⚠️ DRAFT — not yet in force. This document is published in draft, for transparency, while our organisation's registration is being completed. It has not yet been reviewed by a solicitor or a Data Protection Officer, and any detail shown as 'to be confirmed' is not yet finalised. We will replace it with a reviewed, signed version.

Data Protection Impact Assessment — Public Summary — physmat.org

This is a plain-language public summary of our Data Protection Impact Assessment (DPIA) for physmat.org. It is not the full DPIA. The full DPIA is a separate, detailed internal document — the regulator-facing artefact — that records the processing, the risks to children, the mitigations and the residual-risk decision in full, and that must be reviewed and signed by a qualified Data Protection Officer / solicitor before any reliance is placed on it. This summary is written to be read alongside our Privacy Policy, our AI Tutor Notice (see §5) and our Safeguarding Statement.

This service is offered in the United Kingdom. It is not offered in the United States at this time, and we do not target US users.


1. What this is, and what it is not


2. What processing was assessed

The DPIA assesses the personal-data processing involved in running physmat.org for children, and in particular the higher-risk parts:

Our role depends on how a child joins: in the school-provisioned flow the school is the data controller and we act as its processor under an Art. 28 agreement; in the consumer (parent) flow we are the controller.


3. Why a DPIA is required

A DPIA is required where processing is likely to result in a high risk to people's rights and freedoms. This platform combines three factors the ICO treats as high-risk:

On that combination, carrying out a DPIA is treated as mandatory, not optional.


4. Key risks to children we considered

The DPIA identifies the main risks to children. In summary:


5. Mitigations in place or designed

Against those risks the DPIA records the following mitigations:


6. What we are still building

We do not present designed mitigations as if they already run. The DPIA records the following as in progress at the time of this summary:

These gaps are part of the assessment precisely because they affect the residual-risk decision in §7. We will update this summary as each is built and tested, never before.


7. Outcome and residual risk

The DPIA's outcome — the residual-risk rating after mitigations, and the DPO sign-off — is recorded in the full DPIA, not settled here:

Two principles apply to that outcome:


8. Related documents


9. Contact

Questions about this summary or our data protection practices: mail@physmat.org. Data Protection Officer: to be confirmed. You also have the right to complain to the Information Commissioner's Office (ICO) — ico.org.uk. See Privacy Policy §10.