Best Practice Update

Graphic promoting the KCSIE 2026 online course, essential annual training for education staff

Keeping Children Safe in Education is the statutory guidance every school, college and MAT must work to, and every member of staff needs to understand it, every year, without exception. Our new KCSIE 2026 course is now live in your DPE training portal, built to make that annual refresh straightforward, accurate, and genuinely useful, not just a box-ticking exercise.

Digital screen interface representing a school Management Information System (MIS) handling pupil records and DfE

A Management Information System (MIS) is the single most important data processing system a school operates. It holds pupil records, including special category data, safeguarding information, and family contact details. So when the Department for Education publishes guidance on choosing one, DPOs and data protection leads should pay attention, even when, as here, the guidance is framed in commercial rather than data protection terms.

Graphic representing new DfE guidance on EdTech procurement for schools, focusing on data protection.

On 9 July 2026, the DfE added a new section to its Data Protection in Schools guidance: Procuring educational technology (EdTech). It sets out what schools should consider before, during and after procuring EdTech tools, and the questions to put to prospective suppliers. Significantly, it is the first DfE guidance to directly reference the ICO's EdTech Examined audit report, telling schools to take the ICO's findings into consideration when procuring EdTech tools.

ICO EdTech Examined report graphic, highlighting data protection audit findings for UK schools and children'

The ICO's edtech audit programme, covering 28 providers used across UK primary and secondary schools, has resulted in one of the most significant data protection reports to affect the education sector in years. Published in June 2025, the ICO's EdTech Examined report made 596 recommendations and found widespread compliance failures in how edtech providers handle children's personal data. This article sets out what was found and what schools and DPOs need to do about it.

Graphic representing the Department for Education (DfE) Data Protection in Schools guidance update from June

The Department for Education (DfE) updated its Data protection in schools guidance on 17 June 2026, this refresh aligns the guidance with the wider expected KCSIE 2026 guidance and reinforces existing obligations that schools should already be acting on.

This article sets out what has changed, what it means for your school in practice, and the actions your data protection lead should be taking now.

 

  1. The DSL’s Guide to Filtering and Monitoring
  2. Human Error and High Stakes: What the Horizon Academy Trust Incident Teaches Us About School Data Breaches
  3. Reducing risk on World Environment Day and Beyond
  4. Navigating the Future: 2026 Privacy Updates, Data Access, and Student Wellbeing
  5. Can you use AI safely in schools?
  6. Guardians of Privacy: Social Media, Privacy, Children and the AI Threat
  7. Visitor Management: A Guide for Schools
  8. Under surveillance: Why your organisation's CCTV might not be compliant
  9. Update to the DfE Digital Cyber Security Standards for Schools and Colleges
  10. Wireless Network Standards for Schools & Colleges: What's New?
  11. World Backup Day: Backups - Your Safety Net
  12. School Cyber Attack: St Anne's Catholic School
  13. Volunteer Acceptable Use Policy & Agreement
  14. Handling Subject Access Requests (SARs) - at the end of term
  15. How should schools manage paper archives?
  16. Navigating the Redaction Divide: SAR or PEX?
  17. Records Management Toolkit: Where do I start with records management?
  18. What type of request have you received? SAR? Educational Record? Or FOI?
  19. SAR Extension Template
  20. Leavers' Memorabilia
  21. Sharing photos on World Book Day: Privacy considerations
  22. Make sure DPE is your registered DPO with the ICO
  23. Supplier Due Diligence Step by Step: Are you sharing personal data with a third party organisation?
  24. Time to kick-start your Clear Desk and Screen policy?
  25. Are Governors the Frontline of Cyber Security? (February 12th is Governors Awareness Day)
  26. DPE Webinar Schedule
  27. The Danger of the 'Data Dump': Why more information isn't always better!
  28. Introducing our new Recording and Transcription Policy
  29. Parents and students covertly recording conversations
  30. New DfE AI Standards
  31. Shareable Snippet: Office Security Best Practices for the Holidays
  32. CCTV Policy update: retention
  33. Shareable Snippet: Confidential waste
  34. Sharing information to safeguard children and young people in the education sector in the UK
  35. Fraud awareness from the DfE
  36. Complaints vs. Data Rights: A Guide
  37. Data Breach: School sends out names and contact details in a spreadsheet.
  38. September 2025 Policy and Document Updates
  39. KCSIE 2025: Data Protection, AI, and Cyber Security
  40. The Online SCR Data Breach: What You Need to Know
  41. Back to School Basics for Data Protection and Cyber Security Compliance
  42. Building a Secure School: Using the ICO Accountability Framework to Meet DfE Digital Standards
  43. Why Physical and Data Security Must Go Hand-In-Hand
  44. Digital Safeguarding: DfE announces statutory DfE Digital Standards
  45. The Data Protection Lead/Champion Role
  46. Changes to the Academy Trust Handbook 2025
  47. Social Media Day 2025
  48. How Ofsted looks at AI during inspection and regulation
  49. Preschool Employment tribunal for the use of WhatsApp
  50. Data Breaches 2025 Report Highlights
  51. Not everyone needs access: The Key to Protecting Sensitive Data
  52. West Lothian Schools in Cyber Attack
  53. National Honesty Day: Transparency
  54. FOI Request - BBC News
  55. Social Media and Marketing Guidelines and Training
  56. New Governor Resources
  57. Does stress lead to more data breaches?
  58. Are teachers using AI? 83% say its a time-saver
  59. DfE Digital Standards - narrowing the digital divide
  60. Arbor AI - On By Default
  61. DfE Guidance: Choosing a new MIS
  62. HCRG Care Group data breach
  63. The Importance of AI literacy and training staff
  64. Short Guide to AI Video
  65. Safer Internet Day, Cyber Security & Data Protection
  66. The Cyber Resilience Championship
  67. The Multiple Dimensions of Supplier Due Diligence
  68. School shares sensitive pupil information as part of an FOI response
  69. Blacon High School Cyber Attack
  70. WhatsApp and FOI's: ICO Warnings
  71. New AI Guidance from the DfE
  72. What the proposed Government legislative proposal around cyber crime means
  73. ICO report on AI tools in recruitment
  74. DfE update to record keeping and management
  75. Update to data sharing for school immunisation programmes
  76. Early Years Settings and Cyber Security
  77. SLT Digital Lead Profile
  78. The role of governors in cyber security and data protection
  79. Navigating Privacy at the End of Term , Special Occasions and End of Year
  80. Contracts Register
  81. DfE Digital Standards Autumn Update
  82. The importance of knowing how to access your CCTV footage!
  83. Cyber Attack on a Special School
  84. Stealing children's data
  85. What is dark data? (and why does it matter?)
  86. Ofqual highlights the value of cyber security training in schools
  87. Searching for data when you receive a Subject Access Request
  88. Fylde Coast Academy Trust Cyber Attack This Week
  89. Calling all IT leads in schools and mult academy trusts!
  90. Ransomware cyber attack on a school in Bromley
  91. Join Our Social Media Family!
  92. School hit by Cyber Attack
  93. Cyber Security Best Practice Area
  94. DfE Digital Standards for Schools and Colleges Tracker
  95. New Policies, Documents, Letters and Posters page
  96. Schools and Trusts Best Practice Area
  97. The DPE Retention Schedule
  98. Making the Rounds Update (now includes reporting)
  99. ESFA Cyber Essentials Requirement for Colleges from 2024/2025
  100. ICO Reprimands a School
  101. Out of date technology
  102. Data Retention and the Pupil File
  103. Have you assigned your SLT Digital Lead yet?
  104. Getting Started with AI (Artificial Intelligence)
  105. Cyber attack on a school during half term
  106. The rise of cyber attacks in schools are causing pupils to miss classes
  107. ICO: Learning from the mistakes of others report
  108. Cyber attack on a Trust; the aftermath
  109. School Focus: The Vale Federation | Aylesbury
  110. DfE Dealing with Subject Access Requests (SARs) Guidance
  111. Update to the Guidance on Information Sharing from the DfE
  112. FOI Requests generated by Artificial Intelligence
  113. Social Media Best Practice Area
  114. Lettings Best Practice Area
  115. MFA Bombing - What is it?
  116. Protecting your Social Media Accounts
  117. Checklists - Are They Your Most Powerful Compliance Tool?
  118. Product Focus on Checklists : Initial Trust Plan
  119. Product Focus on Checklists : End of Term Checklist
  120. Product Focus on Checklists : Information and Cyber Security
  121. Product Focus on Checklists : Social Media
  122. Product Focus on Checklists : Lettings
  123. Product Focus on Checklists : Record of Processing
  124. Milk Island: The secret location that allows children to view restricted content on Google Maps
  125. Why Data Should Stay Put: Benefits of Keeping Data in Its Original System
  126. Product Focus on Checklists : Data Retention and Destruction
  127. Product Focus on Checklists : Data Migration
  128. Product Focus on Checklists : Biometrics
  129. Product Focus on Checklists : Supplier Due Diligence
  130. Free Cyber help, advice and training with the Cyber Resilience Centres
  131. The Perils of Paper: The Printing Vulnerability
  132. Product Focus on Checklists : FOI
  133. Product Focus on Checklists : Governors and Data
  134. Product Focus on Checklists : DPIA
  135. Product Focus on Checklists : Site Moves
  136. Product Focus on Checklists : Data Breaches
  137. Product Focus on Checklists : Subject Access Requests
  138. Product Focus on Checklists : Bring your own device
  139. Product Focus on Checklists : Working out of school/offsite
  140. Cyber Attack on a School
  141. Product Focus on Checklists : Redaction
  142. Why Due Diligence is Important: Fake apps
  143. Product Focus on Checklists : CCTV
  144. Product Focus on Checklists : Clear desk
  145. Product Focus on Checklists : Commitment to compliance
  146. Product Focus on Checklists : Photos and video
  147. Product Focus on Checklists : Passwords
  148. Product Focus on Checklists : Information Classification
  149. Free cyber training for staff
  150. DfE Digital Standards Update
  151. The Mother of all Breaches
  152. International Data Transfers (part 1): Navigating Cross-Border Data Transfers: Understanding EU SCCs, UK Addendum, and UK IDTA
  153. ClassCharts Possible Data Breach
  154. Where is your data stored?
  155. IAPP looks at AI privacy risks
  156. If you suspect a financial scam .....
  157. School Focus: St Bernadette's Catholic Primary School | Brighton
  158. Guardians of Privacy: 16. Social Media Checklist
  159. Guardians of Privacy: 15. Navigating Social Media in Educational Settings Summary
  160. Guardians of Privacy: 14. Social Media and Cyber Bullying
  161. Guardians of Privacy: 13. Social Media, Copyright and Intellectual Property
  162. Guardians of Privacy: 12. Social Media and Going Viral
  163. Guardians of Privacy: 11. Staff Social Media Accounts
  164. Guardians of Privacy: 10. Social Media and Cookies
  165. Guardians of Privacy: 9. Social Media and Morality
  166. New Resources for Schools from the ICO
  167. Guardians of Privacy: 8. Social Media Policies
  168. Guardians of Privacy: 7. Social Media Data Retention
  169. Guardians of Privacy: 6. Posting Safely
  170. Guardians of Privacy: 5. Social Media and Consent
  171. Guardians of Privacy: 4. Social Media Access Control
  172. Guardians of Privacy: 3. Social Media Channels
  173. Guardians of Privacy: 2. Law and Regulations
  174. The ICO reprimands a Multi Academy Trust
  175. Guidance for the use of school email and applying email retention in schools
  176. Data Protection Tips for Early Years Settings
  177. Children's Privacy around the world is a puzzle
  178. Trust Initial Plan Checklist Update
  179. Records Management Best Practice Update
  180. What do I need to redact?
  181. Trust Initial Plan for Data Protection Compliance (for Multi Academy Trusts)
  182. Google for Education Resources: Helping IT Admins meet DfE digital and technology standards
  183. Lettings Best Practice and Guidance
  184. Considerations when migrating to a new MIS
  185. Public bodies and sensitive data
  186. Get a DPE Badge for your website!
  187. ICO: 10 Step guide to sharing information to safeguard children
  188. Help after a Cyber Attack/Incident
  189. Data Protection and Cyber Security (Inset Day) Training Ideas
  190. How KCSIE is linked to Cyber Strategy
  191. Handling Freedom of Information Requests the right way
  192. Where's Harry the Hacker?
  193. The ICO Reprimands a school
  194. Redaction Guidelines Updated
  195. Using WhatsApp in Schools
  196. How to contact us for support, subject access requests, data breaches and FOI's
  197. FOI: Reinforced Autoclaved Aerated Concrete
  198. FOI: Henry Jackson Society
  199. FOI: Vaccination Justifications
  200. How the Record of Processing Can Help You
  201. What does a Data Protection Officer Do?
  202. Carrying out Supplier Due Diligence
  203. How Long Should You Keep Personal Data For?
  204. B&H FoI: Racist/religious incidents/bullying
  205. Protocol for Setting Up and Delivery of Online Teaching and Learning
  206. Class Dojo International Data Sharing
  207. Model Publication Scheme: Amendments, Improvements and Updates
  208. Transparency
  209. Research projects and GDPR
  210. Secure file transfer of files using Royal Mail
  211. Emergency contacts and consent
  212. Key elements of a successful DPIA
  213. FOI Publication Schemes
  214. Best Practice for Managing Photos and Video
  215. New Drip Feeds: Recognise and Respond to Subject Access Request
  216. When to contact the Data Protection Officer?
  217. National child measurement programme
  218. Headteacher fined for breach of data protection legislation
  219. Acceptable Use Policy

Search