Skip to content
Email our experts
About us
Careers
0345 226 8393
Email our experts
0345 226 8393
About us
Careers
Get your FREE consultation
Login
  • I need help with
  • Employment Law & HR
    • I haveโ€ฆ
    • No HR team
      • Fixed-Fee Service
      • HR Consultancy
      • HR Software
      • Training
    • Small HR team
      • Flexible Fixed-Fee Service
      • HR Consultancy
      • HR Software
      • Training
    • Established HR team
      • Fixed Subscription Service
      • HR Consultancy
      • HR Software
      • Training
  • Health & Safety
    • I haveโ€ฆ
    • No H&S team
      • Fixed-Fee Service
      • Occupational Health
      • CQC Compliance
      • Training
    • Established H&S team
      • Bespoke Services
      • Occupational Health
      • CQC Compliance
      • Training
  • Sectors
  • Resources
  • I need help with
  • Employment Law & HR
    • I haveโ€ฆ
    • No HR team
      • Fixed-Fee Service
      • HR Consultancy
      • HR Software
      • Training
    • Small HR team
      • Flexible Fixed-Fee Service
      • HR Consultancy
      • HR Software
      • Training
    • Established HR team
      • Fixed Subscription Service
      • HR Consultancy
      • HR Software
      • Training
  • Health & Safety
    • I haveโ€ฆ
    • No H&S team
      • Fixed-Fee Service
      • Occupational Health
      • CQC Compliance
      • Training
    • Established H&S team
      • Bespoke Services
      • Occupational Health
      • CQC Compliance
      • Training
  • Sectors
  • Resources
  • I need help with
  • Employment Law & HR
    • Solutions for HR teams of all sizes

      No HR team

      WorkNestโ€™s fixed-fee fully outsourced HR service provides unlimited 24/7 advice, document drafting, online training, and tools for managing people challenges, making it ideal for those without in-house HR support.

      Fixed fee service | HR consultancy | HR software | Training | eLearning

      Small HR team

      Our unique blend of ER advice, technology, training, and hands-on consultancy will empower your HR function to enhance efficiency, improve the effectiveness of your HR processes and ensure compliance with employment law.

      Flexible fixed fee service | HR consultancy | HR software | Training | eLearning

      Established HR team

      Introducing our sister company: esphr โ€“ A new-model employment law service, fusing SRA-regulated legal advice with ER case management technology and online resources. As an extension of your in-house HR and ER team, we provide integrated support services built around people, processes, and technology โ€“ all for a fixed annual subscription.

      Employment law advice | Online HR resources | ER case management | HR compliance e-learning | Immigration support

      Latest news & insights

      View the latest articles

      Best interview techniques for employers | 5 simple strategies for success

      22nd October 2025

      What happens if an employee resigns during the disciplinary process?

      15th October 2025

      6-step guide | How to conduct a fair and legal disciplinary procedure

      15th October 2025

      7-step guide | How to fairly dismiss an employee who pulls frequent sickies

      15th October 2025

      How to avoid grievances in the workplaceโ€‹ | Guide to preventing staff complaints

      9th October 2025

      Challenges in hiring | 3 ways to bridge the recruitment disconnect

      2nd October 2025
  • Health & Safety
    • Solutions for teams of all sizes

      No Health & Safety team

      Our fixed-fee fully outsourced health & safety support services provide personalised solutions for organisations of all sizes, including dedicated local consultant support, risk management software, online training and 24/7 emergency advice.

      Fixed fee service | Health & Safety software | CQC compliance | Training & e-Learning

      Established Health & Safety team

      Our expert consultants offer customised project support, consultancy, and additional resources to strengthen your health and safety systems, improve claims defensibility, and embed a culture of safety throughout your organisation.

      Support for HSEQ teams | Bespoke services | Health & Safety software | Training & e-Learning

      Latest news & insights

      View the latest articles

      Best interview techniques for employers | 5 simple strategies for success

      22nd October 2025

      What happens if an employee resigns during the disciplinary process?

      15th October 2025

      6-step guide | How to conduct a fair and legal disciplinary procedure

      15th October 2025

      7-step guide | How to fairly dismiss an employee who pulls frequent sickies

      15th October 2025

      How to avoid grievances in the workplaceโ€‹ | Guide to preventing staff complaints

      9th October 2025

      Challenges in hiring | 3 ways to bridge the recruitment disconnect

      2nd October 2025
  • Sectors
  • Resources
Contact us
Login
Login

The way in which personal data about staff, pupils and their families and legal guardians is used and protected at your school, academy or trust is set to change in May 2018.

It may feel like a long time away, but it is fast approaching and you need to start planning for the changes now.

In this article, we will explore what some of the changes mean for your school and how best to prepare.

What is changing?

The EU General Data Protection Regulations (GDPR) will replace the current Data Protection Act.

The UK government has been clear that, despite the result of the Brexit referendum, they will implement the regulations.

Some of the most important changes include:

  • In cases of data breaches, for example an accidental loss of data, businesses must notify the relevant data protection authority (in the UK, this will be the ICO) if the breach is likely to result in a risk to the rights and freedoms of individuals. This must be done without undue delay and no later than 72 hours after becoming aware of the breach. Data subjects must also be informed without undue delay about breaches that could pose a high risk to their rights and freedoms.
  • A subject may request for their data to be deleted if, for example, there are no legitimate grounds for retaining or processing the data. This is known as the right to be forgotten or right to erasure.
  • When a subjectโ€™s consent is required, this must be freely given by means of a clear affirmative action, such as a written statement. Silence or inactivity is not a sign of consent. In employment, there is a question as to whether an employee can legitimately consent to most processing, so it will be important to look at why, and how, you process employee information.
  • Organisations must appoint a โ€˜Data Protection Officerโ€™ if they are a Public Authority, process sensitive personal data on a big scale, or regularly and systematically monitor data subjects on a large scale.
  • It imposes higher maximum penalties for failure to comply, including fines of up to โ‚ฌ20 million or 4% of annual global turnover (whichever is higher).
  • The Regulations scrap the option of employers charging a fee for subject access requests. The only exception to the general rule is if the request is โ€˜manifestly unfounded or excessiveโ€™. The employer must respond to a subject access request within one month, which may be extended in certain circumstances, for example, if the employer has to deal with a particularly complex issue or numerous requests.
  • One of the biggest changes is the need to show how data controllers are complying with the GDPR โ€“ this has been called the โ€œAccountability Principleโ€. This can be done by, for example, having up to date policies in place, ensuring that staff are appropriately trained on data protection issues, and having data protection at the forefront of your mind when processing data.

How should Schools prepare?

While there are still a number of outstanding matters in terms of guidance on elements of the GDPR, the ICO has laid down some key steps you should be taking now:

  • Make sure that the decision makers at your school are conscious that the law is changing.
  • Audit what personal data you currently possess, the source of the data and who it is shared with.
  • Review your current data security measures to ensure that they are adequate.
  • Create a plan for making all the necessary changes in time for May 2018.
  • Review your procedures to ensure they cover all the rights individuals have.
  • Revise your procedures with regards to managing subject access requests.
  • Pinpoint the legal basis for the processing of data.
  • Reassess how you acquire, record and manage consent.
  • Reflect on whether you need to put systems in place to verify your pupilโ€™s ages and to acquire parental or guardian consent for the processing of data.
  • Ensure you have the procedures in place to identify and report breaches.
  • Consider whether you need a Data Protection Officer and if so, find someone to take on this responsibility.

Both the ICO and Ofsted will be keen to see that you have the proper policies in place. An e-safety policy will also be helpful to show how you protect the data of staff, pupils, pupilโ€™s parents or legal guardians from viruses, phishing, attacks on networks and systems and the loss or destruction of data.

The ICO have lots of useful guidance on their site, which can be found here.

We support more than 400 schools and education providers with their HR and Employment Law challenges, so give us a ring to find out how we can support you.

Events for employers

Be part of our upcoming in-person events, where industry experts share practical guidance, legal updates, and actionable insights to support your organisation. Network, learn, and stay ahead.

Find an event near you

Sign up to our monthly newsletter

Receive the latest employer news, including employment law updates, expert articles, free resources and event invitations โ€“ all delivered directly to your inbox.  

Our services

Employment Law & HR

Health & Safety

Client Log-in

Refer a friend

Company

About us

Resources

Gender Pay Gap

I need help with

Careers

Contact us

0345 226 8393

enquiries@worknest.com

Head Office

Woodhouse, Church Lane, Aldford
Chester CH3 6JD

View on map

View our locations
Facebook Twitter Linkedin
Click here to start chatting 
Chatbot Avatar Not sure what you need? ร—
wn-l-wh

Nest AI beta

  Click here at any time to speak to an expert.

Powered by WorkNest.
For information see our AI privacy notice .

Facebook Linkedin Youtube

ยฉ 2025 WorkNest   Complaints   Privacy notice  Cookie notice  Artificial intelligence notice  Terms & conditions