The Data Protection Toolkit Every School Should Have

19 minutes
IT Engineer at their desk

Your school is responsible for protecting a considerable amount of personal information. This includes: Pupil records, safeguarding information, assessment results, staff files, parent contact details, photographs, attendance data and health information.

Protecting that information is vital. Schools must comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and they must be able to demonstrate that compliance. 

That can leave school leaders with some understandable questions. What exactly do we need to have? Is this something we can realistically implement? Are we already behind?

The reassuring answer is that a data protection toolkit does not mean investing in costly specialist software or trying to turn school leaders into legal experts. It is a practical set of documented systems, policies, procedures and records that every school can put in place.

Once those elements are organised, GDPR compliance becomes much simpler to manage. Instead of responding to each data protection issue individually, your school has a clear framework that staff understand and can follow.

Why Your School Needs a Data Protection Toolkit

One of the most important concepts behind UK GDPR is accountability. 

The ICO’s guidance on GDPR accountability explains that organisations are responsible for complying with UK GDPR and it is essential to be able to demonstrate that compliance. 

For schools, this means maintaining evidence such as:

  • A written data protection policy that reflects what the school does.
  • Records showing that staff have received appropriate data protection training.
  • Documentation explaining what personal data is processed and why.
  • Risk assessments for new systems or higher-risk processing activities.
  • A clear data breach response procedure and records showing how incidents have been handled.
  • Data Processing Agreements with relevant third-party providers.
  • Records showing how Subject Access Requests have been managed.

The Department for Education’s government guidance for data protection provides schools, academies, and trusts with more practical information.

Without adequate documentation, demonstrating compliance becomes much harder. ICO guidance notes that records of processing activities can cover areas such as processing purposes, data sharing and retention. These may need to be made available to the regulator on request.

Documentation has another important purpose: it makes good data protection repeatable.

When responsibilities, processes and decisions are documented, staff do not need to improvise every time somebody requests their personal information or a laptop containing sensitive data goes missing. They have an established process to follow.

The same notion applies to technical security. Understanding the importance of cybersecurity for schools helps connect GDPR responsibilities with the practical measures needed to protect the information stored on school networks and devices.

A decent data protection toolkit therefore creates both proof and consistency. It shows regulators what the school is doing while helping staff do the right thing every day.

Making It Happen: Your Toolkit Checklist

The simplest way to approach a data protection toolkit is not to think of ten unrelated documents. Each component supports the others.

  • Your data protection policy provides the foundation. It clarifies your school’s overall approach and connects responsibilities such as staff training, breach management and data retention.
  • Your privacy notices tells pupils, parents and staff how their personal information is used.
  • Your data audit establishes what personal data exists, where it is held and how it is processed.
  • Your staff training records demonstrate that employees have been taught how to apply the school’s policies.
  • Your Data Processing Agreements (DPAs) establish appropriate contractual protections where third-party processors handle personal information.
  • Your retention schedule prevents information from simply accumulating indefinitely.
  • Your DPIA process provides a structured way of identifying and managing privacy risks when higher-risk processing is proposed.
  • Your breach response procedure gives staff clear instructions when personal information is accidentally or deliberately compromised.
  • Your SAR procedure helps the school recognise and respond appropriately to requests from people exercising their information rights.
  • Finally, your consent records provide evidence where consent is the lawful basis for a particular processing activity.

Together, these create an interconnected accountability system rather than a collection of compliance tick-boxes.

Use this simple checklist to assess where your school stands:

  • A written data protection policy outlining your approach to handling personal data.
  • Separate, appropriate privacy notices for pupils, parents and staff.
  • A documented data audit showing what personal information you hold and where it is stored.
  • Evidence of staff data protection training, including attendance and dates.
  • Data Processing Agreements with relevant cloud and technology providers, such as Microsoft 365, Google Workspace and MIS providers.
  • A retention schedule specifying how long different categories of information should be kept.
  • A DPIA process or template for assessing risk before introducing processing that is likely to create a high risk to people’s rights and freedoms.
  • A documented data breach response procedure.
  • A procedure for recognising and handling Subject Access Requests within the applicable timeframe.
  • A consent register or equivalent records for processing or sharing that genuinely relies on consent.

If you can securely check all ten, you have the core components of a functioning data protection toolkit.

If you have fewer than five, don’t try to fix everything concurrently. Start with foundational areas such as your data protection policy, privacy notices, training and processor contracts. Then, methodically work through the remaining gaps.

It can also be useful to reflect on how these requirements fit alongside the different IT support services available for schools. Data protection does not operate separately from IT: access controls, devices, cloud platforms, backups and security all influence how safely school data is handled.

If your policy itself needs attention, start by understanding your school’s data protection policy and comparing what is documented with what actually happens in practice.

Qlic can help schools evaluate the tools already in place, identify gaps and establish practical processes for addressing them.

The benefits of good technology governance can be seen in Qlic’s work with Wellington Primary School. Qlic provided thorough training on the school’s new system, helping staff use it effectively while supporting increased productivity and collaboration. Pupils gained secure, age-appropriate access to devices, while teachers experienced fewer technical problems, allowing them to spend more time focused on teaching and learning. The result was a more modern, secure and user-friendly digital environment.

Technology management matters because school environments are seldom simple.

In Qlic’s Cyber Essentials for Education video, Neil Furminger explains the value of separating different parts of the school network and keeping devices properly supported:

“In schools you have different setups. You have a student network, a guest network for other people who come in, a classroom network, and a central business operations network. By using segments and splitting it up, it gives you layers of protection. Everything must be supported, but you can apply them to: desktops, laptops, servers, mobile phones, tablets, routers, firewalls. If you work with Qlic, they will help you manage these and they will talk to you about when they become unsupported, because unsupported devices present a great risk to your organisation.”

This illustrates an essential point: data protection policies and technical controls work together. Documentation defines how information should be protected, but well-managed IT helps make those protections possible in everyday school operations.

The Essential Tools in Your Data Protection Toolkit

Compliance is built from documents, systems and records that provide evidence of accountability. Each tool has a particular job, but the real value comes from using them together.

Data protection policy

A data protection policy is the central document explaining how your school approaches personal information.

In basic language, it tells staff what the school expects when personal data is collected, accessed, stored, shared and deleted. It should also establish responsibilities and explain the processes that staff need to follow.

Department for Education guidance states that schools must have data protection policies and procedures in place and frequently review and update them and their associated documentation.

A useful policy should cover areas including responsibilities, data protection principles, lawful processing, individual rights, security, breaches, retention and links to related procedures.

Schools can use current DfE and ICO resources as a starting point rather than creating everything from scratch. Templates should still be adapted to reflect the school’s practices.

For example, a school may state in its policy that confidential pupil information should only be accessible to authorised staff. The practical implementation could then include role-based permissions in its MIS and cloud environment. The policy establishes the rule, and technical controls help enforce it.

Privacy notice

A privacy notice explains to people what your school does with their personal information.

It should make transparent why information is collected, how it will be used, the lawful basis for processing, who it may be shared with, how long it will be retained and what rights individuals have.

DfE guidance states that schools must make privacy notices freely available to people whose personal information they handle. It also says notices should be clear, accessible and regularly reviewed.

Rather than relying on a single generic notice, schools should provide information appropriate to separate audiences, including pupils, parents and staff. Child-friendly versions may be appropriate so that privacy information is fully understandable to younger pupils.

DfE resources and examples provide a useful starting point for developing and reviewing these documents.

For example, when introducing a new learning platform, a school should check whether its existing privacy information accurately explains any new collection, use or sharing of personal data associated with that platform.

Data audit / data inventory

You cannot protect data effectively if you do not know what you have.

A data audit, sometimes described as a data inventory or data mapping exercise, establishes what personal information the school holds, why it has it, where it is located, who can access it, who it is shared with and how long it should be retained.

This supports the school’s wider record-keeping obligations and makes other compliance tasks much easier. DfE guidance recommends checking each year what data the school holds and whether it still needs to be kept.

Your audit should cover beyond the obvious systems. Look at the MIS, cloud storage, email, safeguarding platforms, HR software, finance systems, paper records, devices and specialist learning applications.

For example, an audit might reveal that a department is keeping old pupil spreadsheets in a shared folder long after the information is required. Once identified, the school can determine whether those records should be securely deleted and tighten the process that allowed them to remain there.

Qlic IT Support Engineer on a call

Staff training program and training records

Policies only work if people understand them.

Data protection training should help staff recognise personal data, understand their responsibilities, handle information securely, identify potential breaches and know how to escalate information rights requests.

Training records provide the evidence that this education has taken place. Record who attended, what training was provided and when it happened.

DfE guidance says senior leaders are responsible for making sure staff receive data protection training every two years and recommends annual training as best practice. It also distinguishes breach reporting and escalation of information rights requests as school-specific processes training should cover.

Schools can use government learning resources alongside training tailored to their own systems and procedures.

A practical example is a teacher unintentionally emailing information about one pupil to the wrong parent. A trained employee is more likely to recognise this immediately as a potential personal data breach and report it through the correct internal process rather than purely deleting the sent email and hoping nothing happens.

Data processing agreements (DPAs)

Schools increasingly rely on external technology companies to process personal information. That can include cloud services, MIS platforms, safeguarding tools, learning applications and other EdTech.

Appropriate Data processing agreements (DPAs) establish the data protection responsibilities that apply when another organisation processes personal information on the school’s behalf.

An appropriate processor contract should address matters including what information is processed, the purpose and duration of processing, security expectations, confidentiality, sub-processors, support with data subject rights and what happens to information when the relationship ends.

ICO accountability guidance identifies written contracts with organisations processing personal information on your behalf as one of the measures supporting accountability.

Templates can provide a useful reference, but schools should also review the actual contractual documentation supplied by each provider and seek appropriate advice where necessary.

For example, before introducing a cloud-based homework platform, the school should establish what pupil information the provider will process, where it will go and what contractual protections apply. Signing up for an online service should not replace correct due diligence.

This is specifically important because schools cannot simply assume that using a major technology platform transfers their data protection responsibilities elsewhere. Jamie discusses this wider responsibility in Qlic’s Ensuring Your IT Environment is Protected & Cyber Aware video:

Working with a technology provider should therefore complement your school’s governance rather than replace it. Appropriate cybersecurity protection for schools helps warrant that the technical environment supports those responsibilities.

Data retention schedule

A data retention schedule establishes how long particular categories of information should be kept and what should happen at the end of that period. Schools accumulate information promptly. Without a retention schedule, “keep it just in case” can easily become the default.

This supports the storage limitation principle. DfE record-management guidance states that schools should only keep data for as long as needed, review what they hold each year and safely dispose of information they no longer need.

Your schedule should cover categories such as pupil records, safeguarding information, HR files, financial records, recruitment information and other relevant school data, with the applicable retention period and disposal method.

For example, when an employee leaves, their account should not simply remain active indefinitely with years of emails and cloud files attached. The school should follow an established leaver and retention process to preserve what is legitimately required, remove access and securely deal with information that is no longer required.

Data protection impact assessment (DPIA) process & template

A DPIA is a structured way to identify privacy risks before a higher-risk processing activity is introduced.

A Data protection impact assessment (DPIA) process should help the school describe the proposed processing, assess its necessity and proportionality, identify possible risks and record measures for reducing those risks.

Under UK GDPR, a DPIA is required where processing is likely to result in a high risk to individuals’ rights and freedoms. DfE guidance describes DPIAs to identify, measure and manage data protection risks.

Schools should have both a defined process and a reusable template. ICO and DfE resources can help provide a starting structure.

For example, before introducing technology that uses pupil biometric information or another form of particularly sensitive processing, the school should assess privacy risks before implementation rather than waiting for concerns to emerge afterwards.

Breach response procedure

A personal data breach is not limited to a cyberattack. It can include personal information being lost, stolen, destroyed, altered or accessed without permission.

A breach response procedure tells staff what to do when something goes wrong.

It should explain how to identify and report a suspected breach, who should be informed internally, how the incident will be investigated, how risks to affected people will be assessed, when notification may be required and how decisions will be recorded.

The school should also maintain a breach log so that incidents and responses are documented.

DfE and ICO breach guidance can be used when building or reviewing the procedure.

Imagine a member of staff loses a school laptop on a train. The school’s response should not depend on whoever happens to be available that day. Staff should know immediately who to contact, while the school should be able to verify what data was accessible, what security controls protected the device and what further action is necessary.

Subject access request (SAR) procedure

A Subject Access Request permits somebody to ask for access to personal information an organisation holds about them, subject to the applicable rules and exemptions.

A documented Subject access request (SAR) procedure helps staff recognise a request quickly, establish responsibility for managing it, locate relevant information, review what can appropriately be disclosed and respond within the required timeframe.

This matters because a request does not necessarily arrive with “Subject Access Request” written at the top. Staff need to recognise requests made in ordinary language and rise them appropriately.

Your procedure should therefore include recognition, verification where appropriate, internal escalation, information searches, review, redaction where necessary, response and record keeping.

Government and ICO guidance can help schools develop a process appropriate to their circumstances.

For example, a parent may email asking to see personal information the school holds about them or, where the relevant rules permit, information concerning their child. A trained administrator should recognise that the message may engage information rights and escalate it rather than leaving it sitting in an inbox.

Consent records / consent register

Consent is one viable lawful basis for processing personal information, but it is not the basis for everything a school does.

Where your school genuinely depends on consent, you need appropriate evidence of it.

A consent register can record who consented, what they agreed to, when consent was obtained, how it was obtained and whether it has subsequently been withdrawn.

This record helps demonstrate that consent was valid for the activity concerned. It should also connect with your privacy information and processes for withdrawing consent.

Templates can be created internally based on ICO guidance. DfE guidance also presents resources relating to parental and carer consent in relevant circumstances.

For example, a school might rely on consent for a particular optional use of pupil photographs. The register should make it straightforward for staff to check the relevant permissions before using an image and to update records if consent is withdrawn.

It is equally vital not to ask for consent unnecessarily. Schools process substantial amounts of information under other lawful bases, including where processing is necessary for legal or public functions. Establishing the correct lawful basis for each processing activity is therefore an important part of the wider toolkit.

Common Compliance Gaps for Schools (and How to Fix Them)

Most schools are not starting from zero. The challenge is usually that individual pieces of the toolkit have developed at different times, leaving gaps between them.

Here are four particularly important areas to check.

  1. “We have a policy but no training records.”

A policy sitting on a shared drive is not evidence that employees know how to follow it.

The immediate fix is to establish regular staff training and document attendance, dates and content. Include practical scenarios employees genuinely encounter, such as misdirected emails, suspicious messages, information requests and the secure use of cloud platforms.

This is increasingly important as cybersecurity standards have risen. Data protection and cybersecurity awareness need to become routine staff responsibilities rather than one-off exercises.

Qlic can help schools connect staff awareness with the technology and security controls employees use every day.

  1. “We don’t have DPAs for the cloud platforms we use.”

Start by making a list of third parties that process personal information for your school. Prioritise your MIS, Microsoft 365 or Google Workspace environment, safeguarding systems and other platforms holding significant or sensitive data.

Then determine what processor terms or contracts are in place and whether they adequately address the relevant data protection requirements.

Do not assume that because a technological platform is well known, the school’s own accountability obligations disappear.

Qlic can help schools review their technology estate, understand which systems are in use and identify areas requiring closer attention.

  1. “We don’t have a data audit and we’re not sure what data we hold.”

This can feel like a daunting problem, but the solution is to start mapping information systematically.

Work through departments and systems. Record what personal information is held, its purpose, location, access arrangements, sharing, lawful basis and retention requirements.

Your first audit does not need to solve every issue it uncovers. Its first purpose is visibility. Once you know where information is, you can prioritise the greatest risks.

  1. “Our data protection policy is three or more years old.”

Policies should reflect current systems and actual practice. A school may have adopted new cloud applications, changed its MIS, introduced new devices or changed how information is shared since the policy was written.

Current DfE guidance says data protection policies, procedures and associated documentation should be regularly reviewed and updated.

The quick fix is to schedule a formal review. Compare the policy against current processes, your latest data audit, privacy notices, supplier relationships, staff practices and current government and ICO guidance.

This is especially relevant in 2026. The DfE updated its school data protection guidance in July to reflect the Data (Use and Access) Act 2025 coming into force. The Act does not replace UK GDPR or the Data Protection Act 2018 but amends and builds on the existing framework.

Schools do not need to tackle these issues unsupported. Qlic’s experience helping educational institutions means support can be aligned with the realities of school IT environments rather than treating data protection as a purely theoretical compliance exercise.

The key is to begin. Finding a gap is beneficial because it gives you something concrete to improve. A structured assessment followed by prioritised action is far more valuable than postponing compliance work because the entire toolkit is not yet perfect.

GDPR compliance is non-negotiable, but building the systems required to support it is achievable.

A practical data protection toolkit turns a broad legal responsibility into manageable processes: understand what information you have, document how you use it, train your people, manage third parties, assess new risks and establish clear procedures for when something goes wrong.

The result is more than a folder of compliance documents. It is a sustainable framework that helps your school protect pupil, parent and staff information regularly.

Start by assessing the ten tools above. Identify what is already functioning, what needs updating and what is missing. Then prioritise the gaps that create the greatest risk.

You do not have to build everything alone. Qlic IT for Education can help schools assess their compliance toolkit, identify gaps, and support implementation. Get in touch today to discuss how we can help your school sustainably navigate GDPR compliance requirements.

Rae Dawson

Marketing

About the Author

Rae supports marketing activities, including creating content, managing social media, coordinating campaigns, and assisting with research and administrative tasks.