Back to all articles
Building a Practical Software and SaaS Register (That Actually Gets Used)
EdTech
6 August 20267 min read

Building a Practical Software and SaaS Register (That Actually Gets Used)

aS

asitplan Strategy Team

Author

RL

Rob Lloyd

Technical Reviewer

06 August 2026

Last Reviewed

DPOs, IT managers, and curriculum leads

Target Audience

The Context

Teachers are constantly looking for innovative ways to engage students, often signing up for free educational web apps (SaaS) using their school email addresses. This well-intentioned behavior creates "Shadow IT"—a sprawling ecosystem of undocumented software processing student data outside the view or control of the IT and safeguarding teams.

Who This Guide is For

Data Protection Officers (DPOs), IT managers, and curriculum leads.

Why This Matters

When a school does not know what software its staff and students are using, it cannot ensure compliance with data protection laws (like GDPR/UK GDPR). If a free spelling app suffers a data breach and exposes student names, the school is liable. Furthermore, schools often pay multiple subscriptions for different apps that perform the exact same function.

What Good Looks Like

A central, visible Software and SaaS Register that documents every approved application, what data it processes, who owns it, and when the contract renews. Crucially, the process for requesting new software is streamlined so staff actually use it rather than bypassing the rules.

Approach and Methodology

  1. Discover the Shadow IT: You cannot manage what you cannot see. Use firewall logs, web filtering reports, or integration with Google Workspace/Microsoft 365 to see which third-party apps staff are authenticating into.
  2. Establish the Baseline: Build the initial register. For each app, record: Name, Purpose, Data Processed (e.g., student names, grades), Business Owner (the teacher who requested it), and Renewal Date.
  3. Data Protection Impact Assessment (DPIA): For any app processing sensitive student data, ensure a DPIA has been completed and the vendor has a signed Data Processing Agreement (DPA).
  4. Consolidate and Cull: Identify overlapping tools. If the math department uses App A and the science department uses App B for the same purpose, standardize on one to save money and reduce risk.
  5. Streamline the Request Process: Create a simple, fast form for teachers to request new software. If the approval process takes 6 weeks, teachers will bypass it. Aim for a 48-hour turnaround for low-risk apps.
  6. Publish the Approved List: Make the register visible to all staff so they know what tools are already available and approved for use.

Evidence to Retain

  • A maintained, accessible Software and SaaS Register.
  • Completed DPIAs and signed DPAs for high-risk applications.
  • A documented, accessible software request procedure for staff.

Questions Leadership Should Ask

  • "How many different applications are currently processing our students' personal data, and have they all been vetted?"
  • "Do we have a process to revoke access to these third-party apps when a staff member leaves the school?"

Common Pitfalls

  • The Spreadsheet Illusion: Creating a register in an Excel file that is never updated after the initial audit.
  • The "Departmental Credit Card": Allowing heads of department to purchase software subscriptions on a credit card without running them past IT or the DPO.
  • Ignoring Free Apps: Assuming that because an app is free, it doesn't need to be vetted. Free apps often monetize by selling the user data they collect.

How asitplan Can Help

asitplan provides a dedicated module to manage your software inventory alongside your hardware. By tracking application ownership, compliance status, and renewal dates in one unified platform, schools can eliminate Shadow IT and regain control over their data privacy.

Ready to simplify your school's IT compliance?

asitplan provides the unified dashboard and automated reporting you need to stay ahead of DfE standards and KCSIE updates.