Information Sharing Policy
Official School Policy Document
INFORMATION SHARING AND CONFIDENTIALITY POLICY
Policy Owner | Executive Headteacher / Headteacher / Designated Safeguarding Lead
Approved by | Directors of SV Academy
Date Approved | September 2026
Last Reviewed | September 2026
Next Review | September 2027, or earlier if legislation or statutory guidance changes
Important commencement note: The new statutory information-sharing duty under section 16LA of the Children Act 2004 comes into force on 30 September 2026. This policy has been written to align with that duty and the September 2026 statutory guidance.
1. Statement of Intent
SV Academy is committed to protecting children and young people, respecting privacy and sharing information lawfully, proportionately and at the right time. Effective information sharing is essential to safeguarding, early help, education, SEND support, attendance, health and wellbeing, safe transitions and effective multi-agency working.
The welfare and best interests of the child are central to decisions about safeguarding information. Data protection law is not a barrier to appropriate information sharing. It provides the framework for sharing personal information fairly, lawfully, securely and proportionately.
This policy replaces the previous SV Information Sharing Policy and applies across SV Academy, including compulsory-school-age statutory or commissioned provision and Post-16 provision.
2. Scope
This policy applies to all Directors, leaders, staff, volunteers, agency staff, contractors and others who handle information on behalf of SV Academy.
For safeguarding purposes, a child is anyone who has not yet reached their 18th birthday. Some Post-16 learners may be aged 18 or over; information about adult learners is handled under data protection law and any applicable adult safeguarding, contractual, funding or legal requirements. Where information about an adult learner is relevant to the safety or welfare of a child, the child safeguarding provisions in this policy also apply.
- information about students, parents, carers and family members;
- safeguarding and child protection information;
- SEND, health, attendance, behaviour, risk and welfare information;
- information received from or shared with referring schools, local authorities and commissioners;
- staff safeguarding and conduct information, where relevant;
- information shared with police, health, social care, youth justice, Prevent/Channel and other agencies;
- educational, assessment, examination, careers and progression information where sharing is necessary and lawful.
3. Legal and Statutory Framework
SV Academy will have regard to current legislation, statutory guidance and regulatory requirements, including the following:
From 30 September 2026, the information sharing duty in section 16LA of the Children Act 2004 comes into force. The proprietor of a registered independent educational institution is a designated education agency for these purposes. This policy adopts the statutory duty and associated September 2026 guidance so that SV Academy is ready to comply from commencement.
- Children Act 1989 and Children Act 2004, including section 16LA;
- Children's Wellbeing and Schools Act 2026;
- Keeping Children Safe in Education 2026;
- Working Together to Safeguard Children 2026;
- DfE Information Sharing Duty statutory guidance, September 2026;
- Education (Independent School Standards) Regulations 2014;
- Data Protection Act 2018, UK GDPR and Data (Use and Access) Act 2025;
- Human Rights Act 1998, including the right to respect for private and family life;
- common law duty of confidentiality;
- Equality Act 2010 and the requirement to avoid discriminatory decision-making;
- Disclosure and Barring Service Code of Practice and relevant statutory referral duties, where applicable.
4. Definitions
Personal information
Information relating to an identified or identifiable individual.
Special category information
Personal information requiring additional protection, including information about health, racial or ethnic origin, religion, sexual orientation and certain other protected categories.
Safeguarding information
Information that may help assess need or risk, make a decision, provide support, protect a child, prevent harm or otherwise safeguard and promote a child's welfare.
Confidential information
Information given or held in circumstances where there is a reasonable expectation that it will be treated confidentially. Confidentiality is important, but it is not absolute where information must or should lawfully be shared to safeguard a child.
Need to know
Access or disclosure limited to people who require the information to carry out a legitimate safeguarding, educational, legal, regulatory or operational function.
5. Leadership and Responsibilities
Directors / Proprietor
Hold overall responsibility for ensuring that SV Academy has effective safeguarding, data protection and information governance arrangements and that statutory duties are met.
Executive Headteacher
Provides strategic oversight of information-sharing arrangements across SV Academy, ensures that systems support effective multi-agency working and addresses significant or cross-provision information-sharing risks.
Headteacher
Is responsible for day-to-day implementation of this policy, ensuring staff follow agreed processes and that information is handled appropriately across teaching, attendance, SEND, behaviour, welfare and operational functions.
Designated Safeguarding Lead (DSL)
Takes lead operational responsibility for safeguarding information, referrals, child protection records and decisions to share safeguarding information. The DSL may consult the Headteacher, Executive Headteacher, Data Protection Officer or other relevant professional where required, but urgent safeguarding action must not be delayed.
Data Protection Officer / Data Protection Lead
Provides advice on data protection, lawful bases, data subject rights, data sharing agreements, breaches and information governance. Data protection advice should support, not obstruct, timely safeguarding action.
All staff
Must recognise that safeguarding is everyone's responsibility, record concerns accurately, share concerns promptly with the DSL or deputy, protect confidential information and never promise absolute confidentiality to a student where safety or welfare may be at risk.
6. Core Information-Sharing Principles
When information is shared, SV Academy will act in a child-centred, timely and proportionate way. Staff must distinguish clearly between fact, direct observation, information reported by another person, professional opinion and untested allegation.
- Necessary and purposeful - there must be a clear reason for sharing;
- Relevant - share information that has a bearing on the decision, support or safeguarding action required;
- Proportionate and data-minimised - share no more than is needed for the purpose;
- Accurate and contextualised - take reasonable steps to ensure information is correct and not misleading;
- Timely - do not allow uncertainty, consent questions or administrative delay to create avoidable safeguarding risk;
- Secure - use an appropriate secure method and confirm the intended recipient;
- Transparent where safe - explain information-sharing arrangements to children and families where this does not increase risk or compromise safeguarding or an investigation;
- Recorded - record what was shared or not shared, with whom, when, why, the lawful basis or statutory duty relied upon where relevant, and any follow-up action.
7. Statutory Information Sharing Duty from 30 September 2026
Where section 16LA of the Children Act 2004 applies, SV Academy must share relevant information with another relevant person or organisation where it considers that sharing may help that recipient assess need or risk, make a decision, provide support or take action to safeguard and promote the welfare of a child. This can include information relevant to a child who may pose a risk to others.
The duty is proactive as well as responsive: staff should not assume that information should only be shared when another agency asks for it.
The statutory limitation is narrow. A decision not to share because sharing would be more detrimental to the child than not sharing should be exceptional, based on professional judgement, carefully recorded and reviewed. Lack of consent, fear of complaint, practitioner discomfort or general concerns about data protection are not, by themselves, valid reasons to withhold information where the duty applies.
8. Deciding Whether and What to Share
For safeguarding information, staff should consider the following three tests before sharing, while avoiding delay in urgent cases:
- Relevance - does the information have a bearing on safeguarding or promoting the child's welfare?;
- May facilitate - could sharing reasonably help the recipient assess need or risk, make a decision, provide support or take action?;
- Detriment - could sharing cause greater detriment to the child than not sharing, and can any risk be mitigated by limiting or structuring the disclosure?
When uncertain
Staff should seek prompt advice from the DSL, Headteacher, Executive Headteacher or Data Protection Officer as appropriate. Seeking advice must not delay emergency action. Where a concern remains about a child, the default should be to focus on the child's safety and welfare and on whether lawful, necessary and proportionate sharing would help protect or support them.
9. Consent, Transparency and Confidentiality
Consent is only one possible lawful basis for processing personal information and is often not the most appropriate basis for safeguarding information sharing. In safeguarding situations, public task, legal obligation or other lawful bases and conditions may be more appropriate.
SV Academy will usually be open with students and parents/carers about how information may be used and shared through privacy notices, enrolment information and safeguarding procedures. However, SV will not seek consent, or will not inform a person before sharing, where doing so could increase risk, prejudice a police or safeguarding investigation, expose a child or another person to harm, or otherwise undermine effective safeguarding.
Staff must not offer a child or family a false choice by asking permission where SV Academy already has a legal duty or clear lawful basis to share. Where safe, staff should explain what information will be shared, with whom and why.
10. Data Protection and Lawful Processing
All sharing of personal information must comply with applicable data protection laws. SV Academy will identify an appropriate lawful basis under UK GDPR and, where special category or criminal offence data is involved, any additional condition required by law.
Safeguarding information may lawfully be shared without consent where the relevant legal requirements are met. The school will apply data minimisation, accuracy, purpose limitation, security, transparency and accountability principles.
Where regular or structured sharing takes place with partner agencies, SV Academy should use appropriate data sharing agreements or local protocols where available. The absence of a data sharing agreement must not prevent necessary, proportionate and lawful ad-hoc or urgent safeguarding sharing.
11. Safeguarding and Child Protection Information
Safeguarding concerns must be recorded and passed promptly to the DSL or deputy in accordance with the Child Protection and Safeguarding Policy. Records should include a clear summary of the concern, how it was followed up, actions and decisions, the outcome and the rationale for information-sharing decisions.
Information may be shared with children's social care, police, health, local authority safeguarding services, youth justice, Prevent/Channel, commissioners, other education providers and other relevant agencies when lawful and necessary to safeguard or promote welfare.
Urgent information may be shared verbally where delay would increase risk. The disclosure and rationale must then be recorded as soon as practicable.
12. Referring Schools, Local Authorities and Commissioners
SV Academy works with referring schools, local authorities and other commissioners. Information-sharing arrangements must support the safety, attendance, education and welfare of the learner and the effective management and review of the placement.
For statutory or commissioned placements, SV may need to share attendance, progress, behaviour, SEND, risk, safeguarding, welfare and placement-review information with the referring school or commissioning authority. Only information relevant to the recipient's role and the agreed or lawful purpose should be shared.
Safeguarding concerns are not restricted by contractual reporting cycles. Where a concern requires immediate or prompt sharing, staff must follow safeguarding procedures without waiting for a scheduled review or commissioner meeting.
13. Transfers and Transitions
When a child leaves SV Academy for another school or college, the DSL or deputy will ensure that the child protection file is transferred securely and separately from the main pupil file as soon as possible and within 5 days for an in-year transfer, or within the first 5 days of a new term where applicable. Confirmation of receipt must be obtained.
The transferred safeguarding file should include a clear, structured summary of current concerns, relevant context and ongoing support needs, distinguishing current risk from historic information. The DSL should consider whether key safeguarding information needs to be shared with the receiving setting before the child starts so that support and risk-management arrangements are ready.
Where a student is moving between SV Academy, a home school, alternative provision, college or another commissioned setting, staff must clarify which organisation holds which records and who is responsible for ongoing safeguarding action.
14. SEND, Health and Welfare Information
Information about SEND, EHCPs, health, medication, disabilities, communication needs, mental health, reasonable adjustments and risk may need to be shared with staff and relevant professionals so that the learner can access education safely and effectively.
Only staff who need the information to carry out their role should have access. The SENCO, DSL, Headteacher and relevant teaching or support staff should work together to ensure that important information is not unnecessarily siloed where doing so could compromise safety, access or support.
15. Post-16 and Learners Aged 18 or Over
KCSIE and the section 16LA child safeguarding duty apply to people under 18. For Post-16 learners who are 18 or over, SV Academy will continue to share information where there is a lawful basis, including where necessary for education, funding, health and safety, safeguarding adults, serious risk, prevention or detection of crime, legal obligations or contractual/commissioning requirements.
Where an adult learner's information also indicates that a child may be at risk, the child safeguarding framework applies to the information relevant to that child. Staff must also consider local adult safeguarding procedures where the learner meets the relevant criteria.
16. Allegations, Staff Conduct, DBS and Professional Referrals
Information about safeguarding concerns or allegations involving staff, volunteers or contractors will be shared only with those who need it for safeguarding, investigation, employment or regulatory purposes, in accordance with KCSIE and SV Academy's staff allegations and low-level concerns procedures.
This may include sharing with the Local Authority Designated Officer (LADO), police, an employment agency, Disclosure and Barring Service, Teaching Regulation Agency or other appropriate body where required or lawful.
The contents of DBS certificates are subject to strict handling requirements and will not be routinely copied or circulated. This does not prevent SV Academy from sharing underlying safeguarding information, risk information, employment decisions or making statutory referrals where the law requires or permits this.
17. Secure Methods of Sharing
Staff must use a method appropriate to the sensitivity and urgency of the information. Before sending information, staff should verify the identity and contact details of the recipient and check attachments carefully.
- secure safeguarding or management information systems with controlled access;
- encrypted or appropriately protected email to a named professional address;
- approved secure portals or local authority systems;
- telephone or face-to-face sharing for urgent matters, followed by a written record;
- secure physical transfer where electronic transfer is not appropriate, with a receipt or audit trail.
18. Recording Decisions
The person making or authorising a safeguarding information-sharing decision must ensure there is an appropriate record. The record should be proportionate to the significance of the decision.
- the concern, purpose or request;
- the information considered relevant;
- what was shared, or what was withheld;
- the recipient and date/time of sharing;
- the legal or safeguarding basis relied upon where relevant;
- whether the child and/or parent/carer was informed, and if not, why not;
- any assessment of detriment or other risk;
- any action, response, acknowledgement or follow-up required.
19. Receiving Information
Information received by SV Academy must be handled as carefully as information generated by the Academy. Staff must consider whether information received requires immediate safeguarding action, risk assessment, SEND support, health planning, changes to supervision or other intervention.
Where information is unclear, incomplete or appears inconsistent, the appropriate member of staff should seek clarification from the source where necessary. Information should not be ignored merely because it is historic; equally, historic information must be presented in context and should not be used to stigmatise or unfairly disadvantage a learner.
20. Information Requests and Data Subject Rights
Requests for access to personal information, including subject access requests, requests from parents or third parties, court orders or law-enforcement requests, must be passed promptly to the appropriate Data Protection Officer/Lead and, where safeguarding material is involved, the DSL.
Safeguarding records may contain third-party information, confidential information or material whose disclosure could cause harm or prejudice safeguarding. Such information must not be released without appropriate review of the applicable legal rights, exemptions and restrictions.
21. Data Breaches and Mis-Sent Information
If personal or safeguarding information is sent to the wrong person, lost, disclosed without authority or otherwise compromised, staff must report it immediately through SV Academy's data breach procedure and notify the Data Protection Officer/Lead and appropriate senior leader. Where safeguarding risk exists, the DSL must also be informed immediately.
SV Academy will take prompt steps to contain the breach, reduce harm, assess notification requirements and record the incident. Staff must not attempt to conceal or privately resolve a data breach.
22. Training and Staff Awareness
Information sharing forms part of safeguarding induction and ongoing staff development. Staff will be supported to understand that lawful information sharing can protect children and that inappropriate withholding of relevant information can create risk.
The DSL and deputies will maintain current knowledge of KCSIE, Working Together, local multi-agency procedures and statutory information-sharing requirements. Leaders will ensure that staff know how to obtain prompt advice when uncertain.
23. Monitoring and Review
The Executive Headteacher and Headteacher, working with the DSL and Data Protection Officer/Lead, will monitor the effectiveness of information-sharing arrangements. This will include consideration of safeguarding audits, complaints, incidents, data breaches, case reviews, transition arrangements and feedback from partner agencies.
This policy will be reviewed at least annually and sooner where legislation, statutory guidance, local safeguarding arrangements, inspection findings or an incident indicates that revision is required.
Appendix 1 - Practical Information-Sharing Checklist
1. What is the concern, need, request or purpose?
2. Is the information relevant to safeguarding, welfare, education or another legitimate purpose?
3. Who needs the information and what can they do with it?
4. If this is safeguarding information, could sharing help them assess need/risk, decide, support or act?
5. Could sharing be more detrimental to the child than not sharing? Can any risk be reduced by limiting the disclosure?
6. What lawful basis or statutory duty applies? Is an additional condition required for special category or criminal offence data?
7. Is consent actually required, or would asking for consent be inappropriate or misleading?
8. What is the minimum necessary information to achieve the purpose?
9. Is the information accurate, current and clearly distinguished between fact, opinion and allegation?
10. What is the safest and fastest appropriate method of sharing?
11. Should the child and/or parent/carer be informed? If not, why not?
12. Record the decision, disclosure, recipient, date, rationale and follow-up.
Appendix 2 - Key Related Policies
- Child Protection and Safeguarding Policy
- Data Protection and Privacy Policy / Privacy Notices
- Safer Recruitment and DBS Policy
- Enrolment Policy
- Attendance Policy
- SEND / Inclusion arrangements
- Prevent Duty, Radicalisation and Extremism Policy
- Staff Code of Conduct and Allegations / Low-Level Concerns procedures
- Records Management and Data Breach procedures
Appendix 3 - Key External Guidance
- Keeping Children Safe in Education 2026 - Department for Education
- Working Together to Safeguard Children 2026 - Department for Education
- Information Sharing Duty: statutory guidance for safeguarding organisations and practitioners - Department for Education, September 2026
- Data protection in schools: Sharing personal data - Department for Education
- Data sharing: a code of practice - Information Commissioner's Office
Official guidance links
- Keeping Children Safe in Education
- Working Together to Safeguard Children
- Information sharing to safeguard children and young people
- Data protection in schools - Sharing personal data
- ICO data sharing guidance
This policy was reviewed and revised in September 2026.