DPO Service
Education-first DPO support, done properly
Not advice-only. We get involved, think it through, and help you land calm, defensible decisions — especially when SARs, safeguarding nuance and third-party data make the generic GDPR answer fall apart.
Why choose us
Different by design
Four things that set the service apart: how we think, how we deliver, why education context matters, and why the service is governed rather than template-led.
Approach
We start with the thinking — law, guidance, context, and risk — then give you a clear position you can stand behind.
Delivery
Advice alone doesn’t ship outcomes. We support delivery: decisions, documentation, evidence handling, and usable outputs.
Education-first
Education is different — safeguarding realities, mixed systems, and tight deadlines. Our service reflects that environment.
Governed service
We provide a governed data protection service, with a framework, operating model, and quality layer behind the work.
Governed service
Not just templates. A controlled operating model.
We provide a governed data protection service, supported by a framework, an operating model and a quality layer.
We do not just provide templates or a portal. We provide a governed data protection service, supported by a framework, an operating model and a quality layer.
School/MAT framework
Shows what good controller governance looks like: decisions, evidence, risks, actions, ROPA, DPIAs, Cases and reporting.
TDS operating model
Keeps the platform, workflows and evidence service reliable through controlled delivery, support, monitoring and service governance.
Quality layer
Proves the service is controlled, measured and improved through defined processes, review, evidence and continual improvement.
What’s included
Clear scope, usable outputs
The aim is practical support you can use — not templates that sit in a folder.
- Named DPO support designed around the realities of schools and trusts.
- Ongoing advice that results in clear written positions and usable decisions.
- Support for SAR and FOI handling with a defensible approach to scope, review, redaction and response.
- Support for incident response from containment through documentation and defensible decision-making.
- Deployable policies that avoid blank-filling and stay usable in the real setting.
- Support for DPIA and ROPA work, aligned to the relevant tier and the organisation’s actual needs.
- Support for ICO correspondence where needed, with the evidence trail kept clear and defensible.
Service coverage
What we cover
A scannable view of the main delivery areas covered by the DPO service.
Data Breach Response
Calm, structured support for containment, assessment, reporting, and records.
ICO Liaison
We handle engagement with the ICO and keep your evidence trail clear if a complaint or incident escalates.
Subject Access Requests
End-to-end SAR handling—from acknowledgement to redaction—with decisions recorded and deadlines met.
ROPA
A maintained Record of Processing Activities that stays current and usable.
DPIA
Practical DPIAs with risk assessed, actions clear, and outputs ready for inspection.
Policy Management
Deployable, school-ready policies that stay consistent as your setting, systems, and guidance change.
FOI Advice
Clear guidance on exemptions, public interest tests, and defensible responses.
Training
Practical staff training—clear, relevant, and designed to improve day-to-day decisions.
Onboarding
A fast, structured start: understand your setting, prioritise gaps, and leave with a clear plan.
How we help
Calm under deadlines
When work is time-sensitive and emotionally charged, structure and defensible decisions matter.
Subject Access Requests
Scope → search → review and redact → output
Freedom of Information Requests
Validate → exemptions → response drafting
Incidents
Contain → assess → decide → document
Portal + TruCredits
Tooling and currency that support delivery
Portal keeps work structured and auditable. TruCredits are the currency used for high-effort one-off tasks.
Portal
- Portal is included in Advisory + Comprehensive
- Standalone Portal: you run it day-to-day (we support and oversee)
- Comprehensive: we manage portal operations with you (we run it day-to-day)
TruCredits
- Used for evidence processing, redaction, and policy packs
- Complexity is confirmed up front before extra credits are applied
- Purchased TruCredits roll over until used
FAQ
DPO Service questions
Use central FAQ registry tags: dpo-service.
What does the Outsourced DPO service include?▾
The Outsourced DPO service provides a named, qualified DPO for schools and trusts. It can cover advice, incident response, SAR and FOI support, annual review and related governance support, depending on the agreed plan.
What’s the difference between Advisory and Comprehensive?▾
Both include the Portal. In Advisory, your team usually runs the day-to-day workflow with our support and oversight. In Comprehensive, we take a more active operational role with you.
Are you advice-only, or do you get involved?▾
We get involved. We help scope the work, support defensible decisions and deliver practical outputs, including policies, SAR and FOI support, and breach handling.
Do you support SARs and FOI?▾
Yes. We support SAR and FOI handling, including defensible decision-making, exemptions where relevant and clear record keeping.
Do I need the Portal to use the DPO service?▾
No. The DPO service stands on its own. Portal access may be included in some plans and can also be purchased separately where appropriate.