Skip to main content

DPIA screening assessment

DPIA screening – Article 35(1) GDPR. Processing in the Pomelo service.

The decision belongs to the school, not to us

This document is provided by Yuzu Educational Thinking AB as supporting material for the controller (the school or school organisation). It documents the assessment of whether a full data protection impact assessment is required.

The decision belongs to the controller, who should have the assessment reviewed by someone with data protection expertise before adopting it.

If you need the fillable version with the decision box and signature fields, contact support@hejpomelo.se.

ServicePomelo, Yuzu Educational Thinking AB, company reg. no. 559558-8137
ControllerTo be completed by the school organisation
School unit(s)To be completed by the school organisation
Version / dateTo be completed by the school organisation
StatusDraft / Adopted

1. Purpose​

Under Article 35(1) GDPR, a data protection impact assessment (DPIA) must be carried out where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons. This document assesses whether the processing in the Pomelo service reaches that threshold.

2. Brief description of the processing​

Personal data processed: staff account data – name, email address and role/permissions.

Students: students answer questions about the learning environment and socio-emotional skills (e.g. feeling safe in class, perseverance and study habits) on various rating scales. Responses are submitted anonymously without logging in, and only aggregates at group/class level are stored. Aggregates are presented only at a level that does not permit identification of individual students. Responses cannot be linked to an individual student, and the data does not constitute health data. Where the school is connected via Skolon, class lists are retrieved to count the students and derive the class year group; no data about individual students is stored.

Location: all storage and processing takes place in Sweden. Operations and the database are hosted at Elastx; backups are stored as described in section 5 of the TOM. Traffic passes Cloudflare, Inc. (USA) for DNS, proxy and TLS termination, but the data is not stored with them. The transfer is made on the basis of standard contractual clauses.

Special categories of data (Art. 9): not processed.

How the anonymity is constructed in practice is described in Anonymity and data handling in surveys. Sub-processors and security measures are set out in Technical and Organisational Measures.

3. Assessment against the high-risk criteria​

Assessment against the EDPB's nine criteria for when processing is likely to result in a high risk. The controller confirms the assessment.

CriterionMet?Comment
Evaluation or scoring (profiling)NoNo individual student assessments; anonymous aggregates only.
Automated decision-making with legal effectNoDoes not occur.
Systematic monitoringNoDoes not occur.
Sensitive data or data of a highly personal natureNoNo sensitive data is processed.
Large-scale processingNoLimited number of staff users; student responses are anonymous.
Matching or combining datasetsNoDoes not occur.
Vulnerable data subjects (e.g. children)NoNo personal data about children is processed; the users are adult professionals, including where the school is connected via Skolon.
Innovative use of new technologyNoOrdinary web-based SaaS.
Preventing data subjects from exercising a right or using a serviceNoDoes not occur.

4. Conclusion​

A data protection impact assessment (DPIA) is not required for the current processing.

Reasoning: the processing covers only staff account data, which is of low sensitivity and limited scope. No sensitive data and no personal data about children is processed. None of the high-risk criteria is met.

Reassessment: this assessment must be revisited if the processing changes materially – in particular if identifiable student data is introduced, if individual follow-up of individual students is introduced, or if sensitive data (Art. 9) begins to be processed. In such cases a full DPIA must be carried out before the processing begins.

5. Decision​

The decision is made and signed by the controller, together with the data protection officer where one has been appointed. Use the fillable version of the document for this.


See also Technical and Organisational Measures and How we work with GDPR.