Menu
Privacy & Data Security 🔒

GDPR, data protection and DPIA support for schools

We take student data security seriously. Smart School Tracking is fully GDPR compliant, hosted securely in the UK, and supported by pre-completed DPIA templates to simplify Local Authority approvals.

Our Data Protection Principles

How we keep school and pupil progress records completely secure.

UK-Based Hosting

Data is hosted in the UK, with encryption in transit and at rest. We can provide supporting data protection documentation, including DPIA and DPA information, to help schools and local authorities complete their approval process.

Strong Encryption

All student records are encrypted in transit and at rest, using secure encryption protocols to protect data.

Data Ownership

The school or local authority remains the sole Data Controller of all student records. Smart School Tracking acts strictly as a Data Processor.

Access Controls

Granular role-based user management (Administrators, Department Heads, Guidance Staff, Teachers) ensures staff only view data required for their role.

DPIA Template & DPA Support

Before deploying software, local authorities require a Data Protection Impact Assessment (DPIA). We make this process painless:

  • Pre-completed Template: Access a complete DPIA layout documenting hosting, processing details, and compliance audits, ready to share with your DPO.
  • DPA Agreements: We sign standard Data Processing Agreements (DPA) required by Scottish Local Authorities.

Security Checklist

  • Hosted on secure AWS London servers
  • Data encryption at rest
  • Secure HTTPS data transfer
  • Regular backups to secure systems
  • No student personal data sold or shared
  • GDPR compliant retention policies
Security FAQ

Data Protection Questions

Who has access to the pupil data?

Only authorised staff members registered by the school admin have access. Users must log in via secure credentials. Smart School support engineers only access databases under strict authorisation during maintenance cycles.

Do you host data outside the UK?

No. All data, databases, systems, and backups are hosted in AWS secure London regions. We do not store or process student records outside the UK.

What happens when we cancel our contract?

Upon contract termination, all uploaded student lists, grades, comments, and reports are permanently deleted from our servers and backup cycles.

Need help getting data protection sign-off?

Get in touch with our team. We can provide standard DPIA reports and help your school or local authority complete their compliance audits.