Data Protection Impact Assessment
1. Overview
Part 4, Chapter 4, section 64 of The Data Protection Act 2018, and article 35 of the UK General Data Protection Regulation (UK GDPR 2018), says that Data Controllers must conduct a DataProtection Impact Assessment (DPIA) where a change to the processing of personal data has the potential to affect the compliance risks associated with that processing.
Additionally, section 2 of the UK Information Commissioner’s Office (ICO) Age-Appropriate Design Code, sometimes referred to as the Children’s Code says that organisations processing personal data relating to children should be carried out to assess and mitigate risks to the rights and freedoms of children who are likely to access a service, which arises from data processing.
The DPIA should consider differing ages, capacities and development needs and should be carried out before processing commences.
While the regulatory obligation to undertake DPIA’s falls on the Data Protection Officer of a Data Controller, this assessment has been conducted by Springpod for the convenience of Data Controllers that want to take advantage of their products and services, particularly the provision of Virtual Work Experience using Springpod as a Data Processor.
2. Impact on Personal Data
The service concerned is creating and delivering virtual insight days and work experience and other associated services, including live workshops and training for qualifying candidates.
To achieve this, Springpod needs to process personal information relating to students, employees of schools, colleges and universities, and employees of companies offering work experience through Springpod.
To create an account, users will need to provide contact information and information relating to their academic performance and preferences. In view of the digital delivery method, images and sounds will be processed.
The lawful basis for providing these services and the sharing of information is clear. Most of the processing will be conducted under the lawful basis of necessity to supply the service, and there are voluntary elements of the processing carried out under the lawful basis of legitimate interest, where that interest can be demonstrated, and consent where informed consent is sought and received.
Data Subjects remain aware of all processing and in complete control at all times.
3. Summary of risk
Data Protection Risk Summary
Processing Risk | Context Risk | Purpose Risk | Necessity Risk | Balance of power Risk |
Low | Low | Low | Low | Low |
Overall risk | Low | |||
Recommendations made | Yes |
4. Processing Risk
What will you collect and store? | To create an account, users will need to provide contact information and information relating to their academic performance and preferences, and given the digital method of delivery, images, and sounds will be processed. | Risk of data type | Low |
How will retention and deletion be managed? | Personal data is in line with Springpod’s retention policy, after which it will be securely erased as far as it applies to the provision of service arranged by a user’s school, college, or university. Springpod may continue to control personal information for their own purposes, subject to satisfying their own obligations around lawfulness and transparency. | Risk of processing longer than is necessary | Low |
What is the source of the data? (Consider third party policies) | In most cases, information is presented by the data subject themselves when they register and manage their accounts, and occasionally, Information will be given to Springpod by schools, colleges, or universities. In such cases, that information will be taken, checked, and enhanced by data subjects directly. | Risk of obtaining unlawfully | Low |
Who will the data be about? | Students, Employees of schools, colleges and universities, and information related to employees of companies working in partnership with Springpod to deliver opportunities. | Risk of data subject type | Low |
What ages of person’s data will be processed? | Most users will be between the age of 13 and their early 20’s, and data concerning clients, employers and school employees of adult age will be processed to fulfil service contracts. There is no intention to process information relating to people under the age of 13. Accounts users must agree that they are 13 years of age or older when subscribing to an account. While account holders must commit to being 13 years old or older, the system does not prevent a person younger than that from accessing the services by fraudulently agreeing. | Risk of data type | Medium |
Are you processing special category data? | Elements of special category data are processed only where requested by a client controller for its own equality monitoring, and the information gathering is voluntary. Springpod is the controller for the user's account and for its own platform purposes. The client is the controller for programme delivery and equality monitoring, and Springpod acts as the client's processor for that processing under documented instructions. There is no joint controller relationship. The client determines its Article 6 lawful basis and, where relevant, relies on Article 9(2)(g) UK GDPR with paragraph 8 of Part 2 of Schedule 1 to the Data Protection Act 2018 for equality of opportunity or treatment. Explicit consent is not relied on. This information is not used to make decisions about individual participants and is not used to provide personalised careers advice. | Risk of data type | Low |
Are you processing inferred data? | While there is no intention of processing inferred data, it is possible that assumptions can be concluded and there are occasions where data subjects can offer data that was not requested. In such cases, the data will be protected to the same high standards as other personal data. | Risk of inference | Low |
How much data will be processed? | Only the required amount of information to enable the delivery of the service. | Risk of scale | Low |
Are any of the individuals vulnerable in any other way? | While there is no intention of processing information relating to vulnerable persons, this may occur inadvertently as part of the process. Data concerning vulnerability may come to light as part of a Safeguarding issue, which would always be handled in strict confidence in any case. | Risk of data type | Medium |
Will the data be shared with any other organisations? | Programme information is made available to authorised users of the commissioning client through the Springpod Partner Portal. Where a programme is reported through the Widening Access Demonstrator (WAD), an internal reporting framework managed and used by NHS | Risk of unlawful sharing | Low |
to NHS England for monitoring, equality and programme-reporting purposes for use within WAD. WAD is not a Springpod product or service and is not provided, operated or managed by Springpod. Participants do not access it through Springpod, and NHS England does not access WAD through the Springpod platform or the Partner Portal. NHS England's use of the information is limited to monitoring, equality monitoring and programme reporting for use within WAD. Access is limited by client, by programme, by user role and to the data necessary for the permitted monitoring, reporting and equality purposes, and no client can see another client's programme information. Information will otherwise be shared securely between educational establishments, necessary third parties, and employers to enable the delivery of the service. | |||
How will the data be secured, including any aspect of sharing? | All parties to data sharing activity must have systems and controls to protect personal information being processed or shared. Data processing/sharing will only be carried out under the protection of a written agreement and where applicable, an appropriate international transfer mechanism. | Risk of insecure processing | Low |
Will existing users port over to a new system? If so, how will you ensure the security standards are updated in line with the new system? | N/A | Risk of unauthorised/insecure access | N/A |
How often will the data be used? | Information will be used throughout the delivery of the services. | Risk of insecure sharing | Low |
What countries will be involved? 5. Context Risk | Activities are currently restricted to the UK, EU or territories covered by an adequacy decision. | Risk of geographical exposure | Low |
Processing Risk | Low | ||
What is the nature of your relationship with the individuals? | There are three types of data subjects: employees of educational Establishments, employees of Workplaces, and students. All three have a relationship with Springpod, which is coordinating | Risk of distant relationship | Low |
the services. | |||
Would they expect you to use their data in this way? | Yes | Risk of processing without knowledge | Low |
How much control will they have? | Subjects will have all the rights they should expect, as detailed in the privacy notice. | Risk of imbalance of power | Low |
Are there prior concerns over this type of processing or security flaws? | Access control for multi-client reporting is a recognised area of risk for platforms of this kind, and it is assessed in section 11. Subject to the controls recorded there operating effectively, no other prior concerns or security flaws are identified. | Risk of data insecurity | Low |
Is it novel in any way? | No, the system is tried and tested by multiple users. | Risk of the unknown | Low |
What is the current state of technology in this area? | Springpod is leading the state of technology in the provision of these services. | Risk of technology | Low |
Are there any current issues of public concern that you should factor in? | No | Risk of known concern | Low |
Are you signed up to any approved code of conduct or certification scheme that could be affected? | Springpod are accredited ISO9001, ISO 14001, and ISO27001 compliant. Nothing in this assessment impacts detrimentally on those accreditations. | Risk of non-compliance | Low |
Are there any public concern issues around this kind of processing? | No | Risk of public concern | Low |
Context Risk | Low |
6. Purpose Risk
Why do you want to process data? What are you trying to achieve? | To facilitate virtual work experience and insight opportunities | Risk of processing unlawfully | Low |
What is the intended effect on subjects? | To help educational establishments with the provision of offering candidates valuable work experience, and to help employers find suitable candidates for opportunities. | Risk of power imbalance | Low |
Who gains from the processing? In what way? | Educational establishments benefit from an improved offering to their students, and students benefit from better opportunities and employers benefit by finding suitable candidates for opportunities. | Risk of power imbalance | Low |
Are there any wider public benefits to the processing? | N/A | Risk of power imbalance | N/A |
How significant are those benefits? | N/A | Risk of Power imbalance | N/A |
What would the impact be if you could not collect or use the data? If mandatory, do not use legitimate interest | Springpod would not be able to offer this service. | Commercial risk (reverse scale) | Low |
Would your use of the data be unethical or unlawful in any way? | No, the processing is beneficial to all concerned. It would be unethical not to undertake the processing for this purpose, limiting opportunities. | Risk of unethical processing | Low |
Purposes Risk | Low |
7. Necessity Risk
How important is the processing? | The experience that students can gain using Springpod services is valuable to them. | Risk of unnecessary processing | Low |
Is it a reasonable way to go about it? | Yes | Risk of unreasonable processing | Low |
Is there another less intrusive way to achieve the same result? | No | Risk of being intrusive | Low |
Is the processing necessary to supply the service you provide? If Yes, do not use legitimate interest | Yes | Risk of being incorrect | Low |
How will you prevent function creep? | All employees of Springpod are briefed on the data protection principle of purpose limitation, and educational establishments and employers undertake in writing to limit the use to the original purpose. | Risk of function creep | Low |
How will you ensure data quality and data minimisation? | Students and employees of educational establishments have access to information to ensure accuracy, and any alteration requests will be managed in line with regulatory guidance. | Risk of using too much data | Low |
What information will you give individuals? | Full transparency will be achieved, working in partnership with educational establishments and employers, using various inform statements, informed consent requests, and privacy notices where appropriate. | Risk of processing without the subjects knowledge | Low |
How will you help to support their rights? | Data subjects will be allowed all the rights that data protection regulations entitle them to. Those rights are detailed in the privacy notice, together with information on how to exercise those rights. | Risk of affecting DS rights | Low |
Is the processing necessary to supply the service you provide? If Yes, do not use legitimate interest | Yes | Risk of unnecessary processing | Low |
Does the processing achieve your purpose? | Yes. | Risk of unnecessary processing Risk of impac | Low |
Is the processing required to adhere to any industry standards or codes of practice? | N/A | Risk of impacting codes of conduct | Low |
The risk that processing doesn’t consider our responsibilities under the applicable equality legislation for England, Scotland, Wales and Northern Ireland | This processing doesn’t have a detrimental impact on equality. | Equality risk | Low |
The risk that processing doesn’t consider any relevant guidance or research on the development needs, wellbeing, or capacity of children in the relevant age range. | This processing doesn’t have a detrimental impact on development needs or wellbeing, and it is specifically built to take the data subject’s age into account. | Wellbeing risk | Low |
8. Balance of Power Risk
What is the nature of your relationship with the individual? | Employees of Educational Establishments and Workplaces employees are adult data subjects that will work in partnership with Springpod to deliver services, and students will be relying on Springpod to provide the services. | Risk of being intrusive | Low |
Is there a need to consult with the holder of parental authority? | Users must commit to being aged at least 13 years old, so there is no requirement to consult the holder of parental authority. | Risk of Children’s third-party authority | N/A |
Is any of the data particularly sensitive or private? | Where specifically requested by a client controller with a documented lawful basis and Article 9 condition, some sensitive information is processed for that client's equality monitoring, with Springpod acting as its processor. It is not used for decisions about individual participants. While there is no other intention of processing sensitive information, there may be sensitive information discussed or otherwise made available. Where this is the case, it will be dealt with sensitively and per data protection legislation. | Risk of data type | Medium |
Is there a need to process geolocation information? | There is no processing of geolocation information | Risk of Geolocation information use. | N/A |
Is there a need for profiling, or to process information in an automatic manner? | There is no automated processing of personal data. | Risk of profiling / automated processing | N/A |
Is there a need to use nudge techniques | There is no use of nudge techniques | Risk of using nudging techniques | N/A |
Would people expect you to use their data in this way? If no, do not use legitimate interest | Yes. | Risk of using data in a manner that would not be expected | Low |
Are you happy to explain it to them? | Yes, this will be done via the website, social media feeds and privacy notices, and further requests for clarity will be handled on a case-by-case basis. | Risk of transparency | Low |
Are some people likely to object or find it intrusive? If Yes, do not use legitimate interest | No objections are expected, but any such complaint will be handled on a case-by-case basis if there are any. | Risk of being intrusive | Low |
What is the possible impact on the individual? | The processing benefits all data subjects. It helps educational establishments deliver opportunities to students, and it allows the students to benefit from those opportunities and helps employers find suitable candidates for opportunities. | Risk of individuals | Low |
How big an impact might it have on them? | There is little potential for a negative impact, but high potential for beneficial outcomes. | The severity of the risk to individuals | Low |
Can you adopt any safeguards to minimise the impact? | Yes, through training and the design of the system. The system is Password protected monitored. | Risk | Low |
Can you offer an opt-out? | No. An opt-out would make it impossible to provide the services. | Risk | Low |
Balance Risk | Low |
9. Lawfulness Test
Lawful Basis Test
Which bases can be used | ||
Consent | Yes | |
Contract requirement | Yes | |
Regulatory obligation | No | |
Vital Interest | Person | No |
Public | No | |
Legitimate interest | Yes |
Rationale
The assessment covers several distinct processing activities. Springpod is the controller for the personal data necessary to create, host, maintain and administer a
Springpod account. That processing is carried out under Article 6(1)(b) UK GDPR where it is necessary to provide the account and requested platform service.
Where a client commissions a programme, the client is the controller for programme delivery and determines and documents the applicable Article 6 lawful basis.
Springpod acts as the client's processor and processes programme information only under the client's documented instructions. Springpod does not determine or inherit the client's lawful basis.
A controller may rely on Article 6(1)(f) for a separate processing activity only where that processing is not necessary to perform a contract, a legitimate interests assessment supports the processing and the data subject's applicable right to object is preserved.
Consent is used only for genuinely optional and separate processing where it can be freely given and withdrawn, such as relevant marketing. Consent is not relied upon for client equality monitoring.
No current processing covered by this assessment relies on vital interests.
10. Transparency Method
Privacy Statement Method | Privacy Statement | Privacy Statement with object | Informed consent request | Privacy notice |
Yes | Yes | Yes | Yes | |
Rationale | Given the mandatory nature of most of the processing, the primary mechanism to achieve transparency is using a privacy statement at the point of collecting data, where possible, together with the information contained in the publicly available privacy notice will be sufficient to achieve transparency. Where information is optional and processed under legitimate interest, there will be an inform statement that details a data subject’s right to object, and where information is processed under the lawful basis of consent, the data subject will receive an informed consent request at the point of collection. |
11. Identifying and Managing Individual Risks
Risk | Inherent Risk | Mitigations | Owners | Next review | Residual Risk |
The risk of third-party / Processor non- compliance | High | Ensure that there are written agreements to govern the sharing of personal data between controllers and processors. | Third-party relationships Managers | July 2027 | Low |
High | Ensure that there is an ongoing process to ensure that the third party is compliant. | Third-party relationships Manager | July 2027 | Low | |
The risk that people younger than 13 set an account up. | Medium | Although we don’t verify the age of people applying for an account, they are asked to confirm that they are 13 years old or older, and even in the event that they do access the service, the data being processed does not represent a significant increase in risk either for Springpod or for the service user. | Marketing | July 2027 | Medium |
The risk that young people can communicate with others during group sessions and as a member of the Springpod community. | Medium | There is no 121 contact, such as break out rooms, as part of any programme, all employees are trained on Safeguarding, and the Springpod Community is actively moderated in real-time. | Head of Customer Experience | July 2027 | Low |
The risk that processing is not transparent. | Medium | Ensure that the processing, including detail about the lawful bases and the fact that processing is taking place using a third-party processor, is covered in the relevant privacy notices. | Marketing / Website content manager | July 2027 | Low |
The risk that transparency around the relationship between third-parties, and their respective relationships with the data subject is not clear. | High | Agree on a process with third-parties to ensure that the correct privacy notice is made available to data subjects at the right point in time, and ensure that there is transparency in privacy statements to identify to data subjects which is the controller and processor of their data at any given time, mainly when there is a change to those roles. | Third-party relationships Manager | July 2027 | Medium |
The risk of failure to compliantly respond to requests from data subjects to exercise their rights. | High | Ensure that all aspects of this processing are catered for in all policies by all parties and procedures relating to data subject rights, including those relating to: Data subject access, Erasure, Rectification, Consent, Restriction, | Data Protection Officers | July 2027 | Low |
The risk of exposure to other regulations in other territories. | Low | While there is the potential for a low grade, non-reportable breach, suggest creating a risk acceptance for this risk, given the low potential for a detrimental outcome. | Low | ||
The risk of processing personal data in a manner that is not considered to be secure by the regulator. | High | Ensure that processing follows internal information security standards. | Third-party relationships Manager | July 2027 | Low |
The risk that an authorised client or partner user is given access to information outside the programme or organisation for which that user is responsible, that excessive personal data fields are displayed, or that access permissions are configured incorrectly. | High | Organisation-level and programme-level access restrictions, so that no client can view another client's programme information. Role-based access control applied on a least-privilege basis. Displayed and exportable fields limited to those necessary for the stated purpose. Access controls tested before release and after any material change. Access logging and periodic access reviews. | Data Protection Officers | July 2027 | Low |
The risk that changes to user roles or programme responsibilities leave obsolete access in place. | Medium | Access is removed or amended when a role or programme responsibility changes. Periodic access reviews confirm that live permissions still match current responsibilities. Monitoring and incident handling procedures apply to any access anomaly identified. | Third-party relationships Manager | July 2027 | Low |
The risk that reporting functions expose identifiable information where aggregated, anonymised or minimised information would meet the reporting purpose. | High | Reporting outputs limited to the data necessary for the monitoring, equality monitoring and programme-reporting purpose. Identifiers suppressed, pseudonymised or anonymised where appropriate to that purpose. Documented controller instructions govern client-controlled reporting. Residual risk is assessed as low only while these controls operate | Data Protection Officers | July 2027 | Low |
12. Approval / Recommendations
Activity Approved | Yes no | Recommendations Yes no | |
DPO notes / Recommendations | The lawful basis for this activity is clear, and the advantages of this processing are numerous and mutually beneficial. Subject to adequate transparency and appropriate measures controlling the sharing aspects, this activity is approved. | ||
Carried out by | Kieran McGeehan Head of Operations | Last reviewed | 30.07.26 |
Process Owner | All employees | To be Reviewed | July 2027 |
13. Roles and responsibilities
1.1. The first line of defence (everyone) is responsible for:
Ensuring their day-to-day business activity falls in line with this assessment.
Ensuring their business area is compliant with this assessment.
Reporting any actual or perceived breaches.
1.2. The second line of defence (the management) is responsible for:
Oversight of implementation.
Acting as an independent, effective challenger of the first line.
1.3. The third line of defence (Risk & Compliance Officer) is responsible for:
Assuring that the assessment meets all regulatory requirements and is being complied with effectively.
Reviewing and approving this assessment.
Supplying advice and guidance to employees implementing the assessment.
1.4. The Board of Directors is responsible for:
Approval of this assessment.
14. Document review
This document will be reviewed at least annually or as needed if significant changes occur in the business structure, responsibilities, or regulatory framework.
15. Related documents
• SPR25.6 – Springpod Data Protection Policy
