ComplyChat Start free

Guide · Data protection

Data protection officer for schools

Every maintained school and academy in England must have a data protection officer (DPO), because Article 37 of the UK GDPR requires any public authority to designate one, and the Department for Education’s guidance says so in terms.

By ComplyChatPublished 14 minute read

A visiting data protection officer in a wool coat crosses the frosty playground of a small rural primary school towards the main door, the headteacher stepping out to meet her, a line of children distant and out of focus behind

The DPO advises and checks; the duty to comply stays with the data controller, which for most school data is the school’s governing body or the academy trust. This guide covers the appointment itself: who the controller is, who can and cannot be the DPO, what the role must be given, and the record that shows the school has done it. For the wider picture of data protection law in a school, read the companion guide to GDPR in schools.

01

The rule: Article 37 of the UK GDPR

Article 37(1)(a) of the UK GDPR requires a controller to designate a data protection officer in any case where “the processing is carried out by a public authority or body, except for courts and tribunals acting in their judicial capacity”. The duty does not depend on the size of the school, the number of pupils or the amount of data: a one-form-entry village primary is caught in exactly the same way as a large secondary.

Whether a school is a public authority is settled by section 7 of the Data Protection Act 2018, which adopts the definition in the Freedom of Information Act 2000. Part IV of Schedule 1 to the Freedom of Information Act 2000 lists “the governing body of” a maintained school or maintained nursery school (paragraph 52) and “the proprietor of an Academy, in respect of information held for the purposes of the proprietor’s functions under Academy arrangements” (paragraph 52A). The Department for Education’s guidance on the role of data protection officers puts the result plainly: “All maintained schools and academies must have a designated data protection officer. A data protection officer can cover more than one school.”

Independent schools that are not academies are not on that list, so the public-authority limb does not reach them. Article 37(1) still requires a DPO where an organisation’s core activities involve regular and systematic monitoring of people on a large scale, or large-scale processing of special category or criminal offence data. The ICO’s guidance on data protection officers says an organisation that decides it does not need one should record that decision “to help demonstrate compliance with the accountability principle”, and that a voluntary DPO carries “the same requirements of the position and tasks” as a mandatory one.

02

Who the data controller is, and whose responsibility data protection is

The DPO is not the controller, and the most common confusion in a school starts there. The controller is the body that decides why and how personal data is processed. The Department for Education’s page on data protection responsibilities in schools says: “For most of the personal data you collect, store and use, the school or the multi-academy trust is the data controller.” In legal terms that is the body the school operates through: the governing body of a maintained school, which is the public authority named in the Freedom of Information Act, and the academy trust for an academy. In a multi-academy trust the trust is a single controller for all its academies, which is why a trust-wide DPO is common.

Responsibility is layered, and the DfE guidance names each layer:

  • Governors and trustees: “The responsibility and accountability for compliance sits with governors and trustees.” They check that the school monitors its data protection performance, supports the data protection officer, has good network security, and “has a business continuity plan in place that includes cyber security”.
  • Senior leaders are accountable for decisions about technology and security, what data is shared and how, the school’s data policies, contracts with processors, getting advice from the DPO, and “making sure staff receive training on data protection every 2 years (we recommend annually as best practice)”.
  • All staff, including catering staff, cleaners, first-aiders, volunteers, governors and trustees, should know what personal data is, what their duties are, and how to recognise and escalate a breach or an information rights request.
  • The DPO advises, monitors and reports, but the ICO is explicit that “the DPO isn’t personally liable for data protection compliance. As the controller or processor it remains your responsibility to comply with the UK GDPR.”

So the short answer to “whose responsibility is data protection within an education setting” is everyone’s for their own handling of data, the governing board’s or trust board’s for compliance, and the DPO’s for advice and oversight. The DfE also notes that as a controller the school “needs to register with the Information Commissioner’s Office”, which in practice means paying the data protection fee in the controller’s own name.

03

Who can be the DPO, and who cannot

Article 37(5) says the DPO “shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39”. No qualification is prescribed. The ICO reads it as “experience and expert knowledge of data protection law”, and says the level of knowledge should be proportionate to the processing, and that “it would be an advantage for your DPO to also have a good knowledge of your industry or sector”. The DfE adds the school-specific list: data protection, UK GDPR, “the way your school operates”, “the technology and systems you use” and cyber security.

Article 37(6) allows the DPO to be “a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract”, and Article 37(3) lets several public authorities share a single DPO, “taking account of their organisational structure and size”. The DfE lists four routes: re-align responsibilities in the current team, share the role between a group of schools, ask for volunteers within the wider school community, or procure a contracted service. Local authority services, trust central teams and specialist providers all supply the role.

The limit is conflict of interest. Article 38(6) allows the DPO to hold other duties only where they “do not result in a conflict of interests”, and the ICO’s explanation is that “the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data”. In most schools that rules out the headteacher, who decides what the school does with data, and often the business manager or IT lead who chooses the systems. The ICO’s contrasting example is that a public authority “could appoint its existing FOI officer / records manager as its DPO”, because those roles ensure compliance rather than decide on processing. The DfE’s word for the requirement is that the DPO “needs to be impartial”.

There is one DPO, though they may lead a team. The ICO says an organisation “must appoint a single DPO to carry out the tasks required in Article 39”, and that other data protection specialists “are not referred to as your DPO”. A school with an external DPO usually also names an in-school data protection lead – often the business manager or office manager – who handles day-to-day requests and is the DPO’s link. That is a sensible arrangement, provided everyone knows which of the two is the DPO.

04

What the role must be given, and what it must do

Article 39(1) sets the minimum tasks: to inform and advise the controller and staff of their obligations; to monitor compliance with data protection law and the school’s own policies, “including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits”; to advise on data protection impact assessments and monitor their performance; to cooperate with the regulator; and to act as its contact point. In a school, the DfE adds the practical version: conducting regular data audits, “developing and updating data protection policies and procedures”, monitoring who has access to personal data, reviewing privacy notices, answering enquiries from staff, parents and pupils, co-ordinating responses to information rights requests, and “reporting to the governing board or trustees about data protection”.

Article 38 sets what the school owes the DPO in return. The DPO must be “involved, properly and in a timely manner, in all issues which relate to the protection of personal data” (38(1)); given the resources, access to personal data and processing operations, and support to maintain their expert knowledge (38(2)); free of instructions about how to do the tasks, protected from dismissal or penalty for doing them, and reporting “directly … to the highest management level of the controller” (38(3)). Data subjects may contact the DPO about any issue relating to their data (38(4)), and the DPO is bound by confidentiality (38(5)).

For a school, the highest management level is the governing board or the trust board. The ICO glosses it as “ie board level”, and adds that this “doesn’t mean the DPO has to be line managed at this level but they must have direct access to give advice to senior managers who are making decisions about personal data processing”. An annual DPO report on the board’s agenda, with the right to raise a matter between meetings, is the usual way to show it.

Two habits make the role real rather than nominal. Ask the DPO before a decision, not after it: a new app, a CCTV camera, a change of management information system or a data sharing request are all “issues which relate to the protection of personal data”. And when the school decides not to follow the DPO’s advice, write down why; the ICO says “you should document your reasons to help demonstrate your accountability”.

Seen from the back of a secondary school drama studio under low house lights, a data protection officer stands to answer a question from governors seated on black staging blocks during an evening board meeting
05

Recording the appointment

The appointment has to be visible, and it leaves a short trail of records that the governing board or trust board should be able to produce:

  1. The board decision. A minute recording who has been designated as DPO, on what basis (employee, shared or contracted), from what date, and the reporting line to the board.
  2. The terms. A job description or service contract that states the Article 39 tasks, the time and resources allotted, the DPO’s independence and access to the board. The ICO says an externally appointed DPO “should have the same position, tasks and duties as an internally-appointed one”.
  3. The published contact details. Article 37(7) requires the controller to “publish the contact details of the data protection officer” and give them to the regulator. The ICO says the DPO’s name need not be published, but the contact details belong in the school’s privacy notices under Articles 13 and 14, and the name must be given when a personal data breach is reported.
  4. The record of processing activities. The ICO lists recording the DPO’s details there among the ways to support the role.
  5. The DPO’s reports and the board’s response, covering audits, training, requests and breaches, and including any advice the school chose not to follow and the reasons.
  6. A review date. Revisit the appointment when the contract ends, when the DPO changes, and when the school changes controller – an academy conversion or a move between trusts makes a different legal body the controller, and the designation, registration and privacy notices need to follow it.

One change of name is recent. On 30 September 2026 the office of the Information Commissioner was abolished and its functions transferred to the Information Commission, under sections 118 and 119 of the Data (Use and Access) Act 2025 as commenced by the Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026; Article 37(7) now reads “communicate them to the Commission”. The regulator’s guidance is still published at ico.org.uk, and anything already done with the Commissioner is treated as done with the Commission. The Act is amending UK GDPR and the Data Protection Act 2018 in stages, so check the date on any ICO page you rely on.

06

The advice the DPO never sees

Article 38(1) asks for the DPO to be involved “in all issues which relate to the protection of personal data”. In most schools, the issues arrive in messages. The deputy head asks in the senior leaders’ group chat whether anyone minds if Year 6 start using a free quiz app on Monday. The office manager tells the business manager by text on a Saturday that a parent has emailed asking for everything the school holds about her son. A teacher posts a photograph of a seating plan with pupils’ medical notes on it into the year team’s chat to save time. A governor forwards a parent’s complaint, with the child’s name in it, to the chair’s personal number.

Each of those is the moment the DPO should have been asked, and each is a record of how the school processed personal data. A new app adopted in a chat thread has no impact assessment; a subject access request that began as a text has a one-month clock that started on Saturday; the seating plan is personal data, some of it about health, now held on a dozen phones the school does not control. When the DPO later monitors compliance, audits access or co-ordinates the response to that request, the conversations that recorded the decisions are not anywhere the school can search or retain, and they will not be in the next annual report because nobody can see them.

None of this is staff being careless; it is how busy people communicate. But a DPO can only advise on what reaches them and monitor what the school can find. The question for the next governing board or trust board meeting is a narrow one: if the DPO were asked to list where staff discuss pupils’ personal data, would the list include the staff group chats, and could the school produce what is in them?

07

Questions people ask

Do schools need a data protection officer?

Yes: every maintained school and academy in England must have a data protection officer, because they are public authorities and Article 37(1)(a) of the UK GDPR requires every public authority to designate one. The Department for Education’s guidance says “All maintained schools and academies must have a designated data protection officer”, and one DPO can cover more than one school.

Who is the data controller in a school?

For most of a school’s personal data, the data controller is the legal body that runs it: the governing body of a maintained school, or the academy trust for an academy. The Department for Education’s guidance says that “for most of the personal data you collect, store and use, the school or the multi-academy trust is the data controller”, and that responsibility and accountability for compliance sit with governors and trustees. The DPO advises the controller but is not the controller.

Who in an education setting is responsible for protecting personal data?

Data protection in an education setting is everyone’s responsibility for their own handling of personal data, with accountability for compliance resting on the governing board or trust board. The Department for Education’s guidance divides it between governors and trustees, senior leaders, all staff, and the data protection officer, who advises and monitors but, in the ICO’s words, “isn’t personally liable for data protection compliance”.

What qualifications do I need to be a data protection officer?

No specific qualification is required to be a data protection officer: Article 37(5) of the UK GDPR requires “professional qualities and, in particular, expert knowledge of data protection law and practices”. The ICO says the law “doesn’t specify the precise credentials” and that the knowledge expected should be proportionate to the processing; for schools, the DfE adds knowledge of how the school operates, its technology and systems, and cyber security.

Is a DPO role full time?

A DPO role does not have to be full time. Article 38(6) of the UK GDPR allows the DPO to “fulfil other tasks and duties” if they cause no conflict of interests, and Article 37(6) allows the role to be done under a service contract, so many schools share a part-time or contracted DPO. Article 38(2) still requires the school to provide the resources the tasks need, and the ICO lists “sufficient time” among them.

Can the headteacher be the data protection officer?

Usually not, because the headteacher decides how the school uses personal data, and the ICO says the DPO “cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data”. Article 38(6) of the UK GDPR allows the DPO other duties only where they do not result in a conflict of interests.

08

Official guidance and your next step

The law is in Articles 37, 38 and 39 of the UK GDPR. The ICO’s guidance on data protection officers includes checklists for appointing a DPO, the DPO’s position and their tasks. The Department for Education’s data protection in schools guidance covers responsibilities and the role of data protection officers; the wider duties are in the GDPR in schools guide.

This guide summarises published law and guidance for schools in England and is not legal advice; a school with an unusual structure, such as a federation or a school changing trust, should take advice on who its controller is.

Then do one thing: find the minute that appointed your DPO. If it does not exist, or names someone who has since left, put the designation on the next board agenda with the DPO’s terms and reporting line attached.

Why we publish this

We build ComplyChat for the work conversations schools need to keep, and a DPO can only oversee the processing a school can find. ComplyChat is not a DPO service and does not do the DPO’s job. It gives staff a channel the school runs, where everyone added is told the conversation is on the record and messages are recorded on the server as they are sent; on paid plans, once the school’s Microsoft 365 tenant is connected, the lasting record files there under the school’s own retention rules, where the DPO can search it.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Article 37(1)(a) of the UK GDPR legislation.gov.uk
  2. Section 7 of the Data Protection Act 2018 legislation.gov.uk
  3. Part IV of Schedule 1 to the Freedom of Information Act 2000 legislation.gov.uk
  4. Role of data protection officers gov.uk
  5. Data protection officers ico.org.uk
  6. Data protection responsibilities in schools gov.uk
  7. Article 38(6) legislation.gov.uk
  8. Article 39(1) legislation.gov.uk
  9. The Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026 legislation.gov.uk
  10. Data protection in schools gov.uk