Helping you complete your DPIA with confidence

At Motional, we're committed to helping schools, trusts and local authorities handle personal data responsibly and securely.

Completing a Data Protection Impact Assessment (DPIA) is the responsibility of the Data Controller - the organisation that determines how and why personal data is processed. In most cases, that's your school, trust or local authority.

As the Data Processor, we can't complete your DPIA on your behalf. What we can do is make the process as straightforward as possible.

This guide brings together the information most commonly requested by Data Protection Officers, procurement teams and information governance leads. We've presented it in a simple question-and-answer format so you can adapt the relevant sections for your own DPIA, where appropriate.

It includes information about:

  • Authentication and account security (including MFA and Passkeys)
  • Access controls and user permissions
  • Data storage, encryption and hosting
  • Data retention and secure deletion
  • Business continuity and disaster recovery
  • Audit logging and monitoring
  • Supplier management and sub-processors
  • Information governance and compliance
  • Privacy and data protection

If there's anything you need that isn't covered here, we're always happy to help.

Data Protection Impact Assessment - Support Pack