Home › Impact assessment & product safety checks
A DPIA, or Data Protection Impact Assessment, is the structured assessment of what a tool will do with personal data and what could go wrong for the people it describes. Done early, before decisions are made, it’s exactly what the DfE guidance expects.
The standard, in two lines
What the law requires: a DPIA where processing is likely to result in a high risk to individuals (UK GDPR).
What this policy recommends: a DPIA before deploying any AI tool that processes personal data.
The second goes further than the statutory minimum, and that’s a conscious governance choice. AI tools change quickly, children’s data is involved, and an assessment made before deployment is the only kind that can still change the decision.
What it is
The trigger and the process: a DPIA before you deploy AI that processes personal data; the product-safety checks that align to the DfE generative AI product safety standards; and the point in procurement where these happen, which is during tool approval, not after go-live. It sets out who coordinates the assessment (your DPO or data protection lead) and who signs it off.
Why it’s important
A DPIA completed after a tool is already embedded changes very little; the decisions have been made. Completed early, it brings the controller and processor question, international transfers, retention, sub-processors, and any training on your data into view before you’re committed. A tool that lacks a particular compliance feature isn’t ruled out automatically: the question is whether you can put sensible operational safeguards around it, and record them.
Mark is very knowledgeable and open to feedback to make sure his sessions meet your exact need and philosophy.
James Tucker · Professional Learning Lead, Diocese of Salisbury Academy Trust
A non-negotiable
A DPIA before you deploy AI that processes personal data is a non-negotiable. The screening tool supports that assessment; it doesn’t replace your DPO’s sign-off.
In practice
- Decision to make
- Whether a tool proceeds, with what safeguards, before it’s deployed.
- Who owns this?
- The DPO or data protection lead coordinates; SLT or the named approver signs off.
- Evidence to retain
- Completed DPIAs and product-safety checks, filed alongside each tool’s entry in the approved register.
Guidance it speaks to
- UK GDPR & Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025); ICO guidance on AI and the ICO AI & data protection risk toolkit.
- DfE position on generative AI in education and the DfE generative AI product safety standards (January 2026).
- ICO Children’s Code, wherever children’s data is involved.
- DfE guidance on procuring edtech and data protection in schools.
Get the screening tool
The AI & Digital Tool DPIA Screening Tool is a plain-English questionnaire that runs in your browser, for any AI or digital product you’re thinking of buying. It works through purpose, data, roles, transfers, retention, automated decisions and what the supplier does with the data, then tells you whether your answers are detailed enough to send to your DPO for sign-off. Unlock a copy to keep and reuse.