Data protection is essential: it means privacy and respect, and freedom from manipulation. This statement is never more pertinent and pressing than when it refers to schools, the data they hold, and the systems they use to keep it safe from loss, theft and exploitation. Here, I’ll walk you through the different types […]
Data protection is essential: it means privacy and respect, and freedom from manipulation. This statement is never more pertinent and pressing than when it refers to schools, the data they hold, and the systems they use to keep it safe from loss, theft and exploitation.
Here, I’ll walk you through the different types of data and data categories, and the systems you can use and steps you should take to keep data safe.
Data and data categories explained
Schools hold an incredible amount of data across a range of sensitive data categories. Below I’ve outlined what this information might look like.
Single central register
All schools must have a SCR, as required by Ofsted, the Department for Education, and as part of a school’s wider safeguarding responsibilities.
It will include an array of information relating to teaching, support, governors, volunteers, agency staff, identification documents details (i.e. passports and driving licences), rights to work, including all pre-employment checks, qualifications, and s128 checks (where relevant). It may also contain other information, such as medical details for staff and contractors.
This document should remain fully up-to-date, such as when new staff join, and protected by high levels of security.
Potential threats to data
A number of potential threats to data exist, many from those with malicious intent but others due to malfunction or even natural disaster:
The graph on page five of the Department for Digital Culture, Media and Sport’s Cyber Security Breaches Survey 2020 provides a revealing insight into the frequency of different types of breaches or attacks. For example, fraudulent emails or being directed to fraudulent websites accounted for 86 and 91 per cent of breaches or attacks in the 12 months 2019-20 for primary and secondary schools, respectively.
Onsite school systems
Research and identify systems that offer encryption both at rest and in transit and are based in countries with adequate protections. For example, the European Economic Area (EEA), New Zealand, Canada, the UK, or any other region/country contractually obliged to provide a high-level of protection for data, data breaches and data subject rights. This is particularly significant for suppliers which transfer and store data inside the USA.
The above guidance is also applicable to information management systems, emails, HR systems, apps and wherever else data is held and/or processed.
Ensure that data is safe when sent to and from these individuals and/or organisations. You can do so by checking that the recipients have adequate and robust contracts, agreements and safeguards in place. Consider the following: where do they process data? Do they have independent certification (i.e. ISO or Cyber Essentials)? Will they support and help you in the event of a breach, or should a student want access to the data about them that you process?
And finally, it’s important to remember: if the school’s system can and is accessed via mobile devices or laptops, then these must have the same security as the school’s system.
Getting the right policies in place
In addition to a Data Protection Policy, schools must have a number of other policies in place to support and govern the above guidance. These include:
For more information regarding data protection policies and systems, and appointing a data protection officer, see our other blog: Your school’s data protection protocols: reassuring your governors.
Child protection and safeguarding information
This is some of the most sensitive data a school is likely to hold and therefore requires the highest levels of security. Most schools now use platforms and apps to protect this data, such as Sleuth or CPOMS, but others are available.
Some schools still insist on keeping files in paper form – this really is not recommended, for a number of reasons. Primarily because you need to have a back-up, as well as a version that all staff can readily access. Should there be a fire or a flood and all child protection and safeguarding records are either paper-based or held on IT systems on local drives, you risk losing them entirely.
And a catch-all point that’s not limited to child protection and safeguarding (although it is hugely important): all highly confidential emails should be sent and received using a sufficiently secure system, such as Egress.
Managing human prevention through training
Perhaps unsurprisingly, human interaction can often be a school’s Achilles heel when it comes to keeping data safe. Which means one thing: training. All staff members should receive robust and regular training and guidance on how to manage and process data safely. This includes:
You can find more information on these principles on the Information Commissioner’s Office website.
Moreover, where possible, contextualising for your specific school – rather than schools in general – can be really useful tool sitting alongside other training. So your school’s data protection officer (DPO) and IT team should ensure that all staff are fully trained and confident about the data a school holds. This training must include:
Take it seriously: the risks are too grave to not
Shockingly, 41 per cent of primary schools identified cyber security breaches or attacks in the 12 months 2019-20. For secondary schools and higher education instituations these numbers jump significantly to 76 and 80 per cent, respectively (Cyber Security Breaches Survey 2020, p.4).
These statistics are cause for concern. With each breach or attack comes the risk of exploitation by those with malicious and a potential ICO investigation. It’s why data and the systems schools use to keep it safe are so important – too important to not get right.
"Information is not knowledge. The only source of knowledge is experience. You need to experience to gain wisdom."
Albert Einstein
Barrister and safeguarding specialist
Simplifying safeguarding so the people who carry it can act with confidence, and look after themselves while they do.
© 2026 Carter Noble Independent Safeguarding Limited. Company Number: 08706015. ICO Registration Number: ZA295796.
Privacy Policy↓
↓