Digital graphic symbolizing a cyber attack and data breach at the Department for Education (DfE).

The Department for Education confirmed that hackers have accessed its internal helpdesk and the Turing Scheme portal, taking more than 600,000 records. Contact details belonging to headteachers, senior school leaders, government officials and university staff were among the data taken, and some of it has since appeared on the dark web.

Understandably, this has caused a lot of anxiety across the sector and, predictably, a lot of speculation. Was this preventable? Should the DfE have done more? Who's to blame?

Digital screen interface representing a school Management Information System (MIS) handling pupil records and DfE

A Management Information System (MIS) is the single most important data processing system a school operates. It holds pupil records, including special category data, safeguarding information, and family contact details. So when the Department for Education publishes guidance on choosing one, DPOs and data protection leads should pay attention, even when, as here, the guidance is framed in commercial rather than data protection terms.

Cover image of the Academy Trust Handbook 2026, detailing new DfE digital standards and procurement requirements.

The Academy Trust Handbook 2026 was published on 15 July 2026 and comes into effect on 1 October 2026. This year's edition strengthens the position on the DfE digital and technology standards and introduces new procurement requirements that have direct data protection implications, most notably around Management Information Systems (MIS).

Graphic representing new DfE guidance on EdTech procurement for schools, focusing on data protection.

On 9 July 2026, the DfE added a new section to its Data Protection in Schools guidance: Procuring educational technology (EdTech). It sets out what schools should consider before, during and after procuring EdTech tools, and the questions to put to prospective suppliers. Significantly, it is the first DfE guidance to directly reference the ICO's EdTech Examined audit report, telling schools to take the ICO's findings into consideration when procuring EdTech tools.

ICO EdTech Examined report graphic, highlighting data protection audit findings for UK schools and children'

The ICO's edtech audit programme, covering 28 providers used across UK primary and secondary schools, has resulted in one of the most significant data protection reports to affect the education sector in years. Published in June 2025, the ICO's EdTech Examined report made 596 recommendations and found widespread compliance failures in how edtech providers handle children's personal data. This article sets out what was found and what schools and DPOs need to do about it.

Graphic representing the Department for Education (DfE) Data Protection in Schools guidance update from June

The Department for Education (DfE) updated its Data protection in schools guidance on 17 June 2026, this refresh aligns the guidance with the wider expected KCSIE 2026 guidance and reinforces existing obligations that schools should already be acting on.

This article sets out what has changed, what it means for your school in practice, and the actions your data protection lead should be taking now.

 

DfE Filtering and Monitoring Core Standard graphic for schools and colleges, essential for safeguarding children.

The Keeping Children Safe in Education (KCSIE) document obliges schools and colleges in England to ensure appropriate filters and appropriate monitoring systems are in place and regularly review their effectiveness”. This responsibility is now a standard, no just a technical tick box, but a core leadership and safeguarding function.

Shottermill Junior School building in Haslemere, Surrey, recently impacted by a

In May 2026, Shottermill Junior School in Haslemere, Surrey became the latest UK primary school to fall victim to a ransomware attack. The LockBit 5.0 group officially listed the school as a victim on 9 June 2026, with threat intelligence monitors detecting the initial network infiltration as far back as 20 May 2026. This means the attackers had approximately three weeks of dwell time inside school systems before the attack became public knowledge.

 

Illustration depicting a cyber attack impacting Powys County Council, symbolizing the theft of personal data from schools in

What Happened?

On 4 June 2026, Powys County Council confirmed that a cyber security incident had resulted in the theft of personal data belonging to pupils, staff, and others connected to schools in mid-Wales. Thirteen schools were affected by the wider incident, with personal data specifically taken from at least one. The attack was first identified in April 2026 and, according to the council, was “quickly contained”, but not before unauthorised access to personal data had already occurred.

Illustration for World Environment Day showing the Earth surrounded by green leaves, symbolizing environmental protection and responsible waste

When we talk about environmental responsibility, we reach for the obvious symbols: carbon footprints, single-use plastic, recycling bins in the staffroom. But in schools and Multi-Academy Trusts, there’s another kind of clutter building up quietly and can carry its own consequence.

Graphic representing online data protection inset training sessions for September, focusing on security and privacy.

📢 Thinking about your training for inset days in September? Then look no further and book onto our online training sessions.

A graphic celebrating World Password Day 2026, emphasizing strong password security and cyber defense

🔒  World Password Day 2026

Keeping your organisation secure in a changing authentication landscape

 

Illustration of the Children's Wellbeing Act, symbolizing agencies collaborating to ensure child safety and wellbeing.

What is this? A new law that came into force on 29 April 2026. It changes how schools, councils, health services and police work together to keep children safe. Several parts of it directly affect how schools handle children's information. Data Protection is now embedded within Safeguarding practice.

Modern visitor management system for schools, balancing safeguarding, data protection, and DfE

Navigating the entry requirements for educational settings can sometimes be confusing for both the school and the visitor.  To ensure a smooth, secure, and legally compliant process, it is essential to balance safeguarding requirements with data protection principles and DfE guidance.

A security camera representing CCTV compliance, UK GDPR, and data protection legal obligations.

Following the popularity of our recent CCTV webinar, we've published some pointers for headteachers, governance professionals, head of operations and estates managers about CCTV compliance.


We discuss the legal obligations and common pitfalls of CCTV surveillance under the UK GDPR and Data Protection law.

Legal Foundations for Organisations

To operate CCTV lawfully, organisations must move beyond just installing camera.

  • Lawful basis - every camera must have a lawful basis.
  • DPIA - is mandatory and should be completed before installation to prove the system is necessary and proportionate/
  • Special category data - CCTV cameras capture sensitive information (i.e. race, health/disability), which requires a specific article 9 condition for processing.

High Risk Locations: Toilets & Changing Rooms

Placing cameras in or near private areas carries extreme legal risk under the Human Rights Act 1998.

  • Expectation of Privacy: pupils and staff have a high expectation of privacy in toilets.
  • Proportionality Test: you must prove that less intrusive methods failed before installing CCTV. This might include increased supervision, better lighting, vaping sensors for example.
  • Criminal Liability: capturing intimate footage of minors can lead to criminal changes.

Top 10 CCTV Compliance Essentials

Mistake

Fix

No DPIA

Conduct an assessment for existing systems immediately.

Wrong Lawful Basis

Update policies appropriately.

Outdated Policy

Review CCTV policies annually; include 2025 Act updates.

Conduct a DPIA for new CCTV systems.

Poor Signage or No Signage

Ensure signs list the operator, purpose, and contact details at appropriate locations. Someone should know they are being filmed!

Excessive Retention

Stick to 14–28 days; set up auto-overwrite.  Ensure your ACTUAL retention period meets your DOCUMENTED retention period in  your retention/CCTV policy. Review our article: The importance of knowing how to access your CCTV footage!

Ensure your footage is long enough to cover a holiday period in the event of a SAR receipt.  Deleting footage relating to a SAR could be a criminal offence (Section 173 Data Protection Act 2018).

Audio Recording

Disable it. Audio capture is rarely justifiable in schools.

No Access Log

Record every time footage is viewed, by whom, and why.

SAR Mishandling

Respond within one month; redact third parties in footage. You will likely need specialised redaction software.

Contact DPE for more advice on CCTV redaction.

Neighbour Privacy

Use digital masking to avoid filming residential properties. Ensure you know what your camera is recording.

Late DPO

 Involvement

Consult your DPO before making system changes.

Summary Checklist

  1. Appoint/Consult a DPO for all CCTV decisions.

  2. Layer your notices: Short signs at entrances, full policy on the website.

  3. Be transparent: Tell parents and staff why and where cameras are used.

  4. Report Breaches: If footage is lost or misused, you must notify the ICO within 72 hours.

Contact for Support: Data Protection Education provides DPO services, DPIA templates, and redaction support. Email: This email address is being protected from spambots. You need JavaScript enabled to view it. | Phone: 0800 0862018

DPE Customers Resources

DPE customers have access to the CCTV Best Practice Area which includes signs, template policies and guidance. We can also do a review of the CCTV when visiting during our data walks (Making the Rounds) or we can come and do a full CCTV Audit.  Customers may also choose to complete the CCTV Checklist as part of their compliance documentation.

  1. Wireless Network Standards for Schools & Colleges: What's New?
  2. How were schools and pupils affected by the C2K cyber attack?
  3. World Backup Day: Backups - Your Safety Net
  4. School Cyber Attack: St Anne's Catholic School
  5. Volunteer Acceptable Use Policy & Agreement
  6. Handling Subject Access Requests (SARs) - at the end of term
  7. Holiday Cheer or Cyber Fear? : Essential Pre-holiday Checks
  8. How should schools manage paper archives?
  9. Navigating the Redaction Divide: SAR or PEX?
  10. What is the Stryker cyber attack and why should schools be wary?
  11. Records Management Toolkit: Where do I start with records management?
  12. What type of request have you received? SAR? Educational Record? Or FOI?
  13. SAR Extension Template
  14. Leavers' Memorabilia
  15. Sharing photos on World Book Day: Privacy considerations
  16. Make sure DPE is your registered DPO with the ICO
  17. Supplier Due Diligence Step by Step: Are you sharing personal data with a third party organisation?
  18. Time to kick-start your Clear Desk and Screen policy?
  19. Are Governors the Frontline of Cyber Security? (February 12th is Governors Awareness Day)
  20. DPE Webinar Schedule
  21. The Data (Use and Access) Act: What does it mean for schools and MATs?
  22. Podcast Episode 2: Data (Use and Access) Act - what does it mean for schools?
  23. The Danger of the 'Data Dump': Why more information isn't always better!
  24. Cyber Alert: Surrey and Sussex Schools Targeted by Phishing and Ransomware Attacks
  25. Introducing our new Recording and Transcription Policy
  26. Parents and students covertly recording conversations
  27. New DfE AI Standards
  28. Is your IT Support Provider Compliant?
  29. The Government Cyber Action Plan
  30. School Cyber Attack: Higham Lane School Hit by Major Cyber Attack: Campus Remains Closed
  31. Shareable Snippet: Office Security Best Practices for the Holidays
  32. CCTV Policy update: retention
  33. Shareable Snippet: Be Cyber Ready
  34. Shareable Snippet: Confidential waste
  35. What does the technology in schools survey tell us?
  36. Four London councils hit by cyber attacks - Hackney, Westminster, Kensington & Chelsea, and Hammersmith & Fulham
  37. IT Support Standards for Schools and Colleges Guidance (DfE Digital Standards)
  38. Sharing information to safeguard children and young people in the education sector in the UK
  39. Is your organisation at risk from Shadow AI?
  40. October 31. On the road to improving cyber resilience
  41. October 30. Cyber Support
  42. October 29. Admin Controls & Accounts
  43. October 28. Phishing: Don't Take the Bait!
  44. October 27. Passwords
  45. October 26. Physical Security of Digital Assets
  46. October 25. Server Security: Protecting Your Digital Core
  47. October 24. Backups: Your Recovery Safety Net
  48. October 23. Filtering and Monitoring
  49. October 22. Hardware: Printers
  50. October 21. Hardware: Asset Management
  51. October 20. Hardware: Safe disposal
  52. October 19. Anti-virus/anti-malware
  53. October 18. Regular Updates: Patching Against Threats
  54. October 17. Access Control: Managing User Privileges
  55. October 16. Access Control: Securing Your Digital Gateways (Wi-Fi & Networks)
  56. October 15. Access Control: Securing Your Home Office (Working From Home)
  57. October 14. Access Control : (Multi-factor authentication)
  58. We've teamed up on a podcast with the Small Business Cyber Security Guy
  59. October 13. Cyber Security Awareness
  60. October 12. Training: Empowering your human firewall
  61. October 11. Policies and Procedures: Cyber Blueprint
  62. October 10. Understanding Your Cyber Posture
  63. Time's Ticking: Windows 10 support ends in October 2025!
  64. October 9. A Guide for Education Providers
  65. October 8. How Can Your Organisation Prevent Ransomware Attacks?
  66. October 7: Under Attack: The Reality of Ransomware
  67. October 6: Cyber Action Plan and A Roadmap to Resilience
  68. October 5: Cyber Responsibilities - We're All in This Together
  69. October 4: When a Cyber Attack Hits
  70. October 3: Data Security, the Core of Protection
  71. October 2: Privacy Protection & Safeguarding Personal Data
  72. October 1: Welcome to Cyber Security Awareness Month!
  73. Nursery Cyber attack
  74. The NCSC Cyber Assessment Framework
  75. Fraud awareness from the DfE
  76. Complaints vs. Data Rights: A Guide
  77. The Classroom's Dark Side: Cyber crime from the Classroom
  78. Data Breach: School sends out names and contact details in a spreadsheet.
  79. September 2025 Policy and Document Updates
  80. KCSIE 2025: Data Protection, AI, and Cyber Security
  81. New e-learning for 2025
  82. The Online SCR Data Breach: What You Need to Know
  83. Back to School Basics for Data Protection and Cyber Security Compliance
  84. The Latest Cyber Threat: The "Murky Panda"
  85. Building a Secure School: Using the ICO Accountability Framework to Meet DfE Digital Standards
  86. Why Physical and Data Security Must Go Hand-In-Hand
  87. Digital Safeguarding: DfE announces statutory DfE Digital Standards
  88. The Data Protection Lead/Champion Role
  89. Changes to the Academy Trust Handbook 2025
  90. Compliance Reporting from the Knowledge Bank
  91. School closes for two days after cyber incident
  92. Social Media Day 2025
  93. How Ofsted looks at AI during inspection and regulation
  94. Podcast Episode 3: Records Management and Retention
  95. Podcast Episode 1 - data protection training for school staff
  96. Preschool Employment tribunal for the use of WhatsApp
  97. Social engineering + impersonation = Fraud ≡ cyber deception
  98. Data Breaches 2025 Report Highlights
  99. Not everyone needs access: The Key to Protecting Sensitive Data
  100. School cyber attack: Outwood Academy, Middlesbrough
  101. Alert: Schools receiving Microsoft File Sharing Phishing Emails
  102. School cyber attack: Framlingham College, Suffolk
  103. West Lothian Schools in Cyber Attack
  104. Getting caught in the Scattered Spider web
  105. A Wake-Up Call for Cyber Vigilance - Danger in the Threat Landscape for Everyone
  106. National Honesty Day: Transparency
  107. FOI Request - BBC News
  108. Social Media and Marketing Guidelines and Training
  109. New Governor Resources
  110. Does stress lead to more data breaches?
  111. Are teachers using AI? 83% say its a time-saver
  112. DfE Digital Standards - narrowing the digital divide
  113. Arbor AI - On By Default
  114. DfE Guidance: Choosing a new MIS
  115. HCRG Care Group data breach
  116. Apple removes its highest level data security tool from UK customers
  117. The Importance of AI literacy and training staff
  118. Short Guide to AI Video
  119. Safer Internet Day, Cyber Security & Data Protection
  120. The Cyber Resilience Championship
  121. The Multiple Dimensions of Supplier Due Diligence
  122. School shares sensitive pupil information as part of an FOI response
  123. AI (Artificial Intelligence) Best Practice Area & Policy
  124. Blacon High School Cyber Attack
  125. WhatsApp and FOI's: ICO Warnings
  126. New AI Guidance from the DfE
  127. The role of Passkeys in Cyber Resilience and Cyber Security
  128. What the proposed Government legislative proposal around cyber crime means
  129. ICO report on AI tools in recruitment
  130. DfE update to record keeping and management
  131. Update to data sharing for school immunisation programmes
  132. Early Years Settings and Cyber Security
  133. SLT Digital Lead Profile
  134. The role of governors in cyber security and data protection
  135. Navigating Privacy at the End of Term , Special Occasions and End of Year
  136. Effectively communicating during a cyber incident
  137. Contracts Register
  138. South East Technological University has experienced a cyber incident
  139. Safeguarding Identity in Microsoft 365: Protecting the UK Education Sector Against Cyber Threats
  140. DfE Digital Standards Autumn Update
  141. The importance of knowing how to access your CCTV footage!
  142. Cyber Attack on a Special School
  143. Stealing children's data
  144. What is dark data? (and why does it matter?)
  145. Ofqual highlights the value of cyber security training in schools
  146. Searching for data when you receive a Subject Access Request
  147. Fylde Coast Academy Trust Cyber Attack This Week
  148. Calling all IT leads in schools and mult academy trusts!
  149. Ransomware cyber attack on a school in Bromley
  150. Join Our Social Media Family!
  151. School hit by Cyber Attack
  152. Cyber Security Best Practice Area
  153. DfE Digital Standards for Schools and Colleges Tracker
  154. New Policies, Documents, Letters and Posters page
  155. Schools and Trusts Best Practice Area
  156. The DPE Retention Schedule
  157. Making the Rounds Update (now includes reporting)
  158. ESFA Cyber Essentials Requirement for Colleges from 2024/2025
  159. ICO Reprimands a School
  160. How does the recent global IT outage affect me?
  161. King's speech introduces new bills in relation to cyber security, smart data and digital information
  162. Out of date technology
  163. Data Retention and the Pupil File
  164. Have you assigned your SLT Digital Lead yet?
  165. What's a Cyber Incident and what should we do?
  166. Getting Started with AI (Artificial Intelligence)
  167. Cyber attack on a school during half term
  168. Free short cyber training for staff
  169. The rise of cyber attacks in schools are causing pupils to miss classes
  170. ICO: Learning from the mistakes of others report
  171. Children's mental health data leaked after a cyber attack
  172. Cyber attack on a Trust; the aftermath
  173. School Focus: The Vale Federation | Aylesbury
  174. DfE Dealing with Subject Access Requests (SARs) Guidance
  175. Update to the Guidance on Information Sharing from the DfE
  176. FOI Requests generated by Artificial Intelligence
  177. Social Media Best Practice Area
  178. Lettings Best Practice Area
  179. MFA Bombing - What is it?
  180. Protecting your Social Media Accounts
  181. Product Focus on Checklists : Initial Trust Plan
  182. Product Focus on Checklists : End of Term Checklist
  183. Product Focus on Checklists : Information and Cyber Security
  184. Product Focus on Checklists : Social Media
  185. Cyber Incident Review: The Benefits
  186. Product Focus on Checklists : Lettings
  187. Product Focus on Checklists : Record of Processing
  188. Milk Island: The secret location that allows children to view restricted content on Google Maps
  189. Why Data Should Stay Put: Benefits of Keeping Data in Its Original System
  190. Product Focus on Checklists : Data Retention and Destruction
  191. Product Focus on Checklists : Data Migration
  192. Product Focus on Checklists : Biometrics
  193. Product Focus on Checklists : Supplier Due Diligence
  194. Free Cyber help, advice and training with the Cyber Resilience Centres
  195. The Perils of Paper: The Printing Vulnerability
  196. Product Focus on Checklists : FOI
  197. Product Focus on Checklists : Governors and Data
  198. Product Focus on Checklists : DPIA
  199. Product Focus on Checklists : Site Moves
  200. Product Focus on Checklists : Data Breaches
  201. Product Focus on Checklists : Subject Access Requests
  202. Cyber attack on a University
  203. Product Focus on Checklists : Bring your own device
  204. Product Focus on Checklists : Working out of school/offsite
  205. Cyber Attack on a School
  206. Product Focus on Checklists : Redaction
  207. Major cyber-criminal gang Lockbit brought down by UK Law Enforcement
  208. Why Due Diligence is Important: Fake apps
  209. Product Focus on Checklists : CCTV
  210. Product Focus on Checklists : Clear desk
  211. Product Focus on Checklists : Commitment to compliance
  212. Product Focus on Checklists : Photos and video
  213. Product Focus on Checklists : Passwords
  214. Product Focus on Checklists : Information Classification
  215. Safer Internet Day 2024
  216. Kent Councils Data Breach
  217. Free cyber training for staff
  218. DfE Digital Standards Update
  219. The Mother of all Breaches
  220. ClassCharts Possible Data Breach
  221. Where is your data stored?
  222. IAPP looks at AI privacy risks
  223. If you suspect a financial scam .....
  224. Guardians of Privacy: 16. Social Media Checklist
  225. Guardians of Privacy: 15. Navigating Social Media in Educational Settings Summary
  226. Guardians of Privacy: 14. Social Media and Cyber Bullying
  227. Guardians of Privacy: 13. Social Media, Copyright and Intellectual Property
  228. Guardians of Privacy: 12. Social Media and Going Viral
  229. Guardians of Privacy: 11. Staff Social Media Accounts
  230. Guardians of Privacy: 10. Social Media and Cookies
  231. Guardians of Privacy: 9. Social Media and Morality
  232. New Resources for Schools from the ICO
  233. Guardians of Privacy: 8. Social Media Policies
  234. Guardians of Privacy: 7. Social Media Data Retention
  235. Guardians of Privacy: 6. Posting Safely
  236. Guardians of Privacy: 5. Social Media and Consent
  237. Guardians of Privacy: 4. Social Media Access Control
  238. Guardians of Privacy: 3. Social Media Channels
  239. Guardians of Privacy: 2. Law and Regulations
  240. Latest ICO Reprimand. Mr. S. Claus, Chief Executive Officer, North Pole Enterprises
  241. Phishing attacks targeting schools - alert from City of London Police
  242. The ICO reprimands a Multi Academy Trust
  243. Guidance for the use of school email and applying email retention in schools
  244. CISA and UK NCSC Announce Joint Guidelines for Secure AI System Development
  245. Data Protection Tips for Early Years Settings
  246. Children's Privacy around the world is a puzzle
  247. Trust Initial Plan Checklist Update
  248. Update on Advisory for Rhysida Ransomware
  249. Records Management Best Practice Update
  250. The Crime in a Cyber Attack and a Data Breach
  251. What do I need to redact?
  252. NCSC Annual Review is published for 2023
  253. Learning from Data Breaches
  254. Windows 11 security ineffective against attacks on old devices
  255. Trust Initial Plan for Data Protection Compliance (for Multi Academy Trusts)
  256. International Counter Ransomware Initiative 2023 Joint Statement
  257. Google for Education Resources: Helping IT Admins meet DfE digital and technology standards
  258. Top Ten Cyber Security Misconfigurations
  259. Lettings Best Practice and Guidance
  260. ICO Reprimand: company suffered a ransomware attack
  261. The UK Online Safety Bill becomes an Act (Law)
  262. Considerations when migrating to a new MIS
  263. The importance of software updates (PaperCut vulnerability and Rhysida ransomware)
  264. Public bodies and sensitive data
  265. Adding offline bulk training using the Certificates function
  266. Ransomware, extortion and the cyber crime ecosystem
  267. Get a DPE Badge for your website!
  268. ICO: 10 Step guide to sharing information to safeguard children
  269. Cyber Resource: The Cyber Resilience Centre Group
  270. Email and Security: ICO recent guidance
  271. Help after a Cyber Attack/Incident
  272. Social Media Policy
  273. Data Protection and Cyber Security (Inset Day) Training Ideas
  274. Changes to Microsoft Free Licensing for Schools
  275. What to do in the event of a Cyber Attack
  276. Cyber Crime: AI Generated Phishing Attacks
  277. Handling Freedom of Information Requests the right way
  278. Cyber Attack: Exam Boards
  279. VICE SOCIETY - Ransomware attacks on schools
  280. Using Tags if you are a group of organisations in the DPE Knowledge Bank
  281. Where's Harry the Hacker?
  282. Be Cyber Aware: USB Sticks
  283. Cyber Insurance in the Public Sector
  284. Types of Cyber Attacks: DDos Attack (Microsoft DDoS Attack in June)
  285. Cyber Attack: Leytonstone School
  286. The ICO Reprimands a school
  287. Be Cyber Aware: Firewalls
  288. Be Cyber Aware: Cyber attacks and transparency. A no blame culture
  289. Cyber Attack: Dorchester School
  290. Knowledge Bank Role Types: Admin, Staff and Trustee
  291. Types of Cyber Attacks: Password Attacks
  292. Be Cyber Aware: Why regular software updates are important
  293. Cyber Attack: Wiltshire School
  294. Keeping your IT systems safe and secure
  295. Types of Cyber Attacks: DDoS Attacks
  296. Types of Cyber Attacks: Phishing
  297. Types of Cyber Attacks: The Insider Threat
  298. Why your data is profitable to cyber criminals
  299. Using WhatsApp in Schools
  300. The Changes to Data Protection in the UK
  301. Knowledge Bank Updates
  302. Types of malware and how they are linked to data protection
  303. Striking Data Breach
  304. IPR Protection Email Scam
  305. Windows Server 2012 & 2012 R2 Retirement
  306. How to contact us for support, subject access requests, data breaches and FOI's
  307. YouTube breached child protection laws
  308. How a school fought back after a cyberattack
  309. Types of Cyber Attacks - Credential Stuffing
  310. January Cyber update - How Can Schools Help Prevent Cyber Attacks?
  311. Assigning courses to staff using to-dos
  312. How the Record of Processing Can Help You
  313. Information Security Basics: What are VPN's?
  314. What does a Data Protection Officer Do?
  315. Are you ready for a Data Breach?
  316. Carrying out Supplier Due Diligence
  317. How Long Should You Keep Personal Data For?
  318. The Education sector now at highest risk of cyber attacks
  319. How to Assess your Data Security
  320. Schools Blocked from Using Facial Recognition Systems
  321. The Children's Code
  322. B&H FoI: Racist/religious incidents/bullying
  323. Cyber Attacks
  324. Protocol for Setting Up and Delivery of Online Teaching and Learning
  325. Class Dojo International Data Sharing
  326. Model Publication Scheme: Amendments, Improvements and Updates
  327. Child friendly privacy notices
  328. Transparency
  329. Secure file transfer of files using Royal Mail
  330. Emergency contacts and consent
  331. Key elements of a successful DPIA
  332. FOI Publication Schemes
  333. SHARE: Avoid disinformation online
  334. Best Practice for Managing Photos and Video
  335. New Drip Feeds: Recognise and Respond to Subject Access Request
  336. When to contact the Data Protection Officer?
  337. National child measurement programme
  338. Compliance Manager released
  339. Headteacher fined for breach of data protection legislation
  340. Emails – good practice and minimising the risk of a data breach

Search

Keep in the Know!

Get our latest news directly to your inbox

Privacy notice