ComplyChat Start free

Guide · Schools

Secure messaging app for schools

Most lists of the best secure messaging apps are written for private individuals, and they rank apps by one thing: whether anyone other than the sender and the recipient can read the messages. A school's needs are different. It has to know who is in a conversation, keep a record it can produce for a subject access request or a safeguarding review, delete that record on schedule, and include people who have no school account, from supply staff to parents. This guide sets out what "secure" has to mean for a school in England, the criteria to judge an app against, the questions to put to a supplier, and the honest alternatives, including the ones that cost nothing.

By ComplyChatPublished 11 minute read

A primary school teacher and a parent walking together beside a coach in a school car park at dawn before a residential trip, children's bags stacked by the kerb
01

What "secure" has to mean for a school

In short

For a school, a secure messaging app is one where the school knows who is in each conversation, the messages are encrypted in transit and at rest, the school holds the record and can produce it, the right people can see what safeguarding requires, messages are kept and deleted to the school's schedule, and parents and staff without school accounts can take part without anyone's personal number being shared.

End-to-end encryption answers only the second of those, and it makes the third much harder. Decide which of these the conversations you are choosing for actually need.

A consumer review of secure messaging apps asks whether messages are end-to-end encrypted, whether the code is open source, whether metadata is collected and whether the company can read your messages. Those are good questions for a private person protecting their privacy. A school is not a private person. It is the data controller for what its staff say about pupils and families, it is a public authority for Freedom of Information if it is a maintained school or academy, and it carries safeguarding duties under Keeping children safe in education 2026 (KCSIE 2026), which expects the staff behaviour policy to cover acceptable use of technology and communications between staff and pupils.

So for a school, "secure" has at least six parts:

  • Identity. Every person in a conversation is who the school thinks they are, was added by someone entitled to add them, and is removed when they leave.
  • Confidentiality. Messages are encrypted on the way and in storage, and nobody outside the conversation and its authorised administrators can read them.
  • The record. The school, not each phone, holds a copy it can search and produce.
  • Safeguarding access. The designated safeguarding lead can see what the school's policy says they may see, and every such access is itself recorded.
  • Retention. Messages are kept for the period the school's retention schedule sets, and deleted when it ends.
  • Reach. The people the school actually needs to talk to can be included, on terms that protect them too.

Most apps are strong on one or two of these. The buyer's job is to know which matter for which use case, because the sensitive data in a school's messages is mostly about children.

02

Who a school needs to message, and why that decides the choice

The right app depends less on features than on who is in the conversation. A typical school has at least five groups, and they sit differently.

  • Staff with school accounts. Teachers and office staff usually have Microsoft 365 or Google Workspace accounts, and the chat that comes with them already meets most of the criteria in this guide for conversations among themselves.
  • Staff and helpers without accounts. Supply and peripatetic teachers, sports coaches, lunchtime supervisors, volunteers and the minibus driver often have no account, and are the people most likely to be added to a staff group on a personal phone.
  • Governors and trustees. Often on personal email, deciding things between meetings in whatever group is to hand.
  • Parents and carers. Outside the organisation entirely, and the group with whom one-to-one conversations most need a record: attendance, behaviour, a concern about a child.
  • Pupils. Governed by the school's staff–pupil communication rules, which for most schools allow only the learning platform and school email. Our guide to the staff–pupil communication policy covers that boundary, and nothing in this guide changes it.

A school whose only need is staff talking to staff with accounts does not need to buy anything. A school whose difficult conversations cross the boundary, to supply staff, governors and families, has a different problem, and it is the one the rest of this guide is mostly about.

03

The criteria, one by one

  1. Identity and membership. How is each person identified: a school account, a verified phone number, an email address? Who can add people to a group chat, and can the school remove a leaver from every conversation at once? An app where anyone can add anyone, tied to a phone number the school does not know, fails here however strong its encryption.
  2. Encryption and where data is stored. Messages should be encrypted in transit and at rest as a minimum. Ask where data is stored and processed, which sub-processors touch it, and whether any of it leaves the UK. End-to-end encryption, in which only the devices of the sender and the intended recipient hold the encryption keys to decrypt a message, protects content from the provider, but it makes it much harder for the school to hold a record of its own: the provider has nothing it can read, so the school has a copy only if the product adds an archive as a participant in the conversation or someone exports it; see criterion 3.
  3. The record. Can the school search and export a conversation, with who said what and when, without borrowing a member of staff's phone? A subject access request must normally be answered within one month, and the ICO's guidance on non-corporate communications channels asks public authorities to use corporate channels for official business and to store official information on corporate systems "as quickly as possible" where they cannot.
  4. Safeguarding access. Who, other than the participants, can read a conversation: the DSL, the head, an administrator? Is that access logged? Are staff and parents told? Access that is written into policy and recorded is proper oversight; access that nobody was told about is not.
  5. Retention and deletion. Does the school set the retention period, or does the product? Can messages be kept for as long as the records they belong to, and deleted when the schedule says? A free tier that deletes history after a few months decides the school's retention for it, and so do disappearing messages, a setting many private messaging apps offer for user privacy; the ICO asks that auto-delete options match the retention policies of official systems.
  6. Parents and people without accounts. Can a parent message the school without a member of staff's personal number, and without every other parent in a group seeing theirs? Can a supply teacher join for a term and be removed at the end of it?
  7. Account security. The Department for Education's cyber security standard expects schools to "control and secure user accounts and access privileges", including multi-factor authentication on staff accounts that reach cloud services. Ask how the app signs people in, how an administrator's own access is protected, and whether voice and video calls, file sharing and any third-party integrations follow the same rules as text messages.
  8. Usability. Staff will use the app that is quickest on a phone at 7am. An app that is secure and awkward loses to a consumer app that is neither governed nor awkward, and the school ends up with both.
04

The honest alternatives

No single product does everything a school needs, and for several of the groups in section 02 the best option is one the school already has. Taking them in turn:

  • Staff with school accounts: Microsoft Teams or Google Chat. Included in the licences most schools hold, managed by the school's own administrators, and within reach of its own retention and search. For staff talking to staff, this is usually the right answer and costs nothing more. For a supply teacher on a long placement, consider whether a school account for the length of the placement would bring them inside the same rules before looking further.
  • Parents, one to many: the school communication platform or parent app linked to the MIS. Built for announcements, letters, payments, trip consent and attendance messages to whole year groups. Good at one-to-many; check how two-way conversations with a parent are kept, who at the school can see them, and whether they reach the school's retention schedule.
  • Governors: a school email address each, and the minutes. A school address keeps governance correspondence out of personal inboxes and within the school's own search. In a maintained school, a decision taken by chair's action between meetings should be "reported in writing to the governing body as soon as possible and recorded in governing body minutes", in the words of the Department for Education's governance guide; our guide to the chair of governors' responsibilities covers when chair's action is allowed.
  • The conversations at the edge. For supply staff, coaches and volunteers without accounts, and a parent's one-to-one worry about a child, the choice is between a consumer messaging app, where the school controls nothing, not membership, not retention, not the copy, and a group shares every member's number (our guide to WhatsApp in schools covers the position in detail); an end-to-end encrypted messenger sold to organisations, with the trade-off in criterion 2; and a messaging service built to keep a record, encrypted in transit and at rest, with the school holding the copy.

Many schools will end up with two or three of these, each for the conversations it suits. What matters is that the staff messaging policy says which channel carries what, so that a concern about a child never ends up in the one that keeps nothing. Our guide to choosing a GDPR compliant messaging app covers the data protection side of that choice.

A designated safeguarding lead and a supply teacher talking quietly in a sunlit secondary school stairwell between lessons, pupils blurred passing on the landing above
05

Questions to ask a supplier, and the DPIA

The Department for Education's guidance on procuring educational technology sets the data protection checks, and a messaging app is within it. It reminds schools that "You must complete a DPIA when the processing of personal data is likely to result in a high risk to the rights and freedoms of individuals", and messages about children and families, some of them special category data, usually meet that test. Involve the school's data protection officer from the start. The questions worth putting to any supplier, and keeping the answers to:

  1. Will you sign a data processing agreement that assigns responsibilities for security, sub-processors, deletion and breach notification, as the DfE guidance expects?
  2. Where is data stored and processed, and what international transfers are there, if any?
  3. What technical measures do you use, such as "encryption, secure authentication, audit logging", and what independent security assessment can you show?
  4. Who at your company can read message content, in what circumstances, and is that access logged?
  5. How long is data kept, can the school set that, and what happens to it at the end of the contract?
  6. Can we export a complete conversation for a subject access request, a safeguarding review or a tribunal, and in what form?
  7. If pupils will use it, does it meet the ICO's Children's code, the age appropriate design code?
  8. What happens to a staff member's access, and to the school's copy of their conversations, when they leave?

Write the answers into the DPIA and keep it with the contract. A supplier who cannot answer questions 4 to 6 in plain English has told you what you need to know.

06

The conversation at the edge of the school

The conversations that test a school's messaging are rarely the ones between two teachers at their desks. They are at the edge. The Year 6 teacher on a residential trip, messaging parents from her own phone because the coach is late. The supply teacher who is not on Teams and hears a disclosure on his third day. The chair of governors agreeing an urgent decision with the head in a group that includes her personal number. The parent who has the class teacher's number from last year's trip and sends a worried message on a Sunday.

Each of those is a record: a message about a child, a safeguarding concern, a governance decision. None is in the school's systems, and most involve someone the school's systems were never designed to include.

ComplyChat is built for those conversations. A mobile number verified by SMS is an identity on it, so supply staff, governors, volunteers and parents can be in a channel without a school account, and without a member of staff giving out a personal number. Messages are recorded on the server as they are sent, and everyone added to a channel is told it is on the record and can object or leave. On paid plans the lasting record files into the school's own Microsoft 365 once its tenant is connected, under the school's retention rules, where its subject access searches already reach. It is not end-to-end encrypted, by design, because the school has to be able to hold the record. It is not a school communication platform for newsletters, payments or attendance, and it does not change the school's rules on staff messaging pupils. ComplyChat Free is one private group, direct messages, up to 25 staff and three calendar months of recent history, with no Microsoft 365 archive, so it cannot meet a retention duty.

A question for the next senior leadership or governors' meeting: when a supply teacher, a governor or a parent needs to reach a member of staff urgently, which app do they use, and could the school produce that conversation next term?

07

Official guidance and your next step

Read Keeping children safe in education 2026 for the safeguarding duties, the Department for Education's data protection in schools guidance, including its section on procuring EdTech, and the digital and technology standards. The NCSC's guidance on choosing an enterprise instant messaging solution is a good framework for the security assessment. The Data (Use and Access) Act 2025 has amended UK GDPR and the Data Protection Act 2018 in stages, so check the date on any ICO or DfE page you rely on. Quotations here are from those pages as published on 25 September 2026.

This guide is general information for schools in England, not legal advice; Wales, Scotland and Northern Ireland have their own safeguarding guidance.

One step to take this half-term: ask your staff, anonymously, which apps they used last week to message colleagues, supply staff, governors or parents about school matters. Compare the answer with your staff messaging policy. The difference is the brief for whatever you choose.

Why we publish this

We build ComplyChat for the school conversations that cross the edge of the school's own accounts, with supply staff, governors and families, and that still have to be kept. A school that chooses well for its staff and its parents may need only what it already has; we would rather say that plainly than sell a product for a problem you do not have.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Non-corporate communications channels ico.org.uk
  2. Cyber security standard gov.uk
  3. Governance guide gov.uk
  4. Procuring educational technology gov.uk
  5. Keeping children safe in education 2026 gov.uk
  6. Data protection in schools gov.uk
  7. Digital and technology standards gov.uk
  8. Choosing an enterprise instant messaging solution ncsc.gov.uk