Schools, colleges and academy trusts sit on a great deal of sensitive personal data: pupils, parents, staff, safeguarding records and more. They also field a constant flow of concerns, often emotional and often urgent. From 19 June 2026, a specific slice of those concerns — the ones about how personal data is handled — comes with a legal process you must follow.[2] [6]
The duty applies to organisations of every kind, with no exemption for the education sector.[4]
What the duty means in a school setting
If a parent, pupil or staff member complains that their personal data has been mishandled, you must be able to take that complaint, acknowledge it within 30 days, look into it, and tell them the outcome.[2]
Two features matter especially in education.
First, complaints arrive through many doors: the school office, a teacher, a website form, an email to the head, even a message on a social media page. You have to accept a data protection complaint however it comes in.[4] In a busy school, the risk is that a complaint is dealt with informally and never logged, while the 30-day clock quietly runs.
Second, trusts running several schools need one consistent approach. A parent should meet the same process whichever school in the trust they contact, and the trust should be able to see all of it in one place.
What this means for you
Build a simple, shared route and make sure people know to use it.
Name who owns data protection complaints across the school or trust. Give parents and staff a clear way to raise one, and tell front-office and teaching staff to pass anything that looks like a data complaint to that owner straight away. Log the date each one arrived, because that is when your 30 days start.
The aim is not bureaucracy. It is making sure a genuine concern from a parent never falls between people, and that you can show you handled it properly if you are ever asked.