ASCL welcomes the ICO’s ongoing commitment to protecting data and the intent of the corporate strategy. However, turning strategy into implementation needs to be supported by funding, technical support, guidance for school and college settings.
The onus and responsibility primarily should be on edtech providers. If the ICO if is expecting data controllers to be more involved, then the level of resources must be increased. Additionally, many school and colleges have a member of staff undertaking the DPO role therefore, opportunities for upskilling and training for DPOs should be made available.
Schools are often required to make complex technical judgements about whether products meet safeguarding, online safety, privacy and data protection expectations. Indeed, the ICO’s own “Edtech examined” report published on 24 June 2026 detailed findings from a programme of audits carried out during 2024 and 2025 with “28 edtech providers whose products are widely used across primary and secondary schools”. The report states “in total, we made 596 recommendations, and providers accepted almost all of them.” The responsibility should be with the edtech providers to meet standards requirements, not for leaders to interpret whether they do.
Alongside changing technology many members have seen a significant rise in the number and complexity of complaints which include subject access requests and freedom of information requests from parents. They spend a great deal of time and energy dealing with these complaints which increases workloads and distracts from other priorities and do not have the resources to deal with them. We would welcome the ICO using this process to review this specific concern to ensure members of the public do not abuse the rights that are afforded to them in a frivolous, vexatious or disproportionate way.
Full response to consultation