Most organisations will ask us to come and do a data walk at some point, when one of our consultants will visit your site and walk around with your data protection lead. If you are a DPO Assure customer, it is included as part of your SLA, but it is also possible to purchase a visit from one of our school consultants.
Understanding "making the rounds" audits, the 12-point compliance framework, and what schools should expect from a report
A data protection walk, sometimes called “making the rounds”, is a physical, walk-through audit of a school or trust's premises to check how personal data is being handled in practice, not just on paper. Rather than reviewing policies from a desk, someone physically walks the site: corridors, offices, staffrooms, reception, server rooms, and classrooms, looking at what's actually happening with data day to day.
It's the practical, on-the-ground companion to a school's written data protection policies, testing whether what's documented matches what's really going on.
Who Does It
Data protection walks are typically carried out by:
- A data protection consultant or advisor from DPE; usually someone who has worked in a school before.
It helps us to walk around with or speak to:
- The school administrator or school business manager
- SLT (head teacher or deputy)
- The SENCO
- The IT Lead
- The site manager or caretaker
What We Talk About
A thorough walk works through several key areas of the site:
• Building and visitor access: are entrances secure, is visitor sign-in handled properly, is there a privacy notice for visitors, and is visitor data limited to what's actually needed?
• Room-by-room observations: is personal information (especially sensitive categories like safeguarding files) visible or accessible? Are rooms and cabinets locked? Are computers left unlocked with applications open? Is confidential waste dealt with properly, and are desks left clear?
• Device management: server room security, network switch cabinets, mobile device management, asset registers, and multi-factor authentication on cloud systems.
• Wi-Fi: consistent coverage and secure segregation of guest access from the main network.
• Lettings: who else gets access to the building (and by extension, to data left out) once the school day ends, and whether external hirers have been told about CCTV and privacy arrangements.
• Paper management: printer/photocopier access controls, confidential waste bins, and what actually turns up in the general recycling.
• CCTV: camera coverage, monitor and DVR security, and footage retention periods.
Each of these prompts typically comes with built-in guidance: why it matters, the risk if it's not managed well, and which UK GDPR principle it relates to (confidentiality, integrity, and so on), thus turning the walk into a teaching moment as well as an inspection.
The Report and the 12-Point Compliance Plan
The output of the walk is a structured report, and the centrepiece is usually a 12-point compliance framework that translates everything observed into a simple status check across each area:
1. Secure storage: sensitive information properly stored; keys not left in locks or drawers; access limited to those who need it.
2. Minimisation of paper folders: evidence of active reduction in paper records in favour of secure digital systems.
3. Secure solutions: paper and electronic files both properly access-controlled, with no unnecessary duplication between the two, and least-privilege access applied.
4. Clear desk/wall policy: surfaces clear of sensitive data at day's end, and regular review of what's displayed on walls or interactive whiteboards.
5. Secure disposal/confidential waste management: proper shredding or locked waste bins in use, with no crossover between confidential and general waste.
6. Device locking: both technical (auto-lockout) and physical locking of devices and device storage.
7. Security controls: MFA configured on cloud systems, and printers requiring PIN or fob release.
8. Retention and records management: clear awareness of retention periods and active processes to remove clutter, both digital and physical.
9. Device management: asset registers and mobile device management in line with recognised digital standards.
10. Staff awareness: staff understand password/device security and the risks of tools like AI, with good general email hygiene.
11. CCTV: camera and footage handling meets requirements, backed by a DPIA where CCTV is in use.
12. Regular audits: evidence that walks like this one happen regularly, with documented feedback to staff.
Each point is scored, and the report rolls this up into an overall compliance status:
• Action Required: significant gaps exist and support is needed
• Making Progress: a good standing overall, with some areas still developing
• Fully Compliant: all 12 points are being met
The report closes with space for DPO feedback and the actions agreed as a result , turning the walk from a one-off snapshot into part of an ongoing compliance cycle.
Customers can do their own data walk:
However, a number of customers ask us how to do this themselves. With that in mind, we've put some guidance together.
A data walk is a good opportunity to view what personal data is on display around your organisation. As you walk around consider who else might have access to the data during the day and when everyone has left. This video gives an overview of what doing a data walk is about and how to record the details on the Knowledge Bank:
A pdf step by step guide can be found in the Using the Knowledge Bank Best Practice Library:
pdf
Making the Rounds(579 KB)
This information about Lettings may also be useful: Lettings Best Practice and Guidance
