DPIAs Made Easy for Schools: New Guidance for Safer Planning
A small change in a school can have a big effect on personal information. A new behaviour system, a revised safeguarding form, a visitor sign-in process, a parent app, or an AI tool might all change who sees information, where it goes, how long it is kept, and what could happen if something goes wrong.
That is where a Data Protection Impact Assessment, or DPIA, helps.
Insight has produced Guidance on Producing DPIAs in Schools, a practical document for schools, academies and trusts in England. It explains what a DPIA is, when one may be needed, and how to complete one in a way that supports good decisions rather than creating unnecessary paperwork.
A DPIA should not feel like a barrier to improvement. Used well, it becomes part of sensible planning. It helps schools spot risks early, ask better questions, and put safeguards in place before pupils, families or staff are affected.

Why DPIAs matter in schools
Schools handle a wide range of personal information every day. Some of it is routine, such as names, addresses, attendance records and contact details. Some of it is more sensitive, including safeguarding information, health needs, special educational needs, behaviour records, photographs, biometric data, and details about family circumstances.
A change to a process can alter the risk around that information.
For example, a school might introduce:
a new system for recording behaviour incidents
an online platform for parents and carers
a revised paper form for medical needs
a visitor management system
a tool that uses artificial intelligence to support learning or administration
a new way of sharing information between a school and a trust
a cloud-based system replacing a local file store
Some changes are clearly digital. Others are not. Insight’s guidance makes clear that DPIAs apply to paper processes as well as electronic systems. A new paper form can still collect too much information, be stored in the wrong place, or be seen by people who do not need access.
A DPIA helps a school pause before the change goes live. It asks simple but valuable questions.
What personal information will be used?
Who will it be about?
Why is it needed?
Who will have access?
How could people be affected if something goes wrong?
What safeguards will reduce the risk?
The point is not to remove all risk. That is rarely possible. The point is to understand the risk and make sound, recorded decisions.
A DPIA need not be complicated
The phrase Data Protection Impact Assessment can sound formal. In practice, a DPIA is a structured way to think through a proposed activity before it starts.
Insight’s guidance presents DPIAs as a manageable process. It encourages schools to describe what they plan to do with personal information, consider how the activity could affect pupils, families or staff, then record sensible steps to reduce risk.
A good DPIA is proportionate. A small, low-risk change should not need pages of detail. A high-risk activity, such as using an AI tool with pupil information or introducing a system that processes sensitive data, will need more careful assessment.
The level of detail should match the activity.
Lower-risk change | Higher-risk change |
Updating the wording on an existing low-risk form | Introducing a new system that stores safeguarding records |
Changing who receives a routine internal report | Using a new tool that analyses pupil performance data |
Moving an existing paper process to a similar approved format | Sharing sensitive information with a new external supplier |
The DPIA process helps schools avoid two common problems.
The first is doing too little too late. If a new system is already live, it becomes harder to fix issues without disruption.
The second is overcomplicating simple decisions. A DPIA should give structure, not create confusion.
The best assessments are clear, practical and honest. They explain the purpose of the activity, set out the risks, and show what the school will do to manage them.

What the new guidance covers
Insight’s Guidance on Producing DPIAs in Schools has been written for schools, academies and trusts in England. It is designed to help staff approach the process with confidence, especially when a proposed activity feels new or uncertain.
The document explains the purpose of a DPIA and shows how to move from concern to action. That matters because risk assessment is only useful if it leads to practical safeguards.
The guidance recommends using the Information Commissioner’s Office sample DPIA template. This supports a consistent approach and reflects ICO guidance. It also helps schools avoid creating their own process from scratch when a recognised model is already available.
The guidance includes school-focused examples, which can make the process easier to apply. Data protection can feel abstract when it is discussed only in legal terms. It becomes clearer when linked to real school activities, such as adopting a new system, changing a form, or reviewing how information is shared.
A DPIA will usually include:
a description of the proposed activity
the types of personal information involved
the people whose information will be used
the purpose of collecting or using that information
who will have access to it
how long it will be kept
the risks to individuals
the steps planned to reduce those risks
advice from the Data Protection Officer where needed
the school or trust’s decision on whether and how to proceed
This is not just a compliance task. It is a way to improve planning.
For example, a DPIA might show that a proposed form asks for information the school does not need. It might reveal that access settings in a system need tightening. It might raise questions about where supplier data is stored, or whether staff need clearer instructions.
Those findings are useful. They help the school improve the proposal before people are affected.
When schools should think about a DPIA
A DPIA is most useful when completed early. If the assessment starts after contracts are signed, forms are printed or systems are launched, the school has fewer options.
A good prompt is simple: will this change how personal information is collected, used, shared, stored or deleted?
If the answer is yes, it is worth considering whether a DPIA is needed.
This might apply when a school is planning to:
introduce a new software system
use an AI tool for learning, assessment or administration
collect a new category of information
use existing information for a new purpose
share information with a new organisation
change access arrangements for staff
move from paper records to digital records
replace an existing process with a different one
use technology to monitor behaviour, attendance or engagement
Not every change will need a full DPIA. Some will need a brief review and a recorded decision. Others will need a more detailed assessment.
The key is to ask the question early enough.
AI tools are a good example. They can bring benefits, but they can also raise questions about transparency, accuracy, data sharing, supplier access, and how outputs are checked. A DPIA gives the school a way to examine those points before the tool is used with real information.
Paper processes deserve the same attention. A new form might seem harmless, but it could collect sensitive details, be passed between several people, or be stored in a place where access is hard to control.
A DPIA helps staff look at the whole process, not just the end product.

Who should complete the assessment
One of the most useful parts of Insight’s guidance is its explanation of responsibilities.
Insight recommends that the person coordinating the new or changed activity completes the DPIA. That person is likely to understand what is being planned, why it is needed, and how it will work in practice.
They should not have to do it alone. A good assessment may need information from:
colleagues who will use the system or process
staff responsible for safeguarding, SEND, attendance or pastoral support
IT or systems staff
the supplier or service provider
senior leaders
the trust central team, where relevant
The Data Protection Officer has a different role. The DPO provides advice and reviews the assessment for good practice and legislative compliance. The DPO can help identify gaps, suggest safeguards, and advise on whether the assessment is proportionate.
The final accountability remains with the school or trust. The DPIA supports decision-making, but it does not transfer responsibility away from the organisation.
Role | Main contribution |
Activity lead | Describes the proposal and completes the assessment |
Colleagues | Explain how the process will work in real school use |
Supplier | Provides details about the system, security, storage and data handling |
Data Protection Officer | Advises, reviews and checks for good practice and compliance |
School or trust | Makes and records the final decision |
This division of responsibility keeps the process practical. The person closest to the activity explains it. The DPO advises. Leaders make sure the final decision is appropriate.
From risks to safeguards
A DPIA works best when it connects each risk to a clear action.
A risk on its own is only a warning. A safeguard shows what the school will do about it.
For example, a DPIA might identify a risk that too many staff could access sensitive pupil information in a new system. A safeguard could be to set role-based access, check permissions before launch, and review access at agreed intervals.
Another risk might be that parents and carers do not understand how their information will be used in a new process. A safeguard could be to update the privacy notice or provide clear information before the process begins.
Some common safeguards include:
limiting the information collected to what is needed
setting clear access controls
checking supplier terms and data processing details
making sure retention periods are defined
training staff who will use the system or process
updating privacy information for pupils, families or staff
testing the process before launch
recording decisions and review dates
These steps do not need to be complex. They need to be practical and followed through.
A DPIA is most valuable when it changes the plan for the better before the activity begins.
The assessment should not sit in a file and gather dust. If it identifies actions, someone should own them. If the activity changes later, the DPIA may need to be reviewed.
Making DPIAs part of safer planning
Schools already plan carefully for curriculum changes, trips, building works, safeguarding arrangements and health needs. DPIAs bring the same careful thinking to personal information.
The aim is not to slow schools down. It is to help them make confident decisions.
When DPIAs become part of normal planning, staff are more likely to ask good questions early. Suppliers can be asked for the right information before decisions are made. Leaders can see the benefits and risks more clearly. The DPO can advise at the right time, rather than trying to fix problems after launch.
That approach protects pupils, families and staff. It also helps schools show that they have taken their data protection responsibilities seriously.
Insight’s new guidance is available at no additional cost to schools, academies and trusts subscribing to Insight’s annual Information Governance support service package.
Subscribers can contact insightmsig@outlook.co.uk to request a copy of the guidance or discuss a proposed activity.

The main takeaway
DPIAs do not need to be daunting. At their best, they are a clear and sensible way to plan changes that involve personal information.
Insight’s guidance gives schools, academies and trusts in England a practical route through the process. It explains when a DPIA may be needed, who should be involved, how the ICO sample template can support the work, and how to turn risks into useful safeguards.
Safer planning starts before a new system, form or tool goes live. A manageable DPIA helps schools get there.




Comments