GDPR For Schools

Thu, 11/16/2017 - 11:25
Education , Data Management , Data Protection

Come May 25th 2018, the GDPR will come into effect changing the way that schools, colleges, academies and all other organizations are required to manage and protect data. Data covered by the regulation includes everything from digital files and folders to paper copies of forms, hidden away in cabinets in reception. Keeping data securely protected is already law but as the Data Protection Act is almost 20 years old and the way that data is created, stored and used has evolved a lot it is time for an update.


What does GDPR stand for?

GDPR stands for the General Data Protection Regulation; The regulation will look to update the Data Protection Act which sets out much of the current guidance on data protection. GDPR aims to strengthen how schools and other organizations manage and protect data, with a focus on the protection of personal data.

While pre-existing legislation that schools must adhere to will remain in place, the GDPR sets out some drastic changes around how data can be processed and gives individuals more rights than they have previously had, concerning their data.


Is the GDPR going to affect my school?

Yes. The GDPR will affect all organizations that hold data on European citizens, even if they aren’t in Europe themselves. Some have called it the ‘Global’ Data Protection Regulation. There are some significant changes in the regulation and the way information is processed internally and externally will be important.


Key points to watch out for

Compliance with the regulation is vital for all schools and given the sensitive nature of the personal data held the risk of a data breach is huge. Compliance is something that needs to be worked towards on an ongoing basis.

Financial penalties

Under the Data Protection Act, the ICO (Information Commissioner’s Office) has the power to give a maximum fine of £500,000 for a major data breach. A data breach is defined as the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, data. Under the GDPR these fines could reach up to €20,000,000 or 4% of global revenue. It’s worth knowing that the ICO, to date, has never fined a school for a breach and is more likely to implement an undertaking with the goal of improving a school’s protection policies and compliance with data protection laws.

Data Protection Officer

Under the GDPR public authorities must appoint a Data Protection Officer (DPO) who will be responsible for helping the organization comply with the regulation and advising on policies. Fortunately for schools, a DPO does not have to be a direct employee of the organization and can be shared between organizations (great news for multi-academy trusts and federated schools).


One of the core aims and principles in the GDPR is to ensure data is protected correctly and with organizations sharing data with partners and external organizations it’s vital to make sure they are compliant too. Under the GDPR, a formal contract or Service Level Agreement (SLA) must be in place and due diligence must be done to ensure that partners and suppliers are also compliant.


Actions to take

Compliance with the GDPR is an ongoing task within a school and with so many different sources of information, no two schools will have the same rules to be compliant. Best practice and actions will help with compliance and ensure that if a breach occurs the ICO will look favourably on the case – Compliance tools are available and can assist in this process.

The ICO guidelines on preparing for the GDPR, set out 12 steps that all organizations can take, some of these are more appropriate for businesses but all can be applied to schools in some way.

  1. Awareness – Making sure that key decision makers within the school understand what the GDPR is and how it applies to them.
  2. Information held – Documenting what data is held within the school and understanding how long it should be held for and where it is stored.
  3. Communicating privacy information – As part of the regulation, privacy notices must be updated.
  4. Individuals rights – Processes in place around how data is used and held must be updated to ensure individuals rights are being protected. This will include data held on staff and pupils.
  5. Subject access requests – Under the GDPR, a data subject (person) can request a copy of the data you have on them. It’s important to have a process in place for this eventuality.
  6. Lawful basis for processing – If your school is processing data you need to have a reason why. If there’s no legal reason to keep data, then don’t.
  7. Consent – Recording and managing data will require consent from an individual unless there is another legal reason. Having up to date information on staff and pupils is enough reason.
  8. Children – There are special rules around the handling of children’s data, as a school this should fall in line with current policies anyway.
  9. Data breaches – Put in place a policy to help you report a breach within 72 hours if one occurs. Hopefully, it won’t.
  10. Data Protection – You should already be doing this under regulations of the Data Protection Act and guidance from the Schools Financial Value Standards.
  11. Data Protection Officers – As a public body, you must have someone responsible for advising on compliance for the school.
  12. International – If your school has International branches then these will also need to be compliant.

Recent Articles

Redstor_Alternative_accountancy_strategic_blog Redstor

Redstor Accounting For Financial Data Backups at The Alternative Accountancy Strategic IT Conference 2018

Continuing from a series of events in the first two months of the year, Redstor will be in attendance of this years, Alternative Accountancy... read more

February 20, 2018
Redstor_CryptoJacking_blog Data Protection

Crypto-jacker Leaves ICO In Its Wake

Cyber-attacks and ‘hacks’ made regular headlines throughout 2017, and in the UK the Information Commissioner’s Office (ICO), was there to oversee all... read more

February 15, 2018
Redstor_100Days_to_GDPR Data Protection

100 Days To Go…

Wednesday 14th February 2018, valentine’s day, but more significantly it’s 100 days until G-day. May 25th, 2018, the day on which The General Data... read more

February 14, 2018