You are here:

Last reviewed on 22 June 2021
Ref: 35177
School types: All · School phases: All

You need to make sure all visiting staff who can access personal data held by your school comply with the UK GDPR. Use the following guidance to help you determine their employment status and satisfy yourself that they’re compliant.

Speak to the visiting staff member to determine their status 

You need to make sure they understand their obligations under the UK GDPR. This is because visiting staff such as counsellors, educational psychologists or peripatetic teachers may have access to personal data through the work they do in your school. 

You're the data controller, so you make the decision on how data is processed by the visiting staff member. This is true even if you determine that they're self-employed and have their own UK GDPR processes in place.  

Speak to the staff member concerned to confirm what their employment status is. Use the following questions to help you do this:

Are they classed as self-employed?

As part of your due diligence process, you should ask the visiting staff member to provide you with evidence that they are compliant with the UK GDPR, for example, by giving you their own privacy notice.

As the data controller, you'll then need to decide if this is acceptable or if you want to issue your own for the staff member to agree to and work under.

Are they a temporary member of staff (is there some form of contract in place between them and your school)?

If the staff member is contracted to your school then they should fall under your school’s remit. You should make sure they process personal data according to your rules.

Are they unsure of their status?

If the staff member is unsure of their employment status with the school, they may fall under your school’s remit. To be on the safe side, you should make sure they process personal data according to your rules.


This was explained to us by the Information Commissioner's Office (ICO).

Document your compliance

Once you’re satisfied with the due diligence you’ve completed for the staff member, show your compliance by documenting it.

Your file for a self-employed individual could include a record saying, for example, that:

  • They’ve provided you with their privacy notice
  • You’re confident that they understand their obligations under the UK GDPR

More from The Key


Bitesize training with a big impact

Our on-demand training has your whole board covered and lets them learn at a time and pace that suits them.

Help your new governors hit the ground running with our expertly-designed induction training, and our role-specific courses support your link governors develop key skills and confidence in their role.

STC logo

INSET, prepared for you 

Join thousands of schools already using Safeguarding Training Centre to prepare for September. 

Reduce your preparation time, deliver memorable safeguarding training to your staff, and keep track of all your safeguarding duties for the new school year.


The Key has taken great care in publishing this article. However, some of the article's content and information may come from or link to third party sources whose quality, relevance, accuracy, completeness, currency and reliability we do not guarantee. Accordingly, we will not be held liable for any use of or reliance placed on this article's content or the links or downloads it provides. This article may contain information sourced from public sector bodies and licensed under the Open Government Licence v3.0.