In this article on GDPR for schools we will explore:
- what GDPR is
- who is responsible for GDPR in schools
- special protections for children under the GDPR
- how GDPR rights work for children
- GDPR and safeguarding
- Risks to be aware of
- Our top tips
What is GDPR?
The General Data Protection Regulations (GDPR) is a Europe-wide framework for data protection. The aim was to create a standardised approach to information security and lawful ways to use personal data across the EEA. It was brought into UK law by the Data Protection Act 2018. In short it:
- describes six key principles that underpin the use of personal data
- lists the lawful ways personal data can be processed
- sets out the rights people have to know and control how their data are used
- defines classes of sensitive personal data that need greater protection
- defines data breaches and how they should be responded to.
The GDPR applies to all organisations processing personal data, including schools.
GDPR for Schools: Who IS Responsible?
The senior management team in a school is ultimately accountable for data protection in schools, but different people have different responsibilities. In reality, like health and safety or safeguarding, everyone has a role in compliance.
At a minimum every school must have a Data Protection Officer (DPO) who has a certain level of expertise in GDPR. In addition people need specific role based training depending on their roles – a teaching assistant will need different skills to a department head or manager, and in turn staff with responsibilities for human resources or finance will need different skills again.
Our experience: while short courses as part a suite of mandatory training is a good start people need more focussed, role specific support. This is partly because it helps them perform their duties better, but also people value this type of training more.
Are there special protections for children under the GDPR?
The GDPR doesn’t have specific provisions for the use of children’s data (children for the purposes of GDPR being anyone under 18). It does recognise the particular needs of children however.
Because children are less likely to be aware of the risks relating to the use of their personal data, and less able to make decisions in their own best interests, additional care must be taken to help them understand how and why their data are being used and ensure they do not come to harm.
In addition people working with children will be more likely to have sensitive personal data such as that relating to health, family life, and other categories of sensitive personal data that has further protections under GDPR.
Schools, and anyone working with children, must be mindful of the first data privacy principle. This says that data processing must be lawful fair and transparent.
The concepts of fairness and transparency are important here because it is harder for children to understand why and how their personal information is being used but as noted below you are responsible for explaining this to children in a way that they will understand.
Our experience: we have found that people sometimes confuse fair and nice. Fair means the appropriate, proportionate use of data to achieve a desired outcome – not necessarily the same as what people want you to do.
Sign Up Here:
Children have the same rights under the GDPR as adults. They apply from birth. Clearly this will present a challenge to schools. Unlike adults in general there is a real risk children will not understand how and why their data are being used or the consequences of any action they take in relation to this. This means assessing a child’s competence to control their data is important. The most important first step you can take when it comes to children’s GDPR rights is providing privacy information in a way that they can understand. This may mean using videos or animations rather than text to help them. Our experience: people often treat their privacy information as a legal document. They use dense legalistic language to set out their uses of personal data. While a privacy statement is a legal requirement, it does not need to be written like terms and conditions or a contract. Instead it is a great opportunity to explain in the simplest terms what you do with personal data and why. GDPR for schools will always need to be mindful of safeguarding. The GDPR recognises there are circumstances where information needs to be used for health, education, social work and safeguarding purposes. While the rules can feel complex you can share information for safeguarding and the GDPR does not inhibit that. Your DPO will have a key role in supporting this critically important work. Our experience: we have occasionally seen a reluctance to share information for safeguarding purposes because of data protection concerns. It is never appropriate to put vulnerable people at risk and there are clear grounds under GDPR to share personal data to protect them from harm. There are particular risks when is comes to processing the data of vulnerable people like children. The biggest compliance risks with GDPR for schools are: There are also real opportunities for schools when it comes to GDPR compliance, like: Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.Do GDPR rights apply to children?
How does GDPR relate to safeguarding?
GDPR for Schools: The Risks
Top Tips for improved compliance
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: