Data Protection Impact Assessment Template
1. Project details
| Project / processing name | Implementation of Payments by iAntz school payment platform |
| School / trust | |
| DPIA owner | |
| DPO (if appointed) | |
| Date | |
| Review date |
2. Describe the processing
2.1 What is the nature of the processing?
The school will use Payments by iAntz (IANTZ LIMITED) to collect and manage payments from parents/guardians for school activities (meals, trips, clubs, uniforms, etc.), manage digital wallets, communicate with parents (in-app, email, SMS, WhatsApp where enabled), and synchronise pupil data from the school's MIS (via Wonde, where configured).
Processing includes: account creation, authentication, payment processing via Stripe, transaction recording, messaging, reporting, and optional AI-assisted features for staff.
School-specific scope: [e.g. which modules: meals, trips, clubs, messaging, MIS sync]
2.2 What is the scope of the processing?
Data subjects: Pupils, parents/guardians, school staff, authorised collectors.
Estimated volume: [number of pupils / parents / staff]
Geographic scope: United Kingdom.
Retention: See Data Inventory appendix. Financial records retained 7 years; account data anonymised on deletion where applicable.
2.3 What is the context of the processing?
Parents expect secure, convenient school payments. Schools have a duty of care regarding pupil data. iAntz is a UK-based processor with Cyber Essentials Plus certification (2026), ICO registration ZC093007, and security and privacy practices aligned with ISO/IEC 27001, 27701, 27017, 27018, and 42001.
Relationship with data subjects: [e.g. existing parent community, FSM considerations, EAL families]
2.4 What is the purpose of the processing?
- Efficient collection of school payments and reduction of cash handling
- Parent visibility of balances and transactions
- School administration, reporting, and reconciliation
- Parent-school communications related to payments and activities
- [School-specific purposes]
3. Consultation
Who was consulted internally?
- [ ] Headteacher / Principal
- [ ] Business manager / finance
- [ ] DPO / data protection lead
- [ ] IT lead
- [ ] Safeguarding lead
Was the vendor (iAntz) consulted? Yes — data protection due diligence pack reviewed ([email protected]).
Were data subjects consulted? [e.g. parent consultation, privacy notice update]
4. Lawful basis and necessity
4.1 Lawful basis (school as controller for pupil data)
Select and justify (Article 6 UK GDPR):
- [ ] Contract — necessary for parent payment of school services
- [ ] Legal obligation
- [ ] Legitimate interests — school administration (document balancing test)
- [ ] Public task — applicable for maintained schools
If special category data (dietary, medical): Article 9 condition:
4.2 Is the processing necessary and proportionate?
iAntz processes only data necessary for payment and related services. Pupil data is not used for marketing or to train public AI models. Card data is not stored by iAntz.
School assessment:
5. Risk assessment
Rate likelihood and severity: Low / Medium / High. Document residual risk after mitigations.
| Risk | Likelihood | Severity | Mitigation (pre-filled where applicable) | Residual risk |
|---|---|---|---|---|
| Unauthorised access to pupil or parent data | RBAC, MFA, audit logs, UK hosting, CREST-accredited penetration testing, Cyber Essentials Plus, ISO/IEC 27001 and 27017 aligned controls | |||
| Payment fraud or misuse | Stripe PCI-DSS Level 1; no card storage; velocity limits; reconciliation | |||
| Data breach at processor or sub-processor | DPA in place; sub-processor list; breach notification; ICO registration | |||
| International transfer of personal data | UK-primary hosting; SCCs/IDTA where transfers occur; see sub-processor list | |||
| Children's data used inappropriately | No direct collection from children; no marketing use; school controls MIS data; DPIAs completed by iAntz | |||
| AI processing creates unexpected outcomes | AI does not move funds; human oversight; no PII model training; data minimisation | |||
| Data subject rights not fulfilled | In-app export/deletion; documented rights process; school DPO + iAntz [email protected] | |||
| [School-specific risk] |
6. Measures to address risks
Technical: Encryption, access controls, secure authentication, segregated environments, monitoring (see Security Summary appendix).
Organisational: DPA with iAntz, staff training, privacy notice update, role-based school permissions, safeguarding policies.
Contractual: Data Processing Agreement, sub-processor transparency, breach notification clauses.
School-specific measures:
7. Decision and sign-off
| Overall residual risk | [ ] Acceptable [ ] Requires ICO consultation [ ] Processing must not proceed |
| DPO advice (if appointed) | |
| Approved by | |
| Date |
8. Appendices (from iAntz data protection pack)
- Data Processing Agreement
- Sub-processor List
- Data Inventory
- Security & Certifications Summary
- Data Subject Rights Process
- Controller & Processor Overview
- Privacy Policy and Security page