GDPR and MFL platforms: a practical school procurement and DPIA checklist
A practical UK school checklist for reviewing an MFL platform: roles, pupil data, hosting, AI, sub-processors, retention, deletion, security, DPAs and DPIAs.
Grade 9 School brings curriculum, lesson planning, practice, homework, feedback, live activities, printables and progress tracking into one connected teaching workflow.
A useful GDPR review does not begin with the question:
“Is this platform GDPR compliant?”
That invites a yes/no marketing answer to something that depends on the actual processing, the school’s use of the service, the contractual roles and the controls around it.
A better review maps what really happens.
For an MFL platform, that can include:
- teacher accounts;
- classes;
- pupil logins;
- vocabulary, grammar and translation work;
- reading/listening answers;
- speaking audio;
- writing submissions;
- teacher feedback;
- progress data;
- AI-supported processing;
- exports and reports.
The procurement task is to understand each data flow well enough to judge necessity, risk, contracts and controls.
This page is an operational checklist, not legal advice.
Explore the topic ↓
One platform for teaching, practice, feedback and progress.
Plan lessons, set homework, run live activities, generate printables, give AI-supported marking and track progress across Spanish, French, German, Portuguese and Italian.
Writing & speaking marking
Set writing and speaking tasks, collect submissions, generate detailed feedback and keep teacher review in the loop.
Explore this guide →
Gradebook & reports
Track scores, completion, engagement and learning evidence across classes.
Explore this guide →
Interactive lessons
Generate, edit, save and reuse complete lesson presentations.
Explore this guide →
Printables in seconds
Vocabulary, grammar, translation, reading, listening, worksheets and booklets.
Explore this guide →
Live games & whiteboards
Turn curriculum content into whole-class competition, retrieval and live response.
Explore this guide →
Assignments & tracking
Set work for a whole class or selected pupils, schedule it and see who has started or finished.
Explore this guide →
Vocabulary, grammar, translation & independent practice
Structured learning paths, flashcards, vocabulary builders, grammar, verb work, translation and tracked independent learning across supported languages.
Explore this guide →
Spanish · French · German · Portuguese · Italian
Use the same platform architecture across the languages your department teaches, while keeping each class in its own language and curriculum context.
Explore language workflows →
From planning to progress, it all connects.
Curriculum management, assignments, AI feedback, printables, gradebook and lesson planning all sit inside the same Grade 9 environment.
Find the detail you need.
Open any section for the key facts, practical detail, examples and sources.
011. Establish who is controller and who is processor⌄
The words in a supplier contract matter, but the actual roles depend on who determines the purposes and essential means of the processing.
In a normal school teaching workflow, a common model is:
- the school decides why pupil data is being processed and which pupils use the platform;
- the supplier processes the teaching data on the school’s behalf under the service agreement.
The ICO’s guidance says controller/processor status depends on the real decision-making relationship, not simply the label chosen by the parties.
Grade 9 School’s documented posture for ordinary school teaching data is that the school is the controller and Grade 9 School Ltd acts as processor. Grade 9 may act as controller for its own company administration records such as business contacts, invoices and statutory accounting records.
Schools should still check that the contract reflects the actual use they intend.
022. Map the data categories before discussing risk⌄
Ask the supplier to list what it processes and why.
For a language platform, categories might include:
| Data category | Example | Why it may be needed |
|---|---|---|
| Teacher account | name, school email, role | authentication, account management |
| School/department | school name, licence membership | setup and support |
| Class data | class, group, teacher link | routing work and reporting |
| Pupil account | username or identifier | sign-in and account continuity |
| Assignment data | task, due date, target class/pupil | homework/classwork workflow |
| Submissions | answers, writing, speaking | marking, feedback, progress |
| Scores/progress | completion, score, trend evidence | teacher review/intervention |
| Resources | teacher-created or generated materials | planning and reuse |
| Technical records | service/security diagnostics | operating and protecting service |
The point is not to create the longest possible inventory. It is to expose what is actually necessary.
033. Check whether direct pupil identifiers are required⌄
The ICO’s data-minimisation principle asks organisations to limit personal data to what is necessary.
Ask:
- Does the platform need pupil names?
- Does it need pupil email addresses?
- Can the school use pseudonymous identifiers?
- Can the school keep any real-name mapping internally?
- Is a direct identifier required for support or merely convenient?
Grade 9 School does not require pupil email addresses for its teacher-created username/password route. Schools can also choose a pseudonymous account model.
That should be described as data minimisation, not anonymisation. Account, class, assignment, submission and progress records can still be personal data when the school can link them back to a pupil.
For a detailed treatment, see the related guide on pupil accounts without email.
044. Understand authentication and account recovery⌄
A privacy review should include what happens when a pupil cannot sign in.
Ask:
- Who creates pupil accounts?
- Are pupils expected to self-register?
- Is school email/SSO required?
- Who can reset credentials?
- Can existing passwords be viewed?
- How are bulk login sheets handled?
- What happens when a pupil changes class?
A secure account design is not just a sign-in screen. It includes the recovery and support path.
055. Record hosting, backups and disaster recovery separately⌄
“Hosted in the UK” is not a complete infrastructure answer.
Ask for:
- the location of the primary teaching database;
- where backups are managed;
- whether the supplier keeps another off-platform copy;
- the intended restore/recovery location;
- whether a separate multi-region standby exists;
- which services host the front end rather than the core database.
The current Grade 9 School reference position is:
- core backend/database: Supabase on AWS eu-west-2, London;
- database backups: managed by Supabase for that project;
- separate off-platform backup maintained by Grade 9: no;
- intended restore location: the same Supabase/AWS London region unless otherwise specifically agreed;
- separate multi-region standby database: no;
- web application hosting/deployment: Netlify.
That is deliberately more precise than claiming “all data stays in the UK”, because optional AI processing is a separate data flow.
066. Treat AI as its own processing route⌄
If a platform contains AI-supported tools, do not assume the main database location describes the AI processing location.
Ask:
- Which AI provider is used?
- Which features use it?
- What pupil/teacher data is sent?
- Is audio or an image sent?
- Is direct identifying data necessary?
- What do the provider terms say about training/product improvement?
- Where can processing occur?
- What logging/cache/retention can occur?
- Can ordinary platform use continue without invoking AI?
Grade 9 School’s current position is that some optional features use the paid Google Gemini API, including resource generation, listening/audio activity generation and teacher-controlled writing/speaking feedback.
The school-facing position does not say that AI processing is UK-only. It describes Google-managed service infrastructure and acknowledges that relevant data may be processed, stored transiently or cached where Google or its agents maintain facilities.
The paid-service terms relied on by Grade 9 state that submitted prompts/files/responses are not used to improve Google’s products. That statement should be rechecked against the current applicable terms before final publication or a procurement decision.
077. Identify sub-processors by purpose⌄
A list of company names is less useful than a list that says what each one does.
For the current Grade 9 School architecture, the relevant school-facing summary is:
| Provider | Purpose |
|---|---|
| Supabase / AWS eu-west-2 London | core backend/database |
| Google Gemini API / Google AI services | optional AI-supported features |
| Netlify | web application hosting/deployment |
A supplier should also explain the distinction between its own chosen sub-processors and a vendor’s broader authorised supplier list. A vendor listing a company in its own documentation does not by itself prove that the school platform sends pupil data to that company for a particular workflow.
088. Ask for retention and deletion in operational language⌄
Avoid vague statements such as “data is deleted when no longer needed” unless the supplier can turn that into a workable process.
Ask:
- How long is teaching data retained during the licence?
- What happens after the licence ends?
- Can the school request earlier deletion?
- What is deleted or anonymised from the live system?
- How quickly?
- What may remain in managed backups or provider logs?
- How are statutory finance records treated separately?
Grade 9 School’s current school-facing position is:
- teaching data is retained for the licence term;
- after licence end, the default retention period is up to 90 days unless the school asks for deletion sooner;
- on written request, relevant pupil/class teaching data is to be deleted or anonymised from the live system within 30 days, subject to legal/accounting obligations;
- data in managed backups or vendor-side logs/cache may remain temporarily until normal retention cycles expire.
That is why Grade 9 does not claim instant deletion from every backup or provider system.
099. Review the processor contract, not just the privacy policy⌄
The ICO says a controller using a processor needs a written contract or other legal act.
The contract should describe the processing and include the Article 28 terms, including matters such as:
- documented instructions;
- confidentiality;
- appropriate security;
- sub-processors;
- data-subject rights;
- assistance to the controller;
- end-of-contract provisions;
- audit/inspection obligations.
Grade 9 School can provide a Grade 9 School Ltd DPA draft for school review. If a school has its own preferred DPA template, the current posture is to review that instead where appropriate.
A DPA is not a decorative attachment. It should describe the service the school is actually buying.
1010. Decide whether a DPIA is required⌄
The ICO describes a DPIA as a process to identify and minimise the data-protection risks of a project. A DPIA is required where processing is likely to result in a high risk to individuals.
Schools should apply their own governance and DPO judgement to the intended use.
A useful DPIA describes:
- the nature, scope, context and purposes of the processing;
- necessity and proportionality;
- risks to individuals;
- measures to reduce those risks.
For an MFL platform, do not skip speaking audio or AI-supported feedback merely because most of the platform is ordinary vocabulary and grammar practice.
Map the actual workflows the school intends to use.
1111. Ask for security evidence at the right level⌄
Security should be risk-based, not reduced to a badge.
Ask about:
- access control;
- authentication;
- encryption in transit and at rest where relevant;
- vulnerability management;
- backup/recovery;
- incident handling;
- staff/admin access;
- supplier security documentation.
The ICO requires appropriate technical and organisational measures relative to the risks of the processing.
A school may reasonably ask for vendor security evidence without expecting a small supplier to hand over unrestricted access to private infrastructure or confidential audit reports.
12A practical procurement table⌄
| Question | Why it matters | Useful evidence |
|---|---|---|
| What pupil data is required? | data minimisation | data-category table, onboarding workflow |
| Can we use pseudonymous accounts? | reduces direct identifiers | account/login documentation |
| Who is controller/processor? | legal responsibilities | DPA / contract |
| Where is the core database? | location and risk mapping | hosting statement |
| Where are backups restored? | continuity and location | backup/DR statement |
| Which features use AI? | separate data flow | AI feature matrix |
| Which AI provider is used? | third-party processing | provider terms / DPA |
| Does AI output reach pupils automatically? | professional judgement | workflow evidence |
| Which sub-processors are used? | onward processing | current sub-processor list |
| What happens at licence end? | storage limitation | retention schedule |
| How do we request deletion? | operational rights/support | deletion procedure |
| What security evidence is available? | risk assessment | supplier/vendor security material |
13Four claims that should trigger a follow-up question⌄
“We do not process personal data.”
Ask how pupil accounts, class membership, submissions and progress are linked.
“Everything is stored in the UK.”
Ask separately about the core database, backups, analytics, email services and AI processing.
“Everything is deleted instantly.”
Ask about the live database, managed backups, logs/cache and legal/accounting records.
“We are fully GDPR compliant.”
Ask for the actual data flows, contracts, security measures, retention and deletion process instead of treating a blanket statement as evidence.
14Current Grade 9 School company reference⌄
For school procurement records, the current company identity is:
- Grade 9 School Ltd
- Company number 17153287
- Registered in England and Wales
- Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ
- Current ICO registration: ZC226583
ICO registration is an administrative fact. It is not presented here as a certification that every possible school use or configuration is automatically compliant.
The school must still assess its own intended processing.
Spanish
French
German
Portuguese
Italian