5 Data Protection & Cyber Security Updates Every School Should Know This Week
- Gerard Strong
- Jul 6
- 4 min read
Published: 6 July 2026
Category: Weekly Intelligence
Welcome to the SchoolDPO Weekly Intelligence Round-up
The pace of change in data protection, cyber security and artificial intelligence is accelerating, making it increasingly difficult for schools to keep up.
Each week, SchoolDPO.com reviews updates from the Information Commissioner’s Office (ICO), Department for Education (DfE), National Cyber Security Centre (NCSC), Ofqual, JCQ and other trusted sources to identify the developments that matter most for schools, academies and trusts.
Rather than simply reporting the news, our aim is to explain what these developments mean in practice and identify the actions schools should consider.
Here are this week’s five key developments.
1. AI in Coursework Is Under Increasing Scrutiny
Artificial intelligence continues to transform education, but it also presents new challenges for schools.
This week, Ofqual’s Chief Regulator highlighted growing concerns about the use of AI in coursework and warned that traditional written assessments face increasing risks from AI-assisted work.
While AI itself isn’t prohibited, schools need confidence that submitted work genuinely reflects a student’s own knowledge, understanding and skills.
What should schools do?
Now is an ideal time to review:
AI guidance for pupils
Staff expectations around AI use
Assessment and coursework policies
Academic integrity procedures
Evidence of drafting and student ownership of work
Schools should also ensure that staff understand the latest JCQ guidance on malpractice and authentication.
SchoolDPO Tip
AI is here to stay. The question is no longer whether students will use it, but whether schools have clear expectations about when its use is acceptable.
2. Schools Should Ask Their IT Provider About Fortinet Security
Recent reporting has highlighted concerns surrounding compromised credentials linked to Fortinet devices.
Many schools use managed IT providers and may not know whether Fortinet products form part of their network infrastructure.
Although this issue won’t affect every school, it serves as a useful reminder that cyber security isn’t simply about installing updates.
Weak passwords, old administrator accounts and poor access controls continue to be among the biggest causes of cyber incidents.
Questions every school should ask
Do we use Fortinet products?
Has Multi-Factor Authentication been enabled?
Have administrator passwords recently been changed?
Are inactive accounts removed promptly?
Are security logs actively monitored?
If your school outsources IT, ask your provider to confirm these checks have been completed.
3. Summer Is the Best Time to Review Your GDPR Compliance
The summer holiday offers schools a valuable opportunity to complete governance and compliance work without the daily pressures of teaching.
Before September, schools should review:
Data Protection Policy
Privacy Notices
Subject Access Request procedures
Records Retention Schedule
Data Sharing Agreements
Data Breach Procedure
Staff training records
AI guidance
Small improvements now can prevent larger problems later in the year.
4. Governors Should Be Asking More Questions About Cyber Security
Cyber security is no longer just an IT responsibility.
It is a governance issue.
Governors and trustees should receive regular assurance that appropriate controls are in place.
Useful questions include:
Have staff completed cyber security training?
Are backups tested?
Is Multi-Factor Authentication enabled?
What would happen if our MIS became unavailable tomorrow?
Have we recently experienced any cyber incidents?
Cyber security should be considered alongside safeguarding, finance and health and safety within the school’s risk register.
5. Artificial Intelligence Policies Are Becoming Essential
Many schools now use generative AI to:
draft communications
support lesson planning
summarise documents
create resources
improve productivity.
However, schools also need clear rules.
Every member of staff should know:
which AI tools have been approved
what personal information must never be entered
when approval is required
who to contact if unsure.
If your school doesn’t yet have an AI Policy, now is the ideal time to develop one before September.
Five Practical Actions This Week
✔ Review your AI guidance for staff and pupils.
✔ Ask your IT provider to confirm cyber security controls.
✔ Check that Multi-Factor Authentication is enabled for key accounts.
✔ Review your Subject Access Request procedure.
✔ Schedule a GDPR policy review before the start of term.
SchoolDPO.com’s View
Schools are increasingly expected to demonstrate not only compliance with data protection law, but also strong governance around technology, artificial intelligence and cyber security.
The schools that are best prepared are not necessarily those with the biggest budgets—they are the ones that regularly review their policies, train staff and ask the right questions.
By making compliance a continuous process rather than an annual exercise, schools can reduce risk, improve confidence and be better prepared for whatever the new academic year brings.
Need Support?
Whether you’re reviewing policies, responding to a Subject Access Request, managing a data breach or looking for an independent Data Protection Officer, SchoolDPO.com is here to help.
We support schools, academies and trusts with:
Independent DPO Services
GDPR Compliance Audits
Subject Access Requests
Data Breach Support
Policy Reviews
Staff Training
AI Governance
Cyber Security Advice
Visit www.schooldpo.com to explore our growing library of free guidance, practical resources and compliance tools designed specifically for schools.
Useful Resources
Information Commissioner’s Office (ICO): https://ico.org.uk/
Department for Education – Data Protection in Schools: https://www.gov.uk/guidance/data-protection-in-schools
National Cyber Security Centre (NCSC): https://www.ncsc.gov.uk/
Joint Council for Qualifications (JCQ): https://www.jcq.org.uk/
Next Week on SchoolDPO Weekly Intelligence
Preparing for September: Your GDPR Checklist
AI Policies for Schools – What Should Be Included?
Cyber Security Questions Every Governing Board Should Ask
Understanding the New Data Protection Complaints Process


Comments