Alternative provision settings hold some of the most sensitive personal data that exists in the education sector. Safeguarding histories, mental health information, EHCP details, family circumstances and behaviour records sit alongside the more routine data every school holds. Getting data protection right is not simply a compliance exercise; it is central to the trust that pupils, families and partner agencies place in a setting.
This guide sets out the practical data protection requirements that apply to AP settings under the UK GDPR and the Data Protection Act 2018, and what good practice looks like in a sector where information sharing across agencies is the norm rather than the exception.
The Legal Basis for Processing Pupil Data
Schools and AP settings process personal data under a number of legal bases, most commonly the performance of a public task or, for independent providers, legitimate interests and contractual necessity. Special category data, which includes health information, safeguarding concerns and information about ethnic origin or religious belief, requires an additional condition to be met, most often that processing is necessary for reasons of substantial public interest connected to safeguarding.
In practice, this means AP settings do not usually need to seek explicit parental consent to hold and share safeguarding-related information, provided the processing is necessary and proportionate. However, settings should be able to explain clearly, if asked, exactly which legal basis applies to which category of data they hold, and this should be documented rather than assumed.
Information Sharing With Other Agencies
AP settings routinely share information with social care, health services, youth offending teams, virtual school heads and the commissioning school or local authority. This is both expected and, in many cases, a safeguarding duty. The government's information sharing guidance is explicit that fear of breaching data protection law should never be a barrier to sharing information where a child's welfare is at risk.
That said, routine sharing of data for non-safeguarding purposes, such as attendance summaries sent to a commissioner, should be governed by a clear agreement setting out what is shared, how often, and by what secure method. Ad hoc sharing by email, without a record of what was sent and why, creates risk and makes it difficult to demonstrate accountability if a data subject later asks what has been shared about them.
Data Minimisation in Practice
One of the core principles of data protection law is that organisations should collect and retain only the data they genuinely need. In AP, where thorough record-keeping is essential for safeguarding, this can feel like it pulls in the opposite direction to good practice. The two are not actually in tension. Data minimisation is about avoiding the collection of irrelevant information and setting sensible retention periods, not about recording less than is needed for safeguarding purposes.
A useful discipline is to review, on a regular basis, whether historic records are still being retained for a clear reason. Safeguarding records typically need to be retained for a defined period after a pupil leaves, in line with your setting's retention schedule, but records with no ongoing safeguarding relevance can usually be archived or deleted once that period has passed.
Access Controls and the Principle of Need to Know
Not every member of staff needs access to every pupil record. Role-based access control, where a keyworker sees the pupils they work with, the designated safeguarding lead sees the full safeguarding picture, and administrative staff see only what their role requires, is both a data protection best practice and a practical safeguard against accidental disclosure.
This is significantly easier to implement and audit in a digital case management system than on paper. A paper file left on a desk or a spreadsheet shared too widely by email are among the most common causes of data breaches reported by schools to the Information Commissioner's Office. Systems with genuine role-based permissions, where access is logged and can be reviewed, reduce this risk substantially.
Subject Access Requests
Parents, carers and pupils themselves, depending on age and understanding, have the right to request access to the personal data a setting holds about them. AP settings must respond within one month, which can be extended by a further two months for complex requests, and this needs to be handled carefully given how sensitive AP records often are.
Requests involving safeguarding information sometimes require redaction, for example to protect information provided by a third party or to withhold information that would seriously harm the physical or mental health of the pupil or another individual. Getting this right requires clear internal guidance and, ideally, access to legal advice for complex or contested requests. Settings that hold records in a single, searchable digital system are able to respond to subject access requests far more efficiently than those relying on physical files scattered across multiple locations.
Data Breaches: What to Do
Under the UK GDPR, a personal data breach that is likely to result in a risk to individuals' rights and freedoms must be reported to the Information Commissioner's Office within 72 hours of the setting becoming aware of it. Given the sensitivity of AP records, the threshold for a reportable risk is often met even by breaches that would be relatively minor in other contexts, such as a safeguarding record being sent to the wrong recipient.
Having a clear, rehearsed breach response process, including who needs to be informed internally and how quickly, makes a genuine difference to how well a setting manages an incident when one occurs. Most breaches in the education sector are the result of human error rather than malicious activity, and the settings that respond best are those with a clear, well-understood process rather than those improvising under pressure.
Building Data Protection Into Everyday Practice
The strongest data protection practice does not come from an annual policy review. It comes from systems and habits that make the right thing to do the easiest thing to do: role-based access by default, a single system of record rather than data scattered across email and spreadsheets, retention periods that are actually enforced, and staff who understand why these safeguards matter, not just that they exist.
For more on how digital systems support safe, auditable record-keeping in AP, see our guide to moving safeguarding from paper to digital and the overview of safeguarding case management in MosaicEd.