GDPR

Back

The General Data Protection Regulation (GDPR), in force since 25 May 2018, continues to apply to all organisations - including schools - that process personal data or special category (formerly “sensitive”) personal data.  NEST Schools handle significant amounts of personal information and remain committed to full compliance with the GDPR, the Data Protection Act 2018, and other relevant UK data protection legislation.

The Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025, further amends but does not replace the UK GDPR or the Data Protection Act 2018. Its purpose is to modernise the UK's data governance framework while supporting innovation and improving public services. For schools, this Act introduces changes such as clarified requirements around Subject Access Requests, updated rules on data access and sharing, strengthened privacy governance, and updates to complaint handling and oversight mechanisms. 

NEST Schools continue to review and update their data protection policies and procedures to align with these requirements and ensure robust, transparent, and compliant handling of personal data.

GDPR Contacts