A reprimand has been issued by the ICO to Parkside Community Primary School in relation to the infringements of Article 5 (1)(f), Article 24 (1) and Article 32 of the UK GDPR. This article discusses the reprimand and looks and what schools can do to avoid this type of breach.
Some of the information in the reprimand document is redacted, but the main details are:
The breach is in relation to the UK GDPRs security principle, meaning that the school failed to prevent unlawful disclosure of personal data.
The school also failed to implement appropriate technical and organisational measures to ensure personal data is kept secure under Article 32 of the UK GDPR.
The findings were that the school did not have:
There were several steps taken and further action recommended which all schools should take into consideration when using these kinds of systems and when handling special category data in a busy school environment:
The further actions recommended were:
The key points to take from the recommendations are that you should always be aware of where you are and who might see what you're working on. Data classification and access controls are vital. Special category requires extra security.
Consider all the advice above with what other safeguarding and special category data that you may have displayed around your school? Consider using our Making the Rounds tool to do your own data walk or get in touch with your Data Protection Education School Consultant to do the walk with your or have a follow-up feedback meeting.
Use our
pdf
DPE Quick Reference Guide(1.64 MB)
for practical advice on what can be displayed around schools.
The full reprimand can be read here: https://ico.org.uk/action-weve-taken/enforcement/parkside-community-primary-school/
We've updated our document redaction guidelines to include more information on the techniques available as well as exemptions.
https://dataprotection.education/best-practice-library/best-practice/redaction
This article is about the use of WhatsApp as a communication tool in schools and recent vulnerabilities. It discusses school staff using WhatsApp as a communication method for school business.
We are sometimes asked by staff whether it is OK for staff to be in a WhatsApp group for important school messages. Staff often wish to use it because it is an easy way to communicate and a platform that a lot of people are familiar with. It is also free. There are issues around this:
The ICO called for a review into the use of private email and messaging apps within government as there is a lack of controls: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/07/behind-the-screens-ico-calls-for-review-into-use-of-private-email-and-messaging-apps-within-government/
WhatsApp says is should not be used for business; it is against their terms and conditions. Although WhatsApp have a business app, this is for businesses to link with their customers (ie the public), not designed for private chat within an organisation: https://support.safeguardinginschools.co.uk/article/36-why-schools-shouldnt-use-whatsapp
This article highlights the lack of user management that can create security issues: https://www.beekeeper.io/blog/why-you-shouldnt-use-whatsapp-for-business-communication/
WhatsApp has previously been fined for data breaches: https://www.fieldfisher.com/en/insights/privacy-notices-post-whatsapp
More recently there has been a warning from Action Fraud about a takeover scam of Whatsapp accounts : https://www.actionfraud.police.uk/alert/warning-issued-to-whatsapp-users-over-account-takeover-scam
Our advice would be to always try to minimise any risk, so consider the following:
Internet Matters offers a WhatsApp social media guide.
Information about whether WhatsApp is safe for children is covered by the NSPCC: Is WhatsApp safe for my child?
If you have been a victim of fraud or cyber crime, report it to Action Fraud or 0300 123 2040, and possibly your DPO, depending on the cyber crime.
This article lists the ways that Data Protection Education can be contacted for general data protection queries, data breaches, subject access requests and freedom of information requests.
While all our customers have a dedicated consultant who can be contact directly, if there is an urgent issue we would always advise emailing
When you email
If you email a reply to the original email notification or any updates you received, then the ticket will be automatically be updated and is something we would recommend. If you send a new email to
You could also login to the Knowledge Bank:
https://dataprotection.education/
and update your ticket directly with the information.
How to add a Subject Access Request:
By logging a subject access request on the Knowledge Bank as soon as you receive it, we can guide you through the process and give any additional support and advice.
Login to the Knowledge Bank and go to 'Data Rights Log', select the white text in the title bar. Choose on the next screen to add a new data breach log. Then complete as much detail as you can in the data breach form.
You can also report a subject access request by emailing
The ICO says you must keep a record of any personal data breaches, regardless of whether you are required to notify them. Logging those breaches in the DPE Knowledge Bank is a good way of keeping a record that your DPO can access and advise on.
Login to the Knowledge Bank and go to 'Breach Log', select the white text in the title bar. Choose on the next screen to add a new data breach log. Then complete the form with as much detail as you can.
You can can also report a data breach by emailing
By logging a freedom of information request on the Knowledge Bank as soon as you receive it, we can guide you through the process and give any additional support and advice.
Login to the Knowledge Bank and go to 'FOI Log', select the white text in the title bar. Choose on the next screen to add a FOI. Complete as much detail as you can in the form.
You can also raise a ticket to ask for advice about an FOI by emailing
https://dataprotection.education/news-top/news
It is also possible to contact us on: 0800 0862018
You may have received this FOI request from ITV News:
(scroll down for our advice)
I am writing to you under the Freedom of Information Act 2000 to request information about any use of Reinforced Autoclaved Aerated Concrete (RAAC) in your school. The questions are outlined in the table below...
My name is Charlotte Littlewood, and I am a Research Fellow at the Henry Jackson Society.
I am writing to you under the Freedom of Information Act 2000 to request the following information:
You may have received an email or letter requesting information on the research and justification of the administration of vaccines, such as:
Dear Sir/Madam,
RE: SCHOOL VACCINE POLICY.
In relation to UK Government COVID-19 'Vaccine' Policy and Childhood Immunization ‘Vaccine’ Policy which includes INFLUENZA, HPV, MEASLES AND POLIO, under the protection of the People's Union of Britain, you are hereby served notice of conditional acceptance that you are lawfully entitled to 'vaccinate' children, whilst in the care of the headteacher at the school, whether on school premises or elsewhere, provided you deliver to me the following:
The Record of Processing can often seem like a daunting process to undertake- but it’s important to view it as exactly that- a process. Documenting the processes your organisation carries out is an ongoing project that you continue to evolve and develop as those processes change. The value you can get out of spending some time and care by completing various ones shouldn’t be underestimated. We’ve spoken to some of the people who have used the RoP tool on the Knowledge Bank, and asked them what they found challenging, and what they found the most useful parts of the tool, in the hope that it will help some of you who may feel that carrying out the Record of Processing is a daunting task.
Under UK GDPR, Public Authorities or Bodies, as well as businesses carrying out certain processes are required to appoint a Data Protection Officer (DPO). This article will explain why you need a DPO and what a DPO does for your organisation.
At Data Protection Education, we have an ongoing project to assess potential organisations that our schools are either currently contracted with to supply a product or service, or may in the future be in contract with.
©2026 Data Protection Education Ltd.