Best Practice Update

 A blue graphic with three children peering over a dark blue banner. The banner has white text that reads "Back to School Basics: Data Protection & Cyber Security." To the left of the text is a stack of school books with a red apple on top. To the right is a laptop displaying a logo with the text "Data Protection Education."

Back to School Basics for Data Protection and Cyber Security Compliance

As schools begin to welcome back students, staff and new joiners, the focus is on the new academic year: curriculum planning, safeguarding and operational logistics.  An equally critical and statutory area that demands attention is data protection and cyber security compliance.  Adhering to data protection law isn't just about avoiding fines; it's about protecting sensitive personal data of children, their families and staff.

A new year means new pupils, new records, new consent forms and new digital and paper footprints.  New staff require onboarding and existing systems should be re-evaluated for vulnerabilities.  Here's a breakdown of key compliance areas for schools to focus on before they head back to school:

Data Protection Checklist for the New Year

Policy Refresh:

Check the following policies and procedures are up to date:

✅ Data Retention:

✅ Consent Management:

  • Review any consent forms and refresh if required and ensure there is a clear process for withdrawing consent at any time.

    DPE Customers should review our Photos & Video Best Practice Area.

✅ Training and Awareness:

✅Procedures:

Cyber Security Compliance

With six of the DfE Digital Standards now required there are elements of cyber security and network security that should be addressed:

✅Device and Network Security:

  • Ensure all school-owned devices and software are fully updated with the latest security patches before the term starts and devices are allocated.
  • Review access control to the network and systems, including Wi-Fi security.
  • Check anti-virus and anti-malware meets the DfE Digital Standards requirements
  • Ensure your BYOD policy is clear, staff (and students if applicable) are aware of their responsibilities and appropriate security measures are in place
  • Ensure you review your Acceptable Use Policy, for both staff and students.

Password Policies:

  • Enforce strong passwords
  • Implement MFA were possible. Share our MFA video which explains to staff how configuring it can help prevent data breaches.

DPE Customers should review: Password Best Practice Area

Awareness

  • Ongoing phishing awareness training.
  • Ongoing cyber response training

Backups:

  • Confirm backups are working and only backing up what is required.
  • Confirm/review/update your incident response plan.

        DPE Customers should review: DfE Cyber Security Standards

Remote Access:

The start of the academic year is a busy time, but prioritising data protection and cyber security compliance is an investment in the safety and trust of your community. By taking proactive steps now you will have a more secure and compliant environment.

Search