A Management Information System (MIS) is the single most important data processing system a school operates. It holds pupil records, including special category data, safeguarding information, and family contact details. So when the Department for Education publishes guidance on choosing one, DPOs and data protection leads should pay attention, even when, as here, the guidance is framed in commercial rather than data protection terms.
The DfE's Commercial considerations when choosing a management information system (MIS) sets out the issues schools should think about when purchasing a new MIS or managing an existing arrangement. We flagged this guidance when it replaced the old MIS comparison table in our earlier article DfE Guidance: Choosing a new MIS. With MIS procurement now in sharp focus following the Academy Trust Handbook 2026 and the DfE's new procurement risk guide for academy trusts, it's worth revisiting what this guidance says and, just as importantly, what it doesn't.
What the guidance covers
The guidance is deliberately high-level and commercial. It reminds schools that MIS arrangements can be complex, layering legacy and new systems, on-premises and cloud services, and that the contract terms can be equally complex. It is not exhaustive and does not provide legal advice; schools are told to consider taking their own technical and legal advice.
The guidance signposts three things every school should already have in hand:
- Compliance with data protection and procurement regulations, linking to the DfE's Data Protection in Schools guidance, recently refreshed, as we covered in DfE updates Data Protection in Schools guidance;
- The DfE digital and technology standards, to check the right infrastructure is in place;
- The DfE cyber security standards: see our summary of the June 2026 update to the Cyber Security Core Standard.
The commercial points through a data protection lens
1. Charges, contract terms and staggered end dates
Payment terms are often variable and may change during the contract. The guidance tells schools to check all charges, how and when prices may increase, the cost of terminating during a fixed term, and whether different service elements have different contract end dates. Staggered end dates are a lock-in risk: there may be no single date on which the school can cleanly exit. Record every MIS-related contract, its term and its end date in your contracts register so nothing renews unnoticed.
2. Accepting new terms by clicking, or just carrying on
This is one of the most important warnings in the guidance. Systems, particularly cloud-based ones, may be designed so that a user agrees to a new contract or changed terms simply by clicking a link or continuing to use the system, and users may not realise they are agreeing to anything. A pop-up accepted by a busy member of office staff could vary the terms under which your school's personal data is processed.
Our advice: nominate who is authorised to accept supplier terms, and instruct all other MIS users to stop and escalate whenever they see a pop-up, email or sign-in notice referring to terms and conditions. Consult your data protection lead before anything is accepted.
3. Support services are a data protection matter too
Suppliers may require schools to have MIS support services in place, and the contract may stipulate who provides them. Schools should check whether they can choose a third-party support supplier (which may be cheaper) and whether support costs are included or additional. From a data protection perspective, remember: a support provider with access to your MIS is a data processor. They need their own UK GDPR Article 28 contract terms and their own due diligence , the same questions we set out in Is your IT Support Provider Compliant? apply here.
4. Corporate changes: academisation, MAT moves and mergers
If a school changes trust, becomes an academy, or undergoes any other corporate change, the MIS contract may be affected. The guidance tells schools to check notice requirements and comply with them. For trusts, this belongs on the due diligence checklist for any conversion or merger, alongside the wider procurement controls in the DfE procurement risk guide and the strengthened expectations in the Academy Trust Handbook 2026.
5. Availability, downtime and contingency planning
Many suppliers will not guarantee 24/7 availability. The guidance tells schools to understand what their agreement says about availability and to put contingency plans in place so they can continue to meet reporting and other obligations if the system is down. Ask the harder question too: if your MIS were unavailable for a week, whether through supplier outage or a ransomware incident like those we covered in the LockBit 5.0 attack on a primary school and the Powys schools attack: could you still safeguard pupils, contact parents and run the school day? Our guidance on what to do in the event of a cyber attack is a good starting point for that planning.
6. School obligations and "information sharing"
Supplier terms usually require the school to accept responsibility for significant commitments, which may include support services and information sharing. Read these sections carefully. Any clause describing what the supplier may do with your data, or what data you must share with them, deserves DPO scrutiny before signature.
7. Iterative services: your MIS will not stand still
Cloud providers often state that their services will develop iteratively. In practice this means schools must keep the MIS, and its terms, under review to spot any change in functionality or in the handling of data. A change in functionality can mean new processing purposes, new sub-processors or new data flows. Each of those can trigger a DPIA review and a privacy notice update.
8. Data on exit
Finally, schools should check what the supplier will do with data if the school moves to a new system. Under UK GDPR Article 28, the contract must provide for the return or deletion of personal data at the end of the contract, and migration is a high-risk moment in its own right. Our article Considerations when migrating to a new MIS and the Data Migration checklist in the Knowledge Bank cover this in detail. Test data portability before you sign, not at termination.
What the guidance doesn't say: DPIA and AI
Two words are missing from the guidance entirely: DPIA and AI.
DPIA: not optional for an MIS
Selecting or switching an MIS is a textbook trigger for a Data Protection Impact Assessment under UK GDPR Article 35: large-scale processing of children's data, including special category data such as SEN and medical information. The DPIA should be carried out before procurement decisions are made, not retro-fitted afterwards, and the guidance's own point about iteratively developing services means the DPIA must be reviewed whenever functionality or data handling changes. See Key elements of a successful DPIA and the DPIA checklist in the Knowledge Bank.
AI: the change you need to watch for
MIS suppliers are actively building AI features into their platforms, and sometimes switching them on by default, as we reported in Arbor AI - On By Default. When an MIS supplier enables an AI feature, that is precisely the change in "functionality or handling of data" the DfE says schools must watch for. It should prompt a DPIA review, scrutiny of whether pupil data is used for model training, and a check against the DfE's AI expectations, see New DfE AI Standards and our practical guide Can you use AI safely in schools?. Our free AI DPIA template is available to download.
MIS supplier due diligence: quick reference
| Question to ask | Why it matters |
| What are all the charges, and how can prices increase? | Payment terms are often variable and can change during the contract. |
| Do all service elements share one contract end date? | Staggered end dates mean there's no single clean exit point — a lock-in risk. |
| Who is authorised to accept terms & conditions? | Clicking a link or continuing to use the system can vary the contract. |
| Can we choose our own support provider and have we done due diligence on them? | A support provider with MIS access is a data processor needing Article 28 terms. |
| What happens to the contract if we convert, merge or change trust? | Corporate change may trigger notice requirements or renegotiation. |
| What availability is guaranteed, and what's our contingency plan? | Most suppliers won't guarantee 24/7 uptime : you must still meet your obligations. |
| How will we be told about changes to functionality or data handling? | Cloud services develop iteratively; new features (including AI) change your risk position. |
| What happens to our data when we leave? | The contract must provide for return or deletion of personal data on exit. |
| Has a DPIA been completed and when was it last reviewed? | An MIS is large-scale processing of children's data; a DPIA is required and must stay current. |
Action list for schools and trusts
- Consult your DPO early: before procurement decisions, contract renewals or system changes, not after.
- Complete or review the MIS DPIA, and diarise a review whenever the supplier announces new features.
- Log all MIS-related contracts (core system, support, add-on modules) in your contracts register with their end dates.
- Nominate who can accept supplier terms and brief all MIS users to escalate pop-ups and T&C notices.
- Run supplier due diligence on the MIS provider and any support provider, our step-by-step guide and The Multiple Dimensions of Supplier Due Diligence explain how, and DPE customers can use the Supplier Due Diligence checklist in the Knowledge Bank.
- Check exit and migration arrangements now, while you have negotiating leverage.
- Test your contingency plan for MIS downtime as part of your wider cyber resilience work under the DfE cyber security standards.
How DPE can help
The DfE has given schools the commercial questions to ask. Your DPO's job is to add the data protection questions the guidance assumes but doesn't spell out: DPIA before procurement, Article 28 contract terms, exit and deletion arrangements, controlled acceptance of terms, and vigilance when suppliers add AI. DPE customers can raise MIS procurement and DPIAs with the helpdesk at any time, and the Knowledge Bank includes supplier due diligence, DPIA and data migration checklists to support the process.
Contact us:
