Data protection and privacy: what schools must publish
The 6 data protection and privacy items schools and academy trusts must, should or are expected to publish on their websites, with the official wording for each.
6 requirements
- Biometric information noticeMustA notice for parents where the school uses fingerprint or face recognition, for example for lunch payments. It must explain the intention to process, the right to object, the non-biometric alternative and how written consent is sought.No fixed date
- CCTV policyMustA policy on how the school runs its CCTV: who is responsible and who can view or disclose footage. Schools that use CCTV must have one, plus an appropriate policy document where it is used to prevent crime or footage goes to the police.No fixed date
- Cookie consentMustA cookie banner or similar tool that asks visitors before any non-essential cookies, such as analytics or embedded videos, are set. Every school and trust website that uses such cookies must ask first, by a clear positive action.No fixed date
- Cookie policyMustA cookie policy that tells visitors the website sets cookies, lists each one and explains what it does and why. Every school and trust website must give this information clearly.No fixed date
- Data protection policyMustThe data protection policy, published with the date it was last reviewed. Schools and academy trusts must have data protection policies and procedures in place and publish the policy with a review date.No fixed date
- Privacy noticeMustA privacy notice telling pupils, parents and staff what personal data the school holds, why it is used, who it is shared with, how long it is kept and what their rights are. Schools and academy trusts must publish one.No fixed date
Want to know which of these your school's website has? We check every one, with the page and the words we found.
Request a free scan