PUBLICTEC | DATA PROTECTION UPDATE
August 2026 | Schools & Multi-Academy Trusts
Practical updates. Regulatory developments. Safer information management.
As we approach the start of the new academic year, there have been several important developments in data protection affecting schools and trusts.
In this month's update, we look at the latest Department for Education security incident, the ICO's findings on EdTech providers, new requirements for handling data protection complaints, updated guidance around photographs and CCTV, and some practical actions to consider before September.
🚨 DfE confirms data security incident
The Department for Education has confirmed a security incident affecting its Customer Help Portal and Turing Scheme portal.
The DfE became aware of the issue following claims made over the weekend of 25–26 July 2026 and temporarily took the affected services offline while investigations and remediation were undertaken.
The DfE has confirmed that information potentially affected relates only to people who directly used the affected services and includes:
- •Name
- •Job title, where provided
- •Email address, where provided
- •Telephone number, where provided
- •Business address, where someone contacted the DfE on behalf of an organisation
The incident has been notified to the Information Commissioner's Office. The DfE is also advising affected users to remain alert to suspicious emails, messages and websites.
PublicTec View
This is a timely reminder that compromised contact information can subsequently be used to make phishing and social-engineering attacks appear much more convincing.
Schools and trusts should remind staff to:
- •Be cautious of unexpected emails claiming to be from the DfE or another trusted organisation.
- •Avoid opening unexpected attachments or links.
- •Verify unusual requests independently, particularly those involving passwords, payments or changes to account details.
- •Report suspicious messages through your normal IT/security process.
- •Report suspected personal data breaches promptly to your DPO.
🎓 ICO puts EdTech data protection under the spotlight
One of the most significant developments for education this year is the ICO's Edtech Examined report.
The ICO audited 28 EdTech providers whose products are widely used across UK primary and secondary schools.
While the ICO identified positive information-security practices, it also found recurring compliance gaps including:
- •Uncertainty over whether EdTech providers were acting as data controllers or processors.
- •Contracts with schools lacking sufficient detail.
- •Incomplete mapping of how children's information moves between systems.
- •Weak application of data minimisation.
- •Problems with retention and storage limitation.
- •Outdated or inaccessible privacy information.
- •Gaps in Data Protection Impact Assessments (DPIAs).
The ICO made 596 recommendations, with providers accepting and implementing 98% of them. The regulator is now discussing with the Department for Education how a potential EdTech Code could further strengthen children's data protection.
What should schools and trusts do?
Schools remain responsible for understanding how suppliers process information on their behalf.
Before introducing a new application, AI platform or EdTech service, consider:
✓ Who is the controller and who is the processor?
✓ What pupil and staff information will the product access?
✓ Where will the information be stored?
✓ Is information transferred outside the UK?
✓ Is information being used for analytics, AI training or product development?
✓ How long will the supplier retain information?
✓ What happens to the information when the contract ends?
✓ Is a DPIA required?
✓ Does your ROPA and software register need updating?
PublicTec recommendation: Don't treat data protection as something to check after an application has been purchased. Privacy and security should form part of the procurement and approval process from the beginning.
📢 New legal requirement: Data Protection Complaints
An important change came into force on 19 June 2026.
Organisations must now have a process for dealing with complaints from individuals about how their personal information has been handled.
Under the new requirements organisations must:
- •Provide a clear way for people to make a data protection complaint.
- •Acknowledge the complaint within 30 days.
- •Take appropriate steps to investigate it without undue delay.
- •Keep the complainant appropriately informed.
- •Inform them of the outcome.
For schools and trusts
This means your procedures should clearly distinguish between a general complaint and a data protection complaint.
For example:
"I don't agree with the school's decision" may be an ordinary complaint.
Whereas:
"The school has shared information about my child with somebody who shouldn't have received it" may constitute a data protection complaint.
Your complaints, data protection and breach-management procedures should work together so these issues are identified and escalated appropriately.
📸 School photos, videos and CCTV – time for a September review
The Department for Education's data protection guidance now contains detailed practical guidance covering the use of photographs, videos and CCTV in schools.
An identifiable image of a pupil, member of staff or another individual is personal data and therefore needs to be handled in accordance with data protection legislation.
Schools should consider:
- •The lawful basis being used.
- •Consent and how opt-outs are managed.
- •Where images are stored.
- •Who can access them.
- •How images are shared.
- •Retention and deletion.
- •Website and social-media publication.
- •Use of photographs by contractors and volunteers.
The DfE also makes clear that volunteers or contractors acting for the school should not normally be storing school photographs on personal devices or personal cloud accounts.
September action
Before the new academic year begins, review your:
Photo & video consent records → Website images → Social-media permissions → CCTV notices → Image storage → Retention arrangements
This is particularly important where parental preferences may have changed or new pupils are joining the school.
📩 Subject Access Requests – would your staff recognise one?
The ICO's updated subject access guidance is another useful reminder that a Subject Access Request doesn't need to say "Subject Access Request".
A person can make a SAR:
- •In writing.
- •Verbally.
- •By email.
- •Through social media.
- •Through an authorised third party.
In most circumstances, organisations must respond without undue delay and within one month.
The ICO also confirms that organisations must carry out a reasonable and proportionate search for information within scope.
A simple test for staff
If somebody is essentially saying:
"I want to see the information you hold about me."
Treat it as a potential SAR and pass it immediately to the person responsible for data protection.
🔐 ICO enforcement reminder: basic cyber security matters
The ICO has recently reprimanded the ACRO Criminal Records Office after cyber-security shortcomings potentially exposed highly sensitive personal information relating to up to 10,920 individuals.
The regulator specifically highlighted the importance of:
- •Clear responsibility for identifying and applying security updates.
- •Effective security monitoring.
- •Investigating warning signs.
- •Acting promptly when potential attacks are detected.
The lesson for education
Cyber security and GDPR shouldn't operate separately.
Good patch management, access control, monitoring, backups and incident response are all fundamental parts of protecting personal information.
🎓 Free ICO Data Protection Essentials training
On 11 August 2026, the ICO launched its new Data Protection Essentials programme.
The free programme provides practical, self-paced data protection training and includes sector-specific examples for education and childcare.
The programme contains 13 bite-sized modules, generally taking around 10–15 minutes each, alongside a self-assessment.
It's primarily designed for smaller organisations without a DPO or high-risk processing activities, but the resources may still be useful for anyone wanting to refresh their understanding of the fundamentals.
✅ PUBLICTEC'S SEPTEMBER DATA PROTECTION CHECKLIST
Before pupils and staff return, we recommend schools and trusts check the following:
01 | Privacy Notices Are pupil, parent, workforce and website privacy notices current?
02 | New Systems & EdTech Have new systems been reviewed and added to your software register and ROPA?
03 | DPIAs Have DPIAs been completed for new high-risk systems, AI tools or processing activities?
04 | Leavers Have accounts and system access for staff who left during the summer been removed?
05 | Photographs & Consent Are photography, video and marketing preferences up to date?
06 | Data Protection Complaints Is there a clear process for recognising, recording and responding to data protection complaints?
07 | SARs & FOIs Do staff know how to recognise a request and where to send it?
08 | Data Breaches Do staff know what constitutes a potential data breach and how to report one?
09 | Suppliers Are appropriate Data Processing Agreements in place with your suppliers?
10 | Staff Awareness Include data protection and cyber-security reminders within September INSET and onboarding.
Need Data Protection Support?
PublicTec supports schools and Multi-Academy Trusts with practical, education-focused data protection advice and compliance management.
Our support includes:
Data Protection Officer services Data breach management Subject Access Requests & FOI support DPIAs Data protection audits Policy and privacy notice reviews EdTech and supplier assessments Training and awareness Compliance monitoring through EduGovern360
Unsure whether something needs reporting?
Get in touch with the PublicTec Data Protection Team before taking action. Early advice can often prevent a small information governance issue becoming a much larger one.
PublicTec Technology | Data Protection | Governance
Practical support. Clear advice. Better governance.
This newsletter provides general information and guidance and should not be treated as legal advice. Individual circumstances should always be considered when making data protection decisions.