• Taking and displaying pupil photos and information There are no hard and fast rules under UK GDPR on displaying pupil photos or other information, but you must have a 'lawful basis' for using personal data, and seek consent where necessary. Use our practical examples to work out how to stay compliant in your specific circumstances.
  • Taking documents home: securing personal data Personal data accessed by staff at home must be kept secure. Take these steps to keep documents containing personal data safe, avoid a data breach and stay compliant with the UK GDPR.
  • The UK GDPR Read our one-page summary of the UK General Data Protection Regulation (UK GDPR) and download a copy to share with your colleagues.
  • The UK GDPR: audit Carry out a data protection audit to make sure your processes comply with the statutory requirements under the UK GDPR and meet best practice. Check your records management and data processing practices, and evaluate the data protection training you deliver.
  • The UK GDPR: ‘lawful basis’ for processing personal data Under the UK GDPR, you must identify a lawful basis (or legal reason) you can use to justify the specific purpose for processing personal data. Use our guidance to work out which of the 6 lawful bases to use and avoid wasting time seeking consent you don't need.
  • The UK GDPR: summary The UK General Data Protection Regulation (UK GDPR) determines how you must process and store personal data – understand what you have to do and the principles of data processing.
  • The UK GDPR: template record of processing activities Under the UK GDPR, you must record how you process the personal data you hold. Use our template and guidance to help you comply with this requirement now and on an ongoing basis in your school.
  • UK GDPR: at what age can pupils give consent? There's no statutory age at which pupils can give consent for data processing under the UK GDPR. Learn what age is usually appropriate, and how to manage issues around seeking pupils' consent.
  • UK GDPR: make sure your suppliers are compliant You must make sure that any third parties that process personal data for your school meet UK GDPR requirements. See the steps you'll need to take, and download our checklist for your provider contracts.
  • UK GDPR mythbuster Use our mythbuster to separate the fact from the fiction around the UK GDPR when it comes to visitor books, photo archives, consent and more.
  • UK GDPR: personal data breach procedure Download our model procedure and use it in the event of a data breach at your school. If you have any data breaches, use our template to record the details.
  • UK GDPR: seeking consent for processing personal data Use our guidance to help you decide whether you need to seek consent for processing personal data under the UK GDPR. If you do, download our template consent forms, or use our checklist to make sure your own forms meet the requirements.
  • UK GDPR: sharing safeguarding information Be confident in how you share safeguarding information under the UK GDPR. Know the principles to follow, your legal basis for sharing data and your responsibilities for information sharing.
  • UK GDPR: staff posters and handout Download our data protection cheat sheet for staff, and display these posters around your school to help everyone remember how to keep personal data safe day-to-day.
  • UK GDPR: using apps and online services with pupils Stay compliant with data protection law when using educational apps or other online services with pupils. Work through these questions before setting up a new app or service to figure out your responsibilities, then check your next steps.