Designated privacy officers and authorised administrators
Privacy & compliance
Before you start: Use your school’s approved privacy policy, retention schedule and incident process. This chapter explains the application’s controls, not legal deadlines.
Open Privacy & complianceActions depend on your school’s enabled modules, your permissions and the record’s current status.
Find your way around
Dashboard · Consent registry · Breaches · Subject requests · Retention · Processing register · Privacy notices · DPO profile. Select these tabs inside the module; scroll the tab row sideways on a phone.

1. Maintain the privacy contact and notices
- Open DPO profile and record the school’s designated contact details.
- Open Privacy notices and create a notice with the approved title and text.
- Save draft and review its content and intended scope.
- Publish through the available confirmation and record acknowledgements where supported.
What to check: The school’s contact and approved notice are recorded with their lifecycle status.
2. Record and review consent
- Open Consent registry and select the relevant person and purpose.
- Record the decision, source and any dates/evidence requested.
- Save and verify the entry.
- When a decision changes, use the appropriate withdrawal or replacement action instead of silently overwriting the history.
- Check related communication or portal settings after an authorised change.
What to check: The consent record identifies the purpose, decision and its history.
3. Manage a breach record
- Open Breaches and create a record for the incident.
- Enter the discovery details, affected data and factual description.
- Record investigation, containment and the available notification/review stages as they occur.
- Assign follow-up and keep the record updated with evidence.
- Close only when the authorised officer has completed the school’s incident process.
What to check: The incident has a documented response history; urgent response must not wait for data entry.
4. Handle a subject request
- Open Subject requests and record the request type, requester and received date.
- Follow the school’s identity-verification process before disclosing or changing data.
- Use the available processing actions and record the work and decision.
- Review any output before sharing it through an approved channel.
- Complete or reject the request with the required explanation and verify its status.
What to check: The request has a recorded decision and completion history.
5. Review processing and retention
- Open Processing register and record the activity, purpose and required data-handling details.
- Review an existing activity and use its reviewed action when the review is complete.
- Open Retention and examine rules and candidate records.
- Review the scope and approval requirements before any purge or irreversible action.
- Check the resulting status or audit record after an authorised operation.
What to check: Processing activities and retention actions are documented; preview and review must precede deletion.