Staff Personal Device and Private Account Policy
- Version
- v1
- Updated
- 7 October 2026
- Reviewed
- 7 October 2026
1. Scope and applicability
This policy applies where staff may handle school-related personal information through personal devices, private email accounts, home computers or private instant-messaging applications. It applies to information about pupils, parents, contacts or other staff where that information is held for school-related purposes.
The arrangements in this policy are conditional on the circumstances, the security risks associated with using devices or services that the school does not control, and the information within the scope of the request.
2. General policy position
Staff should not normally hold school-related personal information on personal devices or private accounts. This includes private email accounts, smartphones, home computers and private instant-messaging applications.
Staff should use the school’s arrangements for handling school-related personal information rather than retaining that information on personal devices or private accounts.
3. Permitted use
The school may permit staff to hold school-related personal information on their own devices or private services only where the circumstances justify that arrangement. Any permitted use must take account of the security risks of holding information on devices or services that the school does not control.
Where permitted use applies, staff should understand that information held on their own devices or private services may be held on the school’s behalf and may be within scope if the school receives a subject access request.
4. Requests to search private services
Where the school has good reason to believe that a staff member holds personal information about the requester on a personal device or private service, the school should ask the relevant staff member to search the private emails, devices or instant-messaging applications as appropriate.
A search request should be limited to the personal information about the requester that is within scope of the request and should reflect the circumstances and relevant security risks.
The relevant staff member should cooperate with an appropriate request to search the private emails, devices or instant-messaging applications identified by the school.
5. Proportionate arrangements
Any decision to permit staff to hold school-related personal information on personal devices or private accounts, and any request to search those devices or services, should be appropriate to the circumstances and the information sought.
The school should avoid treating every personal device or private account as relevant where there is no good reason to believe that personal information about the requester is held there.
6. Staff responsibilities
Staff should not normally retain school-related personal information on personal devices or private accounts. Where the school has permitted such use, staff should search the relevant private emails, devices or instant-messaging applications when the school has good reason to believe that personal information about a requester is held there and asks them to do so as appropriate.
7. Review of this policy
This policy should be reviewed when the school’s arrangements for staff use of personal devices or private accounts change, or when the circumstances of a request require the policy to be reconsidered.
Sources
- How do we find and retrieve the relevant information? | ICOInformation Commissioner's Office (ICO)
