GDS Analytics
For bursars, heads and compliance managers

Data protection and cyber security for independent schools

A named Data Protection Officer and fractional CISO who knows how schools work, from the bursary to the board. We have supported independent schools since UK GDPR came into force in 2018.
Pupil in school uniform jumping with arms raised
Trusted by schools, the public sector and private industry since 2018
St Albans School
Haberdashers' Elstree Schools
Liverpool Experience Campus
The challenge

Independent schools carry the risk without the safety net

73%
of state secondary schools identified a breach or attack in the previous twelve months.
An independent school holds some of the most sensitive personal data of any organisation its size: safeguarding records, medical and SEN information, bursary applications and the financial details of every fee-paying family. It also carries that risk on its own. State schools can fall back on local authority support and the DfE’s Risk Protection Arrangement for cyber cover; independent schools cannot, so their governors, their insurers and their own resilience planning have to fill the gap.
The expectations are rising all the same. Keeping Children Safe in Education asks every school to consider meeting the DfE’s cyber security standards for schools and colleges, which the Department expects schools to be working towards by 2030. Insurers increasingly want evidence of controls before they renew. The ICO expects documented policies, a working breach process and subject access requests answered within one month, including the difficult ones that arrive in the middle of a fee dispute or a separation.
The threat is real rather than theoretical. The government’s Cyber Security Breaches Survey 2025/26 found that 73% of state secondary schools identified a breach or attack in the previous twelve months, and phishing was involved in almost all of them. There is little reason to think that an independent school, with fee payments and parent portals of its own, is a harder target.
How we help

How we help

Four services, which most schools combine into a single annual arrangement.

Named Data Protection Officer

We act as your school’s DPO, registered with the ICO and named in your privacy notices. That covers a complete, school-specific policy suite, subject access and other rights requests (including the contentious ones), DPIAs for new EdTech and AI tools, records of processing, retention schedules for safeguarding and pupil files, annual staff training and a termly report to governors.
Talk to us about DPO support

Fractional CISO

Senior cyber security leadership for the price of a few days a term. We set a practical security strategy, maintain your risk register, map your position against the DfE cyber security standards, prepare you for insurer questionnaires and report to the board in terms that governors can act on. We work alongside your IT team or managed service provider rather than replacing them.
Talk to us about CISO support

Compliance and audit

A clear picture of where you stand and what to fix first. Options include a UK GDPR health check, a gap analysis against the DfE cyber security standards, Cyber Essentials readiness and a data mapping exercise, each delivered with a prioritised action plan and a short summary for governors.
Book a health check

Incident response

When something goes wrong, you need a decision within hours, not days. We help you contain the incident, assess whether it meets the threshold for reporting to the ICO within 72 hours (and to the Charity Commission, if your school is a charity), draft communications to parents and staff, and put the lessons learned into practice afterwards. Clients on an annual arrangement have priority access.
Book a free consultation
What clients say

What clients say about working with us

“
He knows our school, our history, and our risk appetite, so his advice is always grounded in our reality rather than generic guidance.
Rebecca Mitchell
Deputy Clerk to the Governors and Data Protection Manager, St Albans School
“
He communicates in a way that governors and non-technical staff can actually act on.
Rob Hagon
Director of IT, Haberdashers' Elstree Schools
“
I feel like I’ve learnt so much through our partnership, and that’s a testament to how Marc approaches his work.
Matthew Jones
Head of Health, Safety, Risk and Compliance, Liverpool Experience Campus
Marc Davies, Director of GDS Analytics
Why GDS Analytics

Why schools choose GDS Analytics

When you work with GDS Analytics, you work with me and a small dedicated support team. I’m Marc Davies, and I have been the named DPO and security adviser to independent schools since UK GDPR came into force in 2018. I hold the CISSP, CCSP, CISA and CISMP certifications, and I also advise organisations in financial services, hospitality and retail, which means that the controls I recommend to a school are the ones that hold up in regulated industries too.
What schools tell me they value most is continuity. I learn how your school works, who holds which data and where your risk appetite sits, so the advice fits your reality rather than a template. I write one version for the operational team and another for the governing body, and I’d rather build your staff’s confidence than make you dependent on me.
2018
Supporting independent schools since
4
Certifications: CISSP, CCSP, CISA, CISMP
Termly
Board-ready reporting that governors can act on
Getting started

How it works

01

A free 30-minute consultation

We talk through where your school is today, what is worrying you and what your governors or insurers are asking for. There is no obligation and no sales pitch.
02

A fixed proposal within five working days

You receive a written scope and a fixed annual fee, aligned to your financial year, so that the bursar knows the cost before anything is signed.
03

A structured first term

We begin with a health check and a prioritised plan, then settle into a regular rhythm of termly reviews, governor reporting and support whenever you need it.
Annual DPO support for independent schools starts from only £3000.00 per term. Fractional CISO and combined arrangements are priced to the size and complexity of your school.
FAQ

Questions schools often ask

Not always. Article 37 of the UK GDPR makes a DPO mandatory for public authorities and for organisations whose core activities involve large-scale processing of special category data or large-scale monitoring. Independent schools are not public authorities, so whether the duty applies depends on your processing. In practice, most schools we speak to appoint one anyway, because a named DPO is what parents, insurers and inspectors expect to see, and it gives the governing body a clear line of accountability.

They can, but the role must be free of conflicts of interest, and the people who decide how data is used (a bursar, a head or an IT lead) usually cannot also be the person who independently challenges those decisions. An external DPO removes that conflict and brings experience of how other schools handle the same issues.

Keeping Children Safe in Education, which does apply to independent schools, asks schools to consider taking appropriate action to meet them. They are also a sensible benchmark for insurers and governors, which is why we use them as the basis of our gap analysis.

Your IT provider keeps systems running; a CISO decides what risk the school is prepared to accept and holds the provider to it. We work with your IT team and managed service provider, not in competition with them.

Call us on 0333 121 6772. We can support one-off incidents, and the first priority is always to contain the problem and establish whether the 72-hour ICO reporting clock has started.

Our standard arrangement runs for twelve months, aligned to your financial year.

Find out where your school stands

Book a free, no-obligation consultation. In thirty minutes we will talk through your current position, the questions your governors and insurers are asking, and the two or three things worth fixing first. You will leave with a clear view whether or not we work together.

© 2026 GDS Analytics. All rights reserved.

GDS Analytics Limited. Registered in England No. 12389759. Registered office: 32 Lon Gwynfryn, Swansea, SA2 0TR. VAT No. 361 2779 87. ICO registration ZA667093.
Website by Melton Web Design Experts, SBNR