A new academic year brings a full inbox of statutory guidance, policy refreshes and operational pressure — often all landing in the same first few weeks of term. Before the pace picks up, it's worth pausing to check that the key data protection foundations are in place. Here's what should be on your radar this September.
1. KCSIE 2026: know what's changed, and get staff trained early
Keeping Children Safe in Education is statutory guidance that every member of staff must understand annually, without exception: it isn't a box-ticking exercise, and this year's edition brings genuine data protection changes worth building into your INSET planning. The updated guidance reflects the Data (Use and Access) Act 2025 and clarifies expectations around information sharing and the transfer of child protection files, particularly relevant where pupils move between schools or settings.
Practical steps for the first weeks of term:
- Get KCSIE 2026 training scheduled and completed by all staff as early as possible. Make use of the DPE KCSIE Course and assign to staff.
- Review your child protection file transfer process against the updated guidance, especially timeliness when pupils move mid-term.
- Make sure your DSL and data protection lead have actually talked to each other about what's changed: the two roles increasingly overlap on information-sharing decisions.
- Make sure your DSL works with your SLT Digital Lead to meet the DfE Filtering & Monitoring Standards. Review: The DSL's Guide to Filtering & Monitoring.
2. Data protection and cyber training: don't let it slip past September
Annual data protection and cyber security training for all staff is one of the most basic accountability requirements under UK GDPR, and the DfE Digital Standards. The start of term is the natural deadline for it, not something to catch up on once the term is already underway. New starters need it built into their induction from day one, not left until a general refresher session weeks later.
Worth building into your first-weeks plan:
- All returning staff booked onto their annual data protection refresher, with a clear completion deadline rather than an open-ended "sometime this term".
- New starters given data protection and cyber awareness training as a fixed part of induction, alongside safeguarding and KCSIE training, rather than treated as a separate add-on. Data Protection training should be part of your onboarding process for new staff and governors.
- Cyber-specific training covering the basics staff actually encounter: phishing recognition, password hygiene, MFA, since start-of-term is a known high-risk window for exactly these attack routes.
- A simple way of tracking who has and hasn't completed training, so gaps are visible to leadership rather than discovered after an incident.
- Data Protection Training: DPE Customers can assign the updated Data Protection 2026 training course to staff as part of this refresh.
- Continual awareness is the best way to keep both cyber security and data protection at the forefront of everyone's mind. This can be done through posters, and regular updates. We've added a suggested schedule of items you may wish to share in our ICO Accountability Framework: Training Best Practice.
3. Retention schedules: the quiet job that prevents big problems
The start of the year is the natural moment to check your retention schedule is being followed, not just filed away. Two things make this particularly live right now:
- The Statutory Independent Inquiry into Grooming Gangs has issued a formal notice requiring schools to preserve documents potentially relevant to its investigation. Where a preservation notice applies, it overrides your normal retention and disposal schedule: deletion cycles that would ordinarily run at the start of the year need to be checked against this first. Review further guidance: Important Guidance for Schools: Record Retention and the Statutory Independent Inquiry into Grooming Gangs.
- Leavers and transfers: with new starters and Year 6/13 leavers both being processed this term, it's worth confirming your pupil file transfer and retention triggers are actually happening in practice, not just on paper. Checking that photos of leavers have been removed from devices and shared files, not just pupil records.
Before you run any bulk deletion or archiving exercise this term, check nothing in scope is subject to a legal hold.
4. DfE Digital Standards and the Academy Trust Handbook
The Academy Trust Handbook 2026 was published in July and takes effect on 1 October 2026, strengthening the DfE's position on digital and technology standards and introducing new procurement requirements: most notably around Management Information Systems (MIS). If your trust is reviewing or renewing its MIS this year, the DfE's own guidance now points directly to data protection and security considerations as part of that commercial decision, not an afterthought to it.
Worth checking at the start of term:
- Where your school or trust sits against the DfE's cyber security core standard, which was updated in June 2026 to reflect NCSC Cyber Essentials requirements.
- Whether procurement processes for any new EdTech or MIS suppliers this year reflect the DfE's EdTech procurement guidance, which now explicitly references the ICO's own EdTech audit findings. Review: DfE Procurement Risk Guide: Due Diligence and Data Protection for Trusts.
- That governors and trustees have sight of where the trust stands against the Academy Trust Handbook's digital standards ahead of the October deadline.
5. Allergy data: Benedict's Law and safe information sharing
From September 2026, schools have new statutory obligations under Benedict's Law around managing pupil allergy information. This creates a genuine tension for leadership teams: allergy data needs to move quickly to the people who need it: catering staff, first aiders, supply teachers, trip leaders, without that speed compromising how it's handled.
A practical, secure approach (sometimes referred to as the SSCIP model) means:
- Deciding in advance exactly who needs allergy information and by what route, rather than improvising when a new pupil arrives.
- Keeping allergy data out of insecure or informal channels, shared spreadsheets, group chats, printed lists left on staffroom walls.
- Making sure temporary and supply staff are briefed on where to find allergy information securely, rather than being handed it informally on day one.
Getting this right at the start of term, while class lists and catering arrangements are being finalised, is far easier than retrofitting it later. Review: Sharing Pupil Allergy Information Safely in Schools: A Practical Guidance & SSCIP Framework.
6. The wider picture: cyber risk hasn't gone away
The start of term is also a high-risk window for cyber incidents: new user accounts being provisioned, staff turnover, and a general spike in email and system activity all create opportunities. Ransomware attacks on schools and trusts have continued through the year, and the DfE's own systems were affected by a significant breach over the summer. A few basic checks are worth doing before the first full week:
- MFA enabled on all staff and admin accounts, particularly for anyone new.
- Starters and leavers processed promptly in your access control lists: old accounts left active are a common route in.
- Staff reminded, briefly and practically, of what a phishing attempt looks like at the point they're most likely to receive one.
Review: The DfE Cyber Attack: What Schools Should Look Out for Next Term.
7. SARs: know what you're looking at, and let good records management do the heavy lifting
September and October reliably bring a rise in Subject Access Requests: new parents wanting to see what's held on file, family disputes surfacing after the summer, staff changes prompting requests. Before responding to anything, the first job is correctly identifying what type of request you've actually received: a Subject Access Request, an Educational Record request, or a Freedom of Information request each carry different rights, exemptions and timescales, and treating one as another is a common source of delay and error.
Once a request is correctly identified, the real cost of answering it is almost always in the discovery stage: working out where the relevant information actually lives across email, MIS, safeguarding systems and paper files. This is where records management pays for itself directly:
- A well-maintained retention schedule means you're not searching through data that should already have been destroyed.
- Consistent, disciplined email and document retention narrows the discovery net considerably compared with an inbox that has never been cleared.
- Knowing in advance which systems hold personal data (from your record of processing) turns a SAR into a defined search exercise rather than an open-ended one.
Investing in records management discipline now, at the start of the year, is what keeps SAR turnaround manageable in November rather than becoming a fire-fighting exercise against the statutory deadline.
Review: Streamlining your Subject Access (SAR)Discovery Process.
8. Using the DPE Knowledge Bank for a smooth return to school
Return to School provides checklists and advice for the start of the school year or term for data protection leads in schools and trusts. Below is a start of academic year data protection checklist, along with guidance on using the Knowledge Bank's compliance manager to keep it all on track.
Start of academic year data protection checklist:
- Manage any staff changes on the DPE website by removing staff who have left and adding new staff members. Go to the DPE Dashboard → Users → Add Staff, either manually or via bulk import. Further information is available in the How to add users to the Knowledge Bank User Guide (PDF, 377 KB). If you need additional support, email
This email address is being protected from spambots. You need JavaScript enabled to view it. . - For new staff, consider including DPE's e-learning as part of the induction process: see Assigning courses to staff using to-dos.
- Review training taken by staff and assign courses to those requiring an update.
- Ensure any updated policies or documents have also been added to the website, and that staff are aware of them where relevant.
- Ensure any photo/video consent forms from new pupils are received and staff advised.
- If you have a new data protection lead, contact us for a demo of the Knowledge Bank at
This email address is being protected from spambots. You need JavaScript enabled to view it. , so your schools consultant can arrange to meet with you online or in person.
A full Return to school start-up checklist (spreadsheet, 126 KB) is available to work through alongside the above.
Using DPE's compliance manager for managing documents
Schools generally have a list of documents and policies for staff to read either at the start of the academic year or as part of the onboarding process. We'd advise circulating the key documents annually with their file location (for example, the school website or a SharePoint site), and again whenever updates are made. Ideally, the privacy notices and data protection policy will also be displayed on the trust or school website, so you can direct stakeholders: staff, parents, students, visitors, governors, to them when communicating updates. This should include a process for informing new admissions of the above.
If you'd like to track which staff have read which policy document, you can do this easily by uploading the documents and assigning them to staff via DPE's compliance manager.
In short
None of this is new territory, but the start of the year is when gaps show up fastest: new staff who haven't had training, retention routines that lapsed over the holidays, allergy information that hasn't caught up with a new class list. A short, deliberate check against KCSIE, staff training, retention, the DfE digital standards, allergy data handling, SAR readiness and the Knowledge Bank checklist above will save considerably more time than fixing the same issues in November.
Schools that check in regularly with their consultant for a compliance review tend to handle SARs and data breaches more smoothly when they do arise.
