Call it the polished-demo trap: a supplier can show a convincing interface, connect it to a general purpose model and demonstrate one happy path without answering where pupil data goes, who can access it, how long it is kept or what happens on exit.
The question for a special educational needs coordinator (SENCO), multi-academy trust (MAT) operations lead or data protection officer (DPO) is how to tell a serious supplier from a well presented prototype before pupil data is involved.
For a wider test of whether a platform is safe, useful and workable, use our AI-powered SEND software buying guide.
What the polished demo actually proves
A demo proves that the supplier can produce one good outcome on its own data, with its own people controlling the process. It does not show where the text goes when the model is called, who can read it, how long it is kept, or what happens when a teaching assistant's account is used from an unexpected location.
Keep two questions separate. Does the software do the special educational needs and disabilities (SEND) job well? Is the supplier safe to hand children's data to? A product can pass one and fail the other. A glossy screen or stock image is not evidence either. Finding an image through a search engine is a route to discovery, not permission to reproduce it [11].
Cyber Essentials is a floor, not a ceiling
Cyber Essentials is a government backed scheme covering five technical controls: firewalls, secure configuration, user access control, malware protection and security update management [5]. That is a useful baseline against commodity attacks. It is not a data protection audit, artificial intelligence (AI) governance framework, lawful processing arrangement or statement that SEND output is accurate enough to show a parent.
The same applies to "we use encryption". Encryption in transit and at rest does not tell you who can read a pupil's record, how keys are managed, what is written to logs, how backups are tested, how deletion works when a school leaves, or what happens during a security incident. Ask for those answers in writing.
The Information Commissioner's Office (ICO) register: absence can be a compliance failure
Searching the ICO's register of fee payers is not a box-ticking exercise. If the contracting legal entity is a controller processing personal data for a non-exempt purpose, it is required to pay the ICO's data protection fee and keep its registration current. The ICO's education sector fee guidance explains the fee obligation [4], and its penalties guidance states that processing without paying the required or correct fee is breaking the law and can lead to a fixed monetary penalty of up to £4,350, on top of the fee owed [13].
Do not treat an absent entry as a harmless technicality. First match the register search against the exact legal entity and company number. Trading names differ from legal names, a parent or subsidiary may be the actual supplier, and new registrations can take two working days to appear. Once those checks are made, a controller that is required to register but cannot show a current entry or a credible exemption is a procurement red flag, not a neutral finding [4].
Ask which legal entity will contract with the school, its company number and ICO registration reference. Then ask whether it is a controller or processor for each processing activity. A supplier may process pupil records on the school's instructions but act as a controller for its own account, billing, security or product-analytics processing. If it says it is a processor only, ask it to explain that position in writing. If it is a controller and has not paid when required, pause the procurement until the position is corrected and evidenced.
The evidence a real buyer should collect
Ask for documents rather than assurances:
- a data-flow map showing what enters, where it is processed, which components make external calls and what leaves;
- controller and processor roles for each processing activity;
- a Data Protection Act (DPA) covering documented instructions, confidentiality, security, subprocessors, rights requests and deletion or return, as set out in the ICO's controller to processor contract guidance [2];
- named subprocessors, locations, retention periods and deletion terms for records, prompts, outputs, logs and backups;
- a direct answer on model training, zero retention, what is sent to the model and what is stripped first;
- roles, least privilege, multi factor authentication, supplier access and audit logging;
- a usable export and a documented exit process, tested rather than promised.
Those checks cover supplier governance. You should also test how the software fits the daily record workflow, including current versions, review dates, permissions and export. Our guide to SEND management software for UK schools covers those questions.
The ICO's edtech audit findings are useful before writing a Data Protection Impact Assessment (DPIA) [1]. Its data protection by design guidance sets the right expectation: controls should be built into the product [3]. The Department for Education (DfE)'s generative AI guidance also makes clear that staff remain responsible for checking output [12].
Maturity and evidence are different things
Established provision mapping tools can be useful. They centralise records and give leaders visibility across a school or trust. On the EdTech Impact review page, accessed 25 August 2026, reviewers of one established product mention academic-year rollover friction, setup support gaps and continuing manual work. These are self selecting qualitative reviews, not a controlled study, so test the same points in a pilot [9]. Ask every supplier what happens at rollover, during onboarding and when staff still have to write the document themselves.
Built with practitioners, not merely shown to them
MeritDocs consulted data protection officers, SENCO and practising teachers during development, and continues to do so. DPO input shaped the data map, controller and processor explanations, DPIA information, retention and deletion language, logging and the decision to anonymise pupil names before an AI call. SENCO and teacher input shaped document structures, the separation of outcomes and provision, attributable pupil, parent and professional voice, and the choice to show an evidence gap instead of filling it with plausible prose.
That is different from showing two teachers a screen and adding a feature or two. The consultation changed the boundaries of the system and the cases used to test it.
Why synthetic cases
MeritDocs uses fictional and source-based examples that include incomplete or conflicting evidence, so the workflow can make gaps visible for staff review rather than filling them with unsupported certainty.
Where we stand, stated plainly
Applying the same test to ourselves: MeritDocs processes data in the UK and European Union (EU). AI drafting uses zero retention, and pupil data is not used to train models. Pupil names are anonymised before AI calls. Data is encrypted in transit and at rest, access is controlled, actions are recorded in audit logs, documents can be exported and customer data is fully deleted on exit. The school's DPA and DPIA review should still test the exact processing, retention, subprocessor and deletion terms.
The platform runs on Microsoft Azure and AWS. Their data protection terms and privacy commitments form part of the infrastructure contract chain [6][7][8]. They do not replace our DPA, subprocessor schedule, data map or the school's controller responsibilities.
The ten-minute supplier test
Use these five questions on the first serious call:
Which legal entity will contract with us, and is it registered with the ICO? Ask for the company number.
Send me your data-flow map and subprocessor list. A serious supplier should already have them.
What exactly is sent to the AI model, what is stripped first and is it retained? "It is all encrypted" does not answer a retention question.
Show me an export and explain deletion if we leave in March. Export and exit should be demonstrated, not left on a roadmap.
Who supports us in the first week of September, and what happens at academic-year rollover? The answer reveals whether the supplier understands a real school year.
Do not buy the interface or the badge. Buy the evidence: the map, contract, controls, export, exit and an honest account of what still requires professional judgement.
Sources
[1] ICO edtech audit findings.
[1] ICO data protection by design guidance.
[1] ICO education-sector guidance.
[1] National Cyber Security Centre (NCSC) Cyber Essentials overview.
[1] Microsoft AI data privacy guidance.
[1] Microsoft data protection addendum.
[1] AWS EU data protection information.
[1] EdTech Impact provision map listing.
[1] MeritDocs SEND document examples.