Running a children’s day nursery means you’re responsible for a lot more than just looking after the little ones. One key area that often gets overlooked is data protection. With the personal information of children, parents, and staff, it’s crucial to make sure your nursery is compliant with data protection laws. But where do you start?
Here’s our simple guide to help you understand what’s needed.
What is data protection?
Data protection is about keeping personal information safe and ensuring it’s used properly. In the UK, this is covered by the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. These rules apply to any business that handles personal data, including nurseries. Personal data includes things like names, addresses, contact details, and health information.
How to keep compliant
1. Register with the Information Commissioner’s Office (ICO)
Every business, including nurseries, must register with the ICO. Paying the fee and being listed on the ICO’s register of fee payers shows that your company take data protection seriously.
2. Publish a data protection policy
Every nursery should have a clear policy that explains how personal data is collected, stored, and used. This policy should be shared with staff and made available to parents.
3. Always get consent
You need to get permission to collect and use personal data. For example, when you’re collecting health information about a child, you’ll need to ask parents for their consent. This consent should be clearly documented.
4. Keep your data safe
Personal data must be stored securely, whether it’s in paper files or on a computer. This means using passwords, encryption, and locking away any physical files. Make sure that only authorised staff have access to this data.
5. Limit data sharing
Don’t share personal information unless it’s absolutely necessary. If you need to share data with a third party (like a software provider or a health professional), you must ensure that they follow GDPR rules as well.
6. Staff training
All nursery staff should be trained on data protection principles, so they know how to handle personal information properly. This includes understanding what data they can access, how to keep it secure, and what to do in case of a data breach.
7. Data breach procedures
Accidents happen, and if personal data gets lost or accessed by the wrong person, it’s called a data breach. You must have a process in place for dealing with this, including informing the people affected and reporting the breach to the ICO if necessary.
Check your current status
If you’re unsure whether your nursery is data protection compliant, it’s a good idea to carry out a data protection audit. This will help you identify any gaps and take action to fix them. You can also seek advice from a legal expert who specialises in data protection and GDPR compliance.


