Guide · Data protection

GDPR for schools: a 2026 checklist

What UK GDPR means for schools in practice, updated for the Data (Use and Access) Act 2025 and the new Information Commission. Written for heads, bursars, business managers, DPOs and DSLs.

Updated 2 October 2026

What's new in 2026

  • A new regulator name. The ICO became the Information Commission on 30 September 2026 (gov.uk).
  • Subject access requests: a “stop the clock” rule and a “reasonable and proportionate search” standard, both from the Data (Use and Access) Act 2025.
  • Complaints: since 19 June 2026 every school must have a way to handle data protection complaints and acknowledge them within 30 days.
  • KCSIE 2026 now names the Data (Use and Access) Act 2025 alongside UK GDPR and the DPA 2018.

The checklist

  1. Pay the data protection fee and keep the registration current.
  2. Appoint a DPO (required for state-funded schools).
  3. Keep a record of what personal data you hold, why, and your lawful basis for each use.
  4. Publish up-to-date privacy notices for pupils, parents, staff and governors.
  5. Have a process for subject access requests that works in the holidays.
  6. Have a breach log and a 72-hour reporting process.
  7. Set up a data protection complaints process.
  8. Carry out DPIAs for new systems and higher-risk processing, including AI tools.
  9. Have contracts (data processing agreements) with every supplier that handles pupil data.
  10. Get the right consent for photos, videos and biometrics.
  11. Set retention periods and delete data when they end.
  12. Train staff, and record the training.

Do you need a Data Protection Officer?

UK GDPR says “you must appoint a DPO if you are a public authority or body” (ICO). The governing bodies of maintained schools and the proprietors of academies are public authorities (FOIA 2000, Schedule 1), so every state-funded school needs a DPO. One DPO can serve several schools, which is how most trusts and local authorities do it.

Independent schools aren't public authorities. They only need a DPO if their core activities involve large-scale regular monitoring of people or large-scale processing of special category data. Many appoint one anyway, because someone has to own data protection.

Lawful bases: the state and independent difference

Every use of personal data needs a lawful basis. State-funded schools rely mostly on public task for running the school and legal obligation for things like census returns. UK GDPR says legitimate interests can't be used by public authorities “in the performance of their tasks” (Article 6), so for optional uses like marketing, they usually turn to consent.

Independent schools have more room. Because they aren't public authorities, they can rely on legitimate interests where a balancing test supports it. The DfE's photo guidance lists legitimate interests as an option for marketing photos after an assessment (DfE). Since February 2026 there's also a recognised legitimate interest for safeguarding vulnerable people, including anyone under 18, though it isn't available to public authorities for their tasks either.

Photos and videos of pupils

A photo of an identifiable pupil is personal data. The DfE's guidance (updated July 2026) says:

  • Photos used for administration, such as “ID cards, registers, classroom seating plans”, can rely on public task.
  • Website, social media, prospectus and press photos usually need consent, or legitimate interests after an assessment where the school can use it.
  • With older pupils, “often at around the age of 13, it is good practice to ask them directly for consent”.
  • Don't publish images of pupils with safeguarding concerns or court orders, and have a photo policy alongside your privacy notice.

Data protection law is only part of the picture now. In May 2026 UK safeguarding bodies advised schools to stop publishing identifiable, face-on photos of pupils because of AI image abuse (UK Safer Internet Centre). Our guide Can schools post photos of children? covers both, and our free photo consent form collects consent use by use.

An anonymised photo is a safer photo

Safeguard Vision replaces each pupil's face with a newly generated one, so the published photo no longer shows a real child's face. Photos are processed under a data processing agreement, never used to train AI, and deleted after 48 hours. See how it works for schools →

Subject access requests

Pupils (or parents acting for them), parents and staff can ask for a copy of their personal data. The school has one month, extendable by “two further months where that is necessary by reason of the complexity of requests” or their number, if you say so within the first month (DUAA s76).

  • The clock starts when you have the request and any ID you need, and since 5 February 2026 it stops while you wait for clarification you reasonably need.
  • You need to provide what you can find through “a reasonable and proportionate search” (DUAA s78).
  • The DfE is clear: “Education settings cannot extend a SAR response because it is the school holidays” (DfE). Plan who covers requests in August.

Parents at maintained schools also have a separate right to see their child's educational record within 15 school days (Education (Pupil Information) (England) Regulations 2005). It doesn't apply to academies or independent schools, where parents use a subject access request instead.

Data breaches

Report a notifiable breach “without undue delay, but not later than 72 hours after becoming aware of it” (ICO). It's notifiable if it's likely to result in a risk to people, and if that risk is high you must tell the people affected too. Keep a log of every breach, including the ones you decide not to report. Common school breaches include emails sent to the wrong parent, lost laptops and published photos of pupils whose parents had opted out.

Data protection complaints

Since 19 June 2026 the Data (Use and Access) Act 2025 has required every organisation to have a way for people to complain about how their data is handled, and to acknowledge complaints within 30 days (ICO). Many schools add a data protection route to their existing complaints policy.

Biometrics

Fingerprint cashless catering and library systems need written parental consent under the Protection of Freedoms Act 2012. The DfE's guidance says biometric data “must not be processed unless at least one parent of the child consents”, that “a pupil's or student's objection or refusal overrides any parental consent”, and that schools must offer a reasonable alternative (DfE). This applies to maintained, academy and independent schools.

The data protection fee

Schools pay the annual data protection fee. Tier 1 is £52, tier 2 £78 and tier 3 £3,763. Public authorities pick a tier by staff numbers, and charities, including many independent schools, pay the tier 1 fee regardless of size (ICO).

Where to get more help

This guide summarises published law and guidance as of 2 October 2026 and isn't legal advice.

Common questions

GDPR in schools: quick answers.

Does GDPR apply to schools?

Yes. Every school in the UK that handles personal data about pupils, parents or staff must follow the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. KCSIE 2026 lists all three as the data protection laws schools must follow.

Do schools need a Data Protection Officer?

State-funded schools do. Maintained schools and academies are public authorities, and UK GDPR requires public authorities to appoint a DPO. Independent schools aren't public authorities, so they only need one if their core activities involve large-scale monitoring or large-scale special category data, though many appoint one anyway.

How long does a school have to answer a subject access request?

One month, which can be extended by up to two further months for complex or numerous requests if the school tells the requester within the first month. Since February 2026 the clock can stop while the school waits for clarification it reasonably needs. The DfE says schools can't extend the deadline because it's the school holidays.

How quickly must a school report a data breach?

A notifiable breach must be reported to the regulator without undue delay and within 72 hours of the school becoming aware of it. A breach is notifiable if it's likely to result in a risk to people. If the risk is high, the school must also tell the people affected.

Do schools need consent to take photos of pupils?

Not always. DfE guidance says photos for administration, like ID cards and registers, can rely on public task. Photos for websites, social media and marketing usually rely on consent, or legitimate interests after an assessment where the school is allowed to use it. From around age 13 it's good practice to ask pupils directly.

Is the ICO now called the Information Commission?

Yes. On 30 September 2026 the Information Commission replaced the Information Commissioner's Office as the UK's data protection regulator. Existing ICO guidance still applies, and you report breaches and pay the data protection fee in the same way.

Share school life, not pupils' identities.

Try it on two of your own photos now. If it doesn't earn a place in your week, you've lost nothing.

Anonymise 2 photos free →
  • ✓ 2 photos free
  • ✓ No card
  • ✓ ~20 seconds