ChildSafe AI โ Compliance Assessment Platform
This DPIA was prepared in accordance with ICO DPIA guidance (2018, updated 2024) and UK GDPR Article 35. It will be reviewed annually or upon any material change to the processing.
ChildSafe AI processes documents submitted by users. Those documents may contain descriptions of data practices affecting children. The ICO's list of processing operations likely to result in high risk (Article 35(3) UK GDPR) is assessed below:
| Criterion | Applicable? | Notes |
|---|---|---|
| Systematic and extensive evaluation / profiling | No | Documents are assessed, not individuals |
| Processing of special category data at scale | Possible | Submitted documents may describe processing of children's data, but ChildSafe AI does not itself process children's data directly |
| Systematic monitoring of publicly accessible areas | No | N/A |
| Novel technology | Yes | AI/LLM used for compliance assessment โ novel application |
| Prevents access to service / contract | No | N/A |
| Processes children's data | Indirect | Documents assessed may relate to children's data practices |
Decision: DPIA required โ novel AI technology; potential for documents containing personal data; indirect processing of information about children's data environments.
ChildSafe AI is a web-based SaaS compliance assessment tool that enables organisations to upload policy documents (privacy notices, product specifications, terms of service, compliance reports) and receive an AI-generated assessment of compliance with:
The tool generates: a compliance score (0โ100), framework-by-framework findings, a DPIA document, a prioritised remediation roadmap, and a compliance certificate (requiring human expert sign-off).
| Data Element | Source | Legal Basis | Retention |
|---|---|---|---|
| Document content submitted by user | User | Legitimate interests (Art. 6(1)(f)) | Session only โ zero server retention |
| Document name | User | Legitimate interests | Browser localStorage โ user-controlled |
| IP address / request metadata | Automatic (Netlify) | Legitimate interests | 30 days (Netlify standard) |
| User's Gemini API key (optional) | User | Legitimate interests | Browser localStorage โ user-controlled |
| Anonymised audit log entries | Generated | Legitimate interests | Max 50 entries FIFO โ localStorage only |
| Processor | Location | Role | Safeguard |
|---|---|---|---|
| Privacomply Ltd / Google Cloud Vertex AI | ๐ฌ๐ง London, UK (europe-west2) | AI inference โ compliance analysis | UK-region endpoint; data does not leave UK. Google Cloud DPA applies. |
| Netlify Inc. | UK/EU CDN edge | Hosting, serverless function proxy | Transit only โ no content storage. Netlify DPA. |
๐ฌ๐ง All AI inference is routed through Privacomply's configured London (europe-west2) infrastructure. Document content does not leave the United Kingdom for processing purposes. No international transfer mechanism is required for AI processing.
Submitted documents are not themselves special category data. Documents may describe the processing of special category data. ChildSafe AI does not extract, store or further process any special category data found within submitted documents.
| Stakeholder | Consulted | Notes |
|---|---|---|
| DPO / Assessor | Kevin Morrison, CIPP/E CIPM | Dual role โ founder and qualified DPO |
| ICO Regulatory Sandbox | Pending | Application in progress |
| End users (pilot) | Informal | Pre-launch pilot feedback incorporated |
| Processors | Netlify, Google | Standard vendor DPAs reviewed |
โณ Peer review pending: A second IAPP-certified privacy professional has been invited to review 5 sample outputs and countersign this DPIA before ICO submission.
| Question | Assessment |
|---|---|
| Could the purpose be achieved without AI processing? | No โ manual assessment requires a qualified lawyer at prohibitive cost for SMEs |
| Is document content the minimum needed? | Yes โ only first 4,000 characters are transmitted for AI processing |
| Is retention proportionate? | Yes โ zero server-side retention; browser-only where user has control |
| Is the AI model appropriate? | Yes โ Google Gemini with structured prompting and temperature=0 for deterministic outputs |
Article 6(1)(f) UK GDPR โ Legitimate Interests applies to all processing. Balancing test: purpose is clear and beneficial (compliance support); minimum data needed; processing is in users' interests as they actively submit documents; document content is a business document, not personal correspondence.
| Risk | Likelihood | Severity | Overall |
|---|---|---|---|
| R1 Document contains personal data inadvertently | Medium | Medium | Medium |
| R2 AI processing via UK London endpoint โ no international transfer | Low | Low | Low |
| R3 AI generates incorrect compliance advice | Medium | High | High |
| R4 Netlify access logs expose user IP addresses | Low | Low | Low |
| R5 API key in localStorage exposed via XSS | Low | Medium | Medium |
| R6 localStorage accessed on shared device | Low | Medium | Medium |
| Risk | Mitigation | Status |
|---|---|---|
| R1 | Warning advising users not to include personal data; session-only processing | โ Implemented |
| R2 | UK-region endpoint (europe-west2 / London) configured; data does not leave UK | โ Implemented |
| R3 | "Not legal advice" disclaimer on all outputs; HITL certification requirement; temperature=0; criteria reviewed by CIPP/E CIPM | โ Implemented |
| R4 | HTTPS enforced; no additional logging beyond Netlify defaults | โ Implemented |
| R5 | API key stored in localStorage with warning; Content Security Policy headers | โ ๏ธ Partial โ CSP to be added |
| R6 | History stored locally with clear disclosure; users advised to clear browser data on shared devices | โ Documented in UI |
| Risk | Residual Level | Acceptable? |
|---|---|---|
| R1 | Low | Yes |
| R2 | Low | Yes โ UK-only processing |
| R3 | Medium | Yes โ mitigated by HITL and disclaimers |
| R4 | Low | Yes |
| R5 | Low-Medium | Yes โ partial mitigation; CSP to be added |
| R6 | Low | Yes |
Overall residual risk: MEDIUM โ ACCEPTABLE. Mitigations are proportionate and in place.
This DPIA concludes that ChildSafe AI can proceed with the described processing. Residual risks are acceptable given the mitigations in place. The processing is necessary, proportionate, and serves a legitimate public benefit in supporting compliance with children's data protection law.
ChildSafe AI DPIA v1.0 ยท August 2026 ยท Privacomply Ltd ยท Kevin Morrison CIPP/E CIPM ยท Review date: August 2027