Guide · Data protection
GDPR for schools: a 2026 checklist
What UK GDPR means for schools in practice, updated for the Data (Use and Access) Act 2025 and the new Information Commission. Written for heads, bursars, business managers, DPOs and DSLs.
Updated 2 October 2026
What's new in 2026
- A new regulator name. The ICO became the Information Commission on 30 September 2026 (gov.uk).
- Subject access requests: a “stop the clock” rule and a “reasonable and proportionate search” standard, both from the Data (Use and Access) Act 2025.
- Complaints: since 19 June 2026 every school must have a way to handle data protection complaints and acknowledge them within 30 days.
- KCSIE 2026 now names the Data (Use and Access) Act 2025 alongside UK GDPR and the DPA 2018.
The checklist
- Pay the data protection fee and keep the registration current.
- Appoint a DPO (required for state-funded schools).
- Keep a record of what personal data you hold, why, and your lawful basis for each use.
- Publish up-to-date privacy notices for pupils, parents, staff and governors.
- Have a process for subject access requests that works in the holidays.
- Have a breach log and a 72-hour reporting process.
- Set up a data protection complaints process.
- Carry out DPIAs for new systems and higher-risk processing, including AI tools.
- Have contracts (data processing agreements) with every supplier that handles pupil data.
- Get the right consent for photos, videos and biometrics.
- Set retention periods and delete data when they end.
- Train staff, and record the training.
Do you need a Data Protection Officer?
UK GDPR says “you must appoint a DPO if you are a public authority or body” (ICO). The governing bodies of maintained schools and the proprietors of academies are public authorities (FOIA 2000, Schedule 1), so every state-funded school needs a DPO. One DPO can serve several schools, which is how most trusts and local authorities do it.
Independent schools aren't public authorities. They only need a DPO if their core activities involve large-scale regular monitoring of people or large-scale processing of special category data. Many appoint one anyway, because someone has to own data protection.
Lawful bases: the state and independent difference
Every use of personal data needs a lawful basis. State-funded schools rely mostly on public task for running the school and legal obligation for things like census returns. UK GDPR says legitimate interests can't be used by public authorities “in the performance of their tasks” (Article 6), so for optional uses like marketing, they usually turn to consent.
Independent schools have more room. Because they aren't public authorities, they can rely on legitimate interests where a balancing test supports it. The DfE's photo guidance lists legitimate interests as an option for marketing photos after an assessment (DfE). Since February 2026 there's also a recognised legitimate interest for safeguarding vulnerable people, including anyone under 18, though it isn't available to public authorities for their tasks either.
Photos and videos of pupils
A photo of an identifiable pupil is personal data. The DfE's guidance (updated July 2026) says:
- Photos used for administration, such as “ID cards, registers, classroom seating plans”, can rely on public task.
- Website, social media, prospectus and press photos usually need consent, or legitimate interests after an assessment where the school can use it.
- With older pupils, “often at around the age of 13, it is good practice to ask them directly for consent”.
- Don't publish images of pupils with safeguarding concerns or court orders, and have a photo policy alongside your privacy notice.
Data protection law is only part of the picture now. In May 2026 UK safeguarding bodies advised schools to stop publishing identifiable, face-on photos of pupils because of AI image abuse (UK Safer Internet Centre). Our guide Can schools post photos of children? covers both, and our free photo consent form collects consent use by use.
An anonymised photo is a safer photo
Safeguard Vision replaces each pupil's face with a newly generated one, so the published photo no longer shows a real child's face. Photos are processed under a data processing agreement, never used to train AI, and deleted after 48 hours. See how it works for schools →
Subject access requests
Pupils (or parents acting for them), parents and staff can ask for a copy of their personal data. The school has one month, extendable by “two further months where that is necessary by reason of the complexity of requests” or their number, if you say so within the first month (DUAA s76).
- The clock starts when you have the request and any ID you need, and since 5 February 2026 it stops while you wait for clarification you reasonably need.
- You need to provide what you can find through “a reasonable and proportionate search” (DUAA s78).
- The DfE is clear: “Education settings cannot extend a SAR response because it is the school holidays” (DfE). Plan who covers requests in August.
Parents at maintained schools also have a separate right to see their child's educational record within 15 school days (Education (Pupil Information) (England) Regulations 2005). It doesn't apply to academies or independent schools, where parents use a subject access request instead.
Data breaches
Report a notifiable breach “without undue delay, but not later than 72 hours after becoming aware of it” (ICO). It's notifiable if it's likely to result in a risk to people, and if that risk is high you must tell the people affected too. Keep a log of every breach, including the ones you decide not to report. Common school breaches include emails sent to the wrong parent, lost laptops and published photos of pupils whose parents had opted out.
Data protection complaints
Since 19 June 2026 the Data (Use and Access) Act 2025 has required every organisation to have a way for people to complain about how their data is handled, and to acknowledge complaints within 30 days (ICO). Many schools add a data protection route to their existing complaints policy.
Biometrics
Fingerprint cashless catering and library systems need written parental consent under the Protection of Freedoms Act 2012. The DfE's guidance says biometric data “must not be processed unless at least one parent of the child consents”, that “a pupil's or student's objection or refusal overrides any parental consent”, and that schools must offer a reasonable alternative (DfE). This applies to maintained, academy and independent schools.
The data protection fee
Schools pay the annual data protection fee. Tier 1 is £52, tier 2 £78 and tier 3 £3,763. Public authorities pick a tier by staff numbers, and charities, including many independent schools, pay the tier 1 fee regardless of size (ICO).
Where to get more help
- The DfE's Data protection in schools guidance, which KCSIE 2026 points schools to.
- Our KCSIE 2026 summary, for the safeguarding side.
- Your DPO, local authority, trust or association.
This guide summarises published law and guidance as of 2 October 2026 and isn't legal advice.
Common questions
GDPR in schools: quick answers.
Does GDPR apply to schools?
Do schools need a Data Protection Officer?
How long does a school have to answer a subject access request?
How quickly must a school report a data breach?
Do schools need consent to take photos of pupils?
Is the ICO now called the Information Commission?
Share school life, not pupils' identities.
Try it on two of your own photos now. If it doesn't earn a place in your week, you've lost nothing.
Anonymise 2 photos free →- ✓ 2 photos free
- ✓ No card
- ✓ About ~20 seconds