ComplyChat Start free

Guide · Schools

Online safety policy for a school

Every school needs an online safety policy, but Keeping children safe in education 2026 does not ask for a free-standing document so much as an approach that runs through the child protection policy, the staff code of conduct, the curriculum and the school's technology. It also sets specific standards for filtering and monitoring, with named roles and an annual review that has to be recorded. This guide explains what KCSIE 2026 requires, what a school online safety policy should cover in practice, how the filtering and monitoring standards work, and how the policy is reviewed and evidenced.

By ComplyChatPublished 12 minute read

A Year 5 class works in pairs on laptops in a bright primary classroom while their teacher crouches beside one table to talk with two pupils, seen from the back of the room
01

The rule: what KCSIE 2026 says about online safety

Online safety sits in Part two of Keeping children safe in education 2026 (KCSIE 2026), the Department for Education's statutory guidance for schools and colleges in England. It opens plainly: "It is essential that children are safeguarded from potentially harmful and inappropriate online material" (paragraph 164). An effective whole school approach "empowers a school or college to protect and educate pupils, students, and staff in their use of technology and establishes mechanisms to identify, intervene in, and escalate any concerns where appropriate."

On the policy itself, paragraph 169 is short: "Online safety and the school or college's approach to it should be reflected in the child protection policy which, amongst other things, should include appropriate filtering and monitoring on school devices and school networks. Considering the 4Cs (above) will provide the basis of an effective online policy."

So KCSIE does not require a separate document called an online safety policy. Many schools keep one, and that is perfectly sound provided the child protection policy reflects it and the two do not contradict each other. Model policies and online safety policy templates are widely available – from local authorities, the regional grids for learning such as LGfL and SWGfL, and the UK Safer Internet Centre – and they are good practice as a starting point, not as a finished document. A template cannot know the needs of the school: its phase, its devices, its pupils' risks, who its IT support is. The test of any online safety policy is whether staff and pupils could act on it on an ordinary Tuesday. What KCSIE does require is that governing bodies and proprietors "ensure online safety is a running and interrelated theme" in the whole school approach to safeguarding, reflected "in all relevant policies" and considered in the curriculum, staff training, the role of the designated safeguarding lead and parental engagement (paragraph 166).

The designated safeguarding lead "should take lead responsibility for safeguarding and child protection (including online safety and understanding the filtering and monitoring systems and processes in place)" (paragraph 127). Independent schools meet the same expectation through the Independent School Standards, and colleges through the same KCSIE text.

02

What the policy should cover

KCSIE groups online risk into four areas, known as the 4Cs, and they are the natural spine of the policy (paragraph 165):

  • Content: "being exposed to illegal, inappropriate, or harmful content", from pornography, racism and misogyny to self-harm, radicalisation, misinformation and conspiracy theories.
  • Contact: "being subjected to harmful online interaction with other users or generative AI applications that simulate this", including adults posing as children to groom or exploit.
  • Conduct: "online behaviour that increases the likelihood of, or causes, harm", including making, sending and receiving explicit images, "including those generated using AI", and online bullying.
  • Commerce: "risks such as online gambling, inappropriate advertising, phishing and or financial scams".

Around that spine, a school online safety policy that does its job usually covers:

  • Roles and responsibilities – the governing body, the senior leader and governor responsible for filtering and monitoring, the designated safeguarding lead, IT support, all staff, pupils and parents (section 03).
  • Teaching online safety – where it sits in the curriculum. KCSIE expects children to be taught how to keep themselves and others safe, including online, and in schools that runs through Relationships and Health Education and Relationships, Sex and Health Education (paragraphs 158 and 159). KCSIE lists resources to help schools, including the National Crime Agency's CEOP Education programme.
  • Bullying online – how the behaviour policy's anti-bullying measures, which KCSIE says should include cyberbullying, apply to bullying between pupils online.
  • Staff training – online safety as part of induction training, including "an understanding of the expectations, applicable roles and responsibilities in relation to filtering and monitoring", and updates "at least annually" (paragraphs 153 and 154).
  • Acceptable use – agreements for pupils, staff and visitors covering school devices, the network, personal devices and bring your own device arrangements.
  • Mobile phones – KCSIE 2026 adds that "all schools should be mobile phone-free environments by default", and points to the Department's statutory guidance on mobile phones in schools (paragraph 170).
  • Staff conduct online – how staff communicate with pupils and parents, social media and personal devices. KCSIE puts these in the staff behaviour policy, which should include "acceptable use of technologies (including the use of mobile devices), staff/pupil relationships and communications including the use of social media"; the online safety policy should point to it rather than repeat it.
  • Generative AI – whether and how it is used, with reference to the Department's guidance on generative AI in education (paragraph 167).
  • Remote education and parents – how pupils are kept safe when learning remotely, and how the school tells parents and carers what systems it uses and what children will be asked to do online (paragraphs 171 and 172).
  • Responding to incidents – how staff report an online concern, who deals with it, and how it is recorded (section 05).
  • Information security – protecting personal information and meeting the Department's cyber security standards (paragraphs 178 to 180).
03

Filtering and monitoring: the standards and who does what

Paragraph 173 is the heart of the technical duty. Governing bodies and proprietors "should ensure their school or college has appropriate filtering and monitoring systems in place and ensure that a review of their effectiveness is carried out at least once every academic year." The 2026 edition adds who reviews and what is recorded: "Reviews should be carried out by the SLT member responsible for filtering and monitoring, with the support of the school's designated safeguarding lead and IT support. They should include checks that filtering is working appropriately on all internet-connected devices in all relevant locations, and a record should be kept of these checks." What is appropriate is for each school to decide, informed in part by its Prevent duty risk assessment (paragraph 174).

KCSIE then points to the Department's filtering and monitoring standards, which say schools and colleges should:

  1. identify and assign roles and responsibilities to manage filtering and monitoring systems,
  2. review filtering and monitoring provision at least annually,
  3. block harmful and inappropriate content without unreasonably impacting teaching and learning, and
  4. have effective monitoring strategies in place that meet their safeguarding needs.

The standards divide the work clearly. The governing body identifies a member of the senior leadership team and a governor responsible for making sure the standards are met. The senior leadership team scopes needs, buys systems, documents "decisions on what is blocked or allowed and why", reviews effectiveness and oversees reports. The designated safeguarding lead leads on safeguarding and online safety, checks relevant reports, responds to concerns the systems identify, and gives governors assurance that the systems work. IT support, in-house or contracted, maintains the systems, provides reports and completes actions after checks.

Some specifics are firmer than schools expect. Filtering should not have a blanket profile: "as a minimum, student and staff profiles should be in place." Schools must make sure their filtering solution implements the blocklists from the Internet Watch Foundation and the Counter-Terrorism Internet Referral Unit, and KCSIE points to a South West Grid for Learning (SWGfL) tool that checks whether a provider is signed up to the relevant lists. The standards ask, as a minimum, for weekly monitoring reports and immediate reports of high-risk incidents, and expect everyone using the network to know that filtering and monitoring are in place, for example through a message at log-in. KCSIE also warns against the opposite failure: governing bodies "should be careful that 'over blocking' does not lead to unreasonable restrictions as to what children can be taught" (paragraph 163).

04

The annual review, the checks and the record

Two reviews run side by side. KCSIE suggests schools "consider carrying out an annual review of their approach to online safety, supported by an annual risk assessment that considers and reflects the risks their children face" (paragraph 181). The filtering and monitoring review, which KCSIE expects at least once every academic year, can be part of it.

The standards say the filtering and monitoring review should involve the senior leadership team, the designated safeguarding lead and IT support, and the responsible governor, and that you "should record the results of the review and document any actions taken". A review is also due whenever a safeguarding risk is identified, working practice changes (remote access or bring your own device), new technology or generative AI tools arrive, major software updates occur or the network configuration changes.

Between reviews, schools carry out checks on their filtering, on school-owned devices including those taken home, across every site, and for each user group. The standards ask for a log recording:

  • when the check took place,
  • who did the check,
  • what they tested or checked, and
  • resulting actions.

Other records follow from the same standards: documented decisions on what is blocked or allowed, approval by the responsible senior leader of any temporary exception from filtering, and a data protection impact assessment for filtering and any technical monitoring system, since both process personal data about pupils and staff. Data protection law has been amended by the Data (Use and Access) Act 2025, whose data protection provisions are now all in force, so check that any ICO guidance you use reflects the amended law.

Tools help. The Department's Plan technology for your school service lets schools self-assess against the standards (paragraph 176), and KCSIE names the 360 safe self-review tool and the LGfL online safety audit for the wider review. For governors, the UK Council for Internet Safety publishes Online safety in schools and colleges: questions from the governing board, which is a practical agenda for the governor who holds the brief.

A school IT technician and a deputy headteacher stand in a narrow server cupboard off a secondary school corridor, talking over a clipboard, cables and a network cabinet behind them
05

Responding to incidents, and what to record

The policy should make one thing clear to every adult: an online safety concern is a safeguarding concern, and it goes to the designated safeguarding lead by the school's usual route. The filtering and monitoring standards say the DSL "is responsible for any safeguarding and child protection matters that are identified through monitoring", and that there "should be a documented process for recording incidents that includes what action was taken and the outcomes."

The standards also list what staff should report: if they witness or suspect unsuitable material has been created or accessed; if they can access unsuitable material; if they are teaching topics that could create unusual activity on the filtering logs; if the system fails or is misused; if restrictions are unreasonably affecting teaching; and if they notice abbreviations or misspellings that allow access to restricted material. Listing these in the policy turns a technical standard into something a teacher can act on.

Some incidents carry their own guidance. KCSIE 2026 clarifies that "all incidents involving the sharing of nude or semi-nude images require a safeguarding response, whether they are consensual or non-consensual", and treats online bullying and harassment between children under its child-on-child abuse provisions. Online concerns about an adult's conduct follow the Part four route for allegations and low-level concerns, not the online safety policy.

For each incident the record should show what was reported and by whom, when, what the DSL decided and why, who was told, and the outcome, in the same place as any other safeguarding concern, so that an online incident can be seen alongside everything else the school knows about the child.

06

The concern that arrives outside the network

A school's filtering system records every blocked search with a device, a time and, where possible, a name. Its monitoring reports arrive weekly, and high-risk alerts arrive at once. By the standards of most school records, it is meticulous.

Now follow how an online safety concern usually reaches the school. A parent messages the class teacher at ten at night with a screenshot of something said in a pupils' group chat. A Year 9 pupil tells a teaching assistant, who texts the head of year from the bus. The head of year asks in the staff group chat whether anyone knows what is going on between two families. None of that passes through the school network, none of it is in the filtering logs, and most of it lands on personal phones in apps the school cannot see. The record the policy requires begins when someone types it into the safeguarding system, and everything before that point is missing.

The policy cannot reach a parent's phone, and should not try. What the school can decide is where its own staff's work conversations happen. ComplyChat provides a channel for them that the school controls, with everyone added told it is on the record, and a mobile number verified by SMS is an identity on it, so parents, support staff and volunteers without a school account can be in the conversation. On paid plans, once the school's Microsoft 365 tenant is connected, the lasting record files there under the school's own retention rules. It is not a filtering or monitoring product and does nothing on pupils' devices, and it is not a safeguarding case-management system; the concern still belongs in the child's record. ComplyChat Free is personal messaging with one private group, direct messages and three calendar months of recent history, with no Microsoft 365 archive.

A question for the next governors' meeting: our filtering logs can tell us what was searched on a school laptop at 2.14pm last Tuesday. When a parent sent a teacher a screenshot about a pupil last week, where is that recorded, and could we produce it?

07

Official guidance and your next step

The primary sources are Keeping children safe in education 2026, Part two, paragraphs 153 to 183, and the Department for Education's filtering and monitoring standards, updated in September 2026. The mobile phones in schools guidance sets the phone-free default, and the UK Safer Internet Centre's guidance on appropriate filtering and monitoring explains what to ask a provider. Quotations here are from those documents as published in September 2026; the standards in particular are updated between KCSIE editions, so check the page date.

This guide is a practical summary for schools and colleges in England, not legal advice. Schools in Wales, Scotland and Northern Ireland follow their own guidance.

Then do one thing: ask for the record of your last filtering and monitoring review and the log of checks since. If either does not exist, or does not name the senior leader and governor responsible, that is the first line of your next online safety policy review.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. Schools keep careful records of what happens on their network, while the online safety concerns that matter most often arrive by message on a personal phone. Explore Free personal messaging, or compare the paid plans if your school needs a lasting record in its own Microsoft 365.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Filtering and monitoring standards gov.uk
  2. Online safety in schools and colleges: questions from the governing board gov.uk
  3. Keeping children safe in education 2026 gov.uk
  4. Mobile phones in schools guidance gov.uk
  5. UK Safer Internet Centre's guidance on appropriate filtering and monitoring saferinternet.org.uk