DPIAs for Schools
When They’re Needed and How to Approach Them
A practical guide to DPIA Registers, screening and assessment routes for schools and MATs, including when recorded checks, supplier review or a structured DPIA is needed.
The key point: all DPIA decisions belong on the register
For schools and MATs, the important question is not simply “do we need a DPIA?”
The better question is:
What is changing, what personal data is involved, what risk does it create, and how far does the assessment need to go?
Every relevant change should start on the DPIA Register. The register creates the audit trail. It records the change, the data involved, the supplier or system, the people affected, the screening outcome, the route chosen, any DPO advice, required actions and the final decision.
Some entries will need only recorded checks. Some will need a supplier or processor review. Higher-risk entries will need a structured DPIA before the change goes live.
This keeps the process proportionate without losing accountability.
What is a DPIA?
A Data Protection Impact Assessment is a structured way to identify and reduce privacy risks before a school introduces a new system, supplier, project or significant change involving personal data.
A DPIA helps the school understand:
- what personal data will be used;
- why the data is needed;
- who the data relates to;
- who will have access to it;
- where the data will be stored or shared;
- what could go wrong;
- how risks will be reduced; and
- whether the remaining risk is acceptable.
A DPIA is not just a form to complete at the end of a project. It should start early, while there is still time to change the design, adjust the supplier approach or decide not to proceed.
Why DPIAs matter in schools
Schools process large amounts of personal data about children, parents, carers, staff, governors, volunteers and visitors. Some of that data is especially sensitive, including safeguarding, SEND, health, behaviour, attendance, biometric, HR and online safety information.
DPIA governance helps a school or MAT show that it has considered privacy and data protection risks properly before a change goes live.
Used well, the DPIA Register supports:
- safer decision-making;
- clearer supplier checks;
- better data minimisation;
- stronger security controls;
- clearer roles and responsibilities;
- better privacy notices;
- more accurate ROPA records;
- evidence for governors, trustees, auditors or the ICO; and
- a defensible record if a complaint, SAR, breach or challenge arises later.
When should a school create a DPIA Register entry?
A school should create a DPIA Register entry whenever a new or changed activity may affect how personal data is collected, used, shared, stored, monitored, analysed or deleted.
This often includes:
- introducing a new MIS, safeguarding, behaviour, assessment or communication system;
- using software that handles safeguarding, SEND, health or vulnerability information;
- implementing CCTV, biometric systems, monitoring tools or online safety/filtering logs;
- using AI tools with pupil, parent or staff data;
- changing how personal data is shared between systems;
- introducing a new supplier that stores or processes school data;
- outsourcing a process involving personal data;
- collecting new categories of personal data;
- using existing data for a new purpose;
- introducing large-scale data sharing;
- transferring services from one provider to another;
- changing retention, access or reporting arrangements; or
- creating or changing a data-sharing agreement.
Creating a register entry does not mean a full structured DPIA is automatically required. It means the school has captured the change and can evidence how it was assessed.
Screening: deciding how far to go
Screening is the decision point. It looks at the register entry and decides the proportionate route.
The screening should consider:
- whether personal data is involved;
- whether children’s data is involved;
- whether special category, safeguarding, SEND, health, biometric or criminal offence data is involved;
- whether the processing involves monitoring, profiling, AI, CCTV or automated decision-making;
- whether a new supplier or processor is involved;
- whether data will be shared more widely;
- whether data will be transferred outside the UK;
- whether the change affects a large number of people;
- whether the individuals affected may be vulnerable;
- whether the school is using existing data for a new purpose; and
- whether the risk could be high if something goes wrong.
Screening should produce a clear recorded outcome.
Assessment routes
The register entry can move down different routes depending on risk.
1. No structured assessment required
This route applies where the change does not create meaningful data protection risk, or where the processing is already covered by an existing assessment, ROPA entry, privacy notice and supplier record.
The register should still record the decision and the reason.
2. Recorded checks
This route applies where checks are needed, but a structured DPIA would be disproportionate.
Recorded checks may cover:
- what data is involved;
- why it is needed;
- who is affected;
- whether the data is sensitive;
- whether access is limited;
- whether retention is clear;
- whether privacy notices need updating;
- whether the ROPA needs updating;
- whether staff guidance is needed; and
- whether any actions are required before use.
This is not a weaker DPIA. It is a proportionate evidence record showing that the school considered the issue and made a reasoned decision.
3. Supplier or processor review
This route applies where the main issue is whether a product, processor, system or service is suitable for school use.
A supplier or processor review may consider:
- who the supplier is;
- what role the supplier has;
- whether the supplier is a processor, controller or joint controller;
- whether a Data Processing Agreement is in place;
- where data is hosted;
- whether data is transferred outside the UK;
- whether sub-processors are used;
- what security measures are in place;
- whether the supplier provides adequate assurance;
- whether the product uses AI, profiling or analytics;
- whether the product collects unnecessary data;
- whether retention and deletion are clear;
- whether the school can manage access properly; and
- whether the supplier is suitable for the intended school context.
This route replaces the older idea of a “DPIA Light” for software checks. The work is still meaningful; the label is clearer.
4. Structured DPIA
This route applies where the processing is likely to create high risk and needs a formal assessment before go-live.
A structured DPIA should be used where there is likely high risk, including where the project involves:
- large-scale processing of special category data;
- large-scale processing of criminal offence data;
- systematic and extensive processing, including profiling;
- decisions that have legal or similarly significant effects;
- large-scale systematic monitoring of publicly accessible areas;
- safeguarding, SEND, health or vulnerability data at scale;
- intrusive monitoring or filtering;
- biometric data;
- AI tools using pupil or staff data;
- major system replacement or trust-wide migration;
- significant data sharing; or
- unresolved supplier, transfer or security concerns.
The structured DPIA should follow a formal process: describe the processing, assess necessity and proportionality, identify risks, record mitigations, assess residual risk, obtain DPO advice, record sign-off and track actions.
5. Escalation or do not proceed
Some entries may need escalation.
This may happen where:
- supplier evidence is missing or weak;
- high risk remains after mitigation;
- the DPO advises against proceeding;
- senior approval is needed;
- consultation with the ICO may be required; or
- the school decides not to proceed in the current form.
The register should record the reason and the final decision.
Common school examples
Typical school projects that should be registered and screened include:
- new safeguarding software;
- CCTV or body-worn camera use;
- biometric catering or library systems;
- online monitoring and filtering tools;
- behaviour tracking platforms;
- assessment and progress tracking systems;
- SEND case management systems;
- parent communication apps;
- visitor management systems;
- cloud storage changes;
- AI lesson planning or assessment tools;
- HR, payroll or recruitment systems;
- trust-wide MIS migration;
- data dashboards across multiple schools; and
- integrations between MIS, safeguarding, finance or learning platforms.
Not every example will need a structured DPIA, but each should be screened properly.
What should the DPIA Register record?
A good DPIA Register should record:
- the name of the project, system, supplier or process;
- the school, trust or department responsible;
- the person requesting or owning the change;
- the purpose of the processing;
- the categories of people affected;
- the categories of personal data involved;
- whether special category, safeguarding, SEND, health, biometric or criminal offence data is involved;
- the lawful basis for processing, where known;
- any special category condition, where relevant;
- the source of the data;
- where the data will be stored;
- who will have access;
- which suppliers or processors are involved;
- whether data will be transferred outside the UK;
- retention periods;
- security measures;
- privacy notice implications;
- links to the ROPA;
- links to supplier contracts or Data Processing Agreements;
- screening outcome;
- selected assessment route;
- risks identified;
- actions required;
- DPO advice;
- decision and sign-off;
- review date; and
- evidence of completed actions.
The register should show not only the final answer, but how the school got there.
Determine: understand the processing
The first stage is to determine what is actually happening.
The school should establish and document:
- the purpose of the processing;
- whether the school, trust or another organisation is the controller;
- whether any processor, joint controller or independent controller is involved;
- the lawful basis for processing;
- the types of personal data being used;
- the categories of people affected;
- how the data will flow between people, systems and organisations;
- where the data will be stored;
- who will have access;
- how long the data will be kept; and
- what will happen to the data at the end of the lifecycle.
This stage should be factual. It should describe the real process, not the process as people assume it works.
Design: reduce risk before go-live
Once the school understands the processing, the assessment should influence the design.
This may include decisions about:
- reducing the amount of data collected;
- limiting access by role;
- changing default settings;
- applying stronger authentication;
- turning off unnecessary features;
- improving audit logs;
- changing retention settings;
- updating privacy notices;
- adding staff guidance;
- requiring supplier evidence;
- improving contract terms;
- delaying go-live until risks are addressed; or
- deciding not to proceed.
The assessment should feed back into the project plan. It should not sit separately from implementation.
How DPIA work links to ROPA, suppliers and policies
DPIA work should not be isolated.
Where screening or assessment identifies a new or changed processing activity, the school’s ROPA should be updated. The ROPA should reflect the purpose, data categories, lawful basis, recipients, retention period and relevant security measures.
The process may also trigger updates to:
- privacy notices;
- data protection policies;
- retention schedules;
- supplier records;
- Data Processing Agreements;
- data-sharing agreements;
- staff guidance;
- training materials;
- breach response planning; and
- risk or improvement registers.
For MATs, this is especially important. A trust-wide system may have one central supplier, but different schools may use the system in different ways. The register and assessment route should be clear about whether the record applies trust-wide, school-by-school, or only to a specific local process.
Who should be involved?
A DPIA Register entry or structured assessment should involve the people who understand the project and the risks.
Depending on the project, this may include:
- the school or trust project lead;
- the Data Protection Officer;
- the School Business Manager or operations lead;
- IT or technical support;
- the DSL or safeguarding lead;
- SENCO;
- HR;
- the supplier;
- senior leadership;
- governors or trustees, where appropriate; and
- affected users, where consultation is appropriate and proportionate.
The DPO should advise and challenge. The DPO should not simply approve their own assessment without independent scrutiny. The school or trust remains responsible for the decision as controller.
What happens after screening or assessment?
The register should lead to a clear outcome.
The school should decide whether:
- no further action is needed;
- recorded checks are sufficient;
- supplier or processor review is needed;
- a structured DPIA is required;
- the processing can proceed;
- the processing can proceed only after actions are completed;
- further supplier evidence is needed;
- further legal or DPO advice is needed;
- residual risk needs senior approval;
- consultation with the ICO is required; or
- the project should not proceed in its current form.
The final record should be retained as evidence. It should be reviewed when there is a significant change, a supplier change, a new use of data, a breach, a complaint, or a scheduled review date.
Common mistakes
Common mistakes in schools include:
- only thinking about DPIAs after a system has already gone live;
- treating the DPIA Register as optional admin;
- using “no full DPIA needed” as if it means “no checks needed”;
- treating supplier checks as a substitute for understanding local school use;
- copying supplier wording without checking the real process;
- failing to involve the DPO early enough;
- ignoring safeguarding, SEND or special category data;
- failing to link the outcome to the ROPA;
- not updating privacy notices;
- overlooking integrations and data flows;
- assuming a trust-wide assessment covers all school-level use;
- recording risks without assigning actions; and
- failing to review the record when the system changes.
How Tru Data Protection helps
Tru Data Protection supports schools and MATs with practical, evidence-led DPIA governance.
We help schools record relevant changes, screen risk, decide the right assessment route, review suppliers and processors, complete structured DPIAs where needed, record DPO advice, connect outcomes to ROPA and supplier assurance, and produce a clear record of the decision.
The aim is not paperwork for its own sake. The aim is a calm, proportionate and defensible process that helps schools make better decisions before personal data is put at risk.
FAQs
Does every new system need a structured DPIA?
No. Every relevant change should be recorded and screened, but not every entry needs a structured DPIA. Some entries only need recorded checks or supplier review.
Is a supplier review the same as a DPIA?
No. A supplier review checks whether the product, processor or service is suitable and whether appropriate safeguards are in place. A structured DPIA goes further and assesses the wider processing, risks, necessity, proportionality and residual risk.
Should screening happen before or after buying software?
Before, wherever possible. Screening should influence the decision, supplier checks, contract terms, system settings and go-live plan.
Who owns the DPIA Register?
The school or MAT owns the DPIA Register as controller. The DPO can advise, challenge and support, but the controller remains responsible for the decision.
Can one MAT assessment cover all schools?
Sometimes, but not always. A trust-wide assessment may work where the system, settings and use are consistent. If schools use the system differently, school-level risks may still need to be considered.
How often should register entries be reviewed?
A register entry should be reviewed when the processing changes, the supplier changes, a new risk emerges, there is a relevant incident or complaint, or the scheduled review date arrives.
How does this link to ROPA?
The DPIA Register records screening and assessment decisions. The ROPA records the processing activity. If screening or assessment identifies new or changed processing, the ROPA should be updated so the school’s accountability record stays accurate.