In practice that means paying the ICO's data protection fee unless exempt, telling parents and staff what is collected and why, choosing a lawful basis for each use, handling photographs and parents' requests properly, and reporting to the ICO within 72 hours any data breach likely to result in a risk to people. A childminder working alone at home carries the same core duties as a nursery group with forty staff. Which records to keep is a separate question, covered in the record-keeping guides.
The rule: UK GDPR, the Data Protection Act 2018 and the EYFS
There is no separate GDPR for nurseries: a nursery, pre-school or childminder that holds personal information about children, parents or staff is a data controller under the UK GDPR and the Data Protection Act 2018, and the ICO is the regulator. The controller is whoever decides why and how the information is used: the company, charity or committee that is registered with Ofsted for a nursery, and the childminder personally for a childminding business.
The early years frameworks write that duty into Ofsted registration. Paragraph 3.96 of the EYFS statutory framework for group and school-based providers (in force from September 2026) says: “Confidential information and records about staff and children must be held securely and only accessible and available to those who have a right or professional need to see them. Providers must be aware of their responsibilities under the Data Protection legislation and, where relevant, the Freedom of Information Act 2000.” Paragraph 3.97 adds that providers “must ensure that all staff understand the need to protect the privacy of the children in their care”, and that parents “must be given access to all records about their child, provided that no relevant exemptions apply to their disclosure under the Data Protection Act”. The framework for childminders says the same at paragraphs 3.95 and 3.96, with “they and any assistants” in place of staff.
The law itself rests on the seven principles in Article 5 of the UK GDPR: personal data must be processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes; limited to what is necessary; kept accurate; kept no longer than necessary; and kept secure – and the controller must be able to show it has done all of that (accountability). The Data (Use and Access) Act 2025 has amended both the UK GDPR and the 2018 Act, and the ICO's guidance on what the DUAA means for organisations was updated on 19 June 2026 “to reflect that all data protection provisions in the Data (Use and Access) Act 2025 are now in force”. Several ICO pages are still marked as under review, so check the date on any ICO page before relying on it.
What a nursery or childminder must have in place
The personal data an early years provider holds is unusually sensitive for a small organisation: children's names, dates of birth and addresses, who has parental responsibility and who must not collect, health conditions and allergies, medicines given, accidents and injuries, special educational needs, observations and photographs in the learning journal, safeguarding concerns, and parents' bank details for fees and funding. For staff it adds the details of DBS checks, references, qualifications and sickness records. The duties that follow from holding it are:
- The ICO data protection fee. Under the Data Protection (Charges and Information) Regulations 2018, organisations, “including sole traders”, that use personal information must pay the ICO a fee unless exempt. The ICO's guide to the data protection fee sets three tiers: £52 for tier 1 (a maximum turnover of £632,000 or no more than 10 members of staff), £78 for tier 2 and £3,763 for tier 3, with charities paying the tier 1 fee. The exemptions cover purposes such as staff administration and “processing personal information without an automated system such as a computer”; a childminder who keeps children's details on a phone, a laptop or a learning journal app is not processing without a computer. The ICO says the maximum penalty for not paying is a £4,350 fine.
- A privacy notice for parents and one for staff. The right to be informed means telling people, when the information is collected, who the controller is, what is collected, why, on what lawful basis, who it is shared with (the local authority for funding, Ofsted, health visitors, the next school) and how long it is kept. The ICO's guide to using children's information adds that information for children must be given “in a concise, clear and plain style, using language that is easy for them to understand”.
- A data protection officer only where the law requires one. The UK GDPR requires a DPO for a public authority and for organisations whose core activities involve large-scale monitoring or large-scale processing of special category data. The governing body of “a maintained nursery school” is a public authority under Schedule 1 to the Freedom of Information Act 2000, as is the governing body of a maintained school with a nursery class. Section 7 of the Data Protection Act 2018 makes those bodies public authorities for the UK GDPR when they perform a task in the public interest, so both need one. Most private, voluntary and independent nurseries and childminders will not, and the ICO suggests recording that decision; they still need a named person who owns data protection.
- Written contracts with processors. The learning journal app, the nursery management system, the payroll bureau and the cloud storage provider all process children's or staff data on the provider's behalf, and Article 28 of the UK GDPR requires a written contract with each. The provider remains the controller and remains accountable for them.
- Security that fits the data. Locked storage for paper, backups, passwords and two-step sign-in for devices, and an end to shared logins are the basics; paragraph 3.96's footnote points providers to the National Cyber Security Centre.
- A way to handle data protection complaints. Since the Data (Use and Access) Act's provisions came into force, the ICO says every organisation must take steps to help people make complaints about how their information is used, “acknowledge complaints within 30 days and respond to them ‘without undue delay’”. A line in the existing complaints procedure, and a named person, meet it for most settings.
Lawful basis, safeguarding information and photographs
Every use of personal data needs one of the lawful bases in Article 6 of the UK GDPR, and the most common mistake in early years is relying on consent for everything. The records the EYFS requires (the child's details and emergency contacts, the attendance register, the medicines and accident records, the staff suitability checks) are kept because the framework says they must be, so legal obligation is the natural basis; the contract with parents covers fees and invoicing. The ICO notes that consent is one option, but “others may be more appropriate and provide stronger protection for the child”. Consent that the setting would ignore if a parent said no was never consent.
Health, ethnicity and religion are special category data, which need an Article 6 basis and an additional condition. Safeguarding information is where providers hesitate most, and the law is clearer than the hesitation. Paragraph 18 of Schedule 1 to the Data Protection Act 2018 is a condition for processing that is necessary for “protecting an individual from neglect or physical, mental or emotional harm” where the individual is “aged under 18”, without consent in the circumstances it lists. Since the 2025 Act there is also a recognised legitimate interest basis for safeguarding: the ICO's guidance on the safeguarding condition quotes Annex 1 – “the processing is necessary for the purposes of safeguarding a vulnerable individual” – and says “all children and young people under the age of 18 are regarded in this context as ‘vulnerable’”. The Department for Education's information sharing guidance, updated in September 2026, puts it plainly: “Data protection obligations apply and must be complied with – this does not prevent personal information being shared to safeguard and promote the welfare of children.” It names recognised legitimate interests or legitimate interests as bases that “may be appropriate for voluntary and private organisations”.
Photographs are personal data, and the EYFS requires every safeguarding policy to cover “how mobile phones, cameras and other electronic devices with imaging and sharing capabilities are used in the setting” (paragraph 3.6, or 3.7 for childminders). Separate the purposes: observation photographs in the learning journal, which support the EYFS and go only to that child's parents; photographs for the website, a prospectus or social media, which are optional and are where consent belongs; and group photographs that show other people's children. The ICO's page on taking photos in schools, which it marks as under review, says data protection law “doesn't apply to the use of personal data for ‘purely personal or household activity’”, so a parent filming the nativity for the family is outside it, though the setting may still have a safeguarding rule about it; posting to a public account “is likely to go beyond personal use”. Staff photographs of children on personal phones put the setting's data on devices it does not control; the mobile-phone policy should rule them out.
Parents' requests and the child's own rights
A parent asking for “everything you have on my son” is making a subject access request, whatever words they use. The ICO's guidance on recognising a subject access request says “a person can make a SAR verbally or in writing, including by social media” and can make it “to any part of your organisation”, so a request made at the door to a key person starts the clock. The response is due “without undue delay and at the latest within one month of receipt”, extendable by two months for a complex request, under the ICO's guidance on responding to a request, and normally without a fee.
The right belongs to the child, not the parent. The ICO says “the right to access information you hold about a child is the child's right rather than anyone else's”, even when the child is too young to understand it and the request comes from someone with parental responsibility. For a child under five, the parent will usually exercise it, but the provider should still check that the person holds parental responsibility and consider whether disclosure is in the child's best interests – which matters when parents are separated, when a court order limits contact, or when there are safeguarding concerns. The EYFS footnote to paragraph 3.97 makes the same point: a professional “will need to give careful consideration as to whether the disclosure of certain information about a child could cause harm either to the child or any other individual”. Information about other people – another child in the incident record, a member of staff who raised a concern – may need to be withheld or redacted.
Parents and staff, as data subjects, also have rights to rectification, to restrict processing, to object and, for information given on the basis of consent or contract, to data portability. Two come up most. A parent may ask for a photograph or an observation to be deleted; where it was taken on the basis of consent, the right to erasure usually applies, but the EYFS records the setting must retain are not deleted on request. And staff have the same rights: a practitioner in a dispute can ask for every record that mentions them, including emails and messages about them, which is where an unmanaged message history becomes a disclosure problem.

A nursery data breach: 72 hours, and the log of every one
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data – not only a cyber attack. In a nursery it is usually smaller: an invoice emailed to the wrong parent, a photograph posted into another family's learning journal, an allergy list left behind after an outing, a lost staff phone with children's photographs on it, a former employee whose app login still works. For a childminder, it is often a family member using the same tablet. Criminals are part of the picture too: the National Cyber Security Centre's guidance for early years practitioners warns that “regardless of the size and nature of your setting, the information that you hold is of value to a criminal”, and that a virus could “damage, delete, or lock your data until a ransom is paid”. A ransomware attack on a nursery software supplier is still a breach the nursery must assess, because the nursery is the controller.
Under Article 33 of the UK GDPR, a breach that is likely to result in a risk to people's rights and freedoms must be reported to the ICO “without undue delay, but not later than 72 hours after becoming aware of it”, in the words of the ICO's guide to personal data breaches. If full details are not yet known, report within the 72 hours and add the rest later. Where the risk is high – a safeguarding record seen by the wrong family, a child's address disclosed to a parent barred from contact – the people affected must also be told directly and without undue delay under Article 34 of the UK GDPR. The ICO's personal data breach reporting page has a self-assessment tool for deciding whether a report is needed, and a guide for small organisations to the first 72 hours.
Every breach goes in the breach log, reported or not. The ICO's guide says “you must also keep a record of any personal data breaches, regardless of whether you are required to notify”, and Article 33(5) requires the facts, the effects and the remedial action to be documented. Some breaches are also an Ofsted matter: Ofsted's guidance on significant events lists “a device containing children's information being stolen” as an example of an event to notify, within 14 days. One incident can therefore need an ICO decision within 72 hours, an Ofsted notification within 14 days, a call to the family, and an entry in the log – and the first of those clocks starts when the setting becomes aware, which is usually the moment a member of staff mentions it to someone.
The personal data that lives in staff messages
Everything above assumes the setting knows where its personal data is. The part it cannot see is the conversation: the staff group chat where the deputy asks who has the allergy list for the trip; the message to the manager at 9pm saying a child arrived with a bruise and the parent's explanation did not fit; the photograph of a rash sent from a practitioner's phone to the manager's phone for advice; the parent who texts the key person's personal number about a custody arrangement.
Every one of those is personal data about a child, much of it special category, and the setting is the controller for it. It is also the first version of records the EYFS requires, and the first evidence of when the setting became aware of something – the clock that matters for a breach report, a significant-event notification or an allegation. It sits on phones the setting does not own, visible to everyone in the group including people who have since left. A subject access request from a separated parent or a member of staff can reach it; the setting cannot search it, show who saw it, or delete it when its retention period ends.
The answer is not to stop staff talking to each other; a childcare setting depends on it. It is to agree an approved route for work conversations about children that follows the mobile-phone policy, that the setting controls, where everyone in the conversation knows it is kept, and where a concern raised in a message is still passed straight into the safeguarding procedure. The question for the next owners' or committee meeting is a simple one: if a parent asked tomorrow for every message staff have exchanged about their child, could the setting find them all?
Questions people ask
What is GDPR in a nursery?
GDPR in a nursery means the UK General Data Protection Regulation and the Data Protection Act 2018 applied to the personal information a nursery holds about children, parents and staff: the nursery is the data controller, needs a lawful basis for each use, a privacy notice, secure storage and a retention schedule, and must answer requests and report breaches likely to result in a risk to people. The EYFS adds that providers “must be aware of their responsibilities under the Data Protection legislation” (paragraph 3.96 of the group and school-based framework).
Does GDPR apply to childminders?
Yes. A registered childminder is a data controller for the children's and parents' information they hold, and the ICO says organisations “including sole traders” that use personal information must pay the data protection fee unless exempt. Paragraph 3.95 of the EYFS framework for childminders says childminders “must be aware of their responsibilities under the Data Protection legislation”, and paragraph 3.96 requires them and any assistants to protect children's privacy.
What are the 7 GDPR requirements?
The seven requirements are the principles in Article 5 of the UK GDPR, which the ICO's guide to the data protection principles lists as lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability.
Does GDPR apply to safeguarding?
Yes, but it does not stop a nursery sharing information to protect a child. The Department for Education's information sharing guidance says data protection obligations “must be complied with – this does not prevent personal information being shared to safeguard and promote the welfare of children”, and the Data Protection Act 2018 and the UK GDPR's recognised legitimate interest for safeguarding both provide a lawful route without consent where the conditions are met.
Does GDPR apply to kids?
Yes. The ICO says “children have the same data protection rights as adults over their personal information” and “merit specific protection” because they may be less aware of the risks. For a young child, a person with parental responsibility usually exercises those rights on the child's behalf, but the rights remain the child's.
What is the minimum age to consent under GDPR?
In the UK the age is 13, and it applies only to online services offered directly to children: the ICO says that where an information society service relies on consent, “only users aged 13 and over can give their own consent” and under-13s need consent from a person with parental responsibility. It is not a general age of consent for a nursery's records, which rarely rely on consent at all.
Official guidance and your next step
Read the ICO's UK GDPR guidance and resources, starting with its guide to using children's information (updated 15 May 2026 for the 2025 Act), its right of access guidance and its personal data breach guide; section 3 of the EYFS statutory frameworks for the record-keeping and confidentiality requirements; and the Department for Education's information sharing guidance for safeguarding. The ICO also publishes a self-assessment for the data protection fee.
This guide summarises published guidance for England. It is not legal advice, and a contested request, a serious breach or a safeguarding disclosure decision deserves advice on its own facts.
Then do one thing this week: write down every place children's personal data is held in your setting – systems, paper, apps, and phones – and next to each, who can see it. The lines with no clear answer are your data protection plan.
We build ComplyChat for the work conversations organisations need to keep, and in early years those conversations are full of personal data about children. It is not a nursery management system or a learning journal; those stay in your early years software. On paid plans, staff messages about children sit in a channel the setting controls, everyone in it is told it is on the record, and once the setting's Microsoft 365 tenant is connected the lasting record files there under its own retention rules.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Data Protection Act 2018 legislation.gov.uk
- EYFS statutory framework for group and school-based providers gov.uk
- Article 5 of the UK GDPR legislation.gov.uk
- Data (Use and Access) Act 2025 legislation.gov.uk
- Guidance on what the DUAA means for organisations ico.org.uk
- ICO's guide to the data protection fee ico.org.uk
- Exemptions ico.org.uk
- Using children's information ico.org.uk
- Schedule 1 to the Freedom of Information Act 2000 legislation.gov.uk
- Data Protection Act 2018 legislation.gov.uk
- Article 28 of the UK GDPR legislation.gov.uk
- Article 6 of the UK GDPR legislation.gov.uk
- Schedule 1 to the Data Protection Act 2018 legislation.gov.uk
- Guidance on the safeguarding condition ico.org.uk
- Information sharing guidance gov.uk
- Taking photos in schools ico.org.uk
- Recognising a subject access request ico.org.uk
- Responding to a request ico.org.uk
- Guidance for early years practitioners ncsc.gov.uk
- Article 33 of the UK GDPR legislation.gov.uk
- Guide to personal data breaches ico.org.uk
- Article 34 of the UK GDPR legislation.gov.uk
- Personal data breach reporting page ico.org.uk
- Guidance on significant events gov.uk
- Guide to the data protection principles ico.org.uk
- UK GDPR guidance and resources ico.org.uk




