How to Run a Data Protection Review Before Deploying an AI Writing Tool (2026)

<![CDATA[

The data protection review is the step that delays AI deployments, and almost always for the same reason: it starts after the academic decision has been made, when the pressure to approve is highest and the leverage over the vendor is lowest.

Run in parallel with evaluation, the same work takes weeks rather than months and produces better contract terms. Here is the sequence.

Step 1: Map the data flow before you assess anything

You cannot assess a risk you have not described. Produce a single page recording:

  • What personal data enters the system. Student identifiers, submitted text, drafts, supervision comments, usage telemetry. Note that a thesis draft may itself contain personal data about third parties — interview transcripts, clinical material, participant identifiers.
  • Who processes it. The vendor, and every sub-processor behind them. Ask for the sub-processor list by name; “our cloud provider” is not an answer.
  • Where it is stored and processed, by jurisdiction, and whether that changes under failover.
  • How long it is retained, and what happens at contract termination.
  • Who can access it on the vendor side, and under what controls.

That third-party point deserves emphasis because it is routinely missed. A postgraduate uploading interview transcripts is processing research participants’ personal data, and those participants consented to a research project, not to a commercial platform. Where that is in scope, the ethics approval and the data protection review need to agree with each other.

Step 2: Determine whether a DPIA is required — properly

For UK institutions the Information Commissioner’s Office publishes detailed guidance structured around exactly the questions you need to answer: what a DPIA is, when one is needed, how to do one, whether you must consult the ICO, and examples of processing “likely to result in high risk.” The guidance was revised to adopt the European Data Protection Board’s opinion 22/2018 on the ICO’s list of processing operations subject to the DPIA requirement.

One current caveat to check before you copy a template out of your quality system: the ICO states that this guidance is under review following changes made by the Data (Use and Access) Act and may be subject to change. If your DPIA proforma was written a while ago, verify it against the live guidance rather than assuming continuity.

The instinct to treat a small pilot as exempt is worth resisting. The threshold turns on the nature of the processing, not the size of the cohort, and a pilot that processes student work through a third party with novel technology sits close to several of the listed indicators.

Step 3: Settle the model training question in writing

This is the single question that most often changes an institution’s decision, and it must be answered in the contract rather than in a sales call.

Ask it in three parts, because vendors answer different parts of it:

  1. Is submitted content used to train or fine-tune models — the vendor’s own, or any third party’s?
  2. If not by default, can it be enabled, and by whom? An institutional setting a user can override is not a control.
  3. Is the answer contractual, or a statement of current practice that can change with a product update?

A commitment in a data processing agreement is a commitment. The same words on a marketing page are not.

Printed risk register on a desk beside a laptop
Record the residual risk and who accepted it. That record is the point of the exercise.

Step 4: Identify the rights holder — the US detail that catches people

Institutions operating in the United States work under FERPA, the Family Educational Rights and Privacy Act, with the statute at 20 U.S.C. § 1232g. It gives parents rights of access to their children’s education records, the right to seek amendment, and some control over disclosure of personally identifiable information from those records.

The provision that matters for higher education: when a student turns 18 or enters a postsecondary institution at any age, the rights transfer from the parents to the student, who becomes an “eligible student.”

So in a university the rights holder is the student — including a dual-enrolment sixteen-year-old taking college courses. Vendor arrangements, notice, and any consent mechanism must be built around the student. Institutions that have imported a K-12 template will have the wrong party in the wrong place throughout.

Step 5: Cover the AI-specific obligations, not just the data ones

Data protection is necessary and no longer sufficient. For institutions in the EU, Article 4 of Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures ensuring, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf — proportionate to their technical knowledge, experience, education and training, the context of use, and the people the systems are used on.

A university adopting an AI writing platform is a deployer. Practically, that means your review should produce a training record alongside the risk register, and the two should name the same population.

Step 6: Write down what you decided, and who accepted the risk

The purpose of the exercise is not a clean sheet. It is a record showing that the institution identified the risks, applied mitigations, and that a named person with authority accepted whatever remained.

Your output should state, for each identified risk: the mitigation applied, the residual risk after mitigation, the named accepting officer, and the review date. A DPIA with no residual risk recorded anywhere is usually a DPIA that was completed to be filed rather than to be used.

A workable checklist

Area What to establish Where it must live
Roles Who is controller, who is processor, for which processing Data processing agreement
Sub-processors Named list, and notice obligations before changes DPA annex
Location Storage and processing jurisdictions, including failover DPA
Training use Whether content trains any model; whether it is contractual DPA, not marketing copy
Retention and exit Retention periods; deletion and export at termination Contract
Rights requests How the vendor supports access, amendment and deletion requests DPA and internal procedure
Security Certifications, penetration testing cadence, incident notification timescales Contract schedule
Accessibility Conformance statement and known exceptions Procurement file
AI literacy Who is trained, when, and how it is recorded Training record
Residual risk What remains, who accepted it, review date DPIA

Sequencing it so it does not become the bottleneck

Start the review in the same week you start the academic evaluation. Send the vendor questionnaire and the DPIA data-mapping request together. By the time the academic side reaches a view, you will have the answers that determine whether that view is actionable — and if a vendor cannot answer basic sub-processor and training questions in a fortnight, you have learned something useful about the support you would receive as a customer.

The specific questions to send are set out in our procurement question bank, and the surrounding pilot structure in our guide to running a departmental pilot.

If it would help to have the data protection documentation package for an evaluation up front — data flow, sub-processor list, retention and training position — request an institutional evaluation.

Frequently asked questions

Do we need a DPIA for every edtech tool?

No, but you must assess whether one is required against the regulator’s criteria rather than assuming. The ICO publishes both the criteria and examples of high-risk processing.

Is a pilot exempt from a DPIA?

Not inherently. The requirement turns on the nature of the processing, not the number of participants.

Is UK DPIA guidance changing?

The ICO states its DPIA guidance is under review due to changes made by the Data (Use and Access) Act and may be subject to change, so check the live page before relying on an internal template.

Who holds FERPA rights for a university student?

The student. Rights transfer from parents when the student turns 18 or enters a postsecondary institution at any age.

Does FERPA apply to a UK or EU institution?

Not directly, but multi-campus and transnational providers frequently have obligations under more than one regime, and vendor terms are usually written to one. Check which.

What is the most important contract term?

Whether submitted content is used to train models, expressed contractually rather than as current practice.

Does data residency in the EU satisfy GDPR?

Residency is one factor. Lawful basis, transparency, retention, sub-processing and data subject rights all still apply regardless of where the servers sit.

Who signs off the residual risk?

A named officer with authority to accept it on the institution’s behalf, recorded in the assessment with a review date.

What about student work that contains research participants’ data?

Treat it as in scope and align the vendor arrangement with what participants were told during ethics approval.

Should students be able to opt out?

If the tool is mandatory for assessment, an opt-out implies an equivalent alternative route must exist. Decide this before launch, not after the first request.

How does this interact with our detection contract?

They are separate processing operations with separate assessments. Both send student work to third parties, and the evidential weight you place on the detection output is a policy question covered in our analysis of AI detection reliability.

]]>

Bring Tesify to your institution

Scope a departmental pilot: one cohort, one term, and your own measures of what worked.

Request an evaluation We reply within 2 business days

Categories