Data Protection Impact Assessment (DPIA)
Summary version — full signed DPIA held by the DPO on request.
1. Nature of processing
Aspire Connect processes children's personal data (including special-category safeguarding and medical data) and staff HR data on behalf of Aspire Academy and its partner schools. Processing includes recording, transmission (within the platform), storage, and structured retrieval by authenticated staff.
2. Scope
- Approximately 20 pupils aged 11–16 on roll at any time (alternative provision).
- Staff records for approximately 15 employees and contractors.
- Parents/carers and commissioning-school contacts with portal access.
3. Context
Data subjects are children, some with SEND or safeguarding vulnerabilities. Processing is required by statutory duties (KCSIE 2025, Working Together to Improve School Attendance 2024, Education Act 1996). Public expectation of confidentiality is high; parents and pupils would expect strict access controls.
4. Purpose
Attendance registers and DfE returns · Safeguarding case management · Behaviour records · Staff vetting (SCR) and supervision · Medication and first-aid records · Statutory reporting to LA and DfE.
5. Necessity and proportionality
Each data category is mapped to a lawful basis (see Privacy Policy §3). Data minimisation is enforced by role-based access and only recording fields required for statutory duties. Retention is time-bound in line with the IRMS toolkit.
6. Identified risks and mitigations
- Unauthorised access to safeguarding records. Mitigated by RLS, DSL-only visibility, MFA for privileged accounts and audit logging.
- Data leak via export. Mitigated by password re-authentication on bulk exports and letter generation, with an audit trail of every export.
- Retention beyond statutory limits. Mitigated by automated nightly retention purge with admin review at
/admin/retention. - Third-country transfer. Data stored in EU/UK regions by our hosting processor; sub-processors listed on request.
- Loss of availability. Backups managed by hosting provider; audit log kept for 7 years.
7. Consultation
This DPIA has been reviewed by the DSL, HR lead and the school's Data Protection Officer. It will be re-reviewed on major release or at least annually.
8. Sign-off
Approved by the Data Protection Officer, Sam Riches (sam.riches@aspireconnect.org.uk) — signed copy held in school records.