Guide · Schools

GDPR in schools.

Schools handle more personal data, about more vulnerable people, than almost any organisation of comparable size, and they do it with almost no specialist staff. This is a plain summary of what the UK data protection regime requires of a school, which parts most often go wrong, and the category of personal data that schools process constantly without ever being able to find it.

01

Which law applies, and what it asks of a school

There is no separate GDPR for schools. The regime is the UK General Data Protection Regulation and the Data Protection Act 2018, and schools comply with GDPR on the same terms as any other organisation. What differs is the context: schools collect and process personal data about children, hold a great deal of special category and sensitive personal data, and share it across the school community with parents, local authorities, health services and a long list of suppliers.

The school is the data controller for the personal data it holds about pupils, staff, governors and parents. That means it decides why and how the data is processed, and it carries the obligations under data protection legislation, including the duty to demonstrate compliance rather than simply to achieve it.

How schools handle personal data is governed by the same six principles as everyone else, and they drive nearly every practical question. Personal information must be processed lawfully, fairly and transparently; collected for specified purposes; limited to what is necessary; kept accurate; kept no longer than necessary; and kept secure. A seventh requirement, accountability, is the one that turns those into paperwork: the school must be able to show its reasoning, not merely assert it.

Accountability is discharged through documents, and schools need a small standard set rather than a large one. A published privacy notice for pupils and parents, and a second for staff and governors, saying which types of personal data are collected, why, on what lawful basis, who it is shared with and how long it is kept. A data protection policy, sitting above the school's other policies and procedures. A record of processing activities. A data retention schedule. A breach log. Training records showing that staff were told how to protect personal data and when.

Those data protection policies are also the things an inspector or the ICO asks for first, because they are how a school shows it thought about the question before it was asked rather than afterwards.

The Department for Education publishes a data protection toolkit for schools, which is the most practical starting point for a school building its data protection compliance from scratch, and the ICO's education material is the authority on contested points. Certain types of processing have their own rules on top, and those are covered below. One caution about older documents: the regime has been amended more than once since it was new legislation in 2018, so work from current ICO guidance rather than from a policy written in the first year and reviewed by copying its date forward.

02

The data protection officer schools must appoint

Because a school is a public authority, UK GDPR requires it to appoint a data protection officer. This is not optional and does not depend on size: maintained schools, academies and trusts all fall within it, which answers the question small schools most often ask.

The DPO must have expert knowledge of data protection law and practice proportionate to the processing the school carries out, must report to the highest management level, and must be able to act independently. They cannot be instructed how to do the role, and they cannot hold another post that would let them decide the purposes of processing, which rules out the head teacher and usually the business manager.

A trust may appoint one designated data protection officer across all its schools, and small schools commonly buy the role in from the local authority or a specialist provider. Both work. What does not work is naming someone to satisfy the requirement and never involving them, because the DPO's tasks are specific: monitoring compliance, advising on data protection impact assessments, training staff, and acting as the contact point for the ICO and for data subjects.

Give the DPO the retention schedule, the record of processing activities and the breach log, and require an annual report to the governing body. A DPO with no route to the board cannot do the part of the role the regulation actually requires.

03

Lawful basis, special category data and biometrics

Every use of personal data needs a lawful basis, and schools routinely pick the wrong one. Consent is usually inappropriate for core school functions. Consent must be freely given, and the relationship between a school and a family is not one where refusal is realistically free. For teaching, safeguarding, attendance and assessment the correct basis for processing is normally public task, and for some processing legal obligation.

That has a practical consequence worth stating plainly: if the school would carry on processing the data anyway when someone says no, it was never consent. Reserve consent for genuinely optional things such as photographs for the website or a trip newsletter, and make refusal cost nothing.

Special category data needs a lawful basis and an additional condition. Schools hold a great deal of it: health and medical needs, special educational needs, ethnicity, religion and safeguarding information. The DPA 2018 provides the conditions, and the school should record which one it relies on for each type of data rather than deciding at the point of a challenge.

Biometric data has its own regime on top. Where a school uses fingerprints or facial recognition for canteen payments, library systems or registration, the Protection of Freedoms Act 2012 requires the school to notify each parent and obtain written consent from at least one, and the child themselves may refuse regardless of what a parent says. An alternative must be available for anyone who declines, and it must not be a worse experience.

04

Subject access requests and pupils' own rights

A school must respond to a subject access request within one month, extendable by a further two months where the request is complex, and it cannot charge for it. The response covers all the personal data the school holds about that person, not only the file with their name on it.

Two features catch schools out. The right belongs to the child, not the parent. A pupil old enough to understand the right, which in practice is often from around twelve, exercises it themselves, and a parent asks either with their child's authority or as someone acting in the child's interests. And a request does not have to use the words subject access request, be in writing, or go to the right person: an email to a class teacher starts the clock.

There is a separate right of access to the pupil's educational record for parents of children in maintained schools, which runs on a different timescale and covers a narrower set of information. Academies are not covered by it, so a parent at an academy uses the UK GDPR route. Knowing which request you have received is the first step in answering it.

Beyond access, data subjects have rights to rectification, erasure, restriction, objection and portability. Erasure is the one most often misunderstood in a school: where the school processes data under public task, the right to erasure does not straightforwardly apply, and a safeguarding record in particular is not deleted on request.

05

Edtech suppliers, processors and impact assessments

A school's data is spread across a long list of suppliers: the management information system, the safeguarding platform, cashless catering, homework and messaging apps, cloud storage and the assessment tools individual teachers adopt. Each of those is a data processor acting on behalf of the school. Schools rarely have an inventory of their data processors, and building one is usually the single most useful afternoon a data protection lead can spend, because the school remains the controller and remains accountable for every one of them.

Those relationships require written data processing agreements covering the required terms: processing only on documented instructions, confidentiality, security, sub-processors, assistance with data subject rights, deletion or return at the end, and audit. A supplier's standard terms often contain these, and often do not. Read the ones covering sub-processors and deletion, because those are where the gaps are.

Where processing is likely to result in a high risk to the rights and freedoms of individuals, the school must carry out a data protection impact assessment before it starts. In a school that includes biometrics, CCTV, monitoring software on pupil devices, and any large scale processing of children's data by a new supplier. Carrying out data protection impact assessments is one of the DPO's named tasks, and it is a document that has to exist before the contract, not after the complaint.

The unmanaged version of this is the real risk. A teacher who adopts a free app for a class has entered the school into a processing relationship nobody has assessed. Schools handle that best with a short approval route rather than a prohibition, because a prohibition simply moves it out of sight.

06

Breaches, 72 hours, and the data nobody can find

A personal data breach is any security incident leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data. If it is likely to result in a risk to people's rights and freedoms, the school must notify the relevant supervisory authority, the ICO, within 72 hours of becoming aware. Where the risk is high, the people affected must be told too.

Most school breaches are mundane: an email to the wrong parent, a spreadsheet with a hidden tab, a lost memory stick, a safeguarding document left on a printer. What makes them hard is not the reporting form but the clock, because 72 hours runs from awareness, and awareness is usually a member of staff mentioning something to someone else.

Which is where the gap sits. A great deal of the personal data a school processes is now in messages: a parent texting a teacher about their child's medical needs, a staff group chat carrying a safeguarding concern at nine in the evening, a head of year approving something by message. That is personal data, the school is the controller for it, and it is processed on devices the school does not control and cannot search.

The consequences are concrete. A subject access request from a parent covers messages about their child wherever they are held, including on staff personal phones where the messages are about school business. A breach investigation asks when the school became aware, and the answer is usually in a message. And the storage limitation principle cannot be applied to data whose location is unknown, so a retention schedule stops at the edge of the school's own systems.

None of that is staff behaving badly; it is how people communicate. But it is worth asking, at your next leadership meeting, whether the school could answer a subject access request that covered messages, and whether it knows where its own data is.

07

Where to read the official guidance

The DfE's data protection in schools guidance and its accompanying toolkit are written for exactly this audience and are the best starting point. The Information Commissioner's Office holds the authoritative guidance on every point above, including breach reporting and its education sector material on children's data. For biometrics specifically, read the DfE's advice on the Protection of Freedoms Act alongside the ICO's.

Two habits do more than any document to ensure compliance holds: review the processor list once a year, and take the current data protection guidance from the ICO rather than from a summary written when the regime was new. Data privacy and data security are treated as one subject in most school policies, and they are not: security is one of the six principles, not the whole of it.

This page is a summary rather than advice on your school's own processing. Data protection compliance is an ongoing obligation rather than a project, and contested points, particularly around safeguarding and erasure, deserve proper advice and guidance from whoever advises your school.

Why we publish this

ComplyChat gives the conversations in section 06 a channel your school owns, so the messages that are already personal data sit somewhere the school can search, retain and disclose. Once your Microsoft 365 tenant is connected, the lasting record files there under your own retention rules, which is what makes a subject access request answerable. We wrote this guide because that is the part of school data protection that policy alone cannot fix.

How it works · Why us · Pricing · FAQ