top of page

Schools Are Back: 7 Data Protection Checks to Complete This September

Sep 5
6 min read

The first few weeks of a new academic year are some of the busiest in any school.

New pupils arrive. New staff start. Accounts are created. Parents provide updated information. New software may be introduced, suppliers change and thousands of pieces of personal information begin moving around the school again.

So while nobody needs another enormous September checklist, there are a few data protection checks worth completing now.

This year there is another important consideration: AI.

During August, the Department for Education updated its model privacy notices for 2026/27 and also updated its filtering and monitoring standard to make the connection with generative AI clearer.

Here are seven practical checks I would recommend every school, academy and trust completes during the first few weeks of term.


1. Review your privacy notices for 2026/27

The Department for Education updated its model privacy notice documents for the 2026/27 academic year on 13 August 2026.

This doesn’t mean schools should simply download the latest DfE template and replace their existing privacy notices.

The important question is:

Does our privacy notice accurately describe what we actually do with personal information?

Think about what may have changed during the last year.

Have you introduced:

  • a new safeguarding platform?

  • a different parent communication app?

  • electronic visitor management?

  • cashless catering or payment systems?

  • new CCTV?

  • another cloud service?

  • new EdTech?

  • an AI application?

  • a different attendance or management information system?

If the way you process information has changed but your privacy notice hasn’t, the two may no longer match.

DfE recommends that privacy notices are reviewed at least annually and whenever there is a significant change to processing.

September action: review your pupil/parent, workforce and governor/trustee privacy notices against both the new DfE models and what is actually happening in your school.


2. Make sure new staff have completed data protection and cyber security training

September often brings new teachers, teaching assistants, administrators, therapists, support staff and leaders.

All of them will quickly have access to personal information.

Don’t leave GDPR and cyber security training until later in the year.

New staff should understand from the beginning:

  • how to handle personal information;

  • how to recognise phishing;

  • what can and cannot be shared;

  • how to use email securely;

  • what constitutes a data breach;

  • how to report a breach;

  • what to do if they receive a Subject Access Request;

  • how the school expects AI to be used.

And remember: providing training isn’t the same as knowing that it has been completed.

Schools should be able to identify who has completed mandatory training and who still needs to do it.


3. Check that leavers’ accounts have actually been disabled

This is a very simple check, but an important one.

Staff leave schools at the end of the summer term. Some change roles. Temporary staff finish contracts. External users may no longer require access.

Ask your IT provider or internal IT team:

Are there any active accounts belonging to people who no longer work here?

Check access to:

  • Microsoft 365 or Google Workspace;

  • MIS;

  • safeguarding systems;

  • HR and payroll;

  • finance systems;

  • cloud storage;

  • shared drives;

  • remote-access services;

  • specialist school applications.

Removing unnecessary access is both a cyber-security measure and a fundamental part of good data protection.


4. Check MFA and administrator accounts

Cyber criminals don’t always need a sophisticated technical attack.

Sometimes they simply need a password.

Multi-factor authentication provides an important additional layer of protection if a password is stolen.

Schools should particularly review accounts with elevated or administrative privileges.

Check:

  • Is MFA enabled wherever it reasonably can be?

  • Who has administrator rights?

  • Does everyone with administrator access still need it?

  • Are shared administrator accounts being avoided?

  • Are unusual sign-ins monitored?

  • Have old accounts been removed?

A compromised administrator account can turn a relatively small phishing incident into a serious school-wide cyber incident.


5. Include generative AI in your filtering and monitoring review

This is particularly important for 2026/27.

On 25 August 2026, DfE updated its filtering and monitoring standard and linked it explicitly to its Generative AI Product Safety Standards.

Traditional web filtering was largely designed around a straightforward concept: a user requests online content and the system decides whether that content should be permitted.

Generative AI changes that.

AI can create new, personalised content in real time, sometimes inside an application rather than on a conventional website.

That creates an important question:


Can our existing filtering and monitoring arrangements actually identify inappropriate content generated within the AI tools our pupils use?

Your annual filtering and monitoring review should therefore consider AI explicitly.

That conversation should involve the appropriate people across safeguarding, leadership, governance and IT rather than being treated purely as a technical exercise.


6. Find out which AI tools staff are actually using

This may be one of the most useful questions you ask this term:

“Which AI tools are staff currently using for their work?”

You may be surprised by the answer.

Generative AI can save staff considerable amounts of time.

A teacher might use it to improve a lesson plan.

A leader might ask it to restructure a report.

An administrator might use it to draft correspondence.

Those uses can be perfectly reasonable.

The problem begins when personal or confidential information is entered into a service that the school hasn’t assessed.

For example, somebody might ask an AI system to:

  • improve a pupil report;

  • summarise behaviour information;

  • analyse assessment data;

  • draft an EHCP contribution;

  • translate communication about an individual child;

  • summarise safeguarding information.

Suddenly, the question isn’t simply whether AI is useful.

It becomes:


What information have we just given to the AI provider?

Schools need to understand where information goes, how long it is retained, whether it is used to develop models, who can access it and whether it can be deleted.


A sensible starting rule is:

Staff should not enter personal, confidential or safeguarding information into an AI service unless the school or trust has approved that service for the intended purpose.

That doesn’t prevent sensible use of AI.

It allows schools to benefit from AI while retaining appropriate control over their information.


7. Make sure everyone knows what to do when something goes wrong


Imagine that at 9:15 tomorrow morning:

  • a teacher emails a spreadsheet containing pupil information to the wrong parent;

  • a member of staff clicks a convincing phishing link;

  • a laptop containing school information disappears;

  • a supplier tells you its systems have been compromised;

  • or a parent asks for “all the information you hold about my child”.


Would the person receiving that information know what to do next?

Speed matters.

Staff don’t need to understand every detail of UK GDPR.

They do need to know how to recognise a potential problem and where to report it.

A simple message can be more effective than pages of policy:


If you think personal information may have been lost, disclosed, accessed or sent incorrectly, report it immediately. Don’t wait until you know whether it is definitely a data breach.

The DPO can then help assess what has happened and determine what needs to happen next.

The same principle applies to Subject Access Requests. Staff should know where to forward a request immediately rather than leaving it sitting in an inbox.


One extra question: what happens if one of your suppliers is hacked?


Recent cyber incidents provide another reminder that your school doesn’t have to be directly hacked for your data to be compromised.

Schools increasingly depend on external providers for:

  • MIS;

  • safeguarding;

  • HR;

  • payroll;

  • communications;

  • payments;

  • catering;

  • cloud storage;

  • learning platforms;

  • assessment;

  • EdTech and AI.


Those organisations may hold significant amounts of school information.

For your higher-risk suppliers, make sure you know:

  • what information they hold;

  • where it is stored;

  • what security controls protect it;

  • whether MFA protects privileged access;

  • which sub-processors they use;

  • how quickly they will notify you of an incident;

  • how information is deleted when the contract ends.


A data processing agreement is important, but good supplier assurance shouldn’t stop once the contract has been signed.


Data protection doesn’t need to dominate September

Schools have far more important things to do than spend the first few weeks of term buried in GDPR paperwork.

Good data protection should make things simpler and safer, not create unnecessary bureaucracy.


For most schools, the September conversation can start with seven questions:

  1. Are our privacy notices current?

  2. Have new staff completed their training?

  3. Have leavers’ accounts been disabled?

  4. Are MFA and administrator access properly controlled?

  5. Does our filtering and monitoring review include generative AI?

  6. Do we know which AI tools staff are using?

  7. Would everybody know what to do if there was a breach or SAR tomorrow?


If you can confidently answer yes to all seven, you’re starting the academic year in a strong position.


If you can’t, that’s exactly what your DPO should be helping you with.


Looking for a DPO for 2026/27?

SchoolDPO provides independent Data Protection Officer support specifically for schools, academies and trusts.


The aim is straightforward: to take much of the worry around data protection away from school leaders and make compliance practical.

We can support you with:

  • day-to-day DPO advice;

  • data breaches;

  • Subject Access Requests;

  • policies and privacy notices;

  • DPIAs;

  • AI and EdTech;

  • information sharing;

  • staff advice and training;

  • compliance monitoring;

  • and those awkward data protection questions where you’re simply not sure what to do.


Thinking about changing your DPO for 2026/27?

SchoolDPO provides practical, independent DPO support for schools, academies and trusts.




👉 View the SchoolDPO service and pricing


Official guidance

DfE – Data protection and privacy: privacy notices


DfE – Filtering and monitoring core standard


DfE – Generative AI: product safety standards

 
 
 

Comments


DPO member
INCENSU Logo

Follow us on Linked IN

  • Linkedin

Contact us

School DPO
bottom of page