Best Practice Update

Graphic representing new DfE guidance on EdTech procurement for schools, focusing on data protection.

On 9 July 2026, the DfE added a new section to its Data Protection in Schools guidance: Procuring educational technology (EdTech). It sets out what schools should consider before, during and after procuring EdTech tools, and the questions to put to prospective suppliers. Significantly, it is the first DfE guidance to directly reference the ICO's EdTech Examined audit report, telling schools to take the ICO's findings into consideration when procuring EdTech tools.

ICO EdTech Examined report graphic, highlighting data protection audit findings for UK schools and children'

The ICO's edtech audit programme, covering 28 providers used across UK primary and secondary schools, has resulted in one of the most significant data protection reports to affect the education sector in years. Published in June 2025, the ICO's EdTech Examined report made 596 recommendations and found widespread compliance failures in how edtech providers handle children's personal data. This article sets out what was found and what schools and DPOs need to do about it.

Graphic representing the Department for Education (DfE) Data Protection in Schools guidance update from June

The Department for Education (DfE) updated its Data protection in schools guidance on 17 June 2026, this refresh aligns the guidance with the wider expected KCSIE 2026 guidance and reinforces existing obligations that schools should already be acting on.

This article sets out what has changed, what it means for your school in practice, and the actions your data protection lead should be taking now.

 

DfE Filtering and Monitoring Core Standard graphic for schools and colleges, essential for safeguarding children.

The Keeping Children Safe in Education (KCSIE) document obliges schools and colleges in England to “ensure appropriate filters and appropriate monitoring systems are in place and regularly review their effectiveness”. This responsibility is now a standard, no just a technical tick box, but a core leadership and safeguarding function.

AI-manipulated images of smiling children, symbolizing the urgent online safety risks for schools

This article combines guidance from the Guardians of Privacy series, produced by Data Protection Education in collaboration with Litus Digital, with urgent new advice issued in May 2026 following confirmed blackmail attempts against UK schools using AI-manipulated images of children. Key sources include the UK Safer Internet Centre (8 May 2026) and the Internet Watch Foundation.

  1. Visitor Management: A Guide for Schools
  2. Under surveillance: Why your organisation's CCTV might not be compliant
  3. Update to the DfE Digital Cyber Security Standards for Schools and Colleges
  4. Wireless Network Standards for Schools & Colleges: What's New?
  5. World Backup Day: Backups - Your Safety Net
  6. School Cyber Attack: St Anne's Catholic School
  7. Volunteer Acceptable Use Policy & Agreement
  8. Handling Subject Access Requests (SARs) - at the end of term
  9. How should schools manage paper archives?
  10. Navigating the Redaction Divide: SAR or PEX?
  11. Records Management Toolkit: Where do I start with records management?
  12. What type of request have you received? SAR? Educational Record? Or FOI?
  13. SAR Extension Template
  14. Leavers' Memorabilia
  15. Sharing photos on World Book Day: Privacy considerations
  16. Make sure DPE is your registered DPO with the ICO
  17. Supplier Due Diligence Step by Step: Are you sharing personal data with a third party organisation?
  18. Time to kick-start your Clear Desk and Screen policy?
  19. Are Governors the Frontline of Cyber Security? (February 12th is Governors Awareness Day)
  20. DPE Webinar Schedule
  21. The Danger of the 'Data Dump': Why more information isn't always better!
  22. Introducing our new Recording and Transcription Policy
  23. Parents and students covertly recording conversations
  24. New DfE AI Standards
  25. Shareable Snippet: Office Security Best Practices for the Holidays
  26. CCTV Policy update: retention
  27. Shareable Snippet: Confidential waste
  28. Sharing information to safeguard children and young people in the education sector in the UK
  29. Fraud awareness from the DfE
  30. Complaints vs. Data Rights: A Guide
  31. Data Breach: School sends out names and contact details in a spreadsheet.
  32. September 2025 Policy and Document Updates
  33. KCSIE 2025: Data Protection, AI, and Cyber Security
  34. The Online SCR Data Breach: What You Need to Know
  35. Back to School Basics for Data Protection and Cyber Security Compliance
  36. Building a Secure School: Using the ICO Accountability Framework to Meet DfE Digital Standards
  37. Why Physical and Data Security Must Go Hand-In-Hand
  38. Digital Safeguarding: DfE announces statutory DfE Digital Standards
  39. The Data Protection Lead/Champion Role
  40. Changes to the Academy Trust Handbook 2025
  41. Social Media Day 2025
  42. How Ofsted looks at AI during inspection and regulation
  43. Preschool Employment tribunal for the use of WhatsApp
  44. Data Breaches 2025 Report Highlights
  45. Not everyone needs access: The Key to Protecting Sensitive Data
  46. West Lothian Schools in Cyber Attack
  47. National Honesty Day: Transparency
  48. FOI Request - BBC News
  49. Social Media and Marketing Guidelines and Training
  50. New Governor Resources
  51. Does stress lead to more data breaches?
  52. Are teachers using AI? 83% say its a time-saver
  53. DfE Digital Standards - narrowing the digital divide
  54. Arbor AI - On By Default
  55. DfE Guidance: Choosing a new MIS
  56. HCRG Care Group data breach
  57. The Importance of AI literacy and training staff
  58. Short Guide to AI Video
  59. Safer Internet Day, Cyber Security & Data Protection
  60. The Cyber Resilience Championship
  61. The Multiple Dimensions of Supplier Due Diligence
  62. School shares sensitive pupil information as part of an FOI response
  63. Blacon High School Cyber Attack
  64. WhatsApp and FOI's: ICO Warnings
  65. New AI Guidance from the DfE
  66. What the proposed Government legislative proposal around cyber crime means
  67. ICO report on AI tools in recruitment
  68. DfE update to record keeping and management
  69. Update to data sharing for school immunisation programmes
  70. Early Years Settings and Cyber Security
  71. SLT Digital Lead Profile
  72. The role of governors in cyber security and data protection
  73. Navigating Privacy at the End of Term , Special Occasions and End of Year
  74. Contracts Register
  75. DfE Digital Standards Autumn Update
  76. The importance of knowing how to access your CCTV footage!
  77. Cyber Attack on a Special School
  78. Stealing children's data
  79. What is dark data? (and why does it matter?)
  80. Ofqual highlights the value of cyber security training in schools
  81. Searching for data when you receive a Subject Access Request
  82. Fylde Coast Academy Trust Cyber Attack This Week
  83. Calling all IT leads in schools and mult academy trusts!
  84. Ransomware cyber attack on a school in Bromley
  85. Join Our Social Media Family!
  86. School hit by Cyber Attack
  87. Cyber Security Best Practice Area
  88. DfE Digital Standards for Schools and Colleges Tracker
  89. New Policies, Documents, Letters and Posters page
  90. Schools and Trusts Best Practice Area
  91. The DPE Retention Schedule
  92. ESFA Cyber Essentials Requirement for Colleges from 2024/2025
  93. ICO Reprimands a School
  94. Out of date technology
  95. Data Retention and the Pupil File
  96. Have you assigned your SLT Digital Lead yet?
  97. Getting Started with AI (Artificial Intelligence)
  98. Cyber attack on a school during half term
  99. The rise of cyber attacks in schools are causing pupils to miss classes
  100. ICO: Learning from the mistakes of others report
  101. Cyber attack on a Trust; the aftermath
  102. School Focus: The Vale Federation | Aylesbury
  103. DfE Dealing with Subject Access Requests (SARs) Guidance
  104. Update to the Guidance on Information Sharing from the DfE
  105. FOI Requests generated by Artificial Intelligence
  106. Social Media Best Practice Area
  107. Lettings Best Practice Area
  108. MFA Bombing - What is it?
  109. Protecting your Social Media Accounts
  110. Checklists - Are They Your Most Powerful Compliance Tool?
  111. Product Focus on Checklists : Initial Trust Plan
  112. Product Focus on Checklists : End of Term Checklist
  113. Product Focus on Checklists : Information and Cyber Security
  114. Product Focus on Checklists : Social Media
  115. Product Focus on Checklists : Lettings
  116. Product Focus on Checklists : Record of Processing
  117. Milk Island: The secret location that allows children to view restricted content on Google Maps
  118. Why Data Should Stay Put: Benefits of Keeping Data in Its Original System
  119. Product Focus on Checklists : Data Retention and Destruction
  120. Product Focus on Checklists : Data Migration
  121. Product Focus on Checklists : Biometrics
  122. Product Focus on Checklists : Supplier Due Diligence
  123. Free Cyber help, advice and training with the Cyber Resilience Centres
  124. The Perils of Paper: The Printing Vulnerability
  125. Product Focus on Checklists : FOI
  126. Product Focus on Checklists : Governors and Data
  127. Product Focus on Checklists : DPIA
  128. Product Focus on Checklists : Site Moves
  129. Product Focus on Checklists : Data Breaches
  130. Product Focus on Checklists : Subject Access Requests
  131. Product Focus on Checklists : Bring your own device
  132. Product Focus on Checklists : Working out of school/offsite
  133. Cyber Attack on a School
  134. Product Focus on Checklists : Redaction
  135. Why Due Diligence is Important: Fake apps
  136. Product Focus on Checklists : CCTV
  137. Product Focus on Checklists : Clear desk
  138. Product Focus on Checklists : Commitment to compliance
  139. Product Focus on Checklists : Photos and video
  140. Product Focus on Checklists : Passwords
  141. Product Focus on Checklists : Information Classification
  142. Free cyber training for staff
  143. DfE Digital Standards Update
  144. The Mother of all Breaches
  145. International Data Transfers (part 1): Navigating Cross-Border Data Transfers: Understanding EU SCCs, UK Addendum, and UK IDTA
  146. ClassCharts Possible Data Breach
  147. Where is your data stored?
  148. IAPP looks at AI privacy risks
  149. If you suspect a financial scam .....
  150. School Focus: St Bernadette's Catholic Primary School | Brighton
  151. Guardians of Privacy: 16. Social Media Checklist
  152. Guardians of Privacy: 15. Navigating Social Media in Educational Settings Summary
  153. Guardians of Privacy: 14. Social Media and Cyber Bullying
  154. Guardians of Privacy: 13. Social Media, Copyright and Intellectual Property
  155. Guardians of Privacy: 12. Social Media and Going Viral
  156. Guardians of Privacy: 11. Staff Social Media Accounts
  157. Guardians of Privacy: 10. Social Media and Cookies
  158. Guardians of Privacy: 9. Social Media and Morality
  159. New Resources for Schools from the ICO
  160. Guardians of Privacy: 8. Social Media Policies
  161. Guardians of Privacy: 7. Social Media Data Retention
  162. Guardians of Privacy: 6. Posting Safely
  163. Guardians of Privacy: 5. Social Media and Consent
  164. Guardians of Privacy: 4. Social Media Access Control
  165. Guardians of Privacy: 3. Social Media Channels
  166. Guardians of Privacy: 2. Law and Regulations
  167. The ICO reprimands a Multi Academy Trust
  168. Guidance for the use of school email and applying email retention in schools
  169. Data Protection Tips for Early Years Settings
  170. Children's Privacy around the world is a puzzle
  171. Trust Initial Plan Checklist Update
  172. Records Management Best Practice Update
  173. What do I need to redact?
  174. Trust Initial Plan for Data Protection Compliance (for Multi Academy Trusts)
  175. Google for Education Resources: Helping IT Admins meet DfE digital and technology standards
  176. Lettings Best Practice and Guidance
  177. Considerations when migrating to a new MIS
  178. Public bodies and sensitive data
  179. Get a DPE Badge for your website!
  180. ICO: 10 Step guide to sharing information to safeguard children
  181. Help after a Cyber Attack/Incident
  182. Data Protection and Cyber Security (Inset Day) Training Ideas
  183. How KCSIE is linked to Cyber Strategy
  184. Handling Freedom of Information Requests the right way
  185. Where's Harry the Hacker?
  186. The ICO Reprimands a school
  187. Redaction Guidelines Updated
  188. Using WhatsApp in Schools
  189. How to contact us for support, subject access requests, data breaches and FOI's
  190. FOI: Reinforced Autoclaved Aerated Concrete
  191. FOI: Henry Jackson Society
  192. FOI: Vaccination Justifications
  193. How the Record of Processing Can Help You
  194. What does a Data Protection Officer Do?
  195. Carrying out Supplier Due Diligence
  196. How Long Should You Keep Personal Data For?
  197. B&H FoI: Racist/religious incidents/bullying
  198. Protocol for Setting Up and Delivery of Online Teaching and Learning
  199. Class Dojo International Data Sharing
  200. Model Publication Scheme: Amendments, Improvements and Updates
  201. Transparency
  202. Research projects and GDPR
  203. Secure file transfer of files using Royal Mail
  204. Emergency contacts and consent
  205. Key elements of a successful DPIA
  206. FOI Publication Schemes
  207. Best Practice for Managing Photos and Video
  208. New Drip Feeds: Recognise and Respond to Subject Access Request
  209. When to contact the Data Protection Officer?
  210. National child measurement programme
  211. Headteacher fined for breach of data protection legislation
  212. Acceptable Use Policy

Search