Status: Draft for review. This DPIA should be reviewed and signed off by the PawSteps Data Protection lead Ciera O’Rourke, Director (data protection lead; no statutory DPO required) and, where a school is the controller, cross-checked against the school’s own DPIA before deployment. It is not legal advice.
1. Purpose & overview of processing
PawSteps is an online learning and wellbeing platform provided by Pets on the Green Ltd. It offers curriculum-linked lessons (EYFS to A-Level), SEND-ready resources, a daily wellbeing journey, and progress/EHCP evidence tools. This DPIA assesses the processing of personal data — including children’s data — carried out when the platform is used by families and by schools under a site licence.
| Item | Detail |
| Data controller (schools) | The subscribing school or trust is controller for pupil data it directs PawSteps to process. |
| Data controller (families) | The parent/carer, for a personal/home subscription. |
| Data processor | Pets on the Green Ltd (PawSteps) processes on documented instructions. |
| DP lead / contact | Ciera O’Rourke, Director & DSL, orourkeciera@gmail.com |
| ICO registration | C1918829 |
2. Screening — is a DPIA required?
A DPIA is required because processing involves data concerning children and may involve special category data (wellbeing/SEND information). The following screening questions were answered “yes”, confirming a full DPIA is appropriate:
| Screening question | Answer |
| Does the processing involve children’s personal data? | Yes |
| Could it involve special category data (health, SEND, wellbeing)? | Yes — where a user records mood/wellbeing or SEND needs |
| Does it involve profiling or automated decision-making with significant effect? | No automated decisions with legal/significant effect; progress analytics are advisory only |
| Is data matched/combined from multiple sources? | Only where a school opts into integrations it controls |
| Is innovative technology used? | Content-adaptation tools; no biometric identification |
3. Data mapped — what is processed
| Category | Examples | Special category? |
| Account data | Parent/teacher email, school name, subscription details | No |
| Learner profile | First name or nickname, age band / key stage, chosen avatar | No |
| Learning activity | Lessons completed, quiz scores, time-on-task, workbook entries | No |
| Wellbeing journey | Daily mood check-ins, reflections | Potentially — treated as special category |
| SEND / EHCP evidence | Notes, portfolio uploads, EHCP report content (school-directed) | Yes — special category |
Data minimisation by design: The wellbeing journal is stored locally on the user’s own device and is not transmitted to PawSteps servers. Children can use a first name or nickname only. No pupil account is required to browse core content.
4. Lawful basis
| Processing | Lawful basis (UK GDPR Art. 6) | Special category condition (Art. 9) |
| School-directed pupil use | (e) Public task / (c) Legal obligation, as directed by the school controller | (g) Substantial public interest (education) / (j) — per school policy |
| Family subscription | (b) Contract | (a) Explicit consent for any wellbeing data retained |
| Account admin & support | (b) Contract / (f) Legitimate interests | n/a |
5. Necessity & proportionality
Processing is limited to what is necessary to deliver curriculum-linked learning, wellbeing activities and — where a school requests it — progress and EHCP evidence. Alternatives with less data (on-device storage, nickname-only profiles, no-account browsing) are used by default. Retention is time-limited (see the Data Protection & UK Hosting Statement).
6. Risks & mitigations
| Risk | Likelihood / impact | Mitigation | Residual |
| Unauthorised access to children’s data | Low / High | UK-hosted, encryption in transit and at rest, role-based access, MFA for admin | Low |
| Wellbeing data exposure | Low / High | On-device storage by default; no server sync unless explicitly enabled | Low |
| A parent seeing another child’s data | Low / High | Strict per-child token mapping; access controls tested | Low |
| Excessive retention | Medium / Medium | Defined retention schedule; deletion on account closure | Low |
| Sub-processor / hosting failure | Low / Medium | UK data centre Netlify (web) and Supabase (database, EU/London region), DPAs with all sub-processors, backups | Low |
| Child safeguarding disclosure within content | Low / High | Reporting route to school DSL; see Safeguarding Policy | Low–Medium |
7. Consultation
Stakeholders consulted in preparing this DPIA: [e.g. founder/DP lead, pilot school DSL, pilot SENCO]. Where residual risk remains high, the ICO would be consulted prior to processing (Art. 36). No high residual risks are currently identified.
8. Sign-off
| Role | Name | Date | Outcome |
| DP lead (PawSteps) | Ciera O’Rourke, Director & Designated Safeguarding Lead | 13 July 2026 | Approved / integrated measures |
| School DPO (if controller) | Ciera O’Rourke, Director & Designated Safeguarding Lead | 13 July 2026 | Proceed — risks assessed as acceptable with the controls in this DPIA |