Back to home
Legal · Version 1.0 · Last updated 19 July 2026

Data Protection Impact Assessment (DPIA)

Last updated: 19 July 2026

Plain English: A DPIA is a check we do to make sure we're keeping your data safe — especially because we use AI and work with children. This is a summary; the full document is available on request.

Why we do a DPIA

UK GDPR Article 35 requires a DPIA for processing that is likely to result in a high risk to people — especially children, large-scale data, and systematic profiling with AI. GCSE.now meets all three, so a DPIA is mandatory.

Processing we assessed

  • Collection of children's personal data (name, email, learning records).
  • AI marking, grade estimation and adaptive difficulty (profiling).
  • AI tutor conversations (free-text input from children).
  • OCR of uploaded question images.
  • Parent dashboard data sharing.
  • International data transfers (Supabase).

Risks identified and mitigations

1. AI hallucination causing harm

Risk: AI gives wrong marks/grades that mislead a student. Mitigation: Persistent disclaimers, confidence scores surfaced to users, Report button, teacher signposting.

2. Children disclosing personal information to AI

Risk: A child shares phone number, address or distressing information in the chat. Mitigation: Input filter blocks PII and self-harm content, signposts to Childline, no human reads conversations unless flagged.

3. Profiling without awareness

Risk: Adaptive difficulty profiles users without their knowledge. Mitigation: Disclosed in Privacy Policy and AI Disclaimer; opt-out available in Account settings.

4. Excessive data retention

Risk: AI conversations kept forever. Mitigation: 12-month automatic retention with expiry timestamps.

5. International transfer

Risk: Data processed outside the UK. Mitigation: UK Addendum to SCCs, transfer risk assessments, EU-based Supabase data centres as default.

6. Unauthorised access to child's data

Risk: Another user accesses a child's learning data. Mitigation: Row-level security on every table, ownership-scoped policies, no user-to-user contact features.

Age Appropriate Design Code

This DPIA also serves as our child impact assessment under AADC Standard 2. We have assessed all 15 standards; see our Privacy Policy for the child-specific protections.

Review

This DPIA is reviewed at least annually or when we introduce new AI features. Last review: 19 July 2026.

Contact

Request the full DPIA by emailing seun@lotipic.com.