A school discovers that personal data has been accessed without authorization.

It might be a phishing attack that gave an outsider access to staff email, a misconfigured system that exposed pupil records, or a stolen device.

The data breach is serious. But what often causes the most lasting damage is what happens in the hours and days after the discovery – when there is no plan, no process, and no clear ownership of what to do next.

Why So Many Schools Have No Plan in Place

This is more common than it should be, and the reasons are consistent.

IT Support That Focuses Only on Infrastructure

Many schools receive IT support services for schools that cover the technical side of operations but stop short of planning for incidents. Hardware gets maintained. Networks get monitored. But the question of what the school does when something goes wrong is never addressed.

A data breach is not a purely technical event. It requires a coordinated response involving IT, school leadership, data protection officers, and in many cases external reporting. If that coordination has never been planned for, the response will be slow and incomplete.

No Data Protection Officer Involvement in IT Decisions

Schools are required to have a Data Protection Officer. But in many cases, the DPO and the IT provider operate in separate lanes. The DPO handles policies and compliance paperwork. The IT provider handles systems. Nobody sits in the middle asking what happens if those two areas collide in an emergency.

Assumption That It Will Not Happen

Smaller schools in particular often operate on the assumption that they are too small or too low-profile to be targeted. That assumption is wrong. Attackers do not discriminate by institution size. Automated attacks probe for vulnerabilities indiscriminately, and a school with weak security is a target regardless of its profile.

What an Incident Response Plan Should Cover

A proper incident response plan for a school environment addresses the following:

  1. How to identify that a breach has occurred or is suspected.
  2. Who is notified first and in what order – IT provider, headteacher, DPO, governors.
  3. How to contain the incident to prevent further data exposure.
  4. What evidence to preserve for investigation and reporting purposes.
  5. When and how to notify the Information Commissioner’s Office – the legal deadline is 72 hours.
  6. How to communicate with affected parents, students, or staff.
  7. How to review and update systems after the incident to prevent recurrence.

Without a written plan covering each of these areas, the response will be improvised. Improvised responses miss steps, delay notifications, and increase both the regulatory and reputational consequences.

The 72-Hour Reporting Obligation

One of the most commonly missed elements in an unprepared response is the legal requirement to notify the ICO within 72 hours of becoming aware of a personal data breach. This is a requirement under UK GDPR, and failure to comply can result in regulatory action on top of the breach itself.

A school that spends the first 48 hours trying to work out what happened and who to call is unlikely to meet that deadline. A school with a plan will have that notification drafted and submitted while the technical response is still underway.

Business IT support principles apply directly here. Any well-run organisation, school, or business needs a tested incident response plan that defines ownership, timelines, and communication clearly before an incident occurs. The only difference for schools is the presence of pupil data, which adds a safeguarding dimension that makes the stakes higher.

Building the Plan Before It Is Needed

The right time to build an incident response plan is not after a breach. It is during a calm period when there is time to think clearly, involve the right people, and test the plan against realistic scenarios.

That process typically involves the IT provider, school leadership, the DPO, and sometimes an external security consultant. A good IT partner will initiate this conversation rather than waiting to be asked. If yours has not raised it, that is worth addressing directly.

Schools should also consider running a tabletop exercise once the plan is written. This means sitting the relevant staff members down and walking through a simulated breach scenario step by step, without any real systems being affected. It sounds straightforward, but these exercises regularly surface gaps that nobody noticed when the plan was written on paper. A communication chain that looks clear in a document can fall apart quickly when people realise a key contact is unavailable, a login credential is unknown, or a step relies on a system that was never properly set up. Running the scenario before a real incident occurs is the only reliable way to find those gaps and close them.

What to Do When the Plan Has Never Been Tested

Many schools have a data breach policy sitting in a folder somewhere. It was written to satisfy an audit, signed off by the governing body, and filed away. Nobody has looked at it since. That is not an incident response plan. That is a document.

A plan only has value if the people who need to act on it know it exists, know where to find it, and have practised what it asks them to do. In a real incident, staff will not have time to read through a lengthy policy document and work out what applies to them. They need to know their role instinctively because the decisions in the first hour of a breach are the ones that determine how much damage gets done.

Schools that have genuinely tested their plan will have a named person for each critical action, a printed or offline copy accessible if systems go down, and a clear escalation path that does not depend on one individual being available. If the headteacher is unreachable, who makes the call? If the IT provider cannot be reached immediately, what is the first containment step a member of staff can take without technical knowledge? These are the questions a tested plan answers before they become urgent.

FAQ

Q: Is a school legally required to have a data breach incident response plan?

UK GDPR requires organisations to have appropriate technical and organisational measures in place to respond to data breaches. A documented incident response plan is one of the most practical ways to demonstrate compliance with that requirement.

Q: What happens if a school fails to report a data breach to the ICO within 72 hours?

The ICO can take regulatory action, which may include reprimands, enforcement notices, or financial penalties, depending on the severity of the breach and the circumstances of the delayed notification.

Q: How often should a school test its incident response plan?

At a minimum, once per academic year. The test should involve a simulated scenario that exercises the notification process, the communication chain, and the technical containment steps. A plan that has never been tested is unlikely to work smoothly when it is needed.