Skip to the main content.

4 min read

Why school privacy programmes stall after the paperwork is done

Why school privacy programmes stall after the paperwork is done
Why school privacy programmes stall after the paperwork is done
7:41

Most schools have the core documents of a privacy programme somewhere: a Records of Processing Activities (RoPA), a retention schedule, a breach procedure and a privacy notice. The harder part is keeping them working. Data protection touches almost every part of school life, from pupil and staff records to safeguarding information, third-party apps and school communications, and the work of applying it never really stops.

For those leading privacy in schools, the challenge is rarely understanding the principles of the data privacy and protection regulations, It is applying them consistently, across a busy organisation, while technology and school practice keep changing. Here is where privacy programmes most often stall, and what helps them keep moving.

Privacy often sits on top of someone's day job

In many schools, privacy is not led by a dedicated privacy professional. It forms part of a wider role in IT, operations, governance or compliance. The person responsible may be highly capable, but they are working on privacy in the time left over from everything else.

That makes prioritisation the real challenge. With records, retention, requests, incidents, vendors and impact assessments all competing for attention, it is easy to spread effort thinly across everything, or to keep returning to whichever issue is most urgent this week.

Records of Processing go out of date as soon as they are finished

A Records of Processing Activities should give a meaningful picture of how personal data is used across the school. In practice, many are completed once from a template and then left alone.

An effective RoPA depends on the people who actually use the data: the data owners in admissions, HR, finance, safeguarding, the curriculum and beyond. If they are not engaged, or are not asked the right questions, the record quickly drifts away from reality. And because so much other privacy work relies on it, an inaccurate RoPA weakens everything built on top.

Retention schedules rarely reach the systems that hold the data

Having a retention schedule is only one part of records retention. The schedule may say a category of information should be kept for a set period, but that means little if the system holding it cannot delete it, nobody owns the deletion, or the information is scattered across email, shared drives and the management information system (MIS).

This is one of the most common gaps between documented policy and day-to-day practice. Closing it means understanding where information lives, what each system can actually do, and who is responsible for acting.

Requests and incidents never arrive neatly

Information rights requests can become complex very quickly. A subject access request (SAR) normally needs a response within one calendar month, and may involve searches across email, safeguarding records and multiple systems, followed by careful decisions about redaction and third-party information. Requests connected to a parental dispute or a staff grievance raise the stakes further.

Privacy incidents are similar. They rarely arrive with all the facts. A school may need to decide, within 72 hours of becoming aware, whether a personal data breach must be reported to their supervisory authority, often while the picture is still changing. Decisions made early may need revisiting as new information emerges, and every one of them needs a clear record.

Both are hard to handle well for the first time under pressure. Confidence comes from having worked through them before.

Every new app is a new vendor relationship

Schools rely on a growing range of technology providers, and each one that processes personal data is a relationship that needs managing. That means understanding how the provider handles data, identifying material risks, checking contracts and supporting documentation, and reviewing the relationship over time rather than only at the point of sign-up.

Data Protection Impact Assessments (DPIAs) face a similar problem. Done well, they help a school identify and reduce risk before a new system or activity goes live. Done hurriedly, or skipped altogether, they become a box-ticking exercise that offers little protection.

Photos and video raise more than consent questions

Schools create and share a large volume of visual information through photography, video, CCTV, events, websites and social media. Managing it well involves more than obtaining consent. Privacy needs to be weighed alongside safeguarding, dignity, context and the expectations of pupils, families and staff, and new technologies for creating and manipulating images are adding fresh considerations.

What schools should be doing now

No school can tackle every area of privacy at once, and nor should it try. These steps help create momentum:

  • Clarify accountability. Confirm who leads on privacy, who the data owners are, how responsibilities are shared across functions, and how issues are escalated.
  • Prioritise deliberately. Map what is already in place, identify the most significant risks, and recognise dependencies. An accurate RoPA, for example, makes retention and DPIA work far easier.
  • Treat the RoPA as a process, not a document. Build regular conversations with data owners into the year so the record stays current.
  • Test retention against your systems. Pick one or two key systems and check whether the schedule is actually being applied.
  • Rehearse before it is real. Walk through a sample information rights request and a sample incident so the process is familiar before it is needed.
  • Make vendor and DPIA decisions proportionate and documented. Focus effort where risk is highest, and record the reasoning behind decisions.
  • Review how images are used. Check practice against your policy, considering purpose, audience and safeguarding as well as consent.

How the Privacy Academy helps

We created the 9ine Privacy Academy for those responsible for privacy and data protection in schools, including those for whom privacy is one part of a wider role.

The Academy combines expert-led professional development with practical application. It begins with an induction on privacy governance, accountability and planning, after which each school works with a named 9ine Data Privacy & AI Consultant to build a personalised Privacy Roadmap. That roadmap sets out what to prioritise next and the most logical order in which to tackle it, so effort goes where it will have most impact.

Across the year, Foundation sessions and practical Implementation Workshops cover the areas where schools most often stall: Records of Processing, records retention, information rights, incident and breach management, vendor management, DPIAs and visual data ethics. Foundation sessions build or refresh knowledge, while the workshops use realistic school scenarios so participants practise the approach and leave with outputs they can develop further, such as a prioritised retention action plan or an incident decision record.

Participants are supported throughout by the 9ine Platform's Privacy and Governance areas, completed vendor assessments from the 9ine Vendor Library, practical templates and guidance, session recordings and focused consultancy time.

Find out more about the 9ine Privacy Academy.

For further guides, templates and insights, explore our resources library. If you would like to discuss your school's approach with our team, book a meeting.

AI and children’s rights: Why schools need governance, not just guidance

AI and children’s rights: Why schools need governance, not just guidance

AI is already shaping students' lives. Learn why schools must move beyond basic guidance and implement practical AI governance for safeguarding and...

Read More
Microsoft’s AI Safety and Privacy Standard: A New Line in the Sand for AI in Schools

Microsoft’s AI Safety and Privacy Standard: A New Line in the Sand for AI in Schools

Explore Microsoft’s landmark AI safety and privacy agreement with the AFT. Discover what this new contractual standard means for schools and the...

Read More
The coming AI churn in EdTech: Why schools need to look beyond the badge

The coming AI churn in EdTech: Why schools need to look beyond the badge

New vendors are entering the sector with AI-first products. Existing vendors are adding AI features into platforms schools already use. Some are...

Read More