Filtering and monitoring changes in schools

FILTERING & MONITORING IN SCHOOLS

Why Safeguarding, Data Protection and Governance now have to work together

THE 2026 POSITION
Filtering and monitoring can no longer be treated as an IT-only function. The Department for Education now explicitly connects filtering and monitoring with the processing of personal data, while Keeping Children Safe in Education 2026 reinforces expectations around leadership, safeguarding and governance.

 

For many years, filtering and monitoring in schools has largely been seen as a technical matter. Does the web filter block inappropriate websites? Is monitoring software installed? Do alerts reach somebody when something concerning happens?

In 2026, that approach is no longer enough.

Changes to Department for Education guidance on Data Protection in Schools, together with Keeping Children Safe in Education (KCSIE) 2026, make it increasingly clear that filtering and monitoring needs to be managed as a combined safeguarding, data protection and governance responsibility.

This is significant. Filtering and monitoring systems can collect potentially sensitive information about pupils and staff, including browsing activity, searches, images, conversations and activity taking place on devices. The DfE recognises that monitoring reports may contain information such as images shared, chat conversations and search prompts.

Schools and Multi-Academy Trusts therefore need to consider not simply whether their technology works, but whether the entire process around that technology is appropriate, proportionate, lawful, understood, documented and governed.

What has changed?

In June 2026, the Department for Education updated its Data Protection in Schools guidance by adding filtering and monitoring directly into its section covering cyber security and safeguarding.

The guidance now explicitly states that where filtering and monitoring systems are used, schools should restrict access to monitoring data to authorised staff, ensure those staff receive appropriate training, and establish clear retention and safeguarding procedures. Where device monitoring is managed by an internal or external IT provider, those involved should also receive safeguarding training, including online safety.

Importantly, the guidance also says schools should undertake a Data Protection Impact Assessment (DPIA) before introducing a new filtering or monitoring system, or before making significant changes to an existing system.

Filtering and monitoring must also be reflected within the school’s privacy information, including what is monitored, why monitoring takes place, who has access to reports or alerts and how long the information is retained. Schools are also expected to review the privacy information provided by third-party filtering and monitoring suppliers.

That takes filtering and monitoring firmly outside the boundaries of the IT department. It is now an information-governance issue too.

KCSIE 2026 reinforces the safeguarding responsibility

Keeping Children Safe in Education 2026 reinforces the other side of the equation. KCSIE is statutory guidance. Schools and colleges in England must have regard to it when carrying out their duties to safeguard and promote the welfare of children.

Paragraphs 173 to 177 deal specifically with filtering and monitoring. KCSIE says governing bodies and proprietors should ensure appropriate filtering and monitoring systems are in place and that their effectiveness is reviewed at least once every academic year.

Crucially, this is not intended to be an IT technician conducting a technical test in isolation. The review should involve the senior leadership team member responsible for filtering and monitoring, supported by the Designated Safeguarding Lead and IT support.

KCSIE also expects checks to establish that filtering works appropriately across relevant internet-connected devices and locations, with records being retained of those checks. Leadership and relevant staff should understand the arrangements, know how they are managed and know how concerns should be escalated.

The DfE filtering and monitoring standards reinforce this further by expecting a responsible SLT member and governor to be identified, alongside clearly defined responsibilities for the DSL, IT team and any third-party technology provider.

Three responsibilities that now need to work together

1. Safeguarding

The fundamental purpose remains protecting children. Schools need filtering capable of preventing access to illegal, inappropriate and harmful content, alongside monitoring arrangements capable of identifying potentially concerning behaviour.

But simply generating thousands of alerts is not an effective safeguarding strategy. Schools need to know who receives an alert, how quickly it is reviewed, what constitutes a high-risk alert, when something becomes a safeguarding concern, who escalates it to the DSL, what happens outside normal school hours, how actions are recorded, and how leadership knows alerts are actually being acted upon.

The current DfE standard expects monitoring arrangements to include at least weekly monitoring reports, together with immediate reporting where incidents are classified as high risk. There should also be a documented process recording incidents, actions and outcomes. This is safeguarding governance, not simply software configuration.

2. Data Protection

Monitoring necessarily involves processing information. Depending upon the technology being used, that could include usernames, device identifiers, IP addresses, search terms, URLs, screenshots, application activity, typed content, images and communications. Some of that information may be highly sensitive.

The school’s responsibility as data controller does not disappear because the information is collected by a third-party filtering or monitoring supplier. Schools and Trusts remain responsible for deciding why information is being collected, what is required, who it can be shared with and how long it should be retained.

This means schools should be able to demonstrate why monitoring is necessary and proportionate. They also need to consider who can see the data, how long it is retained, where it is processed, what the supplier does with it and what happens when sensitive material is captured.

A DPIA should examine the actual processing taking place, not simply exist as a compliance document. Privacy notices must also reflect reality. It is difficult to demonstrate transparency if a school extensively monitors activity on its devices but its pupil, parent and staff privacy information says nothing about it.

3. Governance

The third element is governance. KCSIE and the DfE standards place strategic responsibility with governing bodies and proprietors. They should be able to obtain assurance that filtering and monitoring arrangements are appropriate and effective.

The DfE standard says schools should identify an SLT member and governor with responsibility for ensuring the filtering and monitoring standards are met. Roles should also be established for the DSL, internal IT staff and third-party IT support.

This creates an important separation of responsibilities: IT provides technical expertise; the DSL provides safeguarding expertise; the DPO provides independent data protection advice; senior leadership makes and owns organisational decisions; and governors or trustees provide scrutiny and assurance. None of these functions should operate independently of the others.

A CLEAR LINE OF ACCOUNTABILITY
Governors / Trustees  →  Senior Leadership  →  DSL  →  DPO  →  IT Support  →  Filtering & Monitoring Provider

What should schools and Trusts do now?

For many organisations, the first step should not be purchasing another product. It should be understanding their existing arrangements.

  1. Assign responsibility: Identify the SLT lead, responsible governor or trustee, DSL involvement, DPO involvement and IT responsibilities.
  2. Map the technology: Establish exactly what filtering and monitoring takes place, on which networks, devices, users, locations and applications, including devices used away from school.
  3. Review safeguarding effectiveness: Determine what is blocked, what is monitored, what alerts are generated, who reviews them and how safeguarding concerns are escalated.
  4. Complete or refresh the DPIA: Document the processing, necessity, proportionality, risks, safeguards, access arrangements and retention periods.
  5. Review third-party providers: Understand what data suppliers receive, where it is stored, how long it is retained, what subcontractors are involved and what their privacy information says.
  6. Update privacy information: Clearly explain what is monitored, why, who can access the information and how long it is retained.
  7. Review policies: Ensure safeguarding, online safety, acceptable use, data protection, staff use and associated policies describe the same operational process.
  8. Define access and retention: Monitoring information should not simply be accessible to every administrator because the technology allows it.
  9. Test and evidence effectiveness: Conduct and record filtering and monitoring checks across devices, user groups, locations and services.
  10. Report through governance: Ensure the findings, risks, exceptions and required improvements are presented to leadership and the governing body or Trust so that appropriate assurance can be provided.

The annual review should also consider the particular risk profile of pupils, including age and SEND, the use of BYOD, locations, relevant safeguarding incidents, teaching requirements and emerging technologies such as generative AI. Reviews should additionally take place when risks are identified, working practices change, new technologies are introduced or significant technical changes occur.

Don’t forget AI

Filtering and monitoring is becoming more complicated as schools adopt generative AI. Traditional filtering was largely concerned with websites and URLs. Increasingly, content is generated dynamically inside websites, applications and AI platforms.

The DfE now specifically asks schools to consider whether their filtering and monitoring systems can deal with real-time, dynamic, personalised and AI-generated content.

Where automated tools or AI are themselves being used as part of filtering or monitoring, they should be used lawfully, proportionately and transparently. This is another reason why annual reviews cannot simply be a tick-box exercise. The technology – and the risks – are changing too quickly.

How IT Systems can help

At IT Systems & Support Limited, we believe filtering and monitoring needs to be approached from all three perspectives: Safeguarding, Data Protection and Technology Governance.

That is particularly important because simply asking an IT provider whether “the filter is working” will no longer give a school or Trust the assurance it needs. We can work with leadership teams, DSLs, governors and trustees to review the complete filtering and monitoring environment.

Filtering and Monitoring Review

We can undertake a structured review against the current DfE Filtering and Monitoring Standard and KCSIE 2026, considering the technical implementation alongside the organisation’s safeguarding requirements. This can include testing filtering across different users, devices and locations; reviewing monitoring arrangements and reporting; assessing escalation processes; identifying gaps; documenting findings and developing an improvement plan.

Data Protection Impact Assessment

As a provider of DPO-as-a-Service, IT Systems can support schools and Trusts with the data protection implications of filtering and monitoring. This includes reviewing or creating the required DPIA, considering necessity and proportionality, examining third-party processing, assessing access and retention arrangements and ensuring identified risks have appropriate controls.

Privacy Notices and Policies

We can review pupil, parent and staff privacy notices to make sure filtering and monitoring is appropriately and transparently explained. We can also examine Acceptable Use, Online Safety, Safeguarding, Data Protection and associated policies so that the documented position reflects what actually happens technically.

Governance and Assurance

For Trusts in particular, consistency across multiple schools is critical. We can help establish a Trust-wide governance framework defining responsibilities across Trustees and Governors, Senior Leadership, DSL, DPO, IT Support and the filtering/monitoring provider. We can also support annual reviews and produce documented evidence that leadership and governors can use to demonstrate how the organisation is meeting the DfE standards.

Technical Assurance

As an education-focused Managed Service Provider, we can work directly with filtering and monitoring technologies, networks, endpoint management and identity systems to establish whether the controls described in policy are actually operating in practice.

THE DIFFERENCE IS EVIDENCE
A policy saying something happens is not the same as being able to demonstrate that it happens.

The key message for schools

Filtering and monitoring is no longer something that should sit quietly in the background as an IT system. It is part of the school’s safeguarding environment. It involves processing personal data. And it requires leadership and governance oversight.

KCSIE 2026 expects schools to review the effectiveness of their arrangements at least once every academic year, with leadership, safeguarding and IT working together. The DfE’s filtering and monitoring standard says schools should already be meeting the standard, while its updated data protection guidance explicitly addresses DPIAs, privacy information, access, retention and third-party monitoring providers.

THE QUESTION HAS CHANGED
Do we have filtering and monitoring?  →  Can we demonstrate that our filtering and monitoring is effective for safeguarding, compliant with data protection requirements, and subject to appropriate leadership and governance?

How IT Systems can support your school or Trust

IT Systems & Support Limited can undertake an independent Filtering, Monitoring, Safeguarding and Data Protection Review, bringing together our education IT, cyber security, safeguarding technology and DPO expertise.

Whether you are an individual school or a Multi-Academy Trust looking for consistency across multiple sites, we can help you understand your current position, identify gaps and put in place the evidence, policies, technical controls and governance arrangements needed to move forward.

Speak to IT Systems about a Filtering & Monitoring Assurance Review.

Further reading and authoritative guidance

What our clients say

Reid Street Primary School have used the services of IT Systems and Support for many years and have found them friendly, knowledgeable and put the interests of our school first.

Any IT issues within our school are critical to the delivery of the curriculum.   Any incidents reported to IT Systems and Support are responded to very quickly and resolved within a short space of time.

Their fast and ‘above and beyond’ services enables our school to continue with the day without disruption or loss of time.

In summary IT Systems and Support offers an outstanding personal service to our school and we would thoroughly recommend them.

They are proactive, creative and flexible in order to fulfil the educational needs of our staff and children.

Reid Street Primary School

Crown Commercial Service Supplier
BSI ISO 22301
BSI ISO 22301
BSI ISO 27001
IWF Member
Ripe NCC Member
Schools North East Commercial Supporter
GDPR Foundation & Practitioner