ComplyChat Start free

Guide · Data protection

Privacy notice for schools

Every school must tell pupils, parents, staff and governors what it does with their personal data. Most schools meet that duty with a privacy notice adapted from the Department for Education's suggested text, published on the website and rarely read again until someone complains. This guide sets out what UK GDPR actually requires a school privacy notice to say, how to use the DfE model notices without inheriting their gaps, which notices a school needs for which people, and the part most notices describe least accurately: how the school really communicates.

By ComplyChatPublished 12 minute read

A parent and a Year 7 pupil read a printed welcome pack together at a small table in a secondary school sports hall on a new-intake evening, other families queuing at a registration desk behind them
01

The right to be informed, and why a school needs a notice

A privacy notice is how a school meets the right to be informed under Articles 12 to 14 of the UK General Data Protection Regulation. The school, or in an academy the trust, is the data controller for the personal data it holds, and the duty to explain that processing sits with it.

Article 12(1) sets the standard for how the information is given: in a "concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child". The last clause matters more in a school than almost anywhere. A notice written for parents in legal register does not meet the standard for pupils who are old enough to understand their own rights.

Article 13 covers personal data collected from the person themselves, such as the admission form or a staff application. Article 14 covers personal data obtained from someone else, which in a school is a large share of the whole: the previous school's file, the local authority, health and social care, the other parent. Both articles set out what the notice must contain, and they overlap almost completely.

The Department for Education's guidance puts the practical rule plainly: every school must make its privacy notices freely available to those whose personal data it handles. The notice sits under the school's data protection policy, not instead of it. The data protection legislation is UK GDPR and the Data Protection Act 2018, and the Data (Use and Access) Act 2025 has amended both, including Article 13 itself, and the ICO confirmed on 19 June 2026 that all its data protection provisions are now in force, so check the date on any ICO page or template you rely on.

02

What the notice must contain

Articles 13 and 14 require the same core list, and a school privacy notice should work through it in order:

  1. Who the controller is and how to contact it: the school or the trust, with an address that reaches someone.
  2. The data protection officer's contact details. Every school must appoint a DPO, and the notice must say how to reach them.
  3. The purposes and the lawful basis for each purpose: teaching, safeguarding, attendance, assessment, meeting statutory data collections, and so on. For most core school functions that is public task or legal obligation, not consent.
  4. Legitimate interests, if any processing relies on them, and what they are.
  5. The recipients, or categories of recipients: the Department for Education, the local authority, the next school, health services, examination boards, and the suppliers who process data for the school.
  6. Transfers outside the UK, and the safeguards that apply, where any supplier processes personal data abroad.
  7. How long the data is kept, or the criteria used to decide. Pointing to the school's retention schedule is the usual answer.
  8. The person's rights: the right to access the personal data the school holds, to have inaccurate personal data corrected, and to erasure, restriction, objection and portability where they apply, plus the right to withdraw consent where consent is the basis. Say how to make a request, and to whom.
  9. The right to complain to the school or trust as controller, and to the ICO. Since 19 June 2026 the notice must mention both.
  10. Whether providing the data is a statutory or contractual requirement, and what happens if it is not provided.
  11. Any automated decision-making, including profiling, with meaningful information about it.

Where the data comes from someone else, Article 14 adds two items: the categories of personal data concerned, and where it came from. It also sets the timing: within a reasonable period and at the latest within one month, or at the first communication with the person, or before the data is first disclosed to another recipient, whichever comes first. Article 14(5) contains exceptions, including where giving the information would be impossible or involve disproportionate effort, which is rarely the position of a school that already corresponds with every family.

One provision is widely missed. Article 13(3) says that where the school intends to use personal data for a new purpose, it must tell people before that further processing. Adopting a new app that uses existing data in a new way is exactly that case.

03

Pupils, parents, the workforce and governors

A school holds personal data about several distinct groups, and one notice cannot address all of them in clear and plain language. Most schools need at least four:

  • Pupils and parents. Often one notice for parents and pupils with a pupil-friendly version, or a layered notice with a short front page. It covers the pupil's record, special category data such as health, SEN and ethnicity, safeguarding, free school meal eligibility, the school census, and sharing with the local authority and the DfE. Parents' own data, such as contact details and the conversations they have with staff, belongs here too.
  • The school workforce. Teachers, support staff, supply and agency workers: recruitment and pre-employment checks, payroll, performance, absence and the school workforce census.
  • Governors and trustees, and others in governance roles: appointment, the checks and information published about them.
  • Volunteers, visitors and contractors, where the school processes their data for checks, sign-in or site access.

The DfE's guidance also says when to give each notice. For pupils: in the induction pack when they join, at the start of each school year, and when they provide extra personal data during the year. For staff: when they apply for a role, accept a contract, are appraised or leave. Publishing the notices on the school website meets the freely available part, and the DfE recognises a layered approach, a short version with a route to the full text, as a way of meeting the clear-and-plain standard.

For younger pupils the pupil version is worth real effort. It does not have to repeat every legal item; it has to explain, in words a ten-year-old follows, what the school writes down about them, who it tells, and who to ask. A secondary school should expect some pupils to read the full notice, and to exercise their own rights under it.

04

The DfE model notices, and how to adapt them

The Department for Education publishes model privacy notices as suggested text in Word format: for an educational setting (pupils and parents), for the school workforce, for school and trust governance roles, for children in need or looked after, and for local authorities and the children's social workforce, with guidance on issuing them. The documents were updated in August 2026 for the 2026 to 2027 academic year. The DfE describes them as wording schools may want to use, not a form to fill in.

They are a sound base, particularly for the statutory data collections, because the DfE's guidance says a school's privacy notice must include what personal data is shared with the DfE. The text on the school census, the national pupil database and the DfE's onward sharing is best taken from the current model and kept current with it.

That section usually does three things. It explains that the school must provide certain pupil information to the DfE through statutory data collections such as the school census, under section 537A of the Education Act 1996 and the regulations made under it. It explains the national pupil database, which the DfE describes as linking personal information from schools and local authorities to attainment data from awarding bodies, and which it uses for research and statistics to improve and promote the education and well-being of children in England. And it tells parents and pupils how to make a request to the DfE itself for the personal information it holds about them, because the right of access runs against the DfE as a separate controller, not through the school.

The rest is the school's own processing, and that is where copied notices fail. Before publishing, check at least these:

  • the controller named is correct: an academy's controller is usually the trust, not the school
  • the DPO's name and contact details are current, and reach the DPO rather than the office
  • every purpose has a lawful basis you would defend, and consent appears only where refusal genuinely costs nothing, such as photographs on the website
  • the recipients match the school's actual list of processors, including the MIS, the safeguarding system, payments, catering, learning platforms and parent communication tools
  • any processing outside the UK is disclosed, which means reading each supplier's terms rather than assuming
  • the retention statement points to a real schedule, and the schedule covers the data the notice describes
  • CCTV, biometrics and any monitoring of school devices are described if the school uses them

The DfE's guidance tells data protection officers to review notices at least annually, or whenever the school makes a significant change to how it processes personal data. A notice whose date has been rolled forward for three years without anyone checking the supplier list is not reviewed; it is re-dated. A school's wider GDPR obligations, the record of processing activities in particular, should be the source the notice is checked against.

A school data manager leans on the balcony rail of a modern school atrium at lunchtime, looking down at the busy hall below
05

Messaging platforms named in the notice

Communication with parents and between staff is one of the largest flows of personal data in a school, and the one privacy notices describe least accurately. Most notices mention a parent communication app, email and text messaging in a line or two. Few say what those messages contain, where they are stored, or how long they are kept.

The notice does not have to name every supplier; the law allows categories of recipient. But it has to be true, and the categories have to be specific enough that a parent can understand where their data goes. Three questions test the messaging part of a notice:

  1. Does it describe every route the school actually uses? A parent app, the school email system, text messaging from the MIS, a video call platform for meetings. If staff use something else in practice, the notice is describing a school that does not exist.
  2. Does it say what happens to messages? Parents write about medical needs, family breakdown, safeguarding concerns and SEN. Those messages are personal data, much of it special category, and the retention schedule should cover them like any other record.
  3. Does it disclose where the processing happens? A messaging supplier that processes data outside the UK is a transfer the notice must mention, with the safeguard relied on.

When the school adopts a new messaging platform, the notice is one of four documents that should move together: the notice, the processor list and data processing agreement, a data protection impact assessment where the processing is likely to be high risk, and the retention schedule. Where the new tool uses existing data for a new purpose, Article 13(3) means families should be told before it goes live, not after the first message arrives.

Where the school communicates with families' permission for something genuinely optional, such as a class photo gallery, record the consent and make withdrawing it easy. Where it communicates because it must, for attendance, safeguarding or emergencies, the lawful basis is public task and the notice should say so, so parents are not led to think they can switch it off.

06

The conversations the notice does not describe

Read almost any school privacy notice and the school communicates through its own systems. Walk round almost any school and it does not only do that.

A parent messages the class teacher's personal number about a hospital appointment. A head of year arranges a meeting about a pupil's behaviour by text, from her own phone. The PE department runs a group chat with parents for fixtures. Staff discuss a child's needs in a group chat at nine in the evening. Every one of those is processing of personal data for which the school is the controller, and none of them appears in the privacy notice, the processor list or the retention schedule. The notice tells families their data goes to the school's systems. In practice some of it goes to personal phones and consumer apps the school has never assessed.

The gap has consequences beyond the notice. A subject access request covers those messages wherever they are held. A breach in one of them is the school's breach. And the transparency principle is not met by a notice that describes the intended system rather than the real one.

There are two honest ways to close it: describe the real routes in the notice and govern them, or give staff and parents a route the school controls and make it the one people use. ComplyChat is designed for the second: conversations with parents and between staff in a channel the school controls, recorded on the server as they are sent. Everyone added is told the channel is on the record and can object or leave, which is the transparency the notice promises, made visible at the point of use. A mobile number verified by SMS is the identity, so parents and staff without a school account can take part. On paid plans the lasting record files into the school's own Microsoft 365 once its tenant is connected, under its retention rules, and messages are stored and processed in the UK, with the supporting services that may process data outside the UK, such as the SMS verification code and push notifications, named on the published sub-processor list. It does not write the notice or replace the DPO's review, and a school should still list it, like any messaging supplier, in its notice and processor list.

A question for the next leadership or governors' meeting: if a parent asked where the messages they have sent to staff this year are held, could the privacy notice answer them truthfully?

07

Official guidance and your next step

The DfE's model privacy notices for schools and local authorities, with its guidance on issuing them, is the starting point, and the DfE's data protection in schools guidance covers the wider duties. The ICO's guidance on the right to be informed is the authority on content and presentation, and the text of Article 13 and Article 14 is on legislation.gov.uk. For what the DfE does with the data schools send it, read how DfE shares personal data. Quotations here are from those pages as read on 25 September 2026.

This guide is a practical summary for schools and academies in England, not legal advice on your own notice. Your DPO should review the final text.

Then do one thing: put the school's privacy notice for pupils and parents next to its list of processors and check that every system on the list appears in the notice, and every route staff use to message parents appears on the list.

Why we publish this

We build ComplyChat for the work conversations schools need to keep. A privacy notice promises families that the school knows where their data goes, and the messages sent to staff are where that promise is hardest to keep. Explore Free personal messaging, or compare the paid plans if your school needs a lasting Microsoft 365 record.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Model privacy notices for schools and local authorities gov.uk
  2. Data protection in schools gov.uk
  3. The right to be informed ico.org.uk
  4. Article 13 legislation.gov.uk
  5. Article 14 legislation.gov.uk
  6. How DfE shares personal data gov.uk