FOI release

Digital Systems Processing Children's Data

This request was refused in part, so we didn't provide some of the information the requester asked for. This may include information where we can neither confirm nor deny that we hold it.

Case reference FOI2026/01638

Received 12 July 2026

Published 10 August 2026

Request

I am requesting the following information under the Freedom of Information Act 2000. Where a question concerns a data protection document, I also ask that you treat it as a request to confirm the existence and status of that document. If any part is refused, please cite the specific exemption and provide the public-interest reasoning.

A. Systems and Suppliers

1) Please list every third-party digital system the authority uses to process the personal data of looked-after children and/or children with Education, Health and Care Plans (for example ePEP Online, EHCP Online, or equivalent), naming the supplier and the start date of each contract, including any predecessor contracts before the current one.

2) Please state the procurement route used for each system (for example the Crown Commercial Service G-Cloud framework), and describe the due diligence carried out on the supplier's security claims at procurement.

3) For each supplier, please provide the security accreditations the authority relied upon (for example UKAS-accredited ISO/IEC 27001, Cyber Essentials Plus, NHS Data Security and Protection Toolkit), and describe how those accreditations were verified.

4) Please provide the total sums paid to each supplier in each financial year since the first contract.

B. Data Protection Governance

1) For each system, please provide the Data Protection Impact Assessment (DPIA) and the date it was completed and last reviewed. If no DPIA exists, please confirm this.

2) Please state the lawful basis under Article 6 UK GDPR, and the condition under Article 9 for processing special-category data, relied upon for each system.

3) Please provide the privacy / fair-processing information (Articles 13–14) given to children, parents and carers that names these systems and suppliers, and state when it was last updated.

4) Please confirm whether any independent penetration testing or security audit of each system has been carried out, and provide the dates.

5) Please provide records of any personal-data breach, complaint or safeguarding concern relating to each system.

6) Please state whether any child-facing communication feature within a system (for example a chat or messaging module) exists, and if so whether and how it is monitored.

C. AI and Automated Processing

1) Please list any artificial intelligence, machine learning or large language model tools used in children's services, adult social care, or in the processing of residents' data, naming the tool and supplier.

2) For each such tool, please provide the DPIA and state whether an Article 22 (automated decision-making) assessment was carried out, and what human-review safeguards apply.

3) Please state whether any personal data is transferred to, or accessible by, the supplier of any AI tool, and whether any data is transferred outside the UK.

D. Reorganisation, Integration and Accountability

1) Please confirm whether any children's services data systems are being merged or integrated as part of local government reorganisation, devolution, or any 'single view of the child' / data-sharing programme, and whether a DPIA and a Best Value assessment have been completed for that integration.

2) Please state which body the authority considers responsible for assuring the security and compliance of third-party systems processing children's data.

3) Please provide any data-sharing agreement between the authority and an Integrated Care Board (ICB) or other partner concerning children's data.

Response

I am requesting the following information under the Freedom of Information Act 2000. Where a question concerns a data protection document, I also ask that you treat it as a request to confirm the existence and status of that document. If any part is refused, please cite the specific exemption and provide the public-interest reasoning.

A. Systems and Suppliers

1) Please list every third-party digital system the authority uses to process the personal data of looked-after children and/or children with Education, Health and Care Plans (for example ePEP Online, EHCP Online, or equivalent), naming the supplier and the start date of each contract, including any predecessor contracts before the current one.

Answer: The details of projects funded by Herefordshire Council is publically available on our council website and can be viewed via the following link:

 

https://www.herefordshire.gov.uk/your-council/our-open-data/council-contracts-register-and-future-opportunities/ 

 

The register includes contract name; brief description; supplier; contract start date; estimated annual value and tender process.

 

Please see the following Contract IDs:

 

o   000511

o   000537

o   106715

o   106827

 

As such we consider this information to be exempt under Section 21 of the Freedom of Information Act 2000 because it is reasonably accessible to you via other means. Please take this letter as a refusal notice under S17 of the Act.

 

The Service Area have advised the following is also used:

WhatsApp – Used by Independent Reviewing Officers to speak with children and young people directly.  This is deployed on mobile devices.

Microsoft Forms – Used by children and young people to provide feedback after reviews/events etc.  This is available as part of our M365 package so no additional charge.

 


2) Please state the procurement route used for each system (for example the Crown Commercial Service G-Cloud framework), and describe the due diligence carried out on the supplier's security claims at procurement.

Answer: Please see the Contracts Register link provided above for the procurement route.

The Service Area have advised, during the process, the supplier is required to complete a Supplier Security Assessment which must be completed and approved by our Information Security Team.

 


3) For each supplier, please provide the security accreditations the authority relied upon (for example UKAS-accredited ISO/IEC 27001, Cyber Essentials Plus, NHS Data Security and Protection Toolkit), and describe how those accreditations were verified.

Answer: Please see the table below:

 

 

Welfare Call

Synergy

Mosaic

Beam Notes

ISO27001

Yes

Yes

Yes

Yes

Cyber Essentials or CE Plus

Yes

Yes

Yes

Yes

 

The Service Area have advised evidence of accreditation is provided during the tender process.

 


4) Please provide the total sums paid to each supplier in each financial year since the first contract.

 

Answer: This information is publically available on our council website and can be viewed via the following links:

 

Contracts Register: https://www.herefordshire.gov.uk/your-council/our-open-data/council-contracts-register-and-future-opportunities/  

 

Record of Officer Decisions: https://councillors.herefordshire.gov.uk/mgListOfficerDecisions.aspx?bcr=1

 

As such we consider this information to be exempt under Section 21 of the Freedom of Information Act 2000 because it is reasonably accessible to you via other means. Please take this letter as a refusal notice under S17 of the Act.

 


B. Data Protection Governance

1) For each system, please provide the Data Protection Impact Assessment (DPIA) and the date it was completed and last reviewed. If no DPIA exists, please confirm this.

Answer: Please see the table below:

 

 

Welfare Call

Synergy

Mosaic

Beam Notes

WhatsApp

Microsoft Forms

DPIA completed

9/9/2025

N/A

N/A

23/12/2025

N/A

N/A

No DPIA exists

N/A

No DPIA held

No DPIA held

N/A

No DPIA held

No DPIA held

UK GDPR Art 6

Legal obligation & public task

Legal obligation & public task

Public task

Public task

Legal obligation

Legal obligation

UK GDPR Art 9

Health or social care

 

Health or social care

Health or social care

 

 

 


2) Please state the lawful basis under Article 6 UK GDPR, and the condition under Article 9 for processing special-category data, relied upon for each system.

Answer: Please see the table above.

 


3) Please provide the privacy / fair-processing information (Articles 13–14) given to children, parents and carers that names these systems and suppliers, and state when it was last updated.

Answer: This information is publically available on our council website and can be viewed via the following links:

 

Privacy Notices:  https://www.herefordshire.gov.uk/info/200148/your_council/15/access_to_information/9

 

Further details regarding data handling:

https://www.herefordshire.gov.uk/your-council/access-to-information/freedom-of-information-foi-and-environmental-information-regulation-eir/

 

As such we consider this information to be exempt under Section 21 of the Freedom of Information Act 2000 because it is reasonably accessible to you via other means. Please take this letter as a refusal notice under S17 of the Act.

 


4) Please confirm whether any independent penetration testing or security audit of each system has been carried out, and provide the dates.

Answer: The Service Area have advised an independent penetration test was carried out on 5th May 2026 and is updated annually.

 


5) Please provide records of any personal-data breach, complaint or safeguarding concern relating to each system.

Answer: The Service Area have advised there are none, specific to this software.

 


6) Please state whether any child-facing communication feature within a system (for example a chat or messaging module) exists, and if so whether and how it is monitored.

Answer: The Service Area have advised WhatsApp is used as the preferred method of communication with children and young people.  It is used to keep in contact and plan to meet etc. 

Microsoft Forms is used to ask for feedback following review meetings.

The local authority has a legal obligation to communicate effectively with children and young people and to gather their views.  They may choose to respond by another method.

 


C. AI and Automated Processing

1) Please list any artificial intelligence, machine learning or large language model tools used in children's services, adult social care, or in the processing of residents' data, naming the tool and supplier.

Answer: The Service Area have advised Microsoft CoPilot is the main AI product in use by Children’s Services.  Magic Notes (Beam) is only used for producing the notes of some meetings.  No other AI products have been approved for use at this time.

 


2) For each such tool, please provide the DPIA and state whether an Article 22 (automated decision-making) assessment was carried out, and what human-review safeguards apply.

Answer: The Service Area have advised none of these products make automated decisions. 

 


3) Please state whether any personal data is transferred to, or accessible by, the supplier of any AI tool, and whether any data is transferred outside the UK.

Answer: The Service Area have advised Magic Notes (Beam) is an AI product.  No data is transferred outside the UK, for any of these products.

 


D. Reorganisation, Integration and Accountability

1) Please confirm whether any children's services data systems are being merged or integrated as part of local government reorganisation, devolution, or any 'single view of the child' / data-sharing programme, and whether a DPIA and a Best Value assessment have been completed for that integration.

Answer: The Service Area have advised there are no plans at present.

 


2) Please state which body the authority considers responsible for assuring the security and compliance of third-party systems processing children's data.

Answer: The Service Area have advised details are set out in the DPIA.

 


3) Please provide any data-sharing agreement between the authority and an Integrated Care Board (ICB) or other partner concerning children's data.

Answer: The Service Area have advised there is an overarching agreement and there may be separate agreements for specific sharing.

 

Documents

There are no documents for this release.

This is Herefordshire Council's response to a freedom of information (FOI) or environmental information regulations (EIR) request.

You can browse our other responses or make a new FOI request.