Skip to main content

Data Protection Impact Assessment (DPIA)

Systematic assessment of data processing risks and mitigation measures

Document Version: 1.1 | Last Updated: December 2025

This DPIA is reviewed quarterly and updated when significant changes occur to our data processing activities.

1. Project Overview

1.1 Service Description

BundleCreator.co is a legal document management SaaS platform that enables legal professionals to create, organise, and export document bundles structured for UK Family Court Practice Direction 27A.

1.2 Data Controller

Organisation: Steleo Publishing Limited

Address: 167 - 169 Great Portland Street, London W1W 5PJ

DPO Contact: dpo@bundlecreator.co

1.3 Purpose of Processing

  • Provide secure document management services to legal professionals
  • Enable creation of court-ready document bundles
  • Facilitate secure collaboration on legal documents
  • Maintain service security and prevent fraud

2. Data Processing Activities

2.1 Types of Data Processed

Personal Data

  • Name and email address
  • Professional information (firm name, role)
  • Authentication credentials (hashed)
  • Usage logs and access patterns

Sensitive Data (within documents)

  • Court documents containing personal information
  • Legal proceedings information
  • Family law matters
  • Financial information in legal documents

2.2 Data Sources

  • Direct collection: User registration and profile information
  • User uploads: Legal documents uploaded for bundle creation
  • Automatic collection: Usage data, logs, and technical information
  • Third parties: Authentication data from OAuth 2.0 Authentication provider

2.3 Data Recipients

  • Internal: Authorised staff for support and maintenance
  • Sub-processors: Cloud database and storage, Cloud hosting platform, OAuth 2.0 authentication
  • Legal authorities: Only when legally required
  • Users: Bundle recipients as directed by data controller

3. Risk Assessment

3.1 High-Risk Factors

  • Processing sensitive legal documents including family law matters
  • Large-scale processing of personal data
  • Automated decision-making for access controls
  • Processing data of vulnerable individuals (via legal documents)

3.2 Identified Risks

Risk 1: Unauthorized access to sensitive legal documents

Impact: High | Likelihood: Low

Risk 2: Data breach through system vulnerability

Impact: High | Likelihood: Low

Risk 3: Loss of encryption keys

Impact: High | Likelihood: Medium

Risk 4: Accidental deletion due to retention policy

Impact: Medium | Likelihood: Low

4. Risk Mitigation Measures

4.1 Technical Measures

  • AES-256 encryption at rest and TLS 1.3 encryption in transit
  • Multi-factor authentication support
  • Row-level security in database
  • Regular security audits and penetration testing
  • Automated threat detection and response
  • Litigation hold functionality to prevent data loss

4.2 Organisational Measures

  • Staff security training and background checks
  • Strict access controls and principle of least privilege
  • Incident response procedures
  • Regular DPIA reviews and updates
  • Data breach notification procedures
  • Vendor security assessments

4.3 Legal and Compliance Measures

  • Clear privacy policy and terms of service
  • Data processing agreements with all sub-processors
  • Regular compliance audits
  • Legal professional privilege protections
  • UK data residency maintained

5. Data Subject Rights Implementation

BundleCreator.co fully implements all GDPR data subject rights:

Automated Rights

  • Access: Data export functionality
  • Rectification: Edit profile and data
  • Erasure: Account deletion option
  • Portability: JSON/CSV export

Manual Rights

  • Restriction: Via support request
  • Objection: Opt-out mechanisms
  • Automated decisions: Human review
  • Complaints: Clear escalation path

6. Consultation and Review

6.1 Stakeholder Consultation

  • Legal team review for compliance requirements
  • Security team assessment of technical measures
  • User feedback on privacy concerns
  • Sub-processor security assessments

6.2 Review Schedule

  • Quarterly: Risk assessment review
  • Bi-annually: Full DPIA review
  • As needed: When processing changes occur
  • Annually: ICO guidance alignment check

7. Approval and Sign-off

October 28, 2025

Data Protection Inquiries

For questions about this DPIA or our data protection practices:

Email: dpo@bundlecreator.co
Post: Data Protection Officer, Steleo Publishing Limited, 167-169 Great Portland Street, London W1W 5PJ

Document Reference: DPIA-BC-001

Next Review Date: May 2026