Posts

Not so long ago, a teacher’s biggest technology concern was whether the interactive whiteboard would cooperate before Period 1. Today, we’re juggling AI-powered learning platforms, educational apps, social media, personalised learning algorithms, digital portfolios, and enough login credentials to make a cybersecurity expert break into a cold sweat.

It’s exciting. It’s innovative. It’s transformative.

It’s also a bit terrifying.

Because while we’re busy marvelling at how quickly AI can generate a quiz or differentiate a worksheet, a quieter question is lurking in the background:

At what point does a student stop being a learner and start becoming a dataset?

 

The Digital Gold Rush

Education technology has promised us many wonderful things. Greater accessibility. Personalised learning. Reduced workload. Better engagement. Faster feedback.

And to be fair, much of it delivers.

AI tools can support lesson planning. Learning platforms can identify gaps in understanding. Social media can connect classrooms with experts and opportunities around the world.

The challenge isn’t necessarily the technology itself. The challenge is that many of these tools are powered by one thing above all else: Data.

Every click, every search, every uploaded piece of work, every profile photo, every behaviour metric and every interaction potentially contributes to a growing digital footprint.

For adults, that’s a concern.

For children, it should be a priority.

 

The “But Everyone’s Doing It” Trap

We’ve all been there.

A colleague discovers a fantastic new AI tool. A tutorial appears on LinkedIn. An education influencer posts a glowing review on X. Suddenly; half the staffroom is experimenting with it before someone asks the awkward question:

“Where does the data actually go?”

Cue silence.

In education, enthusiasm often arrives before due diligence.

The pressure to innovate can sometimes make schools feel like participants in a giant educational technology experiment. Yet under UK data protection law, schools aren’t simply consumers of technology. They’re custodians of children’s personal information.

That distinction matters.

A lot.

 

Children Are Not Mini Adults

One of the most important principles in UK data protection is that children’s data requires particular care.

This is where things become especially significant for educators.

Adults often make informed decisions about sharing information online. We weigh risks and benefits. We understand, at least broadly, what we’re agreeing to.

Children don’t.

A Year 5 pupil uploading a piece of creative writing to an AI-powered platform isn’t making a data processing decision. They’re completing homework.

A Year 9 student appearing in a school social media video isn’t evaluating privacy implications. They’re participating in school life.

The responsibility sits firmly with us.

 

The Social Media Paradox

School social media accounts are a fascinating contradiction.

On one hand, they’re brilliant. They celebrate achievement, strengthen community relationships, showcase learning and provide a window into school life.

On the other hand, every photo, video and success story contributes to a permanent digital record.

The pupil proudly holding a certificate in Year 3 may not particularly appreciate that image resurfacing a decade later.

The child whose attendance at a particular school seems harmless to disclose today may have circumstances that make publicity less appropriate tomorrow.

None of this means schools should disappear from social media entirely. It simply means we need to move from asking:

“Wouldn’t this make a great post?” to: “Is this genuinely necessary, appropriate and proportionate?”

Those are surprisingly powerful questions.

 

When Westminster Starts Asking the Same Questions

Interestingly, schools are not the only institutions wrestling with these concerns.

Discussions about children’s use of social media have moved well beyond staffrooms and parent WhatsApp groups and into Parliament itself. From stronger age-verification measures and limits on harmful content to proposals for restricting social media access for under-16s, policymakers are increasingly questioning how digital platforms collect, use and influence children’s data and behaviour.

For schools, the detail of the legislation matters less than the direction of travel.

For years, the conversation was largely about getting children online and developing digital skills. Increasingly, the conversation is becoming:

How much access is appropriate, and at what cost?

That’s a significant shift.

And if Parliament is questioning how much information social media companies should hold about children, schools may find themselves asking similarly searching questions of ed-tech and AI providers.

Because from a pupil’s perspective, the distinction between a social media platform, a learning app and an AI-powered educational tool is often less obvious than it is to adults.

They’re simply digital environments collecting information about them.

 

AI Has Entered the Chat

Perhaps the most interesting challenge facing schools today is AI.

Generative AI has arrived with the enthusiasm of a supply teacher who thinks they’ve invented group work.

It’s everywhere.

Teachers are using it to create resources. Students are using it to support revision. Organisations are rapidly integrating AI into educational products.

Yet AI introduces an additional layer of complexity: data processing often becomes less transparent.

When information is entered into an AI system, educators need confidence about:

  • What data is being collected
  • Where it is stored
  • Whether it is used to train models
  • Who can access it
  • How long it is retained
  • Whether it leaves the UK

The reality is that many users never read the privacy information. And let’s be honest, some privacy notices appear to have been written specifically to discourage human consumption.

But schools cannot afford to rely on hope as a data protection strategy.

“Probably fine” is not a legal basis.

 

The New Digital Safeguarding

Traditionally, safeguarding discussions focused on physical safety and online behaviour. Increasingly, however, data protection is becoming a safeguarding issue in its own right.

A data breach doesn’t just involve information. It involves people.

Real children.

Real families.

Real consequences.

The accidental sharing of personal data, inappropriate use of AI tools, unsecured platforms or excessive data collection can create risks that extend far beyond compliance checklists.

In many ways, data protection and safeguarding have become close relatives. Different disciplines, perhaps, but increasingly dealing with overlapping concerns.

And as public awareness grows, schools should expect more questions from parents, governors and regulators:

  • Why does this platform need this information?
  • How long will it keep it?
  • Is student work being used to train AI models?
  • What happens to the data when a child leaves school?
  • Can information genuinely be deleted?

Not long ago, these were questions mostly reserved for Data Protection Officers.

Today, they’re becoming leadership questions.

They’re becoming governance questions.

And increasingly, they’re becoming safeguarding questions.

 

Building a Culture, Not a Checklist

The schools navigating this landscape most effectively aren’t necessarily the ones with the longest policies.

They’re the ones with the strongest culture.

A culture where staff regularly ask questions.

A culture where “free” software isn’t adopted without scrutiny.

A culture where privacy considerations are part of procurement conversations from the start.

A culture where children are taught not only how to use technology, but also how to understand the value of their own information.

In other words, a culture that treats data literacy as an essential life skill.

Because it is.

 

A Final Thought

The next generation will grow up in a world where AI is ordinary, social media is embedded into daily life, and digital identities are established long before adulthood.

As educators, we rightly spend enormous amounts of time helping young people protect their wellbeing, develop critical thinking skills and navigate online spaces safely.

Perhaps protecting their data deserves an equally prominent place on that list.

After all, a lost worksheet can be reprinted.

A forgotten password can be reset.

But once personal data enters the digital ecosystem, retrieving complete control over it becomes considerably more difficult.

And that may be the most important lesson technology is teaching us today.

The future of education isn’t just about teaching children how to use technology. It’s about ensuring technology uses children’s information responsibly in return.

If you’ve ever opened your inbox and seen a message from a parent asking for “all the information you hold on my child,” your first thought was probably:

“Subject Access Request!”

But hold on — not every request for pupil information automatically falls under the UK GDPR. Sometimes, it’s actually a request under education regulations, depending on what’s being asked — and the type of school you are.

Understanding the difference is key. Not only does it help you respond lawfully and efficiently, but it also helps manage expectations and avoid unnecessary workload.

There are two main legal routes parents (or pupils themselves) might use to request access to information:

  1. Subject Access Request (SAR) – under the UK GDPR / Data Protection Act 2018

This allows an individual, including a pupil depending on their age and capacity, to request their own personal data.

  1. Request for the Educational Record – under the Education (Pupil Information) (England) Regulations 2005

This allows parents to request a copy of their child’s educational record, but only if the child attends a maintained school.

Let’s look at each in a little more detail.

Subject Access Requests (SARs) – GDPR territory

This is all about personal data.

Anyone can ask for a copy of the data you hold about them, including pupils (depending on their age and maturity), staff, or parents asking for their own data.

When it comes to parents asking for their child’s data, you’ll need to check whether the child is old enough and mature enough to understand what’s being asked. If they are, they should normally be the one making the request or at least give permission for the parent to do it on their behalf.

If they’re younger or not able to understand, the parent can usually make the request.

What does a SAR cover?

Any personal data you hold about that person. That might include:

  • Behaviour notes
  • Emails mentioning the pupil
  • Health or SEN info
  • Safeguarding logs (with care!)
  • CCTV footage (if the pupil is clearly visible)

When it comes to Subject Access Requests, any type of school may receive a request, including maintained, academies, free schools, and independents and you have 1 calendar month to respond.

Request for the Educational Record – Pupil Regulations

This one is specifically for parents of children at maintained schools (i.e. those run by local authorities). It gives them the right to see their child’s educational record, which is basically anything to do with their progress, learning, and life in school.

What counts as an educational record?

Think stuff like:

  • School reports
  • Attendance records
  • SEN plans
  • Notes from parent-teacher meetings
  • Behaviour points
  • Targets or interventions

It doesn’t include:

  • Child protection files
  • Teacher’s personal notes
  • Information that could seriously harm the child or someone else

Under these regulations, you have 15 school days to respond. You can also apply a charge to cover printing or postage, though most schools just send it electronically for free these days.

For academies and free schools, the right to the educational record doesn’t apply. But many still choose to share records in a similar way, just to be helpful and consistent. It is the same deal with Independent schools, there is no right to the educational record. Parents need to go down the SAR route if they want information about their child, and only if the child isn’t old enough to make the request themselves.

While SARs and education record requests are different, there’s a bit of crossover. Some information might be shared under both, and that’s OK. The key is understanding which law applies and making sure you’re not accidentally oversharing or withholding something you shouldn’t.

When in doubt, take a breath, talk to your DPO, and go from there.

Sentry matches the requirements of the ICO

It’s now less than four months until enforcement of the GDPR begins. You’d imagine that every now knows about the regulation even if they’re not totally clear about the impact.

On Tuesday of this week (24th January), the Department for Digital, Culture, Media and Sport released some preliminary results from Cyber Security Breaches Survey.
With less than four months to go until enforcement begins, significant numbers of businesses and charities had not heard of the GDPR. This included 20% of businesses and 25% of charities with more than 250 employees.

The highest levels of awareness were in the finance and insurance, information and communications and education sectors (79%, 67% and 52%). Still meaning that almost half of the organisations in the education sector were still not aware of the regulation. If you remember the game show Family Fortunes, the cross is showing and the ‘Eh-Uhh’ noise is blaring.

Of those who were aware of the GDPR only about a quarter have taken action. Like lots of us with Christmas shopping it looks like there will be a last-minute rush. Of course, just like joining the last-minute rush – you may not get what you want.

The fact that you’re reading this post, plainly means that you’re in the group that’s aware of the GDPR, but you may be wondering what you need to do next.

If you haven’t done it start with an audit of the personal data you are holding. It’s worth remembering that the scope of what counts as personal data is pretty broad. As well as personal data in IT systems, paperwork in any form of filing system may well hold personal data as well.

You may well find that a name and address, for example, is held in 5 different places and be from more than one source. It may take a long time, but once you understand where personal data is located and how it’s held, many of the other requirements for compliance start to fall into place.

If you don’t want to get trampled in the mad last minute rush it’s time to get going.