Effective Date: 01.09.2025
Updated: July 2026 (WTSC 2026 & KCSIE 2026 aligned)
Next Review: July 2027
Version: 2.0
1. Purpose & Scope
This Protocol sets out how LPI Education Ltd handles, stores, shares and disposes of personal data when providing consultancy, school improvement, safeguarding supervision, leadership supervision or audits to schools and multi‑academy trusts.
It aligns with:
UK GDPR and the Data Protection Act 2018
Working Together to Safeguard Children (WTSC) 2026
Keeping Children Safe in Education (KCSIE) 2026
ICO guidance and accountability expectations
DfE record‑keeping and retention requirements
Local multi‑agency safeguarding arrangements (MASA)
This Protocol should be read alongside LPI Education Ltd.’s Privacy Policy.
2. Legal & Statutory Framework
Under UK GDPR, organisations must ensure personal data is:
used fairly, lawfully and transparently
used for specified, explicit purposes
adequate, relevant and limited
accurate and up to date
kept no longer than necessary
handled securely
WTSC 2026 and KCSIE 2026 require:
timely, accurate safeguarding record‑keeping
secure storage and transfer of child protection files
DSL oversight of all safeguarding information
lawful, necessary and proportionate information sharing
clear audit trails for decisions and transfers
We do not use automated decision‑making or profiling.
Individuals have rights to access, correct, erase, restrict, object and request portability of their data.
3. Roles & Responsibilities
LPI Education Ltd
Acts as:
Controller for supervision, training and consultancy notes
Processor or Joint Controller for school improvement and audit work (defined in contract)
Responsibilities:
Secure processing
Encrypted storage
DPIAs where required
Breach notification within 24 hours
Support ICO reporting within 72 hours
Maintain audit trails for safeguarding‑related decisions and transfers
Comply with WTSC 2026 expectations for professional supervision
Designated Safeguarding Lead (DSL)
Provides lawful basis for safeguarding data
Ensures Annex C compliance
Oversees secure storage and transfer of child protection files
Confirms receipt of transferred files
Maintains safeguarding audit trails
Leads multi‑agency information sharing under WTSC 2026
School/Trust Senior Team / DPO
Oversees compliance
Approves retention schedules
Reviews incident logs
Ensures secure disposal
Oversees cyber‑security and digital resilience
4. Categories of Data
Standard pupil/staff data
Names, dates of birth, contact details, attendance, SEND, medical information.
Child protection / safeguarding records
Referrals, concerns, DSL notes, outcomes, agency involvement, multi‑agency communications.
Consultancy and supervision records
Session notes, action plans, anonymised themes, supervision agreements, attendance records.
Data NOT collected by LPI Education Ltd
We do not collect:
identifiable pupil information
identifiable staff information
case details or chronologies
safeguarding records
operational case management information
children’s personal data
This reflects WTSC 2026 expectations for safe supervision boundaries.
5. Collection & Lawful Processing
We collect only the minimum necessary data.
Lawful bases include:
Public task (safeguarding)
Contractual necessity (consultancy, supervision)
Legitimate interests (quality assurance)
Legal obligation (HMRC, safeguarding duties)
Individuals are informed via the school’s Privacy Notice or our own Privacy Policy.
WTSC 2026 requires:
clear documentation of decisions to share safeguarding information
proportionality assessments
multi‑agency liaison where appropriate
6. Secure Storage & Access Controls
Digital Records
Encrypted drives or secure UK‑based or adequacy‑compliant cloud systems
Multi‑factor authentication
Access restricted to named individuals
Access logs maintained where feasible
No use of personal devices
Cyber‑security measures in line with KCSIE 2026
Physical Records
Locked cabinets
Restricted access
Archived securely
Safeguarding Records
Stored separately from pupil files
Access limited to DSL/deputy
Transferred securely to next school
Receipt confirmed and logged
Full audit trail maintained
7. Secure Sharing & Transfer of Data
Encrypted email or password‑protected documents
ICO’s 10‑Step Guide used to assess necessity and proportionality
WTSC 2026 multi‑agency information‑sharing principles applied
Child protection files transferred within 5 working days
Transfer documented and receipt confirmed
Transfer logged in safeguarding audit trail
8. Retention & Secure Disposal
Secure Data Handling Protocol
Secure disposal includes:
Digital deletion
Shredding of physical documents
Removal from backups where feasible
9. Personal Data Breach Response
Notify school/trust within 24 hours
ICO notified within 72 hours where required
High‑risk breaches communicated to individuals
Incident logs maintained with cause, mitigation and learning
Cyber incident response aligned with KCSIE 2026
10. Accountability & Audit
Article 30 Record of Processing Activities maintained
DPIAs completed for high‑risk processing
Schools/trusts may audit shared data annually
Version control and change logs maintained
Safeguarding audit trails maintained in line with WTSC 2026
11. Training & Awareness
Annual data protection and safeguarding training
Training includes WTSC 2026 and KCSIE 2026 updates
Training evidence retained for 3 years
12. Review & Updates
Reviewed annually or sooner if legislation or DfE/ICO guidance changes.
Updates communicated to partner schools and trusts.

