UK GDPR made clear, consistent, and practical for everyday operations.
Featured Products
Everything in Core,plus operational procedures and evidence tools to embed compliance in day-to-day practice.
What’s included:
SAR (DSAR) Procedure Pack
Step-by-step internal workflow for subject access requests, with triage guidance, timeframes, and an audit trail approach (so responses are consistent and defensible).Data Breach / Incident Procedure Pack
A practical response process from containment to assessment, ICO decision-making and recording, plus internal reporting structure.DPIA Checklist + “When to DPIA” Triggers
A simple checklist and trigger list to help staff identify when a DPIA is needed (new systems, apps, CCTV changes, biometrics, monitoring tools, etc.).Lawful Basis Matrix (Schools)
A ready-to-use matrix mapping common school processing activities to the most relevant lawful bases (and special category/child data considerations where needed).KCSIE Mapping (Data Protection Interface)
A clear mapping document showing how data protection controls support safeguarding duties under KCSIE, including information sharing and record-keeping touchpoints.
Best for: Schools that need more than “documents on a shelf”, particularly where there is safeguarding complexity, higher-risk processing, recent incidents, or a need to demonstrate stronger governance and evidence.
Get compliant documentation in place quickly with a clear, inspection-ready baseline for your school. The Core Pack provides a fully indexed Data Protection Policy plus essential companion documents to support day-to-day handling, pupil transparency, and governance sign-off.
What’s Included:
Master indexed Data Protection Policy (Schools, 2026)
Full policy with contents/index, roles and responsibilities, lawful bases, security, retention, rights handling, breaches, governance, and school-specific operational guidance.Staff quick-reference sheet (1 page)
“What to do” guidance for day-to-day handling (DSARs, breaches, sharing info, do’s and don’ts) – Ofsted-friendly.Pupil privacy notices (templates)
Primary, Secondary, and Special versions, child-friendly and school-usable (covers the typical categories of data held, why it’s used, who it’s shared with, rights, and contacts).Governance approval page
SLT/Governor/Trustee approval and review log page (owner, version control, review date, sign-off).
Licence: Single school use (LA-maintained or academy).
Format: Fully editable Word documents.
Best for: Schools needing compliant documentation quickly and a solid inspection-ready baseline.
Services we offer
Up to 1 hour/month for Q&A, template guidance, and light reviews (email + one short call if needed).
Up to 3 hours/month for supplier reviews, DPIA input, DSAR/breach guidance, and monthly governance check-ins.
Up to 5 hours/month plus a rolling evidence check against your inspection index and priority response windows.
Our ethos
Prime Data Compliance exists to make data protection feel doable. We help schools turn UK GDPR into clear, everyday practice that staff can follow with confidence, without getting in the way of safeguarding. Our approach is practical, calm, and evidence-led: we create compliant documents, simple workflows, and inspection-ready records that protect children, support staff, and stand up to scrutiny.
Contact Us
Interested in working together? Fill out some info and we will be in touch shortly. We can’t wait to hear from you!