Last updated: 19 July 2026
Plain English: A DPIA is a check we do to make sure we're keeping your data safe — especially because we use AI and work with children. This is a summary; the full document is available on request.
UK GDPR Article 35 requires a DPIA for processing that is likely to result in a high risk to people — especially children, large-scale data, and systematic profiling with AI. GCSE.now meets all three, so a DPIA is mandatory.
Risk: AI gives wrong marks/grades that mislead a student. Mitigation: Persistent disclaimers, confidence scores surfaced to users, Report button, teacher signposting.
Risk: A child shares phone number, address or distressing information in the chat. Mitigation: Input filter blocks PII and self-harm content, signposts to Childline, no human reads conversations unless flagged.
Risk: Adaptive difficulty profiles users without their knowledge. Mitigation: Disclosed in Privacy Policy and AI Disclaimer; opt-out available in Account settings.
Risk: AI conversations kept forever. Mitigation: 12-month automatic retention with expiry timestamps.
Risk: Data processed outside the UK. Mitigation: UK Addendum to SCCs, transfer risk assessments, EU-based Supabase data centres as default.
Risk: Another user accesses a child's learning data. Mitigation: Row-level security on every table, ownership-scoped policies, no user-to-user contact features.
This DPIA also serves as our child impact assessment under AADC Standard 2. We have assessed all 15 standards; see our Privacy Policy for the child-specific protections.
This DPIA is reviewed at least annually or when we introduce new AI features. Last review: 19 July 2026.
Request the full DPIA by emailing seun@lotipic.com.