To handle data properly, and to encourage staff to think about it differently, we first need to understand what data actually representsHere, Shane Williams presents a simple way to do this through a relatable analogy 

Imagine walking into a school carrying a brand-new smartphone worth around £1,500. Inside that phone is your entire life: messages, emails, banking apps, photos, home security access and personal accounts. The value of that phone is not just the purchase price – it is everything it contains. To you, it is invaluable. 

Now apply that same thinking to a child attending school. When a child joins a school, they are effectively handing over an “imaginary phone” filled with their personal data. This includes their educational records, safeguarding information, medical details, behavioural notes, family circumstances and much more. Schools are entrusted with this data in order to fulfil their duties under the Education Act – to educate, support and safeguard the child. 

 

The Imaginary Phone 

In doing so, schools take on a significant responsibility. That “imaginary phone” must be protected with the same level of care and attention as a valuable physical device. Parents and pupils expect this. They trust that their personal information will be handled safely, securely and only used for appropriate purposes. 

Data protection legislation reinforces this responsibility. It is compensation-based, meaning that if data is lost, mishandled, or disclosed incorrectly, there can be significant financial consequences. The cost of a data breach can far exceed the value of any physical item – often running into thousands of pounds per individual. In this sense, the data held by a school is one of its most valuable and high-risk assets. 

 

Would You Leave It Unattended? 

Consider how we would treat a physical phone left in our care. We would not leave it unattended on a desk in an empty room. We would not leave it visible in a car. We certainly would not hand it to a stranger without verifying who they are and why they need access. Yet, in some cases, schools may unintentionally treat data with less caution than they would a physical object of far lower value. 

Take, for example, a teacher’s personal diary. At first glance, it may seem like an inexpensive notebook. However, if that diary contains notes about 30 pupils – their behaviour, progress, or personal circumstances – it is no longer just a diary. It effectively contains 30 “imaginary phones” worth of sensitive information. Losing that single item could expose the school to significant financial penalties, reputational damage and a breakdown in trust with parents and the wider community. 

This way of thinking also helps when considering how data should be secured. Modern smartphones are protected with passcodes, encryption and biometric security such as facial recognition. This reflects the high risk associated with losing them. Schools should be asking the same question about their data: is it protected to an equivalent standard? Are systems secure? Are staff trained? Are processes robust? 

 

The Importance of Controlling Access 

The analogy also supports a clearer understanding of subject access requests. When a parent or individual makes a request, it can be helpful to view this as the “owner” of the phone asking to see what is on it. This helps remove any emotional response and reinforces that the data belongs to the individual, not the organisation. 

Equally, it highlights the importance of controlling access. If someone unknown walked into the office and asked to look through a staff member’s phone, the answer would be an immediate refusal without proper authority and verification. The same principle must apply to data. Schools should not allow access to pupil information simply because a request comes from a large or authoritative organisation. The identity, purpose, and legal basis for access must always be clear and justified. 

Ultimately, managing data protection is about protecting children. The information held by schools is deeply personal and, if misused, can cause real harm. By thinking of data as something valuable, personal and entrusted – like a mobile phone containing someone’s entire life – staff can better understand the importance of handling it with care. 

No one should access data without a clear reason, and it is the school’s duty to ensure that every child’s “imaginary phone” remains safe at all times.

 

Evolution and Effectiveness

Leave a Reply

Similar Posts

Ofsted Inspection Toolkit Updates: What You Need to Know

OFSTED, Inspection, Inspection Framework, Compliance From September 2026 onwards, updated inspection toolkits...
Finding New Employees. Big Hands with Magnifying Glass Recruiting People. vector

NEWS: DfE Expands Daily Attendance Data Collection

NEWS: DfE Expands Daily Attendance Data Collection As reported by the Department...
Mobile security, data protection concept. Hand holding smartphone, shield lock icon.

NEWS: Trusts Face New Rules on Agency Supply Staff

NEWS: Trusts Face New Rules on Agency Supply Staff As reported by...

Rethinking What “High Risk” Means in School Buildings

Rethinking What “High Risk” Means in School Buildings When we think about...
Digital map showing a highlighted location pin