Last reviewed on 2 September 2022
School types: All · School phases: All
Ref: 32393

Schools must make sure their data processing complies with data protection law under the UK GDPR. Here's what your board needs to do to make sure you and your school are compliant, including a downloadable checklist to monitor compliance.

The UK adopted the EU’s General Data Protection Regulation (GDPR) in 2018, but since the UK's withdrawal from the EU it has used its own version, known as the UK GDPR.

The UK GDPR works with the Data Protection Act 2018 (DPA 2018) to form the UK's data protection framework. Find out more in our summary.

As governors and trustees, you're ultimately responsible for data protection, and this article will help you make sure that you and your school/trust are compliant. It draws together advice from the Information Commissioner's Office (ICO) and 4 of our associate experts: Caroline Collins, Brendan Hollyer, Graeme Hornsby and Leon Ward.

Download our checklist

We've condensed the actions in this article into a checklist that your governing board can tick off: 

This is because you have collective responsibility for data protection. Even if you're lucky enough