DPIA - pre-completed for your school

Last updated: 2 August 2026

Your school is the data controller for pupil data processed in Chapter Schools, so the Data Protection Impact Assessment is your school's document - but there is no reason your DPO should start from a blank page. Everything describing Chapter's processing, security measures and risks is already written and kept accurate by us. Fill in the handful of fields below and the document completes itself as you type, then send it to your DPO to sign in the browser. No downloading, no manual editing, no DocuSign account.

Complete your DPIA

Fill these in and the document below completes itself. Everything else is already written for you.

0/5
required fields

Who you consulted (Step 3)

Optional, but the ICO expects to see it. Usually your DPO, careers lead and DSL.

Confirm your school-side actions

Signing happens here — no DocuSign account needed.

How to use this template

Under UK GDPR your school is the data controller for pupil data processed in Chapter Schools, and a DPIA is your school's document - it must be completed and signed off on your side. To make that a review job rather than a research project, Chapter Technologies Ltd (your data processor) has pre-completed every section that describes our processing, security measures and risks. Sections marked ✎ School to complete are yours: your context, your consultation, your DPO's advice and sign-off. Verify our pre-filled statements against the linked source documents, amend anything to fit your school's circumstances, and keep the completed document with your records of processing.

  • Companion documents: Data Processing Agreement (chapterschools.com/dpa) · Security overview & sub-processor register (chapterschools.com/security) · Chapter's own DPIA (chapterschools.com/dpia) · Safeguarding statement (chapterschools.com/safeguarding-statement)
  • Questions while completing it: luke@chapterapp.co.uk - we answer DPO queries directly.

Document control

School / trust____________________________
Completed by (name, role)____________________________
Data Protection Officer____________________________
Date completed____________________________
Review date____________________________
ProcessorChapter Technologies Ltd (company no. 14743161, ICO registration ZC143219)

Step 1: Identify the need for a DPIA

A DPIA is required. The processing involves children's personal data at scale, delivered through new technology including generative AI features, and includes data about potentially vulnerable data subjects - each an ICO trigger criterion for a mandatory DPIA.

The project: adoption of Chapter Schools, a careers education management platform, to deliver and evidence the school's statutory careers programme (Education Act 1997 s.42A; Gatsby Benchmarks), including MIS roster sync, careers activity tracking, employer encounter management, an optional linked student app, and parent engagement digests.

Step 2: Describe the processing

2.1 Nature

  • Pupil roster imported from the school's MIS via Wonde (school-approved, read-only sync) or CSV upload; synchronised daily.
  • Recording of careers activities, employer encounters, guidance sessions and Gatsby Benchmark evidence by school staff.
  • Optional: pupils link a Chapter student account; engagement summaries flow back to the school dashboard.
  • Optional: parents/carers receive email digests of their own child's careers activity.
  • AI-assisted generation of lesson plans, worksheets and summaries. Prompts use contextual data (year group, activity type); pupil identifiers are not transmitted to AI providers and provider terms exclude use of inputs for model training.

2.2 Data categories

  • Pupils: name, date of birth, UPN, year and form group, careers activity records, guidance notes, work-experience records.
  • Staff: name, email, role.
  • Parents/carers: name, email, link to child (from MIS parental-responsibility data).
  • Employers/providers: business contact details.

Special category data is not intentionally processed. Staff are instructed not to record sensitive personal data in free-text fields (see risk R8).

2.3 Storage, location and retention

  • Primary data storage: Supabase (PostgreSQL), hosted in the United Kingdom (London, AWS eu-west-2). Encrypted in transit and at rest.
  • Limited flows to sub-processors including AI providers (US) under appropriate transfer safeguards - see the sub-processor register at chapterschools.com/security.
  • Retention: pupil data retained for the duration of the subscription and deleted within 90 days of termination (or immediately on request), with export available first. A nightly automated retention engine flags expired pupil data during the subscription. Full schedule: chapterschools.com/dpia.

✎ School to complete: note where this processing appears in your record of processing activities (ROPA), and confirm your privacy notice covers careers education processing and the categories above.

Step 3: Consultation

✎ School to complete: record who you consulted (DPO, careers lead, DSL, IT lead; pupil/parent voice where proportionate) and what they said. Chapter will answer any technical or data protection query from your DPO during this step: luke@chapterapp.co.uk.

ConsulteeDateSummary of views
____________________________________________________________________________________
____________________________________________________________________________________

Step 4: Necessity and proportionality

  • Lawful basis: Article 6(1)(e) public task - delivery of statutory careers education under the Education Act 1997 and the DfE's careers statutory guidance. The school's contract and DPA with Chapter govern the processor relationship (Article 28).
  • Data minimisation: only roster fields needed for careers tracking are synced; teacher access is scoped to assigned groups; parents see only their own child's summary.
  • Accuracy: daily MIS synchronisation keeps records aligned to the school's authoritative source; manual correction available.
  • Data subject rights: export and deletion are supported at any time; subject access, rectification and erasure requests are actioned with the school as controller.
  • Alternatives considered: spreadsheet-based tracking (weaker security, no access control, no automated retention) or no dedicated system (statutory duty harder to evidence).

Step 5: Identify and assess risks

#Risk to individualsLikelihoodSeverityOverall
R1Unauthorised external access to pupil data (attack, credential theft)RemoteSignificantMedium
R2Staff accessing more pupil data than their role requiresPossibleSome impactMedium
R3Pupil identifiers exposed to third-party AI providersRemoteSignificantMedium
R4Parent digest sent to a wrong or non-authorised contact (e.g. estranged parent without parental responsibility)PossibleSignificantHigh
R5Pupil data retained longer than necessaryPossibleSome impactMedium
R6International transfer risk for limited flows to US sub-processorsPossibleSome impactMedium
R7Personal data breach without timely notification to the schoolRemoteSignificantMedium
R8Special category data recorded in free-text guidance notesPossibleSignificantHigh

Step 6: Measures to reduce risk

#Measures (in place unless marked as school action)Residual risk
R1Row-level security isolating each school's data; passwordless email-code sign-in with TOTP multi-factor authentication for staff; encryption in transit and at rest; security headers and rate limiting; UK data hosting.Low
R2Role-based access (careers lead / teacher / governor / parent tiers); teacher visibility scoped to assigned groups; audit logging of staff actions.Low
R3No pupil identifiers in AI prompts; provider commercial terms exclude training on inputs; no persistent storage by providers.Low
R4Parent contacts come from the school's MIS with parental-responsibility flags; parent access is by school-issued, single-use, time-limited invites; each parent sees only their own child. School action: keep MIS contact records and contact-restriction flags current.Low
R5Automated nightly retention engine flags expired pupil data; full deletion within 90 days of subscription end, export offered first.Low
R6Primary data rests in the UK; only limited, minimised flows reach US sub-processors under recognised transfer safeguards (see sub-processor register).Low
R7Processor breach notification to the school without undue delay (target 24-48 hours) with Article 33(3) information, supporting the school's 72-hour ICO deadline.Low
R8Product guidance instructs staff not to record sensitive data in free text; guidance notes access-restricted to authorised roles. School action: brief staff who record guidance notes on what belongs in them.Medium → Low once staff briefed

Step 7: Sign-off and outcomes

ItemName / dateNotes
Measures and residual risks approved by____________________________Integrate actions back into the project plan. If accepting any high residual risk, consult the ICO before going ahead.
DPO advice provided by________________________________________________________ — advises on compliance, the Step 6 measures and whether processing can proceed
Summary of DPO advice____________________________
This DPIA will be kept under review by____________________________Next review ____________. The DPO should also review ongoing compliance.