← Compliance packDocument 1 of 8
🐾 PAWSTEPS · PETS ON THE GREEN LTD

Data Protection Impact Assessment (DPIA)

UK GDPR Article 35 · Company No. 16721467 · Version v1.0 · 13 July 2026 · Review due 13 July 2027
Status: Draft for review. This DPIA should be reviewed and signed off by the PawSteps Data Protection lead Ciera O’Rourke, Director (data protection lead; no statutory DPO required) and, where a school is the controller, cross-checked against the school’s own DPIA before deployment. It is not legal advice.

1. Purpose & overview of processing

PawSteps is an online learning and wellbeing platform provided by Pets on the Green Ltd. It offers curriculum-linked lessons (EYFS to A-Level), SEND-ready resources, a daily wellbeing journey, and progress/EHCP evidence tools. This DPIA assesses the processing of personal data — including children’s data — carried out when the platform is used by families and by schools under a site licence.

ItemDetail
Data controller (schools)The subscribing school or trust is controller for pupil data it directs PawSteps to process.
Data controller (families)The parent/carer, for a personal/home subscription.
Data processorPets on the Green Ltd (PawSteps) processes on documented instructions.
DP lead / contactCiera O’Rourke, Director & DSL, orourkeciera@gmail.com
ICO registrationC1918829

2. Screening — is a DPIA required?

A DPIA is required because processing involves data concerning children and may involve special category data (wellbeing/SEND information). The following screening questions were answered “yes”, confirming a full DPIA is appropriate:

Screening questionAnswer
Does the processing involve children’s personal data?Yes
Could it involve special category data (health, SEND, wellbeing)?Yes — where a user records mood/wellbeing or SEND needs
Does it involve profiling or automated decision-making with significant effect?No automated decisions with legal/significant effect; progress analytics are advisory only
Is data matched/combined from multiple sources?Only where a school opts into integrations it controls
Is innovative technology used?Content-adaptation tools; no biometric identification

3. Data mapped — what is processed

CategoryExamplesSpecial category?
Account dataParent/teacher email, school name, subscription detailsNo
Learner profileFirst name or nickname, age band / key stage, chosen avatarNo
Learning activityLessons completed, quiz scores, time-on-task, workbook entriesNo
Wellbeing journeyDaily mood check-ins, reflectionsPotentially — treated as special category
SEND / EHCP evidenceNotes, portfolio uploads, EHCP report content (school-directed)Yes — special category
Data minimisation by design: The wellbeing journal is stored locally on the user’s own device and is not transmitted to PawSteps servers. Children can use a first name or nickname only. No pupil account is required to browse core content.

4. Lawful basis

ProcessingLawful basis (UK GDPR Art. 6)Special category condition (Art. 9)
School-directed pupil use(e) Public task / (c) Legal obligation, as directed by the school controller(g) Substantial public interest (education) / (j) — per school policy
Family subscription(b) Contract(a) Explicit consent for any wellbeing data retained
Account admin & support(b) Contract / (f) Legitimate interestsn/a

5. Necessity & proportionality

Processing is limited to what is necessary to deliver curriculum-linked learning, wellbeing activities and — where a school requests it — progress and EHCP evidence. Alternatives with less data (on-device storage, nickname-only profiles, no-account browsing) are used by default. Retention is time-limited (see the Data Protection & UK Hosting Statement).

6. Risks & mitigations

RiskLikelihood / impactMitigationResidual
Unauthorised access to children’s dataLow / HighUK-hosted, encryption in transit and at rest, role-based access, MFA for adminLow
Wellbeing data exposureLow / HighOn-device storage by default; no server sync unless explicitly enabledLow
A parent seeing another child’s dataLow / HighStrict per-child token mapping; access controls testedLow
Excessive retentionMedium / MediumDefined retention schedule; deletion on account closureLow
Sub-processor / hosting failureLow / MediumUK data centre Netlify (web) and Supabase (database, EU/London region), DPAs with all sub-processors, backupsLow
Child safeguarding disclosure within contentLow / HighReporting route to school DSL; see Safeguarding PolicyLow–Medium

7. Consultation

Stakeholders consulted in preparing this DPIA: [e.g. founder/DP lead, pilot school DSL, pilot SENCO]. Where residual risk remains high, the ICO would be consulted prior to processing (Art. 36). No high residual risks are currently identified.

8. Sign-off

RoleNameDateOutcome
DP lead (PawSteps)Ciera O’Rourke, Director & Designated Safeguarding Lead13 July 2026Approved / integrated measures
School DPO (if controller)Ciera O’Rourke, Director & Designated Safeguarding Lead13 July 2026Proceed — risks assessed as acceptable with the controls in this DPIA