Nurseries and childcare providers deal with some of the most sensitive personal data there is: children’s names, dates of birth, medical conditions, allergy information, emergency contacts, photographs, and in many cases developmental records and SEND assessments. Under UK GDPR, children’s data is treated as requiring heightened protection. And yet, the realistic cybersecurity posture of most small childcare businesses in 2026 is worryingly thin.

This isn’t a criticism — it’s a gap that’s very fixable, and most of the steps don’t require a specialist or significant budget.

What Data You’re Holding (and Why It Matters)

Before you can protect data, it’s worth being clear on what you have. A typical nursery or childminder holds:

Registration forms with names, addresses, dates of birth, and contact details for children and parents. NHS numbers and GP details if you care for children with medical needs. Allergy and dietary information, medication authorisation forms. Developmental observations and progress reports. In some cases, Child Protection information if a child is on a plan — this is particularly sensitive.

All of this is personal data under UK GDPR. Children’s data in particular carries a higher legal threshold for lawful processing. You need a lawful basis for holding each category, and your privacy notice — the document that tells parents what you do with their data — needs to reflect that accurately.

If you don’t have a written privacy notice, that’s the first thing to fix. The ICO’s small business guidance has a template. It doesn’t need to be long or complicated.

The Three Most Likely Ways You’ll Have a Problem

Lost or stolen devices. A nursery manager’s phone or laptop with parent contacts, photos, and child records is a data breach waiting to happen if it’s lost or stolen and isn’t protected. Full-device encryption is on by default on modern iPhones and Android devices if you’ve set a PIN or passcode. For Windows laptops, BitLocker is built in and free. Make sure any device with work data is encrypted.

Nursery management software accounts. Most nurseries use a platform like Famly, Tapestry, or ParentZone for observations, communications, and billing. These accounts hold a lot of data, and account security is often poor: shared passwords, no multi-factor authentication, staff who left a year ago still having access. Go through your nursery management system’s account settings. Enable MFA on the admin account. Remove former staff immediately. Check who has admin access — it should be a short list.

Email and messaging. Sending a child’s medical information, safeguarding concern, or even just a register to the wrong email address is a reportable breach. Many nurseries also use WhatsApp groups for parent communications, which creates its own complications — WhatsApp is not an appropriate channel for safeguarding discussions or sensitive medical information. Use your nursery management platform’s messaging features for anything sensitive.

Ofsted and Your Data Protection Obligations

Ofsted inspectors can ask about your data protection practices. They won’t conduct a technical cybersecurity audit, but they will want to see that you have a privacy notice, that you handle information about children appropriately, and that you have a policy for what happens when something goes wrong.

If you have a data breach — a lost device, an email sent to the wrong parent, a safeguarding record accessed by someone who shouldn’t have seen it — you may need to report it to the ICO within 72 hours. Not every breach needs to be reported, but you need to be able to assess it quickly and make the decision. The ICO’s self-assessment tool at ico.org.uk helps you determine whether a breach is reportable.

Failing to report a reportable breach can result in an ICO fine. For small businesses, fines are scaled to turnover, but even modest fines are disruptive, and the process itself takes time that childcare providers don’t have.

Practical Steps That Don’t Require a Specialist

You don’t need to hire an IT consultant to cover the basics. Here’s what to actually do this week:

Passwords and MFA: Stop sharing the nursery email password. Give each staff member their own account if possible, or at minimum ensure admin access to sensitive systems is on a single known account. Enable multi-factor authentication on email, nursery management software, and anything else with parent or child data.

Device PIN/passcode: Every phone and laptop with work data on it needs a PIN, passcode, or biometric lock. This activates the encryption that’s already built in. No PIN means no encryption, regardless of what the device manufacturer claims.

Staff leaving: Create a checklist for when staff leave that includes removing their access to email, the nursery management system, shared drives, and any other accounts. Do this on their last day, not three months later.

Backup your records: Nursery management platforms generally handle backup themselves, but any local records — spreadsheets, documents stored on a laptop — should be backed up somewhere else. Google Drive or Microsoft OneDrive with MFA enabled is fine. A USB drive left in a desk drawer is not.

NCSC free resources: The National Cyber Security Centre has specific guidance for small businesses and a free Cyber Action Plan tool (ncsc.gov.uk) that asks ten questions and tells you what to prioritise based on your answers. It takes about fifteen minutes and is a sensible starting point.

Cyber Essentials: Worth Considering

Cyber Essentials is a UK government-backed certification that covers five basic technical controls: firewalls, secure configuration, access control, malware protection, and patch management. Certification costs around £300 for a small business doing self-assessment. It won’t cover everything, but it demonstrates a baseline level of protection and may be required by some funding bodies or local authorities if you’re bidding for nursery places contracts.

The key thing is not to be overwhelmed by what you don’t have in place. A nursery with strong MFA, device encryption, and sensible access control for staff is in a genuinely better position than most small businesses in any sector. Start there.