Data Protection Impact Assessment

Download this pack for Word to fill in and adapt, or work from the page below.

1. Why a DPIA is needed

On the ICO’s criteria, this processing is likely to require a DPIA. Two of the ICO’s screening criteria apply:

Neither the volume nor the sensitivity is at the extreme end – the service holds a first name and a piece of schoolwork, not health, safeguarding or biometric data – but two criteria is the usual threshold, and children plus AI is a combination the ICO expects to see assessed. We would recommend completing one even if your own screening came out marginal.

2. Describing the processing

Nature

Teachers use BA Productivity to generate teaching material, to set quizzes and lessons, and to mark student work. Student information enters the service in five ways: a student types a name and answers into a quiz link; a pupil types a name and works through a lesson; a teacher builds a class roster; a teacher types, pastes or photographs student answers for marking; or – on an organisation plan only – a teacher creates pupil sign-ins, and the pupil signs in and does the work as themselves.

Pupil sign-ins are optional and organisation-only. They exist because a school that wants work set to a named class and marks handed back to the pupil who did it cannot get there by asking children to type their names, which is a guess a person then has to resolve. A school that does not want pupil accounts does not have them, and every other route into the service is unchanged: no account is needed to answer a quiz link or a lesson code, and that remains the only way in outside an organisation.

We are the processor and your school is the controller. The written contract required by Article 28 is our Data Processing Terms, which take effect when your staff accept our Terms & Conditions.

Scope

Context

The children are pupils at your school; the relationship is an educational one, and they would reasonably expect their work to be marked and their teacher to see it. They would not expect it to be used to build a profile of them, to advertise to them, or to train an AI model – and none of those happens. Children have limited ability to exercise their own rights here, which is why requests come to you as controller and why we have kept what we hold to the minimum that makes the feature work.

The student-facing pages are deliberately the plainest part of the service: no analytics, no advertising pixel, no tracking of any kind, and nothing to configure. Where a school uses pupil sign-ins, those pages set one cookie – the session that keeps a pupil signed in while they work – and nothing else. Quiz links and lesson codes still set no cookie at all.

Purposes

To provide the service to the teacher: marking work, showing a class’s results, and keeping the record the teacher chose to keep. We do not use student information for our own purposes, do not sell it, do not profile students, and do not train any model on it.

3. Consultation – for your school to complete

Article 35(9) asks you to seek the views of data subjects or their representatives where appropriate. Schools typically record here:

We cannot complete this section. If it would help, we are willing to join a call with your DPO.

4. Necessity and proportionality

Lawful basis

The lawful basis is yours to determine, and for a maintained school it is normally Article 6(1)(e), the performance of a task carried out in the public interest – the provision of education. Academies and independent schools more often rely on Article 6(1)(e) or 6(1)(f) depending on their constitution. We do not rely on consent from children for this processing, and we do not ask you to obtain it.

Is the processing necessary to achieve the purpose?

Marking and feedback are core educational activities. The question the DPIA should record is whether doing them this way is proportionate. The relevant points on our side:

International transfers

Answers are marked in the United States by CoreWeave, or Baseten as fallback, reached through OpenRouter. Photographs of handwritten work are transcribed by Anthropic, contracted through its Irish entity. Each transfer is covered by the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum. Every marking request is restricted to a fixed list of assessed providers and carries a setting that excludes any provider that stores or trains on what it receives, so the set of companies that can see a marked answer is fixed by us in advance rather than chosen at the moment of the request. Full detail is in section 5 of our Privacy Policy.

Data subject rights

Rights requests come to you as controller. A teacher can satisfy most of them directly: deleting a quiz, lesson, marking set or roster entry deletes the student information in it immediately. If a request reaches us we pass it to you rather than answering it ourselves. Our assistance duty is at section 8 of the Data Processing Terms.

Where pupil sign-ins are in use, erasure of a single pupil is not yet a one-click action in the interface: deleting a class deletes the sign-ins of the pupils only in that class, and a single pupil’s account and work can be erased on request to [email protected], which we action within the statutory month. We are building the self-service equivalent; until it ships, treat that address as the route for a pupil erasure request.

5. Automated decision-making and marking accuracy

DPOs ask about Article 22 here, so we will answer it directly.

There is no decision based solely on automated processing. The service produces suggested marks and written feedback. A teacher sees them, can change them, and remains the person who decides what a piece of work is worth and what goes in a report. The marks are an input to a professional judgment, not a substitute for one. On that basis Article 22 is not engaged, and no explicit consent or Article 22(2) condition is needed.

That conclusion depends on your staff actually working that way. If a school were to pass AI-generated marks into a report or a setting decision without a teacher reviewing them, the position would change and Article 22 would need revisiting. We would recommend recording in section 8 that teacher review is expected practice.

Accuracy. Language models can mark inconsistently, and can misread handwriting. The mitigations built in: transcriptions are shown to the teacher to correct before anything is marked; marking runs against the mark scheme the teacher supplies rather than the model’s own opinion of the question; and every mark is editable. Article 5(1)(d) accuracy is best served here by the teacher review step, which is why it is not optional in the interface.

6. Children’s Code conformance

The Age Appropriate Design Code under section 123 of the Data Protection Act 2018 applies to services likely to be accessed by children. Our student-facing pages were built to it. Against the standards most often asked about:

7. Risks and measures

Risk ratings assume the measures described are in place. “Residual” is our assessment of what remains; your DPO may rate them differently for your context.

8. Risks arising from your own use – for your school to complete

These depend on how your staff use the service, so only you can assess them. The ones we would put in front of a DPO:

If you issue pupil sign-ins, add these:

9. Outcome and sign-off – for your school to complete

Questions on anything here: [email protected]. We will also complete your own supplier security questionnaire if you would rather work from that.