DPIA support pack
Processing context, data flow, technical controls, residual dependencies and controller decisions.
PROCUREMENT & GOVERNANCE
PUBLIC INFORMATION
Controller and processor roles, information categories, access, rights, suppliers, incidents and safeguarding boundaries.
Open document PublishedCurrent automated, keyboard and responsive review position, including the independent-audit gap.
Open document PublishedWhat ODISSYS supports, what remains a human responsibility and the urgent-concern boundary.
Open documentCONTROLLED DOCUMENTS
Processing context, data flow, technical controls, residual dependencies and controller decisions.
Authentication, MFA, session security, role-scoped access, auditing and production configuration controls.
Processing instructions, security, rights assistance, suppliers, return, deletion and controller responsibilities.
Current hosting and transactional-email processing boundaries, locations and transfer safeguards.
Governed response, assessment, decision, export and evidence workflows.
Review triggers, holds, return, deletion and guarded anonymisation boundaries.
We ask which organisation is reviewing the pack so controlled copies can be versioned, contextualised and replaced when material facts change.
ASSURANCE STATUS
Mandatory MFA, privacy locking, role and relationship-scoped access, sensitive-record boundaries and metadata-only audit.
Encrypted incident register, data-rights workflow, safeguarding notification and escalation, and quarterly access review.
DPIA, child-rights assessment, privacy wording, retention decisions and controller–processor terms.
Independent penetration test, restore and deletion exercises, human rehearsals and independent accessibility audit.
The pack distinguishes working technical controls from independent approval. It does not claim AWS, Azure, Postmark, AES-256, TLS 1.3 or a 24-hour incident SLA without applicable evidence and agreement.
Start with the governance structure—not a one-school template stretched across several settings.
Confirm whether the trust, authority, individual schools or a combination determine each processing purpose. The appropriate controller, joint-controller and processor arrangements follow those facts.
Design central reporting, administration and access review without giving every central user unrestricted learner or safeguarding access across every school.
Document school-level DSL ownership, central escalation routes, absence cover and the circumstances in which trust or authority staff require access.
Agree the onboarding sequence, school additions and removals, user lifecycle, support model and volume pricing against the actual number and type of settings.
Processing purposes, lawful basis, special-category conditions, data subjects, rights, retention, suppliers and residual risk.
Human responsibility, access boundaries, notification, acknowledgement, escalation and urgent-concern procedures.
Authentication, permissions, session handling, hosting, suppliers, incident response, recovery and independent testing status.
Scope, implementation, responsibilities, commercial terms and the evidence required by your own purchasing rules.
THE APPROVAL PATH
Confirm organisations, schools, user roles, processing purposes and the workflows required.
Share the controlled pack with your DPO, information-governance lead, safeguarding owner and IT/security reviewer.
Complete controller decisions, contractual schedules, authorised contacts, retention instructions and escalation routes.
Set up scoped access, onboarding, training and agreed readiness checks before live learner records are introduced.
We will provide the current controlled pack and identify any decisions or evidence that remain open.