Skip to main content
Back to home

Data Protection Impact Assessment (DPIA)

Summary version — full signed DPIA held by the DPO on request.

1. Nature of processing

Aspire Connect processes children's personal data (including special-category safeguarding and medical data) and staff HR data on behalf of Aspire Academy and its partner schools. Processing includes recording, transmission (within the platform), storage, and structured retrieval by authenticated staff.

2. Scope

  • Approximately 20 pupils aged 11–16 on roll at any time (alternative provision).
  • Staff records for approximately 15 employees and contractors.
  • Parents/carers and commissioning-school contacts with portal access.

3. Context

Data subjects are children, some with SEND or safeguarding vulnerabilities. Processing is required by statutory duties (KCSIE 2025, Working Together to Improve School Attendance 2024, Education Act 1996). Public expectation of confidentiality is high; parents and pupils would expect strict access controls.

4. Purpose

Attendance registers and DfE returns · Safeguarding case management · Behaviour records · Staff vetting (SCR) and supervision · Medication and first-aid records · Statutory reporting to LA and DfE.

5. Necessity and proportionality

Each data category is mapped to a lawful basis (see Privacy Policy §3). Data minimisation is enforced by role-based access and only recording fields required for statutory duties. Retention is time-bound in line with the IRMS toolkit.

6. Identified risks and mitigations

  • Unauthorised access to safeguarding records. Mitigated by RLS, DSL-only visibility, MFA for privileged accounts and audit logging.
  • Data leak via export. Mitigated by password re-authentication on bulk exports and letter generation, with an audit trail of every export.
  • Retention beyond statutory limits. Mitigated by automated nightly retention purge with admin review at /admin/retention.
  • Third-country transfer. Data stored in EU/UK regions by our hosting processor; sub-processors listed on request.
  • Loss of availability. Backups managed by hosting provider; audit log kept for 7 years.

7. Consultation

This DPIA has been reviewed by the DSL, HR lead and the school's Data Protection Officer. It will be re-reviewed on major release or at least annually.

8. Sign-off

Approved by the Data Protection Officer, Sam Riches (sam.riches@aspireconnect.org.uk) — signed copy held in school records.