Tru Data Protection
AboutDPO ServicePortal
PricingContactSign in →

What is UK GDPR?

A plain-English introduction to UK GDPR for schools and MATs, including personal data, principles, rights, security and practical compliance steps.

The UK General Data Protection Regulation, usually called UK GDPR, is the main data protection law that governs how personal data is collected, used, stored and shared in the United Kingdom.

It gives individuals rights over their personal data and places obligations on organisations that process it.

For schools and MATs, UK GDPR matters because education relies on personal data every day.

What is personal data?

Personal data is information that identifies, or could identify, a living person.

In schools, this may include:

  • names;
  • addresses;
  • contact details;
  • pupil records;
  • attendance information;
  • behaviour records;
  • safeguarding information;
  • SEND records;
  • health information;
  • staff records;
  • photographs;
  • CCTV;
  • online identifiers;
  • assessment data.

Some data is more sensitive, such as health, safeguarding, SEND, biometric or criminal offence information. This needs additional care.

What does UK GDPR require?

UK GDPR requires organisations to handle personal data lawfully, fairly and transparently.

This means schools should be able to explain:

  • what personal data they collect;
  • why they need it;
  • what lawful basis applies;
  • who it is shared with;
  • how long it is kept;
  • how it is protected;
  • what rights individuals have.

The key UK GDPR principles

The main principles are:

Lawfulness, fairness and transparency

Use personal data only where there is a lawful basis and be clear with people about how their data is used.

Purpose limitation

Use data for specified, explicit and legitimate purposes. Do not reuse data for incompatible purposes without proper consideration.

Data minimisation

Collect and use only the data needed for the purpose.

Accuracy

Keep personal data accurate and up to date.

Storage limitation

Do not keep personal data longer than necessary.

Integrity and confidentiality

Keep personal data secure.

Accountability

Be able to show how the school complies.

Individual rights

People have rights under UK GDPR, including:

  • the right to be informed;
  • the right of access;
  • the right to rectification;
  • the right to erasure in some circumstances;
  • the right to restrict processing;
  • the right to data portability in some circumstances;
  • the right to object;
  • rights relating to automated decision-making.

For schools, the right of access is especially important because it includes Subject Access Requests.

Data breach reporting

Some personal data breaches must be reported to the Information Commissioner’s Office.

A breach may involve:

  • data sent to the wrong person;
  • lost documents;
  • unauthorised access;
  • cyberattack;
  • accidental deletion;
  • inappropriate disclosure;
  • stolen devices.

Schools should have a clear breach process so staff know what to report and how quickly to escalate.

UK GDPR and education

Schools process personal data for many legitimate reasons, including:

  • teaching and learning;
  • safeguarding;
  • attendance;
  • SEND support;
  • assessment;
  • communication with parents;
  • health and welfare;
  • HR and payroll;
  • governance;
  • statutory returns.

The challenge is not to avoid using personal data. The challenge is to use it responsibly and keep evidence of decisions.

Practical steps for schools

Schools should:

  • maintain clear privacy notices;
  • keep a Record of Processing Activities;
  • review suppliers and processors;
  • complete DPIA screening where needed;
  • train staff;
  • manage SARs and FOIs properly;
  • record and respond to breaches;
  • review retention;
  • maintain policies;
  • keep evidence of decisions.

Does UK GDPR affect data security?

Yes. Data security is a core part of UK GDPR.

Schools should take appropriate measures to protect personal data, including:

  • access controls;
  • strong passwords and MFA;
  • role-based permissions;
  • secure sharing;
  • encryption where appropriate;
  • staff training;
  • supplier checks;
  • incident response;
  • secure disposal.

How Tru Data Protection helps

Tru Data Protection helps schools and MATs turn UK GDPR into practical governance, not abstract theory.

That includes support with:

  • policies and privacy notices;
  • SARs, FOIs and breaches;
  • ROPA and DPIAs;
  • supplier review;
  • staff guidance;
  • governance reporting.

Conclusion

UK GDPR is not just a legal framework. It is a practical standard for treating personal data responsibly.

For schools and MATs, good data protection supports trust, safeguarding, transparency and accountability.

The aim is not paperwork for its own sake. The aim is to make sure personal data is used fairly, securely and only where appropriate.

Get started

Ready to get started?

See pricing, or get in touch for a quick conversation and a clear plan.

See pricing →Get in touch →
Tru Data Protection

Hosted in the UK (AWS London)

ISO 9001/27001-aligned (certification planned)

Products

  • DPO Service
  • Portal
  • Evidence Processing
  • Redaction
  • Policy Packs & Exports

Company

  • About
  • Founder
  • Contact
  • Pricing
  • Tru-Digital Services

Support

  • Guidance
  • Blog

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms and Conditions
  • Data Processing Agreement
© 2026 Tru Data Protection is a trading name of Tru-Digital Services Limited, company number 16210598. ICO registration: ZB887707.