Tru Data Protection
AboutDPO ServicePortal
PricingContactSign in →

Child Safeguarding Software and Data Protection: Best Practices Guide

A practical guide to child safeguarding software and data protection, including school risks, supplier checks, privacy concerns and governance best practices.

Safeguarding software can be an important part of how schools record, manage and escalate child protection concerns. Systems such as CPOMS, MyConcern and similar platforms help schools organise information that would otherwise be difficult to track consistently.

But safeguarding software is also one of the clearest examples of why schools need strong data protection governance. These systems often involve highly sensitive information, complex access decisions, third-party suppliers and difficult questions about disclosure, retention and accountability.

Why safeguarding software needs careful governance

Safeguarding records may include:

  • child protection concerns;
  • welfare notes;
  • behaviour information;
  • health information;
  • SEND context;
  • family circumstances;
  • staff observations;
  • external agency contact;
  • incident details.

That means the system may contain personal data, special category data and sometimes highly sensitive contextual information.

The question is not whether safeguarding software is useful. It is whether the school understands how that software processes data, who can access it, how long records are kept and what happens when records are disclosed or shared.

Key data protection questions schools should ask

Before adopting or reviewing safeguarding software, schools should ask:

  • What categories of personal data are stored?
  • What is the lawful basis for processing?
  • Is special category data involved?
  • Who can access the system and on what basis?
  • What audit logs exist?
  • What retention settings apply?
  • Are there international transfers?
  • What sub-processors are used?
  • What happens to data when pupils or staff leave?
  • How does the platform support redaction, access control and evidence?

These are not abstract procurement questions. They are the practical questions that determine whether the system can be used defensibly.

Safeguarding and data protection are not in conflict

Schools sometimes worry that data protection will prevent proper safeguarding. That is the wrong framing.

Good data protection does not stop safeguarding. It helps make sure that sensitive information is:

  • recorded appropriately;
  • shared with the right people;
  • kept secure;
  • reviewed properly;
  • retained for the right period;
  • disclosed lawfully when required.

In other words, good governance helps safeguarding work stand up to scrutiny.

Supplier review matters

Safeguarding platforms should be reviewed like any other high-impact product.

That review should consider:

  • hosting location;
  • security controls;
  • role-based access;
  • retention;
  • deletion;
  • contract terms;
  • Data Processing Agreement status;
  • incident handling;
  • sub-processors;
  • support model.

Schools should not rely only on product popularity or word of mouth. A safeguarding tool still needs evidence.

DPIA and ROPA implications

A safeguarding platform may require DPIA screening and, in some cases, a structured DPIA.

The school should also make sure the processing is reflected properly in its Record of Processing Activities, including:

  • purpose;
  • data subjects;
  • data categories;
  • lawful basis;
  • recipients;
  • retention;
  • systems and suppliers;
  • review status.

If the system changes or new features are enabled, those records should be reviewed again.

Access, recording and disclosure

One of the hardest parts of safeguarding systems is not just implementation. It is how the school uses them day to day.

Schools need clear rules for:

  • what should be recorded;
  • how factual the record should be;
  • who can see what;
  • how concerns are escalated;
  • how records are reviewed;
  • what happens when a SAR arrives;
  • what must be withheld or redacted to protect other children or third parties.

This is why staff guidance matters as much as the software itself.

How Tru Data Protection helps

Tru Data Protection helps schools and MATs review safeguarding software in a practical, defensible way.

That may include:

  • supplier and processor review;
  • DPIA screening or structured DPIA support;
  • ROPA updates;
  • policy and retention review;
  • access and disclosure guidance;
  • SAR and redaction support;
  • governance records and action tracking.

Conclusion

Safeguarding software can be valuable, but it should never be treated as “just another app”.

These systems hold some of the most sensitive information a school processes. They need clear governance, proper supplier review, and a realistic understanding of how safeguarding and data protection work together in practice.

Get started

Ready to get started?

See pricing, or get in touch for a quick conversation and a clear plan.

See pricing →Get in touch →
Tru Data Protection

Hosted in the UK (AWS London)

ISO 9001/27001-aligned (certification planned)

Products

  • DPO Service
  • Portal
  • Evidence Processing
  • Redaction
  • Policy Packs & Exports

Company

  • About
  • Founder
  • Contact
  • Pricing
  • Tru-Digital Services

Support

  • Guidance
  • Blog

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms and Conditions
  • Data Processing Agreement
© 2026 Tru Data Protection is a trading name of Tru-Digital Services Limited, company number 16210598. ICO registration: ZB887707.