MustUK GDPR (data-protection law)

Privacy notice

A privacy notice telling pupils, parents and staff what personal data the school holds, why it is used, who it is shared with, how long it is kept and what their rights are. Schools and academy trusts must publish one.

Check this on my website

Who it applies to

Published on
School and trust websites
School type
Academies and maintained schools
School stage
All stages, from early years to sixth form
Does not apply to
No school types are excluded

When is it due?

Renewal
No fixed date

The official sources set no renewal date. Keep it accurate whenever it changes.

What's needed

Publish a privacy notice on its own page.

In this requirement

  1. 1What the notice covers
      15 parts
    • 2CCTV information
        8 parts
      • 3Data protection officer contact
          1 part
        • 4Separate notices for each group
            7 parts

          Section 1 of 4

          What the notice covers

          The school must publish a privacy notice telling pupils, parents and staff what personal data it holds and what it does with it: the controller identity, DPO contact, purposes, lawful basis, recipients / sharing, retention, rights, international transfers and how to complain to the school before the ICO.

            The register sets this section for maintained schools only.

            What it must contain

            15 parts
            • Gives the identity and contact details of the data controllerMust
            • Gives the data protection officer's contact detailsMust
            • States the purposes for which personal data is processedMust
            • States the legal basis for processing personal dataMust
            • Names the recipients or categories of recipients of personal dataMust
            • States how long personal data is kept, or the criteria used to decideMust
            • States the right to request access to, rectification or erasure of personal dataMust
            • States the right to complain to the Information CommissionerMust
            • States that personal data is transferred outside the UK, when it isMust
            • States the right to complain to the school before the Information CommissionerMust
            • Dates when the privacy notice was last reviewed, or gives its version numberMust
            • States the essence of the joint-controller arrangement, when it is a joint controllerMust
            • Links to the privacy notice from every pageMust
            • States the right to withdraw consent at any time, when processing relies on consentMust
            • States the legitimate interests relied on, when processing depends on themMust

            What the official sources say

            Set out in 1 official source:

            UK GDPR (Regulation (EU) 2016/679 as retained), revised

            Version revised (legislation.gov.uk)

            • The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication made under or by virtue of Articles 15 to 22D and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means.

              Must§ Article 12(1)

            • Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:

              Must§ Article 13(1)-(2)

            Show 12 more from this source
            • the identity and the contact details of the controller and, where applicable, of the controller's representative;

              Must§ Article 13(1)(a)

            • the contact details of the data protection officer, where applicable;

              Must§ Article 13(1)(b)

            • the purposes of the processing for which the personal data are intended as well as the legal basis for the processing;

              Must§ Article 13(1)(c)

            • where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party;

              Must§ Article 13(1)(d)

            • the recipients or categories of recipients of the personal data, if any;

              Must§ Article 13(1)(e)

            • where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of relevant regulations under Article 45A, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), the safeguards relied on and the means by which to obtain a copy of them or where they have been made available.

              Must§ Article 13(1)(f)

            • the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;

              Must§ Article 13(2)(a)

            • the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;

              Must§ Article 13(2)(b)

            • where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;

              Must§ Article 13(2)(c)

            • the right to make a complaint to the Commissioner under section 165 of the 2018 Act;

              Must§ Article 13(2)(d)

            • the right to make a complaint to the controller under section 164A of the 2018 Act;

              Must§ Article 13(2)(ca)

            • The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject.

              Must§ Article 26(2)

            Section 2 of 4

            CCTV information

            Where the school uses CCTV, people should be told about it: that they are being recorded, why, where the cameras are and what the footage is used for, with signs and an updated privacy notice, how to exercise your rights, and that subject access requests cover CCTV.

              The register sets this section for maintained schools only.

              What it must contain

              8 parts
              • Says where the cameras areMust
              • Says what the footage is used forMust
              • Says how people can exercise their rightsShould
              • Says people are made aware of the monitoring and whyMust
              • Says the subject access request policy covers CCTVShould
              • Says people are clearly aware they are being recordedShould
              • Places signs where CCTV is in useMust
              • Updates the privacy notices to cover CCTVMust

              What the official sources say

              Set out in 2 official sources:

              Data protection in schools: taking and using photos and videos, and using CCTV

              Updated 23 March 2026

              • If you decide to install CCTV you must: – consult with pupils, parents or carers and staff – explain where the cameras will be

                Must§ Being transparent (CCTV)

              • explain what the footage will be used for

                Must§ Being transparent (CCTV)

              Show 3 more from this source
              • This means: – placing signs where CCTV is in use – updating your privacy notices

                Must§ Being transparent (CCTV)

              • Any guidance you create must be regularly reviewed to ensure it reflects the changes to the use of CCTV , including any modern advancements.

                Must§ Being transparent (CCTV)

              • Your subject access request policy should cover CCTV , as people can ask to see any footage you have recorded of them.

                Should§ Record-keeping

              Video surveillance guidance: how can we comply with the data protection principles when using surveillance systems

              Version revised (legislation.gov.uk)

              • You always need to ensure that those under surveillance are clearly aware that they are being recorded. You should provide individuals with appropriate information about how they can exercise their rights, and that appropriate restrictions on viewing and disclosing images are in place for those using the system.

                Should§ Fairness

              • It may be useful to use websites or social media to inform individuals that certain types of surveillance systems are in operation at a specific time and in a specific area. It is important to note however that publishing information on a website, by itself, is not enough to comply. You have to draw the individuals’ attention to the information. Therefore, you could use physical signage with linked information, so that individuals can find out more if they are interested. This would essentially function as a layered privacy notice.

                Good practice§ Transparency — Example

              Show 1 more from this source
              • – ensure that you make people other than workers, such as visitors or customers, who may inadvertently be caught by monitoring, aware of its operation and why you are carrying it out;

                Must§ Surveillance in the workplace

              Section 3 of 4

              Data protection officer contact

              Schools and trusts must have a data protection officer and publish their contact details, and should say that you can contact the DPO about your data and your rights.

                The register sets this section for maintained schools only.

                What it must contain

                1 part
                • Says that visitors can contact the data protection officer about how their data is usedShould

                What the official sources say

                Set out in 2 official sources:

                UK GDPR (Regulation (EU) 2016/679 as retained), revised

                Version revised (legislation.gov.uk)

                • The controller or the processor shall publish the contact details of the data protection officer and communicate them to the Commissioner.

                  Must§ Article 37(7)

                • Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation.

                  Expected§ Article 38(4)

                Issuing privacy notices: guidance for schools and local authorities

                Updated 13 August 2026

                • Your data protection officer should review privacy notices: – at least annually – whenever you make a significant change to how you process personal data

                  Should§ Issuing and reviewing notices

                Section 4 of 4

                Separate notices for each group

                Schools should publish separate privacy notices for pupils/parents, workforce and governors/trustees, because each group's data is used differently. Each must say what is shared with the DfE, with wording amended to local circumstances and the lawful basis for workforce data.

                  The register sets this section for maintained schools only.

                  What it must contain

                  7 parts
                  • Keeps a privacy notice for pupils and parents accessible at all timesMust
                  • Keeps a privacy notice for the workforce accessible at all timesMust
                  • Has a privacy notice for individuals in governance roles at maintained schools, academies and trustsGood practice
                  • States what personal data is shared with the Department for EducationMust
                  • Tailors the privacy notice wording to local needs and circumstancesMust
                  • States the lawful basis for collecting and using workforce personal dataMust
                  • Gives who to contact about the privacy noticeGood practice

                  What the official sources say

                  Set out in 3 official sources:

                  Issuing privacy notices: guidance for schools and local authorities

                  Updated 13 August 2026

                  • For pupils and staff, you must make sure the privacy notice is accessible at all times.

                    Must§ Inform data subjects about their privacy rights

                  • DfE ’s model privacy notices include suggested wording that schools can tailor to inform staff, parents, carers, and pupils about the collection of data.

                    Good practice§ What to include in a privacy notice

                  Show 5 more from this source
                  • For pupils, these include sharing the school’s privacy notice: – in an induction pack, when joining the school – at the start of each school year – when they provide extra personal data during the school year – through the school website

                    Good practice§ Inform data subjects about their privacy rights

                  • Every school must make its privacy notices freely available to those whose personal data it handles, under this legislation.

                    Must§ Introduction (after 'Providing this information is an important part of')

                  • You must expand and amend this information to reflect local needs and circumstances, because you will process personal data that is not only for use in DfE data collections.

                    Must§ How to use this guide

                  • Your school’s privacy notice must include what personal data your school shares with DfE . You can read examples of this text in DfE ’s privacy notice model documents.

                    Must§ What to include in a privacy notice

                  • Your school’s privacy notice must include what personal data is shared with DfE . Our privacy notice model documents have examples of this text.

                    Must§ Personal information shared with DfE

                  Privacy notice: suggested text for the school workforce

                  Version revised (legislation.gov.uk)

                  • This list is not exhaustive, to access the current list of categories of information we process please see [link to website or location of data asset register / current privacy notice]

                    Good practice§ The categories of school information that we process

                  • We may need to update this privacy notice periodically so we recommend that you revisit this information from time to time. This version was last updated on [insert data notice was drafted/last updated].

                    Good practice§ Last updated

                  Show 3 more from this source
                  • If you would like to discuss anything in this privacy notice, please contact: [Insert name and / contact details of your administrator / data protection officer]

                    Good practice§ Contact

                  • You must review and amend to reflect local needs and circumstances, as you will process data that is not solely for use within data collections]

                    Must§ Header bracket, 'Privacy Notice (How we use workforce information)'

                  • [School / local authority should insert the lawful basis (bases) for collecting and using personal information for general purposes (must include a basis from Article 6, and one from Article 9 where data processed is special category data from the UK GDPR). Ensure you list all relevant legislation that supports the lawful basis.

                    Must§ Why we collect and use workforce information

                  Privacy notice: suggested text for school and trust governance roles

                  Version revised (legislation.gov.uk)

                  • [Suggested wording to make available to individuals in governance roles in local authority maintained schools, academies and academy trusts to explain how their personal information is used.

                    Good practice§ Header bracket

                  Questions schools ask

                  Does every school have to publish the privacy notice?

                  What the notice covers: The official sources we check set no requirement for academies. The official sources we check set no requirement for maintained schools. CCTV information: The official sources we check set no requirement for academies. The official sources we check set no requirement for maintained schools. Data protection officer contact: The official sources we check set no requirement for academies. The official sources we check set no requirement for maintained schools. Separate notices for each group: The official sources we check set no requirement for academies. The official sources we check set no requirement for maintained schools.

                  When does the privacy notice need to be published?

                  Renewal: No fixed date. The official sources set no renewal date. Keep it accurate whenever it changes.

                  What must the privacy notice include?

                  Gives the identity and contact details of the data controller; Gives the data protection officer's contact details; States the purposes for which personal data is processed; States the legal basis for processing personal data; Names the recipients or categories of recipients of personal data; States how long personal data is kept, or the criteria used to decide; and 25 more parts listed above.

                  Where does the requirement for the privacy notice come from?

                  It is set out in UK GDPR (Regulation (EU) 2016/679 as retained), revised, Data protection in schools: taking and using photos and videos, and using CCTV, Video surveillance guidance: how can we comply with the data protection principles when using surveillance systems and Issuing privacy notices: guidance for schools and local authorities and 2 other sources.

                  Changes to the official sources

                  Dated change notes published by the Department for Education on the sources above.

                  1. 13 August 2026 · Issuing privacy notices: guidance for schools and local authorities

                    Updated all documents for the 2026 to 2027 academic year.

                  2. 23 March 2026 · Data protection in schools: taking and using photos and videos, and using CCTV

                    New section added.

                  3. 3 October 2025 · Issuing privacy notices: guidance for schools and local authorities

                    Replaced each document with the latest version.

                  4. 15 August 2024 · Issuing privacy notices: guidance for schools and local authorities

                    Replaced each document with the latest version.

                  5. 30 October 2023 · Issuing privacy notices: guidance for schools and local authorities

                    Updated a link to the National Pupil Database (NPD) privacy notice in the following documents: 'Explanation of privacy notices', 'Privacy notice: suggested text for pupils', 'Privacy notice: suggested text for a local authority' and 'Privacy notice: suggested text for looked-after children and children in need'.

                  6. 16 June 2023 · Issuing privacy notices: guidance for schools and local authorities

                    Documents updated: 'Explanation of privacy notices', 'Privacy notice: suggested text for pupils', 'Privacy notice: suggested text for school workforce', 'Privacy notice: suggested text for school and trust governance roles', 'Privacy notice: suggested web text for a local authority', 'Privacy notice: suggested text for looked-after children and children in need'.

                  20 earlier changes are listed on the source pages.

                  We last checked these sources on 21 September 2026.

                  Is this on your school's website?

                  We check your site the way an inspector or a parent would find it: page by page, against the official wording of each requirement. If it's there, you get the page and the words we found. If it isn't, you get every place we looked.

                  Check this one requirement free, or scan your whole site against every requirement.

                  Any format works: .co.uk, .sch.uk, .org.uk or .com.

                  We email the result here. Privacy notice

                  Free: check up to 3 requirements a year, results by email. Paid: every requirement checked, re-checked after you fix it, and monitored all year.

                  Or scan your whole site free →
                  Official wording that does not apply to schools (4)
                  If standardised icons are published as described in paragraph 6A (and not withdrawn), the information to be provided to data subjects pursuant to Articles 13 and 14 may be provided in combination with the icons. Where the icons are presented electronically they shall be machine-readable.
                  UK GDPR (Regulation (EU) 2016/679 as retained), revised§ Article 12(7) (with 12(6A) and (6B))Version revised (legislation.gov.uk)legislation.gov.uk ↗
                  Unlike for photos, consent is not appropriate as a lawful basis for CCTV
                  Data protection in schools: taking and using photos and videos, and using CCTV§ Considering which lawful basis to use (CCTV)Version revised (legislation.gov.uk)gov.uk ↗
                  In practice, it is often difficult to obtain genuine consent from individuals for processing their personal data in public spaces. Therefore, it is likely the appropriate lawful basis will be either legitimate interests, or a reliance on public task (if you are carrying out your tasks as a public authority in the public interest or under official authority).
                  Video surveillance guidance: how can we comply with the data protection principles when using surveillance systems§ At a glanceVersion revised (legislation.gov.uk)ico.org.uk ↗
                  A business responsible for managing a public multi-storey car park wishes to use CCTV cameras around the premises and in the elevators, to ensure the safety and security of individuals using them.
                  Video surveillance guidance: how can we comply with the data protection principles when using surveillance systems§ Fairness — ExampleVersion revised (legislation.gov.uk)ico.org.uk ↗

                  Official sources last checked 21 September 2026 · register version 1.0.4