GDPR News for Schools

ico logo

At DPAS we have been closely following the ICO audits in schools and multi academy trusts to understand the key areas they are focusing on and the recommended actions they are giving. It’s clear that the ICO are targeting schools and multi academy trusts for audits. 3 audits were published during March. In this article on GDPR news for Schools, we’ve detailed below the scope of the audits. We’ve also included key findings, helping you ensure that you are ready for an audit if the ICO come knocking!

THE GENERAL SCOPE OF THE ICO AUDITS IN SCHOOLS

GOVERNANCE AND ACCOUNTABILITY

The extent to which information governance accountability, policies and procedures, performance measurement controls, and reporting mechanisms to monitor data protection compliance to both the GDPR and national data protection legislation are in place and in operation throughout the organisation.

DATA SHARING

The design and operation of controls to ensure the sharing of personal data complies with the principles of all data protection legislation.

TRAINING AND AWARENESS

The provision and monitoring of staff data protection, records management and information security training and the awareness of data protection regulation requirements relating to their roles and responsibilities.

REQUESTS FOR PERSONAL DATA AND DATA PORTABILITY

There are appropriate procedures in operation for recognising and responding to individuals’ requests for access to or to transfer their personal data.

SOME AREAS OF IMPROVEMENTS ACROSS THE AUDITS

  • The trust should possess full documentation on the risk management process, including risk escalation processes.
  • Implementation of a programme of regular internal data protection audits. Reporting on routine compliance checks is essential.
  • The trust should introduce annual, mandatory information governance training for all staff. It should be reported on as a key performance indicator. Training should include how staff should recognise a subject access request.
  • Introduction of specialist training for key staff. This should include subject access requests, data sharing, and data protection impact assessments.
  • The trust should document fully its approach to data sharing. It should record the details of all data sharing and data sharing decisions centrally.
  • Create processes for dealing with ad hoc disclosures.

General Findings

There is a limited level of assurance that processes and procedures are in place and are delivering data protection compliance. The audit has identified considerable scope for improvement in existing arrangements to reduce the risk of non-compliance with data protection legislation. It was also noted that data sharing and mapping (record of processing activity) requires further attention. Other areas of concern were the lack of DPIAs where personal data is at risk.

Training From The Experts At DPAS

Keeping knowledge fresh and skills up to date is essential. Our Data Protection In Practice For Schools training course meets those needs and also allows you to raise challenges specific to your situation among professionals in a similar situation and share experiences to improve your service delivery.

related posts

Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »
Noah de Wild

How to Assess a Data Breach: A Practical Guide

This blog explains how to assess a data breach by identifying its cause, determining what information was exposed, and evaluating the potential impact on affected individuals and the organisation. It outlines common causes of breaches, the importance of understanding the type and scale of compromised data, and how assessing the timeline of an incident can help businesses respond effectively, meet legal obligations, and reduce long-term risks.

Read More »
Noah de Wild

Don’t Panic: A Pragmatic Guide to the June 2026 Enforcement of the Data (Use and Access) Act Changes

With the June 19, 2026 enforcement of the Data (Use and Access) Act approaching, ensuring your business is compliant doesn’t have to be complicated or expensive. In our latest guide, we break down exactly what the new data protection complaint rules mean for you. Cut through the noise and discover our simple, free six-step checklist to update your protocols, designate handlers, and keep your business confidently compliant.

Read More »

Get a Free Consultation