Effective Date: 01.09.2025

Updated: July 2026 (WTSC 2026 & KCSIE 2026 aligned)

Next Review: July 2027

Version: 2.0

1. Purpose & Scope

This Protocol sets out how LPI Education Ltd handles, stores, shares and disposes of personal data when providing consultancy, school improvement, safeguarding supervision, leadership supervision or audits to schools and multi‑academy trusts.

It aligns with:

  • UK GDPR and the Data Protection Act 2018

  • Working Together to Safeguard Children (WTSC) 2026

  • Keeping Children Safe in Education (KCSIE) 2026

  • ICO guidance and accountability expectations

  • DfE record‑keeping and retention requirements

  • Local multi‑agency safeguarding arrangements (MASA)

This Protocol should be read alongside LPI Education Ltd.’s Privacy Policy.

2. Legal & Statutory Framework

Under UK GDPR, organisations must ensure personal data is:

  • used fairly, lawfully and transparently

  • used for specified, explicit purposes

  • adequate, relevant and limited

  • accurate and up to date

  • kept no longer than necessary

  • handled securely

WTSC 2026 and KCSIE 2026 require:

  • timely, accurate safeguarding record‑keeping

  • secure storage and transfer of child protection files

  • DSL oversight of all safeguarding information

  • lawful, necessary and proportionate information sharing

  • clear audit trails for decisions and transfers

We do not use automated decision‑making or profiling.

Individuals have rights to access, correct, erase, restrict, object and request portability of their data.

3. Roles & Responsibilities

LPI Education Ltd

Acts as:

  • Controller for supervision, training and consultancy notes

  • Processor or Joint Controller for school improvement and audit work (defined in contract)

Responsibilities:

  • Secure processing

  • Encrypted storage

  • DPIAs where required

  • Breach notification within 24 hours

  • Support ICO reporting within 72 hours

  • Maintain audit trails for safeguarding‑related decisions and transfers

  • Comply with WTSC 2026 expectations for professional supervision

Designated Safeguarding Lead (DSL)

  • Provides lawful basis for safeguarding data

  • Ensures Annex C compliance

  • Oversees secure storage and transfer of child protection files

  • Confirms receipt of transferred files

  • Maintains safeguarding audit trails

  • Leads multi‑agency information sharing under WTSC 2026

School/Trust Senior Team / DPO

  • Oversees compliance

  • Approves retention schedules

  • Reviews incident logs

  • Ensures secure disposal

  • Oversees cyber‑security and digital resilience

4. Categories of Data

Standard pupil/staff data

Names, dates of birth, contact details, attendance, SEND, medical information.

Child protection / safeguarding records

Referrals, concerns, DSL notes, outcomes, agency involvement, multi‑agency communications.

Consultancy and supervision records

Session notes, action plans, anonymised themes, supervision agreements, attendance records.

Data NOT collected by LPI Education Ltd

We do not collect:

  • identifiable pupil information

  • identifiable staff information

  • case details or chronologies

  • safeguarding records

  • operational case management information

  • children’s personal data

This reflects WTSC 2026 expectations for safe supervision boundaries.

5. Collection & Lawful Processing

We collect only the minimum necessary data.

Lawful bases include:

  • Public task (safeguarding)

  • Contractual necessity (consultancy, supervision)

  • Legitimate interests (quality assurance)

  • Legal obligation (HMRC, safeguarding duties)

Individuals are informed via the school’s Privacy Notice or our own Privacy Policy.

WTSC 2026 requires:

  • clear documentation of decisions to share safeguarding information

  • proportionality assessments

  • multi‑agency liaison where appropriate

6. Secure Storage & Access Controls

Digital Records

  • Encrypted drives or secure UK‑based or adequacy‑compliant cloud systems

  • Multi‑factor authentication

  • Access restricted to named individuals

  • Access logs maintained where feasible

  • No use of personal devices

  • Cyber‑security measures in line with KCSIE 2026

Physical Records

  • Locked cabinets

  • Restricted access

  • Archived securely

Safeguarding Records

  • Stored separately from pupil files

  • Access limited to DSL/deputy

  • Transferred securely to next school

  • Receipt confirmed and logged

  • Full audit trail maintained

7. Secure Sharing & Transfer of Data

  • Encrypted email or password‑protected documents

  • ICO’s 10‑Step Guide used to assess necessity and proportionality

  • WTSC 2026 multi‑agency information‑sharing principles applied

  • Child protection files transferred within 5 working days

  • Transfer documented and receipt confirmed

  • Transfer logged in safeguarding audit trail

8. Retention & Secure Disposal

Secure Data Handling Protocol

Secure disposal includes:

  • Digital deletion

  • Shredding of physical documents

  • Removal from backups where feasible

9. Personal Data Breach Response

  • Notify school/trust within 24 hours

  • ICO notified within 72 hours where required

  • High‑risk breaches communicated to individuals

  • Incident logs maintained with cause, mitigation and learning

  • Cyber incident response aligned with KCSIE 2026

10. Accountability & Audit

  • Article 30 Record of Processing Activities maintained

  • DPIAs completed for high‑risk processing

  • Schools/trusts may audit shared data annually

  • Version control and change logs maintained

  • Safeguarding audit trails maintained in line with WTSC 2026

11. Training & Awareness

  • Annual data protection and safeguarding training

  • Training includes WTSC 2026 and KCSIE 2026 updates

  • Training evidence retained for 3 years

12. Review & Updates

Reviewed annually or sooner if legislation or DfE/ICO guidance changes.

Updates communicated to partner schools and trusts.