DPIA Summary
The Short Version
- Morechard has an internal Data Protection Impact Assessment covering children's data, the family ledger, and our AI features. It is a working draft (v0.1), not a finished, externally-reviewed document.
- The single highest-priority open item is that no specialist data-protection solicitor has reviewed it yet — we say this plainly rather than implying legal sign-off that hasn't happened.
- We're publishing this summary so a school's DPO can see exactly what's been assessed and what's still open, rather than asking you to take completeness on trust.
What the DPIA covers
The assessment identifies ten risk areas (R1–R10) across the product, including: processing children's behavioural data via nicknames rather than legal identity; the tension between an immutable, hash-chained ledger and the right to erasure; retention of financial-dispute data in separated-family scenarios; and the two AI features (AI Mentor insights and the family audit) that process minimised behavioural summaries.
The ledger and erasure (Risk R10)
The most detailed risk assessment concerns what happens to ledger data after account deletion. Our conclusion: pseudonymised ledger records (amounts, timestamps, and chore patterns with identifiers stripped) are pseudonymous personal data, not anonymous data — the combination of fields could, in principle, act as a behavioural fingerprint. We deliberately corrected an earlier internal description that overstated this as "anonymised." Mitigations in place: no retained linkage key between the pseudonymised records and any identity, no index on behavioural fields, and a hard 7-year deletion at the end of the retention window (aligned to the UK Limitation Act 1980), enforced by an automated purge job.
Automated decision-making
Neither of Morechard's AI features makes a decision with legal or similarly significant effect on a user. Module unlocking and chore approval are rule-based, not AI-driven; AI-generated insights are informational only and always sit in front of a parent for review, not in place of one.
What's still open
We think a DPO evaluating a pilot deserves to see the gaps as clearly as the coverage:
- Specialist legal review has not yet taken place. This DPIA has been produced through internal analysis, not sign-off from a data-protection solicitor. Given the combination of children's data, an immutable ledger, and use in custody-dispute contexts, this is our own top priority before scaling beyond a small pilot.
- Conformance against the ICO's 15 Children's Code standards has not been fully documented standard-by-standard yet.
- Final lawful basis wording for a couple of processing activities is still being tightened, tracked in our internal Record of Processing Activities.
Requesting the full document
Schools considering a pilot are welcome to request the full internal DPIA draft for their own DPO's review. Email [email protected].