In a school that often means new systems that touch pupils’ data, such as CCTV, biometric catering, filtering and monitoring, a new management information system or an edtech app with special category data. This guide explains when a DPIA is required, what any template must contain, how the risks are scored and signed off, and when the assessment has to be reopened.
The rule: Article 35 of the UK GDPR
Article 35(1) of the UK GDPR requires a controller to assess the impact of processing “prior to the processing” where it “is likely to result in a high risk to the rights and freedoms of natural persons”, particularly when it uses new technologies. For a maintained school the controller is the governing body; for an academy, the trust. The ICO’s guidance on data protection impact assessments describes a DPIA as “a process to help you identify and minimise the data protection risks of a project” and puts the duty simply: “You must do a DPIA for processing that is likely to result in a high risk to individuals.”
Four further parts of the Article shape the document. Article 35(2): “The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment”, and every maintained school and academy must have one. Article 35(3) names three cases where a DPIA is always required: systematic and extensive automated evaluation of people with significant effects, large-scale processing of special category or criminal offence data, and “systematic monitoring of a publicly accessible area on a large scale”. Article 35(7) sets the minimum contents. And Article 35(11) requires a review “at least when there is a change of the risk represented by processing operations”.
Where a DPIA shows a high risk that the school cannot reduce, Article 36 requires it to consult the regulator “prior to processing”. The Department for Education’s guidance on data protection policies and procedures repeats the consequence for schools: “You may not begin processing the personal data in question until you have acted on the ICO’s advice.”
When a school needs a DPIA
Most of what a school does with data every day – registers, assessment, the single central record – is existing processing that does not need a fresh DPIA each term. The trigger is something new or changed that screens as likely high risk. The Department for Education says schools “should consider and document carrying out a DPIA” of personal data collected about vulnerable data subjects, including “children (because of their age)” and “employees (because the power imbalance means they cannot easily consent or object to the processing of their data by an employer)”, and by innovative technologies, naming “biometrics”, “internet of things applications”, “safeguarding equipment, such as CCTV” and “filtering and monitoring systems”.
The ICO adds its own list of processing that always needs a DPIA, several of which describe ordinary school projects:
- processing biometric data, in combination with another high-risk criterion – a fingerprint or facial recognition system for catering, the library or registration;
- tracking people’s location or behaviour, in combination with another high-risk criterion – CCTV across a site, or the monitoring of pupils’ activity on school devices;
- profiling children – an edtech app that builds a picture of each pupil’s performance or behaviour;
- matching or combining datasets from different sources – a new management information system that pulls in assessment, attendance and behaviour data;
- processing data that might endanger someone’s physical health or safety in the event of a breach – safeguarding and child protection records.
The DfE’s CCTV guidance says that before installing CCTV a school “should also consider if you need to complete a data protection impact assessment”, and that for automatic number-plate recognition in the car park “you need to complete a DPIA”. Its guidance on procuring educational technology says “high-risk processing, such as profiling pupils or processing biometric data on a large scale, usually requires a DPIA”, and that it should be completed “ideally before any decisions are made on how personal data will be processed”. In practice that means before the contract is signed, not after the system goes live.
Where the school screens a project and decides a DPIA is not needed, it should keep that decision. The ICO says to “document your decision and the reasons for it, including your DPO’s advice”, and that this “does not have to be a burdensome paperwork exercise”: “you could simply keep an annotated copy of the checklist”. Article 35(1) also allows “a single assessment” for “a set of similar processing operations that present similar high risks”, and the ICO says “a group of controllers can do a joint DPIA”, which suits a trust rolling the same system out across its schools.
What a DPIA template must contain
There is no prescribed form. The DfE says “there’s no definitive DPIA format you must follow” and that schools “can download a suggested DPIA template from the ICO website”; the ICO says you can “use or adapt our sample DPIA template, or create your own”, provided it covers the key elements. Whatever the layout, Article 35(7) requires at least “a systematic description of the envisaged processing operations and the purposes”, an assessment of “necessity and proportionality”, an assessment of the risks to people, and “the measures envisaged to address the risks”. The ICO’s guidance on how to do a DPIA says a DPIA “should begin early in the life of a project, before you start your processing, and run alongside the planning and development process”, and turns it into seven steps, each of which is a section of the template:
- Identify the need. Which screening criteria the project meets, and the DPO’s view.
- Describe the processing. Its nature (how data is collected, stored, used and shared, who has access, which processors, retention periods, security), its scope (what data, how sensitive, how many people, how often, for how long), its context (the relationship with the people, whether they include children or other vulnerable people, what they would expect) and its purposes.
- Consider consultation. The ICO says you “should seek and document the views of individuals (or their representatives) unless there is a good reason not to”; for a school that may be the pupil council, parents or staff, as well as the IT lead and the supplier, whose contract should require them to assist.
- Assess necessity and proportionality. Does the plan achieve the purpose, and “is there any other reasonable way to achieve the same result?” Record the lawful basis, how function creep will be prevented, data minimisation, privacy information, support for individuals’ rights, processor terms and any international transfers.
- Identify and assess the risks to individuals – loss of control over their data, discrimination, loss of confidentiality, physical or emotional harm – and the security risks, scoring each for likelihood and severity.
- Identify measures to reduce the risks, recording against each risk whether the measure reduces or eliminates it.
- Sign off and record the outcomes: the additional measures adopted, whether each risk is eliminated, reduced or accepted, the residual risk, the DPO’s advice, and whether the regulator must be consulted.
A fictional example DPIA shows the shape. Fernhollow Primary (an invented school) plans fingerprint recognition for its cashless canteen. The description records 340 pupils’ fingerprint templates held by the catering supplier as processor, deleted when a pupil leaves. The necessity section notes the reason (faster queues, no lost cards) and the alternative that must exist anyway. The risk section scores a template breach as unlikely but serious. The measures include notifying every parent and obtaining consent before any child is enrolled, as section 26 of the Protection of Freedoms Act 2012 requires, and providing “reasonable alternative means” for any child who does not take part. The DPO advises, the head signs off, and the review date is set for the contract renewal. None of the details belongs to a real school; the structure is what to copy.
Scoring the risks, signing off and consulting the regulator
The ICO says that “to assess the level of risk, a DPIA must consider both the likelihood and the severity of any impact on individuals”, and that the assessment must be objective. It explains that “harm does not have to be inevitable to qualify as a risk or a high risk”: “any significant possibility of very serious harm may still be enough to qualify as a high risk”, and “a high probability of widespread but more minor harm may still count as high risk”. A simple matrix of likelihood against severity is enough, and a school can use the risk method it already uses for its risk register.
The measures are where a DPIA earns its keep. The ICO’s examples translate directly into school decisions: not collecting certain data, reducing the scope of the processing, shortening retention periods, adding security measures, training staff, pseudonymising data, writing internal guidance, using a different technology, putting data sharing agreements in place, changing privacy notices, or offering an opt-out where appropriate. A DPIA “does not have to indicate that all risks have been eradicated”, the ICO says, “but it should help you document them and assess whether or not any remaining risks are justified”.
Sign-off records the decision, not just the form. The ICO says that “as part of the sign-off process, you should seek and document DPO advice on whether the processing is compliant and can go ahead. If you decide not to follow their advice, you need to record your reasons.” Reasons for going against the views of pupils, parents or staff who were consulted should be recorded too. Who signs depends on the school’s scheme of delegation: commonly the headteacher or a trust executive, with high-residual-risk projects reported to the governing board.
If a high risk remains, the school must consult the regulator before it begins. The ICO says “you don’t need to send every DPIA to the ICO and we expect the percentage sent to us to be small”, but “you cannot begin the processing until you have consulted us”, and it “will generally respond within eight weeks (although we can extend this by a further six weeks in complex cases)”. Article 36(3) lists what goes with the request, including the DPO’s contact details and the DPIA itself.

Reviewing, publishing and keeping the DPIA
A DPIA is not finished when it is signed. The ICO says “you must integrate the outcomes of your DPIA into your project plans”, identifying action points and who is responsible for each, and “you need to keep your DPIA under review”. The DfE says “a DPIA is not a one-off exercise” and lists the triggers for a school to reopen one: a new security flaw, a new technology, a new contractor, or public concern about the processing or about the vulnerability of a group of data subjects. Its edtech guidance adds supplier updates: when a tool changes, check that new processing is not “automatically switched ‘on’” and update the DPIA and privacy notice if it is. For CCTV, the DfE says to check after updates that switched-off features “such as facial recognition or audio” remain off.
Publishing is optional but encouraged. The ICO says “publishing a DPIA is not a requirement of UK GDPR”, but recommends publication “where possible, removing sensitive details if necessary”, and reminds public authorities, which includes schools, to think about their wider transparency obligations under the Freedom of Information Act.
No law sets a retention period for a DPIA. A sensible approach is to keep each DPIA with the record of processing activities for as long as the processing runs, and set a period after it ends in the school’s retention schedule; it is the evidence of the decision if the processing is questioned later. A short DPIA register – project, date, screening outcome, DPO advice, sign-off, review date – lets the DPO and governors see which assessments are overdue.
One change to watch: the ICO marks its detailed DPIA guidance as under review because of the Data (Use and Access) Act 2025, which is amending UK GDPR in stages, and on 30 September 2026 the Information Commissioner was replaced by the Information Commission. The guidance remains at ico.org.uk; check the date on the page before relying on it.
The processing nobody assessed
Step 2 of every DPIA asks how data is collected, where it is stored, who has access and how long it is kept. Schools answer those questions carefully for the canteen system and the CCTV, and almost never for the place where staff discuss pupils most: their messages. The year team’s group chat where a teacher posts that a pupil has disclosed self-harm. The senior leaders’ chat where a behaviour incident is described, with names, at ten at night. The photograph of a class list with medical notes, sent to a colleague to save printing it. The SENCO texting a parent from a personal phone about a diagnosis.
Run that through the ICO’s screening list and it meets several criteria at once: children’s data, special category data, information that could endanger a child if it leaked, held on personal devices, in an app with which the school has no contract and over which it has no retention control. It is processing for which the school is the controller, and it usually has no DPIA, no entry in the record of processing activities and no retention period, because nobody decided to start it. It simply grew.
The point is not that every message needs an assessment. It is that the screening question applies to how staff communicate as much as to any system the school buys. The question to take to the next leadership or governing board meeting is this: if the DPO screened the staff group chats the way they screened the last edtech app, what would the DPIA say about where that data is and who controls it?
Questions people ask
What is a DPIA template?
A DPIA template is a structured form for recording a data protection impact assessment: the description of the processing, its necessity and proportionality, the risks to people and the measures to reduce them, as Article 35(7) of the UK GDPR requires. The ICO publishes a sample DPIA template that schools can use or adapt, and the Department for Education points schools to it; no particular format is compulsory.
How do you write a DPIA?
Write a DPIA in the seven steps the ICO sets out: identify the need, describe the processing, consider consultation, assess necessity and proportionality, identify and assess the risks, identify measures to reduce them, and sign off and record the outcomes. Start early, before the processing begins, and seek the data protection officer’s advice, which Article 35(2) of the UK GDPR requires.
Does a school need a DPIA for CCTV?
Usually yes: the ICO’s CCTV guidance says a DPIA “is a legal requirement and applies in most cases, due to the inherent privacy risks”, and the Department for Education says a school installing CCTV should consider whether it needs one. The DfE also says the DPIA should be reviewed when the CCTV technology changes, and that automatic number-plate recognition in a school car park needs one.
Are schools exempt from data protection requirements under GDPR?
No: schools in England must comply with the UK GDPR and the Data Protection Act 2018 like any other controller, and as public authorities they must also appoint a data protection officer under Article 37 of the UK GDPR. The DPIA requirement in Article 35 applies to schools in full; there is no education exemption from it.
Do you have to publish a DPIA?
No: the ICO says “publishing a DPIA is not a requirement of UK GDPR”, but it recommends publishing where possible, with sensitive details removed, to build trust. Schools are public authorities under the Freedom of Information Act 2000, so a DPIA may also be requested under it.
Official guidance and your next step
The law is Article 35 and Article 36 of the UK GDPR. The ICO’s DPIA guidance has the screening, process and quality checklists, its step-by-step guide explains each stage, and its sample DPIA template is the one the DfE suggests. For school-specific triggers read the DfE’s data protection policies and procedures, its photos, videos and CCTV guidance and its edtech procurement guidance. The wider data protection duties are in the GDPR in schools guide.
This guide summarises published law and guidance for schools in England and is not legal advice; a project that screens as high risk deserves your DPO’s advice from the start.
Then do one thing: list every system the school has introduced or changed in the last two years and mark which have a DPIA or a recorded screening decision. The gaps are the assessments to start this term.
We build ComplyChat for the work conversations schools need to keep, and section 06 is the processing a DPIA is most likely to miss. ComplyChat does not write DPIAs and does not replace the school’s DPO. It gives staff a channel the school runs, where everyone added is told the conversation is on the record and messages are recorded on the server as they are sent, so the school can describe where that data is; on paid plans, once the school’s Microsoft 365 tenant is connected, the lasting record files there under the school’s own retention rules.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Article 35(1) of the UK GDPR legislation.gov.uk
- Guidance on data protection impact assessments ico.org.uk
- Article 36 legislation.gov.uk
- Data protection policies and procedures gov.uk
- Procuring educational technology gov.uk
- Sample DPIA template ico.org.uk
- How to do a DPIA ico.org.uk
- Section 26 of the Protection of Freedoms Act 2012 legislation.gov.uk
- Photos, videos and CCTV guidance gov.uk




