-after status - and an attendance percentage with a persistent-absence flag, used to prioritise careers guidance and destination follow-up for the pupils who most need it (see 2.2 and risk R14).
  • Recording of careers activities, employer encounters, guidance sessions and Gatsby Benchmark evidence by school staff.
  • The Chapter student game (web, iOS and Android), for pupils the school brings on: careers exploration, quests, CV and personal-statement builders, work-experience diaries, interview practice and AI guides that pupils chat with and can share documents with. Engagement summaries flow back to the school dashboard. Social features - chat, multiplayer and friend requests - connect only pupils verified as belonging to the same school, show pupils each other's names, and are switched off entirely for primary-age pupils.
  • Optional: where a pupil has linked a Chapter student account, their apprenticeship application stages, pathway intentions and post-rejection reflections flow from the student app back to the school's apprenticeships tracker. This is covered by the school's public task - the careers guidance duty at Education Act 1997 s.42A, and the Gatsby Benchmark 3 requirement to keep a record for each pupil. Parent visibility is student-initiated for pupils aged 13 and over (ICO guidance on competent children), and rests on two decisions the pupil makes: sharing that individual application, and agreeing that the school may process their apprenticeships record at all. Both are required - without both, the parent sees nothing.
  • Optional: parents/carers receive email digests of their own child's careers activity.
  • Optional: work-experience placements, with parent/carer consent captured in the Chapter Family app or by emailed link (name, email, phone, the signature, and the network address and time the consent was given, kept as evidence).
  • Optional: pupils' leaver destinations and stated aspirations recorded by staff, or answered by the pupil in the student app, to meet the school's destination-tracking duty.
  • AI-assisted tools for staff. Lesson plans, worksheets and slides use contextual data only (year group, topic). Guidance-session summaries, student insight profiles, UCAS personal-statement and reference feedback send the relevant free text to the AI provider (Anthropic) with the pupil's names replaced by an opaque placeholder before it leaves Chapter, and restored in the response. The AI guides in the student game receive the pupil's stage (year-group band), stated interests and the conversation - not their name or age. Documents a pupil or member of staff chooses to share with an AI tool, such as a CV, are sent as written and may contain identifying details. The provider's commercial terms exclude use of inputs for model training and do not retain them. Dictated session notes are transcribed by OpenAI and the audio is not stored; photographed handwritten notes and filled-in pupil worksheets are read once and the image is not stored.
  • Everything a pupil writes in the student app - chat, diary entries, messages - passes through automated moderation (OpenAI moderation model, configured to block if unavailable). A concern about an identifiable pupil is routed to the school's designated safeguarding lead, who decides what happens next.
  • The Chapter student game and the Chapter Family parent app: When the school brings its pupils and their families onto Chapter - through the MIS sync, a school invite or join code, or a pupil linking their own account to the school - the school is the controller for their data in the Chapter student game, including its social features, and in the Chapter Family app, and Chapter processes it for the school under the Data Processing Agreement. When a pupil leaves the school, or if the school stops using Chapter, the pupil's game account carries on with them and Chapter becomes the controller for it from then on, under the game's privacy policy; a pupil under 13 carries on only with a parent or carer's agreement, as that policy sets out. The School keeps its own records of the pupil's time at the school, and any destinations follow-up it asks Chapter to run stays the school's. Chapter is also the controller for what a pupil or family does with Chapter independently of the school, such as a pupil aged 13 or over using their own account outside the school's use of it, or a Chapter Premium subscription a family buys for themselves. Pupils and parents are told this in the game's privacy policy (chaptergame.com/privacy).

2.2 Data categories

  • Pupils: name and legal name, date of birth, UPN/ULN, admission number, school email, year and form group, named adviser; careers activity, encounter and Gatsby evidence records; guidance-session notes and action plans; work-experience placement, consent and diary records; UCAS choices, personal-statement drafts and reference text where the school uses those tools; apprenticeship applications and stated pathway intentions; leaver destinations; in the student game, avatar and game progress, conversations with AI guides and (within the school) with other pupils, and documents or photos the pupil uploads. Location is used on the pupil's own device only if they switch it on, to show nearby opportunities, and is not stored by Chapter.
  • Support indicators (Wonde only): yes/no flags for free school meals or Pupil Premium eligibility, SEND and looked-after status, and attendance percentage with a persistent-absence flag. No details of a pupil's needs, and no medical, behaviour or safeguarding records, are imported.
  • Staff: name, email, role, sign-in and audit records.
  • Parents/carers: name, email, phone, link to child (from MIS parental-responsibility data), consent evidence, digest delivery records.
  • Employers, providers and volunteers: business contact details, event and encounter feedback.

Special category data: a SEND flag can indicate information about a pupil's health, so the school should treat it as special category data (UK GDPR Article 9) and record the condition it relies on - for many schools Article 9(2)(g) substantial public interest with a Data Protection Act 2018 Schedule 1 condition, to be confirmed by your DPO. Chapter does not otherwise intentionally process special category data. Free-text fields could incidentally contain sensitive information, so staff are instructed not to record it there (see risk R8).

2.3 Scope and context

  • Scope: every pupil on roll in the year groups the school enrols (from primary or prep years through to sixth form, depending on the school), their parents and carers, and the staff who run the careers programme, for the whole subscription plus the 90-day deletion window. Processing is continuous (nightly sync) and UK-wide in coverage.
  • Context: the data subjects are children, so the ICO Age Appropriate Design Code applies: high-privacy defaults, no advertising, no profiling for commercial purposes, geolocation off, and notices written for the youngest pupil. Access is school-mediated, so pupils and parents can reasonably expect careers-education processing by their school; the student app is a new technology (a game with AI guides), which is why this assessment is required.

2.4 Storage, location and retention

  • Primary data storage: Supabase (PostgreSQL), hosted in the United Kingdom (London, AWS eu-west-2). Encrypted in transit and at rest.
  • Limited flows to sub-processors including AI providers (US) under appropriate transfer safeguards - see the sub-processor register at chapterschools.com/security.
  • Retention: pupil data retained for the duration of the subscription and deleted within 90 days of termination (or immediately on request), with export available first. An automated retention process flags pupil data that has passed its retention period during the subscription. Full schedule: chapterschools.com/dpia.

✎ School to complete: note where this processing appears in your record of processing activities (ROPA), and confirm your privacy notice covers careers education processing and the categories above.

Step 3: Consultation

✎ School to complete: record who you consulted (DPO, careers lead, DSL, IT lead; pupil/parent voice where proportionate) and what they said. Chapter will answer any technical or data protection query from your DPO during this step: luke@chapterapp.co.uk.

ConsulteeDateSummary of views
____________________________________________________________________________________
____________________________________________________________________________________

Step 4: Necessity and proportionality

  • Lawful basis: Article 6(1)(e) public task - delivery of statutory careers education under the Education Act 1997 and the DfE's careers statutory guidance. The school's contract and DPA with Chapter govern the processor relationship (Article 28).
  • Data minimisation: only roster fields needed for careers tracking are synced; teacher access is scoped to assigned groups; parents see only their own child's summary.
  • Accuracy: daily MIS synchronisation keeps records aligned to the school's authoritative source; manual correction available.
  • Data subject rights: export and deletion are supported at any time; subject access, rectification and erasure requests are actioned with the school as controller.
  • Privacy information: the school updates its pupil and parent privacy notices to name Chapter as a processor for careers education; Chapter's own notices for the student and parent apps are written for the youngest user.
  • Function creep: school data is used only to provide the platform to the school - never for advertising, never to train AI models, never sold; the Data Processing Agreement fixes this and any new purpose needs the school's written instruction.
  • International transfers: data rests in the UK; the limited flows to US AI and infrastructure providers rely on the UK Extension to the EU-US Data Privacy Framework or the IDTA/UK Addendum, as recorded per vendor on the sub-processor register.
  • Processor compliance: the Data Processing Agreement contains every Article 28(3) term; sub-processor changes come with 30 days' notice and a right to object; audits are allowed on reasonable notice.
  • Alternatives considered: spreadsheet-based tracking (weaker security, no access control, no automated retention) or no dedicated system (statutory duty harder to evidence).

Step 5: Identify and assess risks

#Risk to individualsLikelihoodSeverityOverall
R1Unauthorised external access to pupil data (attack, credential theft)RemoteSignificantMedium
R2Staff accessing more pupil data than their role requiresPossibleSome impactMedium
R3Pupil personal data sent to third-party AI providersRemoteSignificantMedium
R4Parent digest sent to a wrong or non-authorised contact (e.g. estranged parent without parental responsibility)PossibleSignificantHigh
R5Pupil data retained longer than necessaryPossibleSome impactMedium
R6International transfer risk for limited flows to US sub-processorsPossibleSome impactMedium
R7Personal data breach without timely notification to the schoolRemoteSignificantMedium
R8Special category data recorded in free-text guidance notesPossibleSignificantHigh
R9AI-generated content (summaries, feedback, lesson material) is inaccurate or biased and influences guidance given to a pupilPossibleSome impactMedium
R10A pupil discloses a safeguarding concern in free text in the student app and it is not acted onPossibleSevereHigh
R11Pupil-to-pupil contact or user-generated content in the student app exposes a child to harmful content or contactPossibleSignificantHigh
R12Loss of availability or of data (outage, corruption, failed backup) leaves the school unable to evidence its programmeRemoteSome impactLow
R13Recommendations or insights derived from a child's activity amount to profiling that shapes decisions about themPossibleSome impactMedium
R14Support indicators (free school meals or Pupil Premium, SEND, looked-after status, attendance) are seen by staff who don't need them, or used in a way that labels or stigmatises a pupilPossibleSignificantHigh
R15An AI guide in the student game gives a pupil a harmful, inaccurate or manipulative response, or encourages them to rely on it instead of the adults supporting themPossibleSignificantHigh

Step 6: Measures to reduce risk

#Measures (in place unless marked as school action)Residual risk
R1Row-level security isolating each school's data; passwordless email-code sign-in with TOTP multi-factor authentication for staff; encryption in transit and at rest; security headers and rate limiting; UK data hosting.Low
R2Role-based access (careers lead / teacher / governor / parent tiers); teacher visibility scoped to assigned groups; audit logging of staff actions.Low
R3Pupil names replaced by placeholders in staff AI tools; the game's AI guides receive stage and interests, not name or age; documents a pupil or member of staff chooses to share (e.g. a CV) are sent as written and may identify the pupil; provider commercial terms exclude training on inputs; no persistent storage by providers. School action: remind staff to share only what the task needs.Low
R4Parent contacts come from the school's MIS with parental-responsibility flags; parent access is by school-issued invite; each parent sees only their own child. School action: keep MIS contact records and contact-restriction flags current.Low
R5Automated nightly retention engine flags expired pupil data; full deletion within 90 days of subscription end, export offered first.Low
R6Primary data rests in the UK; only limited, minimised flows reach US sub-processors under recognised transfer safeguards (see sub-processor register).Low
R7Processor breach notification to the school without undue delay and within 24 hours of becoming aware with Article 33(3) information, supporting the school's 72-hour ICO deadline.Low
R8Product guidance instructs staff not to record sensitive data in free text; guidance notes access-restricted to authorised roles. School action: brief staff who record guidance notes on what belongs in them.Medium → Low once staff briefed
R9AI output is a draft for a qualified member of staff, never sent to a pupil or parent unreviewed; summaries are shown next to the source notes; prompts forbid inventing facts; content is labelled as AI-assisted. School action: the careers lead reviews AI drafts before they are used.Low
R10Automated moderation of all pupil free text, configured to block when unavailable; flagged content routed to the school's designated safeguarding lead through the safeguarding queue; Chapter's named safeguarding lead available for escalation. School action: name the DSL contact in the platform and keep it current.Low
R11Moderation of chat, messages and uploads; report and block controls in the app; social features connect only pupils verified at the same school, who see each other's names, and are off for primary-age pupils; community rules written for children; the social features are part of what the school uses Chapter for, and Chapter, as the provider of the student game, meets the Online Safety Act duties for it.Low
R12Managed UK database with automated backups; 99.5% monthly availability target; full export available to the school at any time.Low
R13Suggestions (courses, careers, next steps) are shown to the pupil and to staff as options, never acted on automatically; no solely automated decision with legal or similar effect is made about a pupil; profiling for advertising is not done.Low
R14Yes/no flags only - no details of a pupil's needs, and no medical, behaviour or safeguarding records; visible only to school staff in the dashboard, never shown to pupils or parents and never sent to AI providers; used only to prioritise careers guidance and destination follow-up. School action: decide which staff roles need to see them, and make sure staff understand they are there to target support, not to label pupils.Low
R15AI guides are scoped to careers and study; everything a pupil writes is moderated before it reaches the guide, blocking if moderation is unavailable; concerns about an identifiable pupil go to the school's designated safeguarding lead; the guides are presented as AI characters, not people; pupils' names and ages are not sent to the provider; Chapter works to the DfE's generative AI product safety standards. Because a conversational AI can still get things wrong, this risk is reduced rather than removed and is kept under review. School action: tell pupils the guides are AI, and how to report anything that worries them.Medium - kept under review

Step 7: Sign-off and outcomes

ItemName / dateNotes
Measures and residual risks approved by____________________________Risk status: R1-R14 reduced to low by the Step 6 measures (R8 once staff are briefed); R15 (AI guides) reduced to medium and kept under review; none eliminated, none remaining high. Prior consultation with the ICO is not required unless the school accepts a high residual risk. Integrate the school actions into the project plan.
DPO advice provided by________________________________________________________ - advises on compliance, the Step 6 measures and whether processing can proceed
Summary of DPO advice____________________________
This DPIA will be kept under review by____________________________Next review ____________. The DPO should also review ongoing compliance.