Best Practice Update

Best practice in white chalk on a blackboard, orange background, data protection education logo in blue

We've put all the specific school and trust related data protection guides, documents and queries into one area to make it easier for you.

As data protection is closely linked to cyber security the section covers guidance for raising staff awareness with cyber security and other guidance.

Be cyber aware in orange text on a blue background above a mobile phone and padlock. Also the Data Protection Education logo

The time following a cyber attack can be very stressful, and in the heat of the moment it can be difficult to know what the best thing to do between working out what went wrong, how to recover and what went missing, it can be hard to know where to start first.

We provide some help and guidance in our Information and Cyber Security Best Practice Area, which also includes the checklist:  document What to do immediately after a Cyber Attack (58 KB) .

Child with their hands over their eyes in front of a computer laptop. Yellow background. White desk

The DfE recently published an update to the Keeping Children Safe in Education Document 2023.  The document has a strong emphasis on making sure everyone is aware of the online dangers of using the internet and makes recommendations about how schools and colleges should put processes in place to keep children safe online. 

Blue data breach text on blue cyber background,  and orange reprimand stamp

A reprimand has been issued by the ICO to Parkside Community Primary School in relation to the infringements of Article 5 (1)(f), Article 24 (1) and Article 32 of the UK GDPR. This article discusses the reprimand and looks and what schools can do to avoid this type of breach.

Some of the information in the reprimand document is redacted, but the main details are:
A safeguarding email was shared in the classroom via the electronic whiteboard. The ICO has found that the school

Image of a hand holding a phone with a white keyboard and the word 'Access'

As we are in the last part of the school year, this is often the time that we see a rise in the number of Subject Access Requests received by schools.  This article, therefore, covers guidance and support around subject access requests, how to recognise them and how to respond.

What is the right of access? Commonly referred to as a subject access request (SAR), gives someone the right to obtain a copy of their personal information from your organisation.
Do people have to submit a

Using WhatsApp in Schools

This article is about the use of WhatsApp as a communication tool in schools and recent vulnerabilities. It discusses school staff using WhatsApp as a communication method for school business.

We are sometimes asked by staff whether it is OK for staff to be in a WhatsApp group for important school messages. Staff often wish to use it because it is an easy way to communicate and a platform that a lot of people are familiar with.  It is also free. There are issues around this:

  1. How to contact us for support, subject access requests, data breaches and FOI's
  2. FOI: Reinforced Autoclaved Aerated Concrete
  3. FOI: Henry Jackson Society
  4. Subject Access Requests and Children's Data
  5. FOI: Vaccination Justifications
  6. How the Record of Processing Can Help You
  7. What does a Data Protection Officer Do?
  8. Blog: Best Practice on the Retention of Child Protection Information
  9. Carrying out Supplier Due Diligence
  10. Email and retention periods
  11. Sharing this year’s Nativity play online
  12. How to Handle a Data Breach
  13. A quick introduction to the Phishing Simulation tool
  14. B&H FoI: Racist/religious incidents/bullying
  15. B&H FOI Request: ‘Racial Literacy Training 101’
  16. Protocol for Setting Up and Delivery of Online Teaching and Learning
  17. Class Dojo International Data Sharing
  18. Model Publication Scheme: Amendments, Improvements and Updates
  19. Transparency
  20. Brexit...what we know so far.
  21. Parents and students covertly recording conversations
  22. SAR? ER? FOI?
  23. Research projects and GDPR
  24. Cyber security alert issued following rising attacks on UK academia
  25. Emergency contacts and consent
  26. Quick guide to key contact information: LA and other information
  27. Quick guide to key contact information: Official DfE guidance
  28. Key elements of a successful DPIA
  29. FOI Publication Schemes
  30. Best Practice for Managing Photos and Video
  31. New Drip Feeds: Recognise and Respond to Subject Access Request
  32. When to contact the Data Protection Officer?
  33. National child measurement programme 2019
  34. Make sure DPE is your registered DPO with the ICO
  35. Passwords – simplifying the approach

Search