The rule: what requires the policy, and what it has to contain
The requirement sits in Part two of Keeping children safe in education 2026, the statutory guidance every governing body and proprietor must have regard to. Paragraph 123 lists the policies staff must be given at induction, and among them is “a staff behaviour policy (sometimes called the code of conduct) which should, amongst other things, include low-level concerns, allegations against staff and whistleblowing, plus acceptable use of technologies (including the use of mobile devices), staff/pupil relationships and communications including the use of social media”. That sentence is the whole legal basis for a staff–pupil communication policy: it can be a chapter of the code of conduct or a document of its own, but the governing body has to be able to point to where those words are answered.
Behind the guidance are three pieces of law. Section 175 of the Education Act 2002 requires the governing body of a maintained school to exercise its functions “with a view to safeguarding and promoting the welfare of children who are pupils at the school” and to “have regard to any guidance given from time to time by the Secretary of State”; the Education (Independent School Standards) Regulations 2014 place the same duty on the proprietor of an independent school, which for an academy is the trust. The Teachers’ Standards, Part Two, require every teacher to uphold public trust “within and outside school” by “treating pupils with dignity, building relationships rooted in mutual respect, and at all times observing proper boundaries appropriate to a teacher’s professional position”. And the footnote to paragraph 123 reminds the drafter of section 16 of the Sexual Offences Act 2003: it is an offence for a person aged 18 or over in a position of trust to have a sexual relationship with a child under 18 “even if the relationship is consensual”, and the position of trust covers anyone who “looks after children under 18 in the same establishment as the child, even if they do not teach the child”.
A note on what a search turns up. Much of what is published under “teachers messaging students policy” is American: school-district policies on “electronic communication” between staff and students, written to state law and district-approved platforms, with mandatory reporting rules that have no counterpart here. The rules for school staff in England come from KCSIE, the safer working practice guidance and the Teachers’ Standards, and they are stricter in one respect – there is no approved list of personal channels, because there are none – and simpler in another, because the whole policy can be stated as a boundary rather than a catalogue of apps.
So the policy is not a courtesy document about professionalism. It is the school’s statement of the boundary the Teachers’ Standards require, written so that a member of staff can tell in advance which side of it a message falls, and so that the school can show, when asked, that it set the boundary and kept a record of what happened at it.
What the policy has to cover in practice
A policy that meets paragraph 123 answers the situations staff actually meet, not the ones a drafter imagines. In a typical secondary school those are:
- Which channels may carry a message from a member of staff to a pupil at all: the school’s learning platform and the school email account, and nothing else, is the usual answer, with the school’s own phones for trips and remote teaching. Homework, an assignment deadline, a change to the fixture schedule and a co-curricular club notice all go through the same school channels, and to the class or group rather than to one child.
- Personal contact details: the staff member’s mobile number, personal email addresses and social networking identities are never given to a pupil, and the policy says what to do when a pupil finds them anyway.
- Social media: friend and follow requests to personal social media accounts from current pupils, from pupils who have just left, and from parents; comments on a pupil’s posts; staff profiles that pupils can see; and what teaching staff and support staff may say about the school online.
- Group chats: whether any staff member may ever be in a chat with pupils in it (the team, the trip, the revision group), on which platform, who else must be in it, and who can see it afterwards.
- Hours and tone: when a message may be sent, what it may say, and the rule that a one-to-one exchange with a pupil is never the place for anything personal, humorous or private.
- Trips, fixtures and residentials: the school-provided phone, the emergency number given to pupils and parents, and what happens to the messages afterwards.
- Remote and online lessons: the platform, the settings, and the rule that a lesson is never one adult and one child in a private call unless the policy says so and someone else knows.
- Sixth-formers, former pupils and pupils who are 18: the position of trust does not end on a birthday, and the policy says when, if ever, contact with a former pupil is acceptable.
- Images: never on a personal device, contrary to school policy, which KCSIE gives as its own example of a low-level concern.
- What a pupil does: the pupil-facing version, so that a child who is contacted inappropriately by an adult knows it is not allowed and knows who to tell.
Two rules from Part two of KCSIE sit alongside all of that. Paragraph 170 says “all schools should be mobile phone-free environments by default; anything other than this should be by exception only”, so in the school day the pupil side of the exchange should not exist. And the policy is given to every member of staff at induction, including supply staff, volunteers and contractors on a “proportionate risk-based approach” (paragraph 125), because the boundary applies to the visiting coach as much as to the head of year.
The standard the sector already uses: safer working practice
Most schools do not write the communication rules from scratch; they adopt the Safer Recruitment Consortium’s Guidance for safer working practice for those working with children and young people in education settings, last revised in February 2022 to fold in KCSIE’s low-level concerns expectations. It is non-statutory, but Ofsted inspectors, local authority designated officers and disciplinary panels all know it, and section 12, “Communication with children (including the use of technology)”, is the sector’s working definition of the boundary.
Its starting point is that “communication with children both in the ‘real’ world and through web based and telecommunication interactions … should take place within explicit professional boundaries”, and it lists what that includes: “computers, tablets, phones, texts, e-mails, instant messages, social media such as Facebook and Twitter, chat-rooms, forums, blogs, websites, gaming sites, digital cameras, videos, web-cams and other hand-held devices”, adding that the list “gives examples only and is not exhaustive”. The rules that follow are short enough to quote in the policy itself:
- “Staff should not request or respond to any personal information from children other than which may be necessary in their professional role. They should ensure that their communications are open and transparent and avoid any communication which could be interpreted as ‘grooming behaviour’.”
- “Staff should not give their personal contact details to children for example, e-mail address, home or mobile telephone numbers, details of web-based identities. If children locate these by any other means and attempt to contact or correspond with the staff member, the adult should not respond and must report the matter to their manager. The child should be firmly and politely informed that this is not acceptable.”
- Staff should “not seek to communicate/make contact or respond to contact with pupils outside of the purposes of their work”, should “use only the equipment and internet services provided by the school or setting, unless school policies state otherwise”, and should “not discuss or share data relating to children/parents/carers in staff social media groups”.
The guidance then turns the rule on the employer, and this is the clause schools most often leave out: education settings should “wherever possible, provide school devices such as cameras and mobile phones rather than expecting staff to use their own (e.g. on school trips, remote teaching, etc)”. A policy that forbids personal contact details while sending staff on a residential with only their own phones has written a rule it has made impossible to keep. The device budget is part of the policy.
Writing the clauses
With the rule and the standard in hand, the school can write practical clauses. The suggestions below are policy choices to adapt to the setting, rather than a statutory checklist; allow for legitimate family relationships and authorised exceptions, with safeguarding advice where needed.
- The channel rule. Name the platforms staff may use for electronic communication with a pupil (the school’s learning platform, school email, school-owned phones for trips and remote lessons) and state that every other channel – personal mobile, personal email, WhatsApp, Snapchat, Instagram, gaming chat and the rest – is prohibited for any communications with students, for any purpose, at any hour, including contact with students outside of school. The exception process, if the school wants one, goes through a senior member of staff in advance and in writing.
- The contact-details rule, in the safer working practice wording, with the two follow-on steps: what the staff member says to the pupil, and the report to the manager, which is itself a record (below).
- Social media. No friend, follow or connection with a current pupil on any personal account; privacy settings that keep personal accounts out of pupils’ view; no comment on a pupil’s public content; and a rule for former pupils that names an age and a time since leaving, because “not until they have left” is where most breaches happen.
- Group chats. Either none with pupils in them, or only on the school’s platform, created by the school, with at least two members of staff in every group, visible to the designated safeguarding lead, and closed when the trip or the season ends. A staff member who is added to a pupils’ group on a consumer app leaves it and reports it.
- Tone, hours and content. Messages to pupils are about the work, are written as if the parent and the headteacher will read them, and are sent in the school day unless the activity (a trip, an evening fixture) says otherwise. Nothing about the staff member’s own life; nothing improper, nothing that could not be said in front of the class; and no personal data about another pupil or family.
- Self-referral. KCSIE paragraph 519 asks schools to create an environment where staff “feel confident to self-refer” when they “have found themselves in a situation which could be misinterpreted”. The policy says how: a message to the DSL or the head, the same day, assessed under the appropriate safeguarding route and recorded with the staff member’s own account of it.
- Images. Photographs and video of pupils only on school devices, only under the school’s image policy and the consents it holds, never on a personal phone.
- What pupils and parents are told. A short version in the pupil behaviour policy and the parent handbook: staff will not message you personally, will not accept you on social media, and here is who to tell if an adult does.
Draft it to be read in a corridor. The safer working practice guidance is right that “online risks are posed more by behaviours and values than the technology itself”; a policy that lists apps will be out of date by the next intake, while one that states the boundary in terms of purpose, channel and record will not.

When the boundary is crossed: low-level concern, allegation and the record
KCSIE 2026 gives the policy its teeth by tying every breach to one of two routes. A concern that an adult “may have acted in a way that is inconsistent with the staff code of conduct” but “does not meet the harm threshold” is a low-level concern (paragraph 509), and the term “does not mean that it is insignificant” – it covers anything “no matter how small, and even if no more than causing a sense of unease or a ‘nagging doubt’”. The guidance’s own examples include “being overfriendly with children”, “having favourites” and “taking photographs of children on their mobile phone, contrary to school policy”. A teacher who replies to a pupil’s message from a personal account, adds a pupil on a social platform or is found in a pupils’ group chat may fall within that definition; assess the context, the code and whether the harm threshold may be met, and paragraph 510 says why the school still has to act: such behaviour “can exist on a wide spectrum, from the inadvertent or thoughtless … through to that which is ultimately intended to enable abuse”.
The harm threshold itself is set out in Part four, section one, paragraph 437: an allegation is where a person “behaved in a way that has harmed a child, or may have harmed a child”, “possibly committed a criminal offence against or related to a child”, “behaved towards a child or children in a way that indicates he or she may pose a risk of harm to children”, or “behaved or may have behaved in a way that indicates they may not be suitable to work with children”. A message suggesting sexual misconduct or grooming may meet the harm threshold and needs immediate handling through the allegations procedure and consultation with the local authority designated officer. Concealment is a concern to assess in context, rather than a separate automatic threshold. Paragraph 518 covers the doubt in between: “if schools and colleges are in any doubt as to whether the information which has been shared … meets the harm threshold, they should consult with their LADO.”
Whichever route, the school keeps a record, and paragraphs 520 to 523 say what it looks like. “All low-level concerns should be recorded in writing. The record should include details of the concern, the context in which the concern arose, and action taken”, with the name of the person who raised it noted (or their anonymity respected “as far as reasonably possible”). Records “must be kept confidential, held securely and comply with data protection laws”, and – the sentence that matters most for communication breaches – they “should be reviewed so that potential patterns of inappropriate, problematic or concerning behaviour can be identified”. One reply to a pupil at ten at night is a conversation with the teacher; the third, in the file, is a pattern that paragraph 522 says may “move from a low-level concern to meeting the harm threshold”. Retention is recommended “at least until the individual leaves their employment” (paragraph 523), and paragraph 524 keeps the two routes apart in references: substantiated allegations that meet the harm threshold are disclosed, while “a low-level concern which relates exclusively to safeguarding (and not to misconduct or poor performance) should not be referred to in a reference”.
The paragraph most policies never answer: where the message ends up
Read the clauses above again and notice what they assume. Every one of them describes a message – the pupil who found a teacher’s Instagram, the reply that should not have been sent, the report to the manager, the self-referral to the DSL, the group chat that should have been closed – and the school’s ability to act on any of it depends on being able to see the message. The policy needs to establish which system holds each of them.
The pupil’s message arrives on the teacher’s personal phone, in an app the school cannot open. The teacher’s report to the head of year, done properly and promptly, is a WhatsApp at half past nine because that is where the head of year answers. The self-referral is a text. The trip group is a chat on a parent’s phone that nobody at school was ever in. When the LADO asks what was said and when, or the disciplinary panel asks whether the pattern was visible, the school is asking individuals to hand over screenshots from devices it does not own, and the only contemporaneous record of a safeguarding conversation is a personal export whose completeness nobody can verify.
The policy fixes the pupil side of this by closing the channels: staff simply do not communicate with pupils outside the school’s systems, and the school provides the devices so the rule can be kept. It cannot fix the staff side the same way, because the report, the referral and the discussion between adults about the pupil are exactly the conversations that have to happen out of hours and away from a desk. Those are records within the meaning of paragraph 520, and if they are in a consumer app on a personal handset the school does not hold them. Everyone added to a channel the school runs can be told it is on the record; nobody in a personal chat has been told anything.
Use a restricted reporting route, with access limited to the people who need the information. A recorded message is not proof that someone has read or acted on a concern: follow the safeguarding procedure, contact the responsible person directly when action is urgent, and use the local authority or emergency route when required. Add the relevant information and decisions promptly to the formal safeguarding record.
So the question to take to the next governors’ or trustees’ meeting is not whether the school has a staff–pupil communication policy. It is this: when a pupil contacted a member of staff inappropriately last term, could the school produce, today, the message, the report and the conversation that followed, from systems it controls?
Official guidance and your next step
The primary sources are Keeping children safe in education 2026 (Part two, paragraph 123 on the staff behaviour policy; paragraph 170 on mobile phones; Part four, section one on allegations and section two, paragraphs 508 to 528, on low-level concerns), the Safer Recruitment Consortium’s Guidance for safer working practice (2022, section 12), the Teachers’ Standards (Part Two), section 175 of the Education Act 2002 and section 16 of the Sexual Offences Act 2003. Farrer & Co’s guide to developing a low-level concerns policy, which KCSIE itself cites at paragraph 528, is the fullest treatment of the recording side.
This guide is a summary of published guidance for England, not a substitute for it and not legal advice. Independent schools should read the Independent School Standards alongside KCSIE; colleges should read the college-specific paragraphs.
Then do one thing: ask the designated safeguarding lead to list every occasion in the last year on which a pupil contacted a member of staff outside the school’s systems, and for each one, where the message, the report and the follow-up are now. If the answer for any of them is “on someone’s phone”, that is the gap the policy has to close.
We build ComplyChat for the work conversations organisations need to keep. The organisational archive described here is available on paid plans, with a connected Microsoft 365 tenant and retention configured by the organisation. It is not a channel for pupils and it does not replace a school’s learning platform. It is the channel the adults use: the report to the designated safeguarding lead at nine at night, the head of year’s conversation with the class teacher, the trip leader’s messages to the office, and the school’s channels with parents and families, who are outside the organisation and have no school account. Every channel is owned by the school, works on a compatible phone including a personal one, is on the record from the first message with everyone in it told so, and files into the school’s own Microsoft 365 once the tenant is connected, under the school’s own retention rules. A member of staff’s own messages stay in their own apps. There is no WhatsApp, Signal or Meta anything in the path.
How it works · Why us · Pricing · FAQ



