Skip to main content

Trust, security and data protection

Clear answers before a school has to ask.

This centre brings procurement and data-protection information together. Published answers describe the current public offer; deployment-specific details are confirmed with each school.

Verified and published

Start with the answers already available

A procurement-ready conversation

Four areas every school should test with any supplier

These are not badges or blanket promises. They are the exact subjects that should appear in a school’s supplier review, DPIA and contract discussions.

01

Data protection

  • Controller and processor responsibilities
  • Documented data flows and lawful instructions
  • DPIA support and information for school review
  • Sub-processors and processing locations
02

Security and access

  • Authentication and account controls
  • Role-appropriate access
  • Encryption in transit and at rest
  • Audit history and privileged access
03

Resilience and lifecycle

  • Backups and recovery
  • Retention and secure deletion
  • Incident response and notification
  • Service continuity
04

Portability and inclusion

  • Data and media export
  • Contract exit and deletion
  • Accessibility evaluation
  • Implementation and support responsibilities

Deployment-specific answers are confirmed against the relevant configuration, agreement and implementation scope rather than relying on blanket assurances.

Bring your school’s checklist

We can walk through the public answers and the details that depend on deployment with school leaders, data-protection leads and IT colleagues.

Tell us about your school

Start a conversation

Share a little about your school and what you’d like to talk about, and we’ll get back to you.

We use these details only to respond. Please do not include pupil names, health information or other sensitive personal data. Read our privacy notice.