The Information Commissioner has highlighted a series of data breaches involving children’s personal information, after five school‑related incidents were reported between April and June.
In its latest quarterly update, the regulator said the cases showed recurring mistakes, including staff accessing systems with someone else’s password, failing to use Bcc on emails, and sensitive medical details for an entire school trip being left visible on a wall.
One breach raised a potential safeguarding concern when a school issued correspondence containing both parents’ addresses, despite being aware the parents were estranged and one should not know the other’s location.
Children’s Data
The Commissioner said children’s data often sits alongside “complex family arrangements, court orders, custody disputes, health needs or safeguarding concerns”, meaning disclosures that appear minor can have serious real‑world consequences.
The update urges organisations to take “an extra moment” when handling children’s information, checking whether data is necessary, whether sensitive details are visible, whether recipient information is correct, and whether any safeguarding considerations apply.
Q1 figures show 65 personal data breaches, up from 45 in the previous quarter, though the number of people affected fell sharply, 10,750 compared with 16,600 in Q4, when several large incidents were linked to new technology rollouts.
Of the breaches reported this quarter, 26% were classed as high risk, similar to the previous period. 71% were reported within the required 72‑hour window.
The Commissioner closed 32 breach cases during Q1, with no regulatory action issued.


