Teachers and schools primarily focus on learning, which means data protection – in all forms, whether it is how and where pupil records are held through to data being stored on devices and apps – often gets overlooked. Mat Pullen, Director for Education at Jamf, discusses the misconceptions, challenges and cultural shifts needed to bring compliance and classroom learning back into sync.

Digital tools have come to increasingly dominate the classroom, but one crucial lesson is often missing from the lesson plan – data protection.
Behind every device, app and online platform sits a wealth of pupil information that must be safeguarded almost as carefully as the students themselves. Getting it wrong can result in a serious infringement of privacy or lead to a compliance nightmare that takes digital tools off the table.
Yet too often, data protection is treated as an IT afterthought rather than a foundation for safe, effective learning.
Why is data protection important? How does poor practice undermine teaching and learning?
Student safeguarding is a serious priority for all educators, but the digital side is often overlooked.
Educators themselves are more focused on their lesson plans and often lack the training and experience to really get to grips with issues like data protection. As a result, there is a common assumption that device security is purely an IT issue and not something education staff need to concern themselves with.
Tight budgets and limited resources also mean IT personnel are more likely to prioritise keeping devices and systems online, rather than fine-grained strategies like device management.
However, it absolutely needs to be on everyone’s radar, as data protection issues can quickly bring education to a grinding halt.
I’ve seen this many times, both in my education career and now working to support schools. In one example that always comes to mind, a school had a large number of iPads, enough for a one-to-one provision. Naturally, they featured heavily in lesson plans.
However, one day it became apparent that the devices were too old to receive the latest software and security updates, which also meant they could no longer meet data protection compliance demands. Overnight, teachers lost access to the tools they’d built their lessons around, and they had a tough time going from a one-to-one provision to one-to-many with little notice.
Data management is another area that can cause serious issues. If pupil information isn’t handled safely or devices aren’t properly secured, it can quickly escalate into a major safeguarding incident as well as leading to more regulatory problems.
What about privately owned devices used in the education setting? Where does responsibility fall?
Many educators are adopting an approach where privately owned devices can be used as part of lesson plans. We’re seeing a lot of this because it’s potentially a great way to get more devices into the classroom without inflating the budget.
On paper, the parent owns the device, but during the school day, it’s being used in a managed, shared environment. That’s where things get complicated and can start causing problems if not tightly managed.
Children could be downloading apps or accessing content that isn’t appropriate or safe for school. On the flip side, educators should not be able to access the private elements of the device during school hours either.
I advocate a parent-funded, school-managed model to handle this. In this set-up, the school can manage the device securely while it’s being used for learning, ensuring compliance and classroom safety. Then, once the school day ends, control can switch back to the parent.
It’s about finding the right balance between privacy, safety and practicality. With clear communication and the right tools, schools can protect pupils and data without overstepping into family territory.
Let’s talk regulations. The GDPR has been in place for years – why are schools still struggling with it?
You’d think that after eight years, GDPR would be second nature to everyone in education – certainly, we all heard enough about it when it first launched.
But it’s still a common area of confusion. The biggest misunderstanding is that using a ‘GDPR-compliant’ app or tool somehow makes the whole school compliant. It doesn’t. Compliance isn’t something you can buy – it’s a set of behaviours and processes that need to be embedded across the school.
One thing in common is that most schools don’t have someone dedicated to data protection. In smaller schools, IT is likely to be outsourced to a provider that specialises in managing administrative systems and ensuring smooth operations.
There’s also a tendency to oversimplify. People will often focus on top-level messaging that they absorbed when the regulation first came in, like the idea of two separate pieces of data together being personally identifiable information (PII). But then in practice, it gets applied the wrong way, either creating unnecessary restrictions or leaving them exposed to risk.
Solving this requires putting the time and resources into building a culture where everyone understands their role in protecting information, rather than having a tick-box data handling course every year or two.
How can schools start to build a sustainable, long-term digital strategy?
One of the biggest barriers in education is that technology, compliance and teaching are often treated as completely separate things. IT focuses on devices, compliance teams look at regulations and teachers just want lessons to run smoothly. But in reality, all three should be working towards the same goal – creating a safe, effective learning environment.
Thinking long-term is really important here. Too often, devices are bought to meet an immediate classroom need, without considering how they’ll be managed or refreshed in a few years’ time. I’ve seen many cases like the iPad example I mentioned, where schools have invested heavily in equipment only to realise it’s become unusable a few years later. It’s a big waste of budget, and potentially a huge disruption to teaching too.
I suggest aiming to create a five-year technology plan that factors in maintenance, replacement and security. This plan also needs to factor in staff training to ensure personnel can follow best practice and regular audits to check everything is on track.
Finally, it shouldn’t have to sit with IT alone – budgets for literacy, inclusion and wellbeing can all contribute because technology supports every aspect of learning. When schools break down those silos and share responsibility, they get far better value from their investment, and far more confidence in their digital future.


