Data Protection Impact Assessment

Edited

1. Overview

Part 4, Chapter 4, section 64 of The Data Protection Act 2018, and article 35 of the UK General Data Protection Regulation (UK GDPR 2018), says that Data Controllers must conduct a DataProtection Impact Assessment (DPIA) where a change to the processing of personal data has the potential to affect the compliance risks associated with that processing.

Additionally, section 2 of the UK Information Commissioner’s Office (ICO) Age-Appropriate Design Code, sometimes referred to as the Children’s Code says that organisations processing personal data relating to children should be carried out to assess and mitigate risks to the rights and freedoms of children who are likely to access a service, which arises from data processing.

The DPIA should consider differing ages, capacities and development needs and should be carried out before processing commences.

While the regulatory obligation to undertake DPIA’s falls on the Data Protection Officer of a Data Controller, this assessment has been conducted by Springpod for the convenience of Data Controllers that want to take advantage of their products and services, particularly the provision of Virtual Work Experience using Springpod as a Data Processor.


2. Impact on Personal Data

The service concerned is creating and delivering virtual insight days and work experience and other associated services, including live workshops and training for qualifying candidates.

To achieve this, Springpod needs to process personal information relating to students, employees of schools, colleges and universities, and employees of companies offering work experience through Springpod.

To create an account, users will need to provide contact information and information relating to their academic performance and preferences. In view of the digital delivery method, images and sounds will be processed.

The lawful basis for providing these services and the sharing of information is clear. Most of the processing will be conducted under the lawful basis of necessity to supply the service, and there are voluntary elements of the processing carried out under the lawful basis of legitimate interest, where that interest can be demonstrated, and consent where informed consent is sought and received.

Data Subjects remain aware of all processing and in complete control at all times.


3. Summary of risk

Data Protection Risk Summary

Processing Risk

Context Risk

Purpose Risk

Necessity Risk

Balance of power Risk

Low

Low

Low

Low

Low

Overall risk

Low

Recommendations made

Yes


4. Processing Risk

What will you collect and store? 

To create an account, users will need to provide contact information and information relating to

their academic performance and preferences, and given the digital method of delivery, images,

and sounds will be processed.

Risk of data type 

Low

How will retention and deletion be

managed?

Personal data is in line with Springpod’s retention policy, after which it will be securely erased as

far as it applies to the provision of service arranged by a user’s school, college, or university.

Springpod may continue to control personal information for their own purposes, subject to

satisfying their own obligations around lawfulness and transparency.

Risk of processing longer than

is necessary

Low

What is the source of the data?

(Consider third party policies)

In most cases, information is presented by the data subject themselves when they register and

manage their accounts, and occasionally, Information will be given to Springpod by schools,

colleges, or universities. In such cases, that information will be taken, checked, and enhanced by

data subjects directly.

Risk of obtaining unlawfully 

Low

Who will the data be about? 

Students, Employees of schools, colleges and universities, and information related to employees

of companies working in partnership with Springpod to deliver opportunities.

Risk of data subject type 

Low

What ages of person’s data will be

processed?

Most users will be between the age of 13 and their early 20’s, and data concerning clients,

employers and school employees of adult age will be processed to fulfil service contracts.

There is no intention to process information relating to people under the age of 13. Accounts

users must agree that they are 13 years of age or older when subscribing to an account.

While account holders must commit to being 13 years old or older, the system does not prevent

a person younger than that from accessing the services by fraudulently agreeing.

Risk of data type 

Medium

Are you processing special category

data?

Elements of special category data are processed only where requested by a client controller for

its own equality monitoring, and the information gathering is voluntary. Springpod is the

controller for the user's account and for its own platform purposes. The client is the controller for

programme delivery and equality monitoring, and Springpod acts as the client's processor for

that processing under documented instructions. There is no joint controller relationship. The

client determines its Article 6 lawful basis and, where relevant, relies on Article 9(2)(g) UK GDPR

with paragraph 8 of Part 2 of Schedule 1 to the Data Protection Act 2018 for equality of

opportunity or treatment. Explicit consent is not relied on. This information is not used to make

decisions about individual participants and is not used to provide personalised careers advice.

Risk of data type 

Low

Are you processing inferred data? 

While there is no intention of processing inferred data, it is possible that assumptions can be

concluded and there are occasions where data subjects can offer data that was not requested.

In such cases, the data will be protected to the same high standards as other personal data.

Risk of inference 

Low

How much data will be processed? 

Only the required amount of information to enable the delivery of the service. 

Risk of scale 

Low

Are any of the individuals vulnerable in

any other way?

While there is no intention of processing information relating to vulnerable persons, this may

occur inadvertently as part of the process.

Data concerning vulnerability may come to light as part of a Safeguarding issue, which would

always be handled in strict confidence in any case.

Risk of data type 

Medium

Will the data be shared with any other

organisations?

Programme information is made available to authorised users of the commissioning client

through the Springpod Partner Portal. Where a programme is reported through the Widening

Access Demonstrator (WAD), an internal reporting framework managed and used by NHS

Risk of unlawful sharing 

Low

to NHS England for monitoring, equality and programme-reporting purposes for use within WAD.

WAD is not a Springpod product or service and is not provided, operated or managed by

Springpod. Participants do not access it through Springpod, and NHS England does not access

WAD through the Springpod platform or the Partner Portal. NHS England's use of the information

is limited to monitoring, equality monitoring and programme reporting for use within WAD.

Access is limited by client, by programme, by user role and to the data necessary for the

permitted monitoring, reporting and equality purposes, and no client can see another client's

programme information. Information will otherwise be shared securely between educational

establishments, necessary third parties, and employers to enable the delivery of the service.

How will the data be secured, including

any aspect of sharing?

All parties to data sharing activity must have systems and controls to protect personal

information being processed or shared. Data processing/sharing will only be carried out under

the protection of a written agreement and where applicable, an appropriate international

transfer mechanism.

Risk of insecure processing 

Low

Will existing users port over to a new

system?

If so, how will you ensure the security

standards are updated in line with the

new system?

N/A 

Risk of unauthorised/insecure

access

N/A

How often will the data be used? 

Information will be used throughout the delivery of the services. 

Risk of insecure sharing 

Low

What countries will be involved? 5. Context Risk

Activities are currently restricted to the UK, EU or territories covered by an adequacy decision. 

Risk of geographical exposure 

Low

Processing Risk 

Low

What is the nature of your relationship

with the individuals?

There are three types of data subjects: employees of educational Establishments, employees of

Workplaces, and students. All three have a relationship with Springpod, which is coordinating

Risk of distant relationship 

Low

the services.

Would they expect you to use their data

in this way?

Yes 

Risk of processing without

knowledge

Low

How much control will they have? 

Subjects will have all the rights they should expect, as detailed in the privacy notice. 

Risk of imbalance of power 

Low

Are there prior concerns over this type of

processing or security flaws?

Access control for multi-client reporting is a recognised area of risk for platforms of this kind,

and it is assessed in section 11. Subject to the controls recorded there operating effectively, no

other prior concerns or security flaws are identified.

Risk of data insecurity 

Low

Is it novel in any way? 

No, the system is tried and tested by multiple users. 

Risk of the unknown 

Low

What is the current state of technology in this area?

Springpod is leading the state of technology in the provision of these services.

Risk of technology

Low

Are there any current issues of public

concern that you should factor in?

No

Risk of known concern

Low

Are you signed up to any approved code

of conduct or certification scheme that

could be affected?

Springpod are accredited ISO9001, ISO 14001, and ISO27001 compliant. Nothing in this assessment

impacts detrimentally on those accreditations.

Risk of non-compliance

Low

Are there any public concern issues

around this kind of processing?

No

Risk of public concern

Low

Context Risk

Low


6. Purpose Risk

Why do you want to process data? What are you trying to achieve?

To facilitate virtual work experience and insight opportunities

Risk of processing unlawfully

Low

What is the intended effect on subjects?

To help educational establishments with the provision of offering candidates valuable work experience, and to help employers find suitable candidates for opportunities.

Risk of power imbalance

Low

Who gains from the processing?

In what way?

Educational establishments benefit from an improved offering to their students, and students benefit from better opportunities and employers benefit by finding suitable candidates for opportunities.

Risk of power imbalance

Low

Are there any wider public benefits to the

processing?

N/A

Risk of power imbalance

N/A

How significant are those benefits?

N/A

Risk of Power imbalance

N/A

What would the impact be if you could

not collect or use the data? If mandatory, do not use legitimate interest

Springpod would not be able to offer this service.

Commercial risk (reverse scale)

Low

Would your use of the data be unethical

or unlawful in any way?

No, the processing is beneficial to all concerned. It would be unethical not to undertake the processing for this purpose, limiting opportunities.

Risk of unethical processing

Low

Purposes Risk

Low


7. Necessity Risk

How important is the processing?

The experience that students can gain using Springpod services is valuable to them.

Risk of unnecessary

processing

Low

Is it a reasonable way to go about it?

Yes

Risk of unreasonable

processing

Low

Is there another less intrusive way to achieve the same result?

No

Risk of being intrusive

Low

Is the processing necessary to supply the

service you provide? If Yes, do not use legitimate interest

Yes

Risk of being incorrect

Low

How will you prevent function creep?

All employees of Springpod are briefed on the data protection principle of purpose limitation, and educational establishments and employers undertake in writing to limit the use to the original purpose.

Risk of function creep 

Low

How will you ensure data quality and

data minimisation?

Students and employees of educational establishments have access to information to ensure accuracy, and any alteration requests will be managed in line with regulatory guidance.

Risk of using too much data 

Low

What information will you give individuals?

Full transparency will be achieved, working in partnership with educational establishments and employers, using various inform statements, informed consent requests, and privacy notices where appropriate.

Risk of processing without the

subjects knowledge

Low

How will you help to support their rights?

Data subjects will be allowed all the rights that data protection regulations entitle them to. Those rights are detailed in the privacy notice, together with information on how to exercise those rights.

Risk of affecting DS rights 

Low

Is the processing necessary to supply the service you provide? If Yes, do not use legitimate interest

Yes

Risk of unnecessary

processing

Low

Does the processing achieve your purpose?

Yes.

Risk of unnecessary

processing

Risk of impac

Low

Is the processing required to adhere to

any industry standards or codes of

practice?

N/A

Risk of impacting codes of

conduct

Low

The risk that processing doesn’t consider

our responsibilities under the applicable

equality legislation for England, Scotland,

Wales and Northern Ireland

This processing doesn’t have a detrimental impact on equality.

Equality risk

Low

The risk that processing doesn’t consider any relevant guidance or research on the development needs, wellbeing, or capacity of children in the relevant age range.

This processing doesn’t have a detrimental impact on development needs or wellbeing, and it is specifically built to take the data subject’s age into account.

Wellbeing risk

Low


8. Balance of Power Risk

What is the nature of your relationship

with the individual?

Employees of Educational Establishments and Workplaces employees are adult data subjects that will work in partnership with Springpod to deliver services, and students will be relying on Springpod to provide the services.

Risk of being intrusive

Low

Is there a need to consult with the holder

of parental authority?

Users must commit to being aged at least 13 years old, so there is no requirement to consult the holder of parental authority.

Risk of Children’s third-party

authority

N/A

Is any of the data particularly sensitive or private? 

Where specifically requested by a client controller with a documented lawful basis and Article 9 condition, some sensitive information is processed for that client's equality monitoring, with

Springpod acting as its processor. It is not used for decisions about individual participants. While

there is no other intention of processing sensitive information, there may be sensitive

information discussed or otherwise made available. Where this is the case, it will be dealt with

sensitively and per data protection legislation.

Risk of data type 

Medium

Is there a need to process geolocation

information?

There is no processing of geolocation information 

Risk of Geolocation

information use.

N/A

Is there a need for profiling, or to process

information in an automatic manner?

There is no automated processing of personal data. 

Risk of profiling / automated

processing

N/A

Is there a need to use nudge techniques 

There is no use of nudge techniques 

Risk of using nudging

techniques

N/A

Would people expect you to use their

data in this way?

If no, do not use legitimate interest

Yes. 

Risk of using data in a manner

that would not be expected

Low

Are you happy to explain it to them? 

Yes, this will be done via the website, social media feeds and privacy notices, and further

requests for clarity will be handled on a case-by-case basis.

Risk of transparency 

Low

Are some people likely to object or find it

intrusive?

If Yes, do not use legitimate interest

No objections are expected, but any such complaint will be handled on a case-by-case basis if

there are any.

Risk of being intrusive 

Low

What is the possible impact on the

individual?

The processing benefits all data subjects. It helps educational establishments deliver

opportunities to students, and it allows the students to benefit from those opportunities and

helps employers find suitable candidates for opportunities.

Risk of individuals 

Low

How big an impact might it have on

them?

There is little potential for a negative impact, but high potential for beneficial outcomes. 

The severity of the risk to

individuals

Low

Can you adopt any safeguards to

minimise the impact?

Yes, through training and the design of the system.

The system is Password protected monitored.

Risk 

Low

Can you offer an opt-out? 

No. An opt-out would make it impossible to provide the services. 

Risk 

Low

Balance Risk 

Low


9. Lawfulness Test

Lawful Basis Test

Which bases can be used

Consent

Yes

Contract requirement

Yes

Regulatory obligation

No

Vital Interest

Person

No

Public

No

Legitimate interest

Yes

Rationale

The assessment covers several distinct processing activities. Springpod is the controller for the personal data necessary to create, host, maintain and administer a

Springpod account. That processing is carried out under Article 6(1)(b) UK GDPR where it is necessary to provide the account and requested platform service.

Where a client commissions a programme, the client is the controller for programme delivery and determines and documents the applicable Article 6 lawful basis.

Springpod acts as the client's processor and processes programme information only under the client's documented instructions. Springpod does not determine or inherit the client's lawful basis.

A controller may rely on Article 6(1)(f) for a separate processing activity only where that processing is not necessary to perform a contract, a legitimate interests assessment supports the processing and the data subject's applicable right to object is preserved.

Consent is used only for genuinely optional and separate processing where it can be freely given and withdrawn, such as relevant marketing. Consent is not relied upon for client equality monitoring.

No current processing covered by this assessment relies on vital interests.


10. Transparency Method

Privacy Statement

Method

Privacy Statement 

Privacy Statement with object 

Informed consent request 

Privacy notice

Yes 

Yes

Yes 

Yes

Rationale

Given the mandatory nature of most of the processing, the primary mechanism to achieve transparency is using a privacy statement at the point of collecting data,

where possible, together with the information contained in the publicly available privacy notice will be sufficient to achieve transparency.

Where information is optional and processed under legitimate interest, there will be an inform statement that details a data subject’s right to object, and where

information is processed under the lawful basis of consent, the data subject will receive an informed consent request at the point of collection.


11. Identifying and Managing Individual Risks

Risk 

Inherent Risk 

Mitigations 

Owners 

Next review 

Residual Risk

The risk of third-party / Processor non-

compliance

High 

Ensure that there are written agreements to govern the sharing of

personal data between controllers and processors.

Third-party

relationships

Managers

July 2027 

Low

High 

Ensure that there is an ongoing process to ensure that the third party is

compliant.

Third-party

relationships

Manager

July 2027 

Low

The risk that people younger than 13 set an

account up.

Medium 

Although we don’t verify the age of people applying for an account,

they are asked to confirm that they are 13 years old or older, and even

in the event that they do access the service, the data being processed

does not represent a significant increase in risk either for Springpod or

for the service user.

Marketing 

July 2027 

Medium

The risk that young people can

communicate with others during group

sessions and as a member of the

Springpod community.

Medium 

There is no 121 contact, such as break out rooms, as part of any

programme, all employees are trained on Safeguarding, and the

Springpod Community is actively moderated in real-time.

Head of Customer

Experience

July 2027 

Low

The risk that processing is not transparent. 

Medium 

Ensure that the processing, including detail about the lawful bases and

the fact that processing is taking place using a third-party processor, is

covered in the relevant privacy notices.

Marketing /

Website content

manager

July 2027 

Low

The risk that transparency around the

relationship between third-parties, and

their respective relationships with the data

subject is not clear.

High 

Agree on a process with third-parties to ensure that the correct privacy

notice is made available to data subjects at the right point in time, and

ensure that there is transparency in privacy statements to identify to

data subjects which is the controller and processor of their data at any

given time, mainly when there is a change to those roles.

Third-party

relationships

Manager

July 2027 

Medium

The risk of failure to compliantly respond to

requests from data subjects to exercise

their rights.

High 

Ensure that all aspects of this processing are catered for in all policies

by all parties and procedures relating to data subject rights, including

those relating to:

Data subject access, Erasure, Rectification, Consent, Restriction,

Data Protection

Officers

July 2027 

Low

The risk of exposure to other regulations in

other territories.

Low 

While there is the potential for a low grade, non-reportable breach,

suggest creating a risk acceptance for this risk, given the low potential

for a detrimental outcome.

Low

The risk of processing personal data in a

manner that is not considered to be secure

by the regulator.

High 

Ensure that processing follows internal information security standards. 

Third-party

relationships

Manager

July 2027 

Low

The risk that an authorised client or partner

user is given access to information outside

the programme or organisation for which

that user is responsible, that excessive

personal data fields are displayed, or that

access permissions are configured

incorrectly.

High 

Organisation-level and programme-level access restrictions, so that

no client can view another client's programme information.

Role-based access control applied on a least-privilege basis.

Displayed and exportable fields limited to those necessary for the

stated purpose.

Access controls tested before release and after any material change.

Access logging and periodic access reviews.

Data Protection

Officers

July 2027 

Low

The risk that changes to user roles or

programme responsibilities leave obsolete

access in place.

Medium 

Access is removed or amended when a role or programme

responsibility changes.

Periodic access reviews confirm that live permissions still match

current responsibilities.

Monitoring and incident handling procedures apply to any access

anomaly identified.

Third-party

relationships

Manager

July 2027 

Low

The risk that reporting functions expose

identifiable information where aggregated,

anonymised or minimised information

would meet the reporting purpose.

High 

Reporting outputs limited to the data necessary for the monitoring,

equality monitoring and programme-reporting purpose.

Identifiers suppressed, pseudonymised or anonymised where

appropriate to that purpose.

Documented controller instructions govern client-controlled reporting.

Residual risk is assessed as low only while these controls operate

Data Protection

Officers

July 2027 

Low


12. Approval / Recommendations

Activity Approved 

Yes no 

Recommendations Yes no

DPO notes /

Recommendations

The lawful basis for this activity is clear, and the advantages of this processing are numerous and mutually beneficial.

Subject to adequate transparency and appropriate measures controlling the sharing aspects, this activity is approved.

Carried out by 

Kieran McGeehan

Head of Operations 

Last reviewed 

30.07.26

Process Owner 

All employees 

To be Reviewed 

July 2027


13. Roles and responsibilities

1.1. The first line of defence (everyone) is responsible for:

  • Ensuring their day-to-day business activity falls in line with this assessment.

  • Ensuring their business area is compliant with this assessment.

  • Reporting any actual or perceived breaches.

1.2. The second line of defence (the management) is responsible for:

  • Oversight of implementation.

  • Acting as an independent, effective challenger of the first line.

1.3. The third line of defence (Risk & Compliance Officer) is responsible for:

  • Assuring that the assessment meets all regulatory requirements and is being complied with effectively.

  • Reviewing and approving this assessment.

  • Supplying advice and guidance to employees implementing the assessment.

1.4. The Board of Directors is responsible for:

Approval of this assessment.


14. Document review

This document will be reviewed at least annually or as needed if significant changes occur in the business structure, responsibilities, or regulatory framework.


15. Related documents

• SPR25.6 – Springpod Data Protection Policy

Was this article helpful?

Sorry about that! Care to tell us more?

Thanks for the feedback!

There was an issue submitting your feedback
Please check your connection and try again.