Education

/upload/images/content/marker_e.jpg

Data protection – looking after the information you hold about pupils and students

If you handle and store information about identifiable, living people – for example, about school pupils – you are legally obliged to protect that information. Under the Data Protection Act, you must:

  • only collect information that you need for a specific purpose
  • keep it secure
  • ensure it is relevant and up to date
  • only hold as much as you need, and only for as long as you need it
  • allow the subject of the information to see it on request.

Find out about your data protection obligations here.

Your pupils and students have rights to see their personal information. They can make a subject access request to see the personal information you hold about them. They – and their parents – also have the right to see their educational records. More information on this and what you need to do can be found here:

You will also find help on your obligations regarding the storing and release of any references and professional opinions you supply.

Notification with the ICO

If you handle personal information, you may need to notify as a data controller with the Information Commissioner. Notification is a statutory requirement and every organisation that processes personal information must notify the Information Commissioner’s Office (ICO), unless they are exempt. Failure to notify is a criminal offence. Please check here for details. If your establishment is not-for-profit, you may be exempt – see our advice here.

Employment

As an employer, you are obliged to protect your employees’ personal information. For more information, see our section on employment here; our Quick Guide to the Employment Practices Code gives practical advice on handling employees’ personal information, on monitoring at work and on employees’ rights. You will also find help on your obligations regarding the storing and release of any references you supply.

Exams

Individuals have the right to see their examination results – see our Good Practice Note here on the type of requests you might get and how to handle them. If you intend to publish exam results in the media, you must inform your pupils and students first – see our guidance here.

Taking photos in schools

The Data Protection Act does not prevent parents and teachers from taking photos of events such as the Christmas play or sports day – asking permission to take photos is normally enough to ensure compliance. See our Good Practice Note here.

Freedom of information – making public information available

If the educational establishment you work in is a public authority, the Freedom of Information Act means you must produce a Publication Scheme, which outlines the information you will routinely make available to the public - such as minutes of meetings, annual reports or financial information. To help you, we have provided a model publication scheme for all public authorities to follow. We have also produced specific guidance for educational establishments and a template for schools to use - please have a look here.

The Freedom of Information Act also means you must disclose official information when people ask for it (unless there is a good legal reason for you not to), and you must reply within 20 working days. Find out about your Freedom of Information obligations here.

Research

We have commissioned some research about young people and data protection. Our most recent research is about young people’s views of privacy in relation to social networking – you can see it here.

Education resources

The ICO intends to develop more resources for educational use over the next three years.

Relevant downloads


View the document library