ComplyChat Start free

Guide · Schools

Information sharing agreements for schools

From 30 September 2026 a school that holds information which may help another organisation safeguard a child must share it. The duty is short. The agreement that makes it work day to day is not: it names the partners, the routes, the lawful basis, who answers a subject access request and what everyone keeps. This guide reads the statutory guidance published on 10 September 2026 and the two template agreements that came with it, sets them beside the ICO's checklist, and ends with the one thing the guidance asks a school to write down every time.

20 minute read

A designated safeguarding lead in a plain hi-vis tabard talks with a visiting social worker under a primary school's entrance canopy in light rain
01

The duty the agreement sits under

Section 16LA of the Children Act 2004, inserted by the Children's Wellbeing and Schools Act, creates an information sharing duty for organisations with a safeguarding function, and the Department for Education's statutory guidance was updated on 10 September 2026 to reflect that the duty "comes into force on 30 September 2026". The guidance applies to local authorities, integrated care boards, NHS trusts, the police, education, early years, prison and probation services, youth justice, youth custody and primary care. A maintained school, an academy, a college and a nursery are all inside it, and so are the staff members who act for them: the duty is the organisation's, exercised by its practitioners.

The duty is stated in one paragraph. It "applies to information that may help another relevant person exercise their functions, including assess risk, make a decision, provide support or take action to safeguard and promote the welfare of a child". Where it applies, "organisations must share information with another organisation, or the requestor, if it is considered that sharing may help the recipient's relevant functions". It bites in two situations: where you "consider that they hold relevant information", and where you "receive a request for relevant information from another organisation and practitioner". It covers "both children with known needs, and those with needs being identified for the first time", and it extends to information about "another named individual connected to a child", which is where most of the awkward cases involving parents and carers or other adults in a child's life arise.

Two things the duty changes deserve to be said plainly, because they are the two things staff most often get wrong the other way. First, consent. The guidance says "Consent is not required to share information under data protection law", that it is "highly unlikely to be the most appropriate choice when sharing information under the duty", and that practitioners "should avoid seeking consent if they intend to share information in any case". Second, confidentiality: "The common law duty of confidentiality (CLDoC) does not apply to information shared in compliance with the information sharing duty". A school does not need a parent's agreement to share welfare information with the family hub, and should not imply that the parent's agreement is what decides it.

There is one limit, and it is narrow. The duty "does not apply in extremely limited circumstances where a practitioner, acting on behalf of their organisation, determine through professional judgement that sharing information would be more detrimental to the child than not sharing". That is a judgement about the child, not about the organisation's convenience, and section 05 of this guide is largely about how you show you made it.

Charities, private providers and community groups are not, in general, inside the duty. The guidance's non-statutory chapter says information can still be shared with them "so long as data protection law and CLDoC (if applicable) are accounted for", and that "in most cases it will be more appropriate to seek relevant information instead". A school that runs a breakfast club through a charity, refers a family to a community organisation or works with a youth service for older children and young people is sharing outside the duty and needs its ordinary lawful basis for doing so. The agreement should say which is which.

02

What an information sharing agreement is, and what it is not

The ICO's data sharing code of practice is where the document is defined, and it starts with the point most people miss: an agreement "is not mandatory", but "it is good practice to have a data sharing agreement in place", because it "can form a major part of your compliance with the accountability principle". The code accepts the names organisations use for it, "an information sharing agreement", "a data or information sharing protocol or contract", "a personal information sharing agreement", and then says what does not count: "a memorandum of understanding", "a list of standards" or "an addendum to a purchase agreement" are not, on their own, a data sharing agreement. A school that has signed a local authority's memorandum and nothing else has not yet got one.

The statutory guidance turns that good practice into an expectation for the safeguarding system. Under section 16E of the Children Act 2004 the safeguarding partners in each area, the local authority, the integrated care board and the police, must make local arrangements, and "Each multi agency safeguarding partnership (Partnership) must have published their arrangements and should have a data sharing agreement (DSA) sitting alongside that". Partnerships "will need to revisit those data sharing agreements and revise them to take account of this duty and review them regularly", and "An overarching Data Protection Impact Assessment is likely to be required prior to a Partnership agreeing a DSA". Schools are relevant agencies in those arrangements, and the guidance says the partners and any relevant agencies "are required to act in accordance with such local arrangements". So for most schools the agreement is not one they draft; it is one they are asked to sign up to, and the job is to read it, check it against sections 03 and 04 below, and know where their own copy is.

The DfE published two templates with the guidance, and the difference between them is the difference between the strategic and the operational. The Tier 1 template is the partnership-wide agreement, "for safeguarding organisations and their practitioners", signed at organisation level by each signatory organisation. Its chapters run through the data protection principles, who is a controller, joint controller or processor, administration and version control, scope, purpose and benefits, responsibilities and partner commitments, lawfulness (UK GDPR, the common law duty of confidentiality, the information sharing duty, special category and criminal offence data), security standards including a role-based access model, patching schedules, remote access and recovery objectives, proportionality and necessity, retention, individuals' rights, transparency, staff training, incident management and complaints, and a list of common sharing initiatives such as child death reviews, child safeguarding practice reviews and child protection notifications. The Tier 2 template is the operational agreement for a particular sharing activity, and its fourteen sections are a checklist in themselves: administration; background; the DPIA; purpose limitation; categories of personal data, split into personal, special category and criminal offence data; categories of data subjects; lawfulness, fairness and transparency; accuracy; integrity, confidentiality and security; data breaches; storage limitation and retention; data subject rights requests; onward sharing; and miscellaneous. The two "should be read and understood as dependent documents".

One more distinction the guidance draws, because it decides which template applies. Most sharing is case by case: a concern, a request, a decision. But the guidance also describes strategic and routine sharing: where partners "have agreed, at a strategic level, that certain safeguarding and welfare information is necessary to fulfil their functions, that information may be shared on a regular basis, rather than only in response to individual incidents or referrals", giving school attendance and patterns of absence as the example. "Decisions and rationales for regular sharing arrangements should be documented and kept under review." A school that sends an attendance extract to the local authority every fortnight is in a routine flow, and that flow needs a Tier 2 agreement of its own, not a line in a policy.

The question to ask your partnership

Has the partnership's data sharing agreement been revised for the section 16LA duty, and is the version your school is working to the revised one? The guidance expects the revision; a school that cannot say which version it holds cannot show it is acting in accordance with the local arrangements.

03

What the agreement has to set out

The ICO's code says "You should address a range of questions in a data sharing agreement", and lists them. Read against the DfE's Tier 2 sections, the two line up almost one for one, which is a reasonable test of any agreement a school is handed: if it cannot answer these, it is a memorandum with a different title.

  1. Who the parties are, and who is the data controller at every stage. The agreement "should state who the controllers are at every stage, including after the sharing has taken place". Where two organisations act as joint controllers there is "a legal obligation to set out your responsibilities in a joint control arrangement" under Article 26 of the UK GDPR, and the agreement must "state in the agreement which controller is the contact point for data subjects".
  2. The purpose. "the specific aims you have", "why the data sharing is necessary to achieve those aims" and "the benefits you hope to bring to individuals or to society more widely", documented "in precise terms". The statutory guidance narrows the purpose for information received under the duty to "safeguarding and promoting the welfare of children", and says any further use "must only do so if they can comply with data protection laws". The same purposes appear, in the guidance's words, "in their data sharing agreement and published privacy notices", so the school's privacy notice for pupils and parents has to say what the agreement says.
  3. Every organisation involved, with contact details for their data protection officer, and "procedures for including additional organisations in the data sharing arrangement and for dealing with cases where an organisation needs to be excluded".
  4. The data items. "the types of data you are intending to share. This is sometimes known as a data specification." The code notes it may be right "to share only certain information held in a file about an individual, omitting other, more sensitive, material", and to attach permissions so that only certain roles can see certain items. The statutory guidance makes the same point from the other side: the duty "requires the sharing of relevant information, not the sharing of documentation where extracted or summarised information would suffice".
  5. The lawful basis, and the legal power. "You need to clearly explain your lawful basis for sharing data. The lawful basis for one organisation in a data sharing arrangement might not be the same as that for the other one." The guidance suggests the candidates: Article 6(1)(c), legal obligation, because "s16LA is a 'legal obligation' to share information when the criteria are met"; Article 6(1)(e), public task, which "will apply to most public bodies"; and Article 6(1)(ea), recognised legitimate interest, or 6(1)(f), legitimate interests, for "voluntary and private organisations". The legal power is section 16LA itself, and the agreement should cite it alongside the UK GDPR and the Data Protection Act 2018 rather than leave the reader to infer it.
  6. Special category and criminal offence data. "You must document the relevant conditions for processing". The guidance points to Article 9(2)(g), substantial public interest, "relying on the condition in Schedule 1(18) of the DPA2018, where the processing is necessary to protect a child from neglect or physical, mental or emotional harm", and Article 9(2)(h) for health and social care; for criminal offence data, the same Schedule 1 paragraph 18 condition, with parental imprisonment as the example.
  7. Access and individual rights. "procedures for compliance with individual rights", including "what to do when an organisation receives a request for access to shared data", and a clear statement that "all controllers remain responsible for compliance" even where the tasks are divided. The Tier 2 template gives this a whole section, listing the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability and to object.
  8. Information governance. The code's practical list: detailed advice about which datasets can be shared "to prevent irrelevant or excessive information being disclosed"; accuracy, "for example by requiring a periodic sampling exercise and data quality analysis"; recording data "in the same format"; "common rules for the retention and deletion of shared data items" and a procedure "where different organisations may have different statutory or professional retention or deletion rules"; "common technical and organisational security arrangements, including the transmission of the data and procedures for dealing with any breach"; staff training; procedures for access requests and complaints; "a timescale for assessing the ongoing effectiveness of the data sharing initiative"; and termination, "including the deletion of shared data or its return to the organisation that supplied it originally".
  9. An annex with "a summary of the key legislative and other legal provisions", "a diagram to show how to decide whether to share data", and optionally "a data sharing request form" and "a data sharing decision form". Those two forms are the record in section 05, given a shape.

The retention line deserves a school's particular attention, because a school's retention rules and a local authority's are not the same. A child protection file is kept by the school under the Department for Education's record-keeping rules and transferred with the child; a social care record is kept by the council under its own schedule; the police keep theirs under theirs. An agreement that says "retain in line with your own policy" has not answered the ICO's question. It should say what happens to the copy each party holds of what the other shared, and when.

04

Routes: how information actually moves

A well-drafted agreement fails at the point where a member of staff does not know which route to use. The guidance treats this as a design question and lists what the partnership's agreement has to consider in "getting information to the right place":

  • Range. "Every relevant agency locally needs to be included", with the acknowledgement that "it can be appropriate to have varied arrangements for different types of organisations". A primary school and an NHS trust do not share the same way.
  • Breadth of system. Sharing has to work "from early help through to child protection" and for children looked after by the local authority, not only at the point of a formal referral.
  • Routes. "Formal referrals, for example for a formal assessment, may be shared through a different route to Family Help referrals and again for smaller, more contextual pieces of information." And, underlined: "It is critical that partnerships have mutually established the best route for sharing urgent information, where there is an immediate threat."
  • Awareness. "Each organisation needs to be aware what local arrangements are in place so that they can feed information to the right places through the right routes, as well as know who to contact if the information needs to go to another area."
  • Oversight. "Where the wrong routes or mechanisms are used, agreed processes are not followed, or similar, there should be feedback loops and dialogue", including "clear incident management arrangements".
  • Security. "Mechanisms used to share information need to have appropriate security measures, including compliance with data protection by design and default."

For a school, three routes come up so often that the agreement, or the school's own safeguarding policy sitting under it, should name them. The referral route to the front door or the multi-agency safeguarding hub, which the MASH guide on this site covers step by step. The request route, when a social worker, a health visitor or another school asks the school for what it holds: the duty applies to that request as much as to a concern the school raises itself, and the guidance's list of what organisations MUST do includes "Consider and respond to requests for information from other organisations and practitioners in line with the information sharing duty". And the transfer route when a pupil moves school, most often from a primary to one of the local secondary schools, which the DfE's data protection guidance treats separately: "If a pupil moves to another school, you should transfer their records to the new school. This includes the pupil's common transfer file and educational record", securely and traceably, using the school-to-school system, encrypted email to a named person, the local authority, or delivery in person, within the fifteen school days the Education (Pupil Information) (England) Regulations 2005 allow.

The DfE's guidance adds a step before routine sharing that agreements often assume rather than state: schools "should carry out a data protection impact assessment to assess any risk before sharing personal information about your pupils", and before sharing with a local authority should "Confirm who needs the data, what data is needed and what they'll use it for", "Make sure that you have the ability to share the specified data securely" and "Check that the actions cannot be completed or verified without the data". Those are the questions the Tier 2 template's DPIA section asks; the point is that they are asked once, for the flow, not every time a member of staff shares something inside it.

The guidance also says something about digital systems that a school's leadership team should hear as a question about its own: "It is important that organisations ensure their digital infrastructure is fit for purpose, to reduce the logistical barriers to effective multi-agency working, and support practitioners understanding of what digital information is available and how to access it appropriately." Section 06 returns to what that means in practice.

A family support worker and a school SENCO walk along a leafy path between a school and a family hub on a bright morning
05

The record of every decision to share, or not to share

The guidance tells schools what they MUST do and what they SHOULD do, and the record sits in the second list, which is where an inspector or a reviewer will look first. Organisations "SHOULD", in line with established best practice, "Be able to demonstrate accountability for compliance with the information sharing duty, and with data protection law. Record the decision for sharing, or not sharing, including any rationale pertaining to relevance, the facilitation of another organisation's relevant functions, detriment and anything else they determine necessary to comply with their internal governance, data protection or any other statutory obligations." Read that sentence twice: it asks for the decision not to share to be recorded with its reasons, which is the decision nobody writes down.

The DfE's data protection guidance for schools gives the same instruction in plainer words for the designated safeguarding lead, who "should make sure they record: who they're sharing that information with, why they're sharing the data, whether they have consent from the pupil, parent or carer". Put the two together with the MUST list and the shape of a per-decision record is clear:

  1. What you held, and why it was relevant. The information, in the words it was recorded in, and the function of the other organisation it "may help": assessing risk, making a decision, providing support, taking action.
  2. Who asked, or who you decided to tell, and by which route. The requestor's organisation and role, the date of the request, the route from section 04 that was used and why that one.
  3. The lawful basis and, where it applies, the special category or criminal offence condition, from the agreement rather than reasoned afresh each time.
  4. What exactly was shared. The extract or summary, not "the file": the guidance is explicit that the duty requires "relevant information, not the sharing of documentation where extracted or summarised information would suffice". If the whole file went, the reason it had to.
  5. The detriment question. Whether sharing was considered more detrimental to the child than not sharing, and the professional judgement behind the answer. This is the only ground on which the duty does not apply, so it is the line a decision not to share must carry.
  6. Transparency. Whether the child and the parents and carers were told what was shared and why, or, if not, why not: the guidance says to inform them "unless doing so would increase risk or is impracticable", and to keep the child's wishes and feelings "under active consideration".
  7. Acknowledgement and feedback. The guidance expects the recipient to "Provide acknowledgement and timely feedback" so that sharing "should be understood as a dialogue". Record what came back, and when. Silence is a fact worth dating.
  8. Emergencies. Where the usual process could not be followed, the guidance says practitioners "should take a proportionate approach, and document their decision-making". The record can be written afterwards; it cannot be skipped.

Where the child is a pupil, this record belongs in the child protection file, held separately from the educational record with restricted access, and transferred with the child under Keeping children safe in education; the school-records guide on this site sets out the retention that applies to it. The accountability principle is the reason it exists at all. The guidance lists accountability among the data protection principles that apply to sharing under section 16LA, "having appropriate measures in place and keeping records to demonstrate your compliance", and adds, in the same breath, "It is recommended to have a data sharing agreement in place". The agreement is the standing record; the decision log is the record of each use of it.

A test you can run this half-term

Take the last request your school received from another agency, and the last concern your DSL decided not to refer. For each, can you produce, from the file, the date, the route, what was shared or why nothing was, and the feedback? If the answer to any part is "it will be in someone's messages", that is the finding, and section 06 is about it.

06

The sharing usually happens in a message first

Every agreement in this guide describes routes, and every route it describes is formal: a referral form, a portal, a secure email to a named officer. That is not where the information sharing starts. A social worker texts the DSL's personal mobile at half past five to ask whether a child was in today. The SENCO and the family hub worker have a WhatsApp thread going back to the spring. The school nurse messages the pastoral lead a photograph of a bruise so that the right form can be filled in. The Year 6 teacher tells a colleague at the secondary school, in a direct message, what the transfer file will not say. Each of those is information sharing within the meaning of section 16LA, each is personal data about a child, and each is a decision the guidance says should be recorded with its rationale.

The guidance's own criteria for a route, security "including compliance with data protection by design and default", oversight through "feedback loops" and "clear incident management arrangements", and awareness of "the right places through the right routes", are the criteria a personal-phone thread fails. It is not on the school's systems, so it is not in the child protection file. It cannot be produced for a subject access request the ICO's code says the agreement must have a procedure for, or for a child safeguarding practice review the Tier 1 template lists as a common sharing initiative. When the child moves school the thread stays on the phone of a member of staff who may, by then, have moved too. And an end-to-end encrypted consumer app is designed so that nobody but the two handsets can read the message, which is exactly why the organisation that carries the duty cannot.

This is not an argument against staff talking to each other quickly; the guidance wants them to "Act promptly and be proactive; avoid unnecessary delay". It is a records question about where the conversation lands, and it belongs with the leadership team and the safeguarding governor rather than with the individual who picked up the phone. Two practical answers exist. The first is a rule that every share in a message is followed by an entry in the file, which works exactly as well as the busiest week of the year allows. The second is to give the conversations that carry sharing decisions a place to happen that the school controls, where everyone in the channel is told it is on the record, the record is written as the message is sent, and it can be produced when the agreement's procedures say it must be. That is what ComplyChat is designed to do, and what it is not: it does not replace the referral form, the portal or the partnership's secure email, and it is not a case management system. It is where the conversation around those routes can be kept.

The question for the next safeguarding governor's visit is a small one. Of the routes named in the partnership's agreement, which one is used at six in the evening, and where does that one keep its record?

07

Official guidance and your next step

The primary sources are Information sharing: advice for practitioners providing safeguarding services, the statutory guidance for the section 16LA duty, published with the Tier 1 and Tier 2 template data sharing agreements; the ICO's Data sharing: a code of practice, in particular its chapter on data sharing agreements; the DfE's Data protection in schools: sharing personal data; and, alongside them, Working together to safeguard children and Keeping children safe in education, which the statutory guidance says it "should be read alongside, and does not replace". The ICO's guidance is under review following the Data (Use and Access) Act, so check the date on the page you read.

This guide is a practical starting point for schools and colleges in England, not advice about any individual child or case. Your designated safeguarding lead, your local authority's front door and, where a child is at immediate risk, the police on 999 come first.

Then do one thing: find your safeguarding partnership's published arrangements and the data sharing agreement that sits alongside them, confirm it is the version revised for the 30 September 2026 duty, and write its name, version and the three routes from section 04 into your child protection policy where it describes how the school shares information. A request that arrives on a Friday evening should not depend on the DSL remembering which portal the council prefers.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. Under the information sharing duty a message between a school and another agency is a sharing decision that must end in a record, and the message is the part most schools cannot produce. Explore Free personal messaging, or compare the paid plans if your organisation needs a lasting Microsoft 365 archive.

Explore Free · How it works · Compare plans