Grade9School
For MFL departments

GDPR and MFL platforms: a practical school procurement and DPIA checklist

A practical UK school checklist for reviewing an MFL platform: roles, pupil data, hosting, AI, sub-processors, retention, deletion, security, DPAs and DPIAs.

Grade 9 School brings curriculum, lesson planning, practice, homework, feedback, live activities, printables and progress tracking into one connected teaching workflow.

On this page

A useful GDPR review does not begin with the question:

“Is this platform GDPR compliant?”

That invites a yes/no marketing answer to something that depends on the actual processing, the school’s use of the service, the contractual roles and the controls around it.

A better review maps what really happens.

For an MFL platform, that can include:

  • teacher accounts;
  • classes;
  • pupil logins;
  • vocabulary, grammar and translation work;
  • reading/listening answers;
  • speaking audio;
  • writing submissions;
  • teacher feedback;
  • progress data;
  • AI-supported processing;
  • exports and reports.

The procurement task is to understand each data flow well enough to judge necessity, risk, contracts and controls.

This page is an operational checklist, not legal advice.

Explore the topic ↓
grade9school.com
Grade 9 School teacher dashboard for classes and assignments
Everything in one place

One platform for teaching, practice, feedback and progress.

Plan lessons, set homework, run live activities, generate printables, give AI-supported marking and track progress across Spanish, French, German, Portuguese and Italian.

One department, one workflow

Spanish · French · German · Portuguese · Italian

Use the same platform architecture across the languages your department teaches, while keeping each class in its own language and curriculum context.

Explore language workflows →
Explore the topic

Find the detail you need.

Open any section for the key facts, practical detail, examples and sources.

011. Establish who is controller and who is processor

The words in a supplier contract matter, but the actual roles depend on who determines the purposes and essential means of the processing.

In a normal school teaching workflow, a common model is:

  • the school decides why pupil data is being processed and which pupils use the platform;
  • the supplier processes the teaching data on the school’s behalf under the service agreement.

The ICO’s guidance says controller/processor status depends on the real decision-making relationship, not simply the label chosen by the parties.

Grade 9 School’s documented posture for ordinary school teaching data is that the school is the controller and Grade 9 School Ltd acts as processor. Grade 9 may act as controller for its own company administration records such as business contacts, invoices and statutory accounting records.

Schools should still check that the contract reflects the actual use they intend.

022. Map the data categories before discussing risk

Ask the supplier to list what it processes and why.

For a language platform, categories might include:

Data categoryExampleWhy it may be needed
Teacher accountname, school email, roleauthentication, account management
School/departmentschool name, licence membershipsetup and support
Class dataclass, group, teacher linkrouting work and reporting
Pupil accountusername or identifiersign-in and account continuity
Assignment datatask, due date, target class/pupilhomework/classwork workflow
Submissionsanswers, writing, speakingmarking, feedback, progress
Scores/progresscompletion, score, trend evidenceteacher review/intervention
Resourcesteacher-created or generated materialsplanning and reuse
Technical recordsservice/security diagnosticsoperating and protecting service

The point is not to create the longest possible inventory. It is to expose what is actually necessary.

033. Check whether direct pupil identifiers are required

The ICO’s data-minimisation principle asks organisations to limit personal data to what is necessary.

Ask:

  • Does the platform need pupil names?
  • Does it need pupil email addresses?
  • Can the school use pseudonymous identifiers?
  • Can the school keep any real-name mapping internally?
  • Is a direct identifier required for support or merely convenient?

Grade 9 School does not require pupil email addresses for its teacher-created username/password route. Schools can also choose a pseudonymous account model.

That should be described as data minimisation, not anonymisation. Account, class, assignment, submission and progress records can still be personal data when the school can link them back to a pupil.

For a detailed treatment, see the related guide on pupil accounts without email.

044. Understand authentication and account recovery

A privacy review should include what happens when a pupil cannot sign in.

Ask:

  • Who creates pupil accounts?
  • Are pupils expected to self-register?
  • Is school email/SSO required?
  • Who can reset credentials?
  • Can existing passwords be viewed?
  • How are bulk login sheets handled?
  • What happens when a pupil changes class?

A secure account design is not just a sign-in screen. It includes the recovery and support path.

055. Record hosting, backups and disaster recovery separately

“Hosted in the UK” is not a complete infrastructure answer.

Ask for:

  • the location of the primary teaching database;
  • where backups are managed;
  • whether the supplier keeps another off-platform copy;
  • the intended restore/recovery location;
  • whether a separate multi-region standby exists;
  • which services host the front end rather than the core database.

The current Grade 9 School reference position is:

  • core backend/database: Supabase on AWS eu-west-2, London;
  • database backups: managed by Supabase for that project;
  • separate off-platform backup maintained by Grade 9: no;
  • intended restore location: the same Supabase/AWS London region unless otherwise specifically agreed;
  • separate multi-region standby database: no;
  • web application hosting/deployment: Netlify.

That is deliberately more precise than claiming “all data stays in the UK”, because optional AI processing is a separate data flow.

066. Treat AI as its own processing route

If a platform contains AI-supported tools, do not assume the main database location describes the AI processing location.

Ask:

  • Which AI provider is used?
  • Which features use it?
  • What pupil/teacher data is sent?
  • Is audio or an image sent?
  • Is direct identifying data necessary?
  • What do the provider terms say about training/product improvement?
  • Where can processing occur?
  • What logging/cache/retention can occur?
  • Can ordinary platform use continue without invoking AI?

Grade 9 School’s current position is that some optional features use the paid Google Gemini API, including resource generation, listening/audio activity generation and teacher-controlled writing/speaking feedback.

The school-facing position does not say that AI processing is UK-only. It describes Google-managed service infrastructure and acknowledges that relevant data may be processed, stored transiently or cached where Google or its agents maintain facilities.

The paid-service terms relied on by Grade 9 state that submitted prompts/files/responses are not used to improve Google’s products. That statement should be rechecked against the current applicable terms before final publication or a procurement decision.

077. Identify sub-processors by purpose

A list of company names is less useful than a list that says what each one does.

For the current Grade 9 School architecture, the relevant school-facing summary is:

ProviderPurpose
Supabase / AWS eu-west-2 Londoncore backend/database
Google Gemini API / Google AI servicesoptional AI-supported features
Netlifyweb application hosting/deployment

A supplier should also explain the distinction between its own chosen sub-processors and a vendor’s broader authorised supplier list. A vendor listing a company in its own documentation does not by itself prove that the school platform sends pupil data to that company for a particular workflow.

088. Ask for retention and deletion in operational language

Avoid vague statements such as “data is deleted when no longer needed” unless the supplier can turn that into a workable process.

Ask:

  • How long is teaching data retained during the licence?
  • What happens after the licence ends?
  • Can the school request earlier deletion?
  • What is deleted or anonymised from the live system?
  • How quickly?
  • What may remain in managed backups or provider logs?
  • How are statutory finance records treated separately?

Grade 9 School’s current school-facing position is:

  • teaching data is retained for the licence term;
  • after licence end, the default retention period is up to 90 days unless the school asks for deletion sooner;
  • on written request, relevant pupil/class teaching data is to be deleted or anonymised from the live system within 30 days, subject to legal/accounting obligations;
  • data in managed backups or vendor-side logs/cache may remain temporarily until normal retention cycles expire.

That is why Grade 9 does not claim instant deletion from every backup or provider system.

099. Review the processor contract, not just the privacy policy

The ICO says a controller using a processor needs a written contract or other legal act.

The contract should describe the processing and include the Article 28 terms, including matters such as:

  • documented instructions;
  • confidentiality;
  • appropriate security;
  • sub-processors;
  • data-subject rights;
  • assistance to the controller;
  • end-of-contract provisions;
  • audit/inspection obligations.

Grade 9 School can provide a Grade 9 School Ltd DPA draft for school review. If a school has its own preferred DPA template, the current posture is to review that instead where appropriate.

A DPA is not a decorative attachment. It should describe the service the school is actually buying.

1010. Decide whether a DPIA is required

The ICO describes a DPIA as a process to identify and minimise the data-protection risks of a project. A DPIA is required where processing is likely to result in a high risk to individuals.

Schools should apply their own governance and DPO judgement to the intended use.

A useful DPIA describes:

  • the nature, scope, context and purposes of the processing;
  • necessity and proportionality;
  • risks to individuals;
  • measures to reduce those risks.

For an MFL platform, do not skip speaking audio or AI-supported feedback merely because most of the platform is ordinary vocabulary and grammar practice.

Map the actual workflows the school intends to use.

1111. Ask for security evidence at the right level

Security should be risk-based, not reduced to a badge.

Ask about:

  • access control;
  • authentication;
  • encryption in transit and at rest where relevant;
  • vulnerability management;
  • backup/recovery;
  • incident handling;
  • staff/admin access;
  • supplier security documentation.

The ICO requires appropriate technical and organisational measures relative to the risks of the processing.

A school may reasonably ask for vendor security evidence without expecting a small supplier to hand over unrestricted access to private infrastructure or confidential audit reports.

12A practical procurement table
QuestionWhy it mattersUseful evidence
What pupil data is required?data minimisationdata-category table, onboarding workflow
Can we use pseudonymous accounts?reduces direct identifiersaccount/login documentation
Who is controller/processor?legal responsibilitiesDPA / contract
Where is the core database?location and risk mappinghosting statement
Where are backups restored?continuity and locationbackup/DR statement
Which features use AI?separate data flowAI feature matrix
Which AI provider is used?third-party processingprovider terms / DPA
Does AI output reach pupils automatically?professional judgementworkflow evidence
Which sub-processors are used?onward processingcurrent sub-processor list
What happens at licence end?storage limitationretention schedule
How do we request deletion?operational rights/supportdeletion procedure
What security evidence is available?risk assessmentsupplier/vendor security material
13Four claims that should trigger a follow-up question

“We do not process personal data.”

Ask how pupil accounts, class membership, submissions and progress are linked.

“Everything is stored in the UK.”

Ask separately about the core database, backups, analytics, email services and AI processing.

“Everything is deleted instantly.”

Ask about the live database, managed backups, logs/cache and legal/accounting records.

“We are fully GDPR compliant.”

Ask for the actual data flows, contracts, security measures, retention and deletion process instead of treating a blanket statement as evidence.

14Current Grade 9 School company reference

For school procurement records, the current company identity is:

  • Grade 9 School Ltd
  • Company number 17153287
  • Registered in England and Wales
  • Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ
  • Current ICO registration: ZC226583

ICO registration is an administrative fact. It is not presented here as a certification that every possible school use or configuration is automatically compliant.

The school must still assess its own intended processing.