Cyber security and data protection sit side by side. Cyber security protects the systems; data protection governs what happens to the personal data inside them. In a school, that data is mostly about children, so the stakes are higher than in most sectors.
Data security is the core of protection
Data privacy is the protection of personal data from those who shouldn't have access to it, and the ability of individuals to know and control who does. Access control, both physical (who can walk into the server room) and online (who can log into which system), is central to that. As more school data moves online and into the cloud, controlling access has become one of the most basic and most important parts of data protection.
This is where privacy by design comes in. It means thinking about privacy at the start of a project, not bolting it on afterwards, whenever you introduce a new product, process or service that involves personal data. In practice, that thinking happens through a Data Protection Impact Assessment.
What is a DPIA, and when do you need one?
A Data Protection Impact Assessment (DPIA) is a structured way of identifying and reducing the data protection risks of a project before it goes ahead. Under UK GDPR, you must carry out a DPIA where processing is likely to result in a high risk to individuals, for example large-scale processing of special category data, systematic monitoring, or new technology.
In a school, that commonly means a DPIA is needed for:
- A new MIS, safeguarding or wellbeing system
- CCTV, including facial recognition or biometric attendance systems
- Any AI tool that processes pupil or staff data, including tools used for marking, safeguarding monitoring, or admin
- Cloud services that store or process personal data
- Data sharing arrangements with other organisations
Getting this wrong exposes children's and staff's most sensitive information: safeguarding notes, special educational needs information, and behavioural or medical records. A DPIA done well identifies the risk before the system goes live, when it's still cheap and easy to fix. Done after the event, the same risk becomes an ICO investigation, or worse, a real harm to a child.
Why this matters more with AI
New AI tools are appearing in schools faster than most policies can keep up with. Before any AI tool touches pupil or staff data, whether it's used for marking, safeguarding triage or admin, it needs its own DPIA that considers the specific risks of that tool: what data it processes, where it's hosted, whether it's used to make decisions about a child, and whether staff and families have been told how it works.
The Data (Use and Access) Act 2025 hasn't removed this requirement
Some of the headlines about the Data (Use and Access) Act 2025 (DUAA) have suggested UK data protection law has been relaxed. It hasn't. The DUAA amends the UK GDPR and DPA 2018; it doesn't replace them, and the DPIA requirement is unchanged. What has changed for schools is mostly procedural: a new statutory duty to have a data protection complaints process in place (from June 2026), and a clearer "relevant time period" for subject access requests. The DUAA also introduces "recognised legitimate interests", but most school processing relies on the public task basis, so this has limited practical effect. Review your data protection policy to make sure it now refers to your data rights complaints process.
What good access control looks like
- Least privilege: Staff and pupils should only have access to the data and systems they need for their role.
- Regular reviews: Review who has access to what at least once a term, and remove access immediately when someone leaves or changes role.
- Strong authentication: Passwords and multi-factor authentication protect the accounts that hold the data.
- Physical security: Server rooms, filing cabinets and unattended screens all count.
- Know your data: You can't protect what you haven't mapped. A record of processing activities (ROPA) tells you what personal data you hold, why, and who can access it.
💡 Today's Cyber Tip: Check whether your next project needs a DPIA
Before you sign off on a new system, app or AI tool this term, ask: does this involve personal data, and could it be high risk? If you're not sure, treat it as a DPIA trigger and speak to your DPO before go-live, not after.
DPE Knowledge Bank Guidance and Support
Our DPO team can help you complete a DPIA for any new system, process or AI tool before it goes live: Supplier Due Diligence Step by Step
Review our Data Protection Best Practice Area for policies, templates and guidance.
Explore our AI Policy and DPIA templates.
Our DfE Digital Standards Trackers helps you track your cyber resilience and progress.
