Skip to main content
Share via Share via Share via Copy link

The ICO sets its plans for next two years: Education sector guide

10 August 2026
Claire Archibald

The Information Commissioner’s Office (ICO) has published its draft corporate strategy for 2026 to 2028, and it is open for public consultation until 23 August 2026.

Any organisation, individual, or sector body can respond. The strategy has implications for schools, multi-academy trusts, and universities, with a clear view of where the regulator's attention will be focused over the next two years, and the education sector will be a central part of that. 

What the strategy says

The ICO has identified four regulatory priorities for 2026 to 2028:

  1. Personal data use that helps, not harms, children.
  2. Promoting trust and transparency in AI.
  3. Public services that use people's data responsibly.
  4. Building cyber resilience to keep people's data safe.

The strategy places children's data at the very top of the ICO's agenda, including naming education technology services explicitly. Following its ‘Edtech examined’ report, the ICO notes that children's use of EdTech continues to grow and that it places children at greater risk of profiling, targeted advertising, and exposure to harmful content. 

Going forward, the ICO intends to work with EdTech providers and with those in the education sector to embed privacy by design. That is not just a message for the tech companies – it is a message for every school and trust procuring and deploying those tools.

On artificial intelligence, the ICO's concern is that the pace of adoption is outrunning organisations' ability to deploy AI safely. In education, this means the pressure is on to ensure that AI tools being used for marking, adaptive learning, behaviour monitoring, or any other purpose are properly assessed. In our spring 2025 School Leaders Survey, three-quarters of respondents felt there was insufficient AI expertise in their organisation. 

Data protection impact assessments, documented lawful bases, and clear accountability will be central to what the ICO will be looking for.

On cyber resilience, the picture is increasingly alarming. The UK is the most targeted country in Europe, with national economic losses from data breaches exceeding £14.7bn per year. The education sector is a known target. If your cyber incident response plan has not been reviewed recently, now would be a good time.

Why this is an opportunity, not just a warning

It would be easy to read a draft regulatory strategy and file it under 'things to worry about later'. But that would be to miss something important.

Knowing where a regulator is going to focus gives your educational organisation an opportunity to get ahead. If the ICO is going to scrutinise EdTech procurement, and you have already audited your supplier agreements, reviewed your data processing contracts, and documented your decision-making, you are in a very different position to an institution that has not.

If the ICO is going to look carefully at AI, and you have already built an AI governance framework, you are demonstrating exactly the kind of accountable, proactive approach the ICO wants to see.

This is not about fear of the regulator. It is about recognising that the ICO's strategic priorities are, in this instance, well aligned with what good data protection practice in education looks like anyway. The strategy is an invitation to reflect on your own organisation's strategic direction and to ask whether your data protection and AI governance function has the visibility, resource, and leadership support it needs to meet what is coming.

Why your response to the consultation matters

The education sector processes some of the most sensitive data of any public sector context. It looks after children's safeguarding records, SEND information, mental health data, and family circumstances, often with limited dedicated data protection resource and under significant financial pressure. The ICO's strategy, as currently drafted, focuses heavily on what EdTech providers must do. It says less about the practical reality facing the DPO in a primary school who is also the school business manager, or the trust data protection lead covering dozens of sites.

If you think the strategy should say more about the reality of proportionate regulatory expectations, accessible guidance, or the specific vulnerabilities of children's data in educational settings, then this consultation is your chance to say so. 

What to do now

  • Read the draft strategy. It is available on the ICO's website and is shorter than you might expect.
  • Respond to the consultation before 23 August 2026.
  • Use the strategy as a prompt to review your own data protection priorities for the coming year, particularly around EdTech procurement, AI governance, and cyber incident response.

The ICO has laid out its stall. The education sector now has a brief window to respond, to shape it, and to use it. Both would be time well spent. If you would like support reviewing your EdTech procurement processes, AI governance arrangements, or data protection strategy in light of the ICO's priorities, please get in touch.

You may be interested in...