GDPR Policy

Policy Owned By: Head of IT
Date Last Reviewed: September 2026
Date of Next Review: September 2027

(For information on managing a data breach go to Reporting a Data Breach.)

Executive Summary – Why a GDPR Policy is Important in Schools

Schools hold a wide range of personal information about children, young people, parents, and staff. This includes contact details, health and wellbeing records, safeguarding information, exam results, and even photographs or digital learning data. Because of the sensitivity of this information, schools are considered high-risk environments under data protection law.

The General Data Protection Regulation (GDPR) and the Data Protection Act 2018 require schools to manage this data lawfully, fairly, and securely. Having a clear GDPR policy ensures that:

  • Children’s rights are protected – safeguarding their privacy is part of safeguarding their overall wellbeing.
  • Parents and carers can trust the school – knowing their family’s information is kept safe, used properly, and not shared inappropriately.
  • Staff understand their responsibilities – from handling registers to managing digital platforms, every member of staff has a duty to protect data.
  • The school avoids legal and reputational risks – non-compliance can lead to fines, complaints, and a loss of confidence in the school community.
  • A culture of respect and accountability is built – modelling responsible use of data teaches students the importance of privacy and digital responsibility.

For St Leonards.  GDPR is not only a legal duty,  it is part of safeguarding, part of professional practice, and part of building trust with families.

 

Introduction

St Leonards is committed to conducting its business in compliance with all applicable UK data protection legislation, including:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018 (DPA 2018)
  • Privacy and Electronic Communications Regulations (PECR)
  • Protection of Freedoms Act 2012 (for biometric data)
  • Data (Use and Access) Act 2025 (DUAA)
  • The ICO’s Age Appropriate Design Code (Children’s Code)

and in line with the highest standards of ethical conduct.

This policy details the expected behaviours of St Leonards employees and third parties in relation to the collection, use, retention, transfer, disclosure and destruction of any personal data belonging to St Leonards’s customers, pupils, families, and staff (i.e. the Data Subject), irrespective of the media used to store the information.

Personal data is any information (including opinions and intentions) which relates to an identified or identifiable natural person. Personal data is subject to legal safeguards that impose restrictions on how organisations may process it.

St Leonards, as a Data Controller, is responsible for ensuring compliance with the requirements of UK GDPR, DPA 2018 and related legislation.

Non-compliance may expose St Leonards to complaints, regulatory action, fines and/or reputational damage. Leadership is fully committed to continued and effective implementation of this policy and expects all employees and third parties to share in this commitment.

Any breach of this policy will be taken seriously and may result in disciplinary action or business sanction.

 

Scope

This policy applies to all St Leonards entities where personal data is processed:

  • in the context of business activities of the school
  • for the provision or offer of goods or services to individuals (including free services)
  • to actively monitor the behaviour of individuals, including use of cookies or IP tracking to profile individuals

It covers personal data in electronic form (including email and documents) and structured manual files. This policy establishes a baseline standard for processing and protecting personal data by all St Leonards employees. 

Note: This policy does not cover personal data belonging to St Leonards employees, which is subject to separate HR data protection procedures.

 

Governance

  • Data Protection Officer (DPO): Douglas Birrell, Head of IT Services
  • See RACI matrix for accountability. 
  • Contact: gdpr@stleonards-fife.org

All queries about lawful bases, consent, privacy notices, retention, security, international transfers, automated decision-making, marketing compliance (PECR), or data breaches must be directed to the DPO.

 

Lawful Bases for Processing

St Leonards will identify and record an appropriate lawful basis under Article 6 UK GDPR for every processing activity. The bases the school relies on are:

  • Legal obligation – for example statutory returns, safeguarding and health-and-safety duties.
  • Contract – for example administering a pupil’s place or an employee’s contract of employment.
  • Public task / legitimate interests – for the day-to-day running of the school, including the internal use of pupil images (see the Photography and Videography Policy).
  • Consent – where required, for example external and public-facing marketing use of pupil images, certain optional activities, and electronic marketing under PECR. Consent is freely given, specific, informed and unambiguous, and can be withdrawn at any time.
  • Vital interests – in an emergency, to protect someone’s life.

Where the school processes special category data (such as health, or biometric data used for identification) or criminal offence data, it will also identify the additional condition required under Article 9 or Article 10 UK GDPR and Schedule 1 DPA 2018, and record why it applies.

The Data (Use and Access) Act 2025 recognises direct marketing as capable of being a legitimate interest and introduces a limited list of “recognised legitimate interests” (such as safeguarding and responding to emergencies) which do not require a balancing assessment. Where the school relies on legitimate interests outside those recognised categories, it completes and retains a Legitimate Interests Assessment (LIA). PECR consent requirements for electronic marketing continue to apply regardless of the DUAA change.

The school maintains a Record of Processing Activities (data inventory) recording, for each activity, the data, purpose, lawful basis, retention period, recipients and any international transfer.

The DPO’s remit expressly includes the school’s obligations under the Data (Use and Access) Act 2025, including the data protection complaints duty (see “Data Protection Complaints” below), automated decision-making and AI, and international transfers.

 

Policy Dissemination and Enforcement

The Executive Team must ensure:

  • All employees responsible for processing personal data are trained and comply with this policy.
  • All third-party processors engaged by St Leonards provide assurances of compliance before being granted access to personal data.

 

Data Protection by Design

All new or revised systems/processes must include Data Protection Impact Assessments (DPIAs) as required under UK GDPR (Articles 35–36). The IT Department must work with the DPO to review risks and mitigation. Deficiencies are to be reported to the Executive Team.

 

Data Protection Principles (UK GDPR & DPA 2018)

St Leonards adopts the following principles for personal data:

  1. Lawfulness, Fairness & Transparency
  2. Purpose Limitation
  3. Data Minimisation
  4. Accuracy
  5. Storage Limitation
  6. Integrity & Confidentiality
  7. Accountability

 

Data Collection

Personal data should be collected directly from the data subject unless:

  • it is necessary to collect from another party for business purposes
  • it is an emergency (protecting vital interests)
  • law requires collection from another source

Where required, data subjects must be notified promptly and within one year.

 

Individual Rights and Subject Access Requests

Data subjects have the rights set out in UK GDPR: to be informed; of access; to rectification; to erasure; to restrict processing; to data portability; to object; and rights relating to automated decision-making and profiling.

The school responds to a Subject Access Request or other rights request without undue delay and within one calendar month. Where a request is complex or numerous the period may be extended by up to two further months, and the requester will be told. The school may “stop the clock” where it reasonably needs clarification, and starts the month only once any necessary identity verification is received. Searches will be reasonable and proportionate. A request will only be refused where it is manifestly unfounded or excessive, and the reasons will be explained. The detailed process is set out in the school’s Subject Access Request Policy.

These timescales and the “stop the clock” and reasonable-and-proportionate-search positions reflect the Data (Use and Access) Act 2025 and current ICO guidance.

 

International Transfers

Some of the school’s systems and suppliers store or access personal data outside the UK. The school maps these transfers (including cloud hosting, support access from overseas and onward transfers by processors). Where a transfer is to a country not covered by UK adequacy regulations, the school puts in place an appropriate safeguard – typically the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs – and completes a Transfer Risk Assessment. For transfers to the United States, the school checks whether the recipient is certified under the UK Extension to the EU-US Data Privacy Framework. Old EU Standard Contractual Clauses are not relied on for UK transfers.

The DUAA moves the UK to a more risk-based approach to adequacy; the school keeps its transfer arrangements under review as adequacy regulations and ICO guidance develop.

 

Automated Decision-Making, Profiling and AI

The school does not routinely make decisions with legal or similarly significant effects on individuals using solely automated processing. Where any such automated decision-making or profiling is introduced, the school will identify a lawful basis, tell individuals, and provide a route to obtain human review, to make representations and to challenge the decision, consistent with UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025. Significant decisions based on special category data are subject to additional restrictions.

Before adopting any new AI tool, or any tool that processes pupil or staff data at scale, the school completes a DPIA (see Data Protection by Design) and considers AI-specific risks, including the risk of images or other personal data being reused, scraped or used to train AI models. This links to the safeguards in the Photography and Videography Policy.

 

Children’s Data

Because the school’s services are used by children, it applies a higher standard of protection, following the ICO’s Age Appropriate Design Code and the enhanced children’s-data provisions of the Data (Use and Access) Act 2025. This means considering age and developmental stage, designing systems with privacy in mind, and giving children age-appropriate information about their data (see the pupil-facing annex).

Under the Age of Legal Capacity (Scotland) Act 1991, a child aged 12 or over is generally presumed to have the capacity to exercise their own data protection rights. The school takes this into account when responding to rights requests and when seeking or acting on a child’s own preferences, alongside those of parents or guardians.

 

GDPR Policy for Parents

At St Leonards, we take the privacy of our students, families, and staff seriously. We follow the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other relevant laws to ensure personal data is collected, used, and stored securely.

 

What information do we collect?

We may collect personal information such as:

  • Student details (name, date of birth, contact details, school records, reports, attendance, learning progress)
  • Parent/guardian details (names, addresses, phone numbers, email addresses, emergency contacts)
  • Health and wellbeing information (where needed to keep students safe and supported)
    Safeguarding records (where legally required)
  • Photos, videos, and work produced by students
  • Payment and financial information (e.g. for fees, trips, activities)

 

Why do we use personal data?

We use this information to:

  • Support student learning and wellbeing
  • Keep students safe and meet safeguarding requirements
  • Communicate with parents and guardians
  • Manage school trips, events, and activities
  • Meet legal and government reporting obligations

 

How do we protect data?

  • Data is stored securely, with access limited to staff who need it.
  • Information is only kept as long as necessary.
  • We use technical and organisational measures to prevent unauthorised access, loss, or misuse.
  • If a data breach occurs, we will inform the Information Commissioner’s Office (ICO) within 72 hours and notify families if their data is affected.

 

Who is responsible for data protection?

  • Data Protection Officer (DPO): Mr Douglas Birrell, Head of IT Services
  • Contact: gdpr@stleonards-fife.org
  • The DFO is the accountable policy owner.

 

Your rights as parents and families

Under data protection law, you and your child have the right to:

  • Access – request a copy of personal data we hold
  • Correction – ask us to update inaccurate or incomplete data
  • Deletion – request removal of data, where possible
  • Restriction – ask us to limit how data is used
  • Objection – opt out of certain uses, such as direct marketing
  • Data portability – request data be transferred to another organisation (where applicable)

Requests can be made through the DPO.

 

Sharing data

We may share personal data with:

  • Local authorities, exam boards, and government bodies (where legally required)
  • Service providers (such as IT systems, payment providers, trip organisers) – always under strict contracts ensuring GDPR compliance
  • Emergency services, where required to protect a child’s vital interests

We never sell personal data to third parties.

 

Conclusion

St Leonards is committed to protecting the personal data of students, parents, and families. We continually review and improve our practices to meet legal requirements and uphold the trust placed in us.

If you have any questions or concerns about how your data is used, please contact our DPO at gdpr@stleonards-fife.org.

Contact us to find out more or to arrange a visit

You cannot copy content from this page.