Home Page

General Data Protection Regulations (GDPR)

As you may already be aware, the 25th May 2018 marks the enforcement of the General Data Protection Regulation (GDPR). The GDPR will replace the Data Protection Act 1998 and is designed to strengthen the safety and security of all data held within an organisation, and make sure processing and storage procedures are consistent. 


First and foremost, it is important that you understand your rights under the GDPR; you have the right to:

  • Be informed about how we use your personal data.
  • Request access to the personal data that the school holds.
  • Request that your personal data is amended if it is inaccurate or incomplete.
  • Request that your personal data is erased where there is no compelling reason for its continued processing.
  • Request that the processing of your data is restricted.
  • Object to your personal data being processed.


The GDPR will result in some significant changes for the school, which I would now like to take a moment to explain. The school will have to prove their compliance with the GDPR, by having effective policies in place. There have also been some changes to the rights that individuals have – such as the right to have your information erased.


Privacy notices must also include new information, such as an individual’s right to complain to the Information Commissioner’s Officer (ICO). The GDPR takes into account the information of children too – parental consent is needed for children up to the age of 13, at which point, the child may be able to consent for themselves.


A data breach notification duty is applied to all schools, and those that are likely to cause damage, e.g. identity theft, have to be reported to the ICO within 72 hours – failure to do so can result in a fine. A data protection impact assessment will be completed, which will likely be carried out when using new technologies and the processing is likely to result in a high risk to the rights and freedoms of individuals.


One of the biggest changes has been in terms of consent; consent must be a ‘positive indication’, which means that it has to be opted into, clear and unambiguous. Any consent given under the Data Protection Act 1998 will be reviewed and reobtained if necessary. This means the school may have to ask for you to consent to things again.


Finally, schools are required to appoint a data protection lead (DPO) – the DPO for North Lakes School is Mr M Soulsby and he can be contacted on or 01768 899876.


The GDPR will require changes to be made to some school policies and procedures. While some policies will need small updates, others will require re-writes. Under the new GDPR we will require all parents and carers to read our new Privacy Notice then resubmit all forms on our Online Parent Portal. The good news is that we will only require  you to do this once during your child’s time at North lakes school unless there are changes to legislation or our policy and practice – we will notify you when it is time to do this. Before you give consent to anything, it is vital that you have read and understood the privacy notice, as the school wants to ensure that you understand what we are doing with your data and that you know we are acting legally. A copy can be downloaded below.


When policies have been checked and ratified, they will be published on this page.  If you have any questions about GDPR, you can contact the ICO on 0303 123 1113 or by using their live chat, or you can visit their Guide to the General Data Protection Regulation webpage. You are also welcome to direct any questions you have to the DPO, Mr Soulsby.

Mrs A Nellis acts as a representative for the school with regard to its data controller responsibilities; they can be contacted on 01768 899876 or


Mr M Soulsby is the data protection lead. Their role is to oversee and monitor the school’s data protection procedures, and to ensure they are compliant with the GDPR. The data protection lead can be contacted on 01768 899876 or