top of page

The Laws Schools, Trusts, Councils, Vendors and Cloud Providers Are Breaching — And The Ones Parents Must Watch For.

Phones, Data, Vendors, Councils — Explained Clearly for Parents

Schools, trusts, councils, and their private vendors are now running phone bans, confiscation policies, digital behaviour systems, biometrics, multi‑agency pipelines, and cloud platforms that collect and share children’s data.

Parents are rarely told the law behind any of this. Below is every law that applies, who it applies to, and what behaviour actually breaches it — in plain English.

📱 1. PHONES, CONFISCATION & PROPERTY

Schools often claim they can “take phones all day” or “require daily surrender”. The law does not support this.

Common Law: Trespass to Goods

Applies to: schools, trusts, staff What it means: A school may only touch or move a child’s phone briefly to stop disruption.

Breach happens if the school:

  • takes phones as a blanket rule,

  • takes phones when there is no disruption,

  • takes phones from bell to bell,

  • takes phones for mere possession, not misuse.

➡ Daily phone surrender meets the breach condition.

Common Law: Conversion

Applies to: schools, trusts, staff What it means: Conversion = keeping someone’s property as if it were your own.

Breach happens if the school:

  • keeps phones until the end of the day,

  • refuses to return them until a parent comes in,

  • conditions return on punishment or compliance,

  • demands daily hand‑in.

➡ Keeping phones all day = conversion.

Education & Inspections Act 2006 — Section 91

Applies to: schools, trusts What it allows: Confiscation only to stop immediate disruption.

Breach happens if the school:

  • uses Section 91 to justify blanket bans,

  • takes phones even when switched off,

  • takes phones because “it’s policy”,

  • keeps phones longer than needed.

➡ Bell‑to‑bell confiscation is outside Section 91.

Human Rights Act 1998 — Article 8

Applies to: schools, trusts, councils Breach happens if:

  • the school interferes with private/family life or personal property

  • without necessity or proportionality.

➡ Blanket bans are not proportionate.

Children Act 1989 — Section 3 (Parental Responsibility)

Applies to: schools, trusts, councils Breach happens if:

  • schools override parental decisions about communication or property

  • without statutory authority.

➡ Daily surrender overrides parental responsibility.

Parent Summary

Schools may only take a phone briefly to stop disruption. They cannot lawfully take or keep phones all day, require daily surrender, or punish children for refusing to hand over their property. Doing so may breach common‑law property rights, misuse Section 91 powers, and interfere with parental responsibility and Article 8 rights.

🧾 2. CONSENT, CONTRACTS & UNFAIR TERMS

Schools, councils, and vendors often act as if parents and children are “bound” by digital terms they never agreed to.

Contract Law (Offer, Acceptance, Consideration, Capacity)

Applies to: schools, trusts, councils, vendors Breach happens if:

  • parents are treated as bound by terms they never saw,

  • consent is assumed because a child clicked something,

  • digital systems are imposed without genuine choice.

➡ Hidden or forced policies = unfair contract behaviour.

Minors’ Contracts Act 1987

Applies to: schools, trusts, vendors Breach happens if:

  • a child’s “agreement” is treated as legally binding,

  • vendors rely on a child’s consent for digital systems or biometrics.

➡ Children cannot enter binding contracts with vendors.

Consumer Rights Act 2015

Applies to: schools, trusts, councils (as service providers), vendors Relevant sections:

  • Section 62 — Fair terms

  • Section 64 — Transparency

  • Section 68 — Plain English

  • Schedule 2 — Grey list of unfair terms

Breach happens if:

  • terms are hidden, unclear, or bundled,

  • parents are penalised for not agreeing,

  • consent is coerced or implied,

  • policies are not written in plain English.

➡ If parents never genuinely agreed, the terms may be unfair.

Parent Summary

Schools and councils cannot impose hidden, unfair, or coercive terms. Children cannot legally “agree” to corporate systems. If consent is bundled, unclear, or forced, it may breach the Consumer Rights Act and contract law.

🔐 3. DATA PROTECTION (UK GDPR & DPA 2018)

This is where schools, trusts, councils, and vendors most often breach the law — together.

Article 5 — Principles

Breach if:

  • too much data is collected,

  • data is kept indefinitely,

  • parents are not told clearly.

➡ Often breached by schools + vendors + councils.

Article 6 — Lawful Basis

Breach if:

  • “public task” is misused,

  • consent is invalid,

  • processing has no lawful basis.

Article 7 — Consent

Breach if:

  • consent is bundled, implied, coerced, or not withdrawable.

Article 8 — Children’s Data

Breach if:

  • extra protections for children are ignored.

Articles 12–14 — Transparency

Breach if:

  • parents are not told what data is collected,

  • vendors are hidden,

  • lawful bases are unclear.

Article 15 — Subject Access Requests (SARs)

Breach if:

  • SARs are delayed, refused, or incomplete.

Article 17 — Erasure

Breach if:

  • valid deletion requests are ignored.

Article 21 — Objection

Breach if:

  • parents object and processing continues without assessment.

Article 22 — Automated Decisions

Breach if:

  • behaviour scoring or risk profiling affects a child without safeguards.

Article 28 — Processor Contracts

Breach if:

  • no proper contract exists between school and vendor.

➡ Often breached by schools + vendors.

Article 32 — Security

Breach if:

  • data leaks, exposed dashboards, poor security.

➡ Often breached by vendors + trusts + councils.

Article 35 — DPIAs

Breach if:

  • high‑risk systems (biometrics, behaviour platforms) are used without a DPIA.

Articles 44–49 — International Transfers

Breach if:

  • data is exported outside UK/EEA without safeguards.

➡ Usually breached by cloud vendors + councils + trusts.

Data Protection Act 2018 — Schedule 1 (Special Category Data)

Breach if:

  • biometric data is processed without explicit consent.

➡ Breached by biometric vendors + schools + councils if consent is missing.

Parent Summary

If schools, councils, or vendors collect too much data, hide vendors, ignore consent rules, or export data abroad, they may breach multiple GDPR articles at once. Most GDPR breaches involve the school, the trust, the council, and the vendor together.

👶 4. HUMAN RIGHTS & CHILDREN’S RIGHTS

Human Rights Act 1998 — Article 8

Applies to: schools, trusts, councils Breach if:

  • surveillance, phone bans, or digital systems are excessive,

  • policies are not necessary or proportionate.

Children Act 1989 — Section 3 (Parental Responsibility)

Applies to: schools, trusts, councils Breach if:

  • schools override parental decisions without authority.

Parent Summary

Schools cannot override parental responsibility or interfere with private life unless strictly necessary. Blanket bans and forced digital systems may breach Article 8 and Section 3.

🏛️ 5. COUNCILS, MULTI‑AGENCY PIPELINES & VENDORS

Children Act 2004 — Sections 10 & 11

Applies to: councils, trusts, schools Breach if:

  • data is shared without lawful basis, necessity, or transparency.

➡ Often breached by councils + trusts + vendors.

Crime and Disorder Act 1998 — Section 115

Applies to: councils, police, multi‑agency teams Breach if:

  • behaviour/safeguarding data is shared under crime powers without justification.

Freedom of Information Act 2000

Applies to: councils, trusts Breach if:

  • contracts, DPIAs, or vendor details are refused without lawful exemption.

Misrepresentation Act 1967

Applies to: vendors Breach if:

  • vendors mislead schools about data use, security, or international transfers.

➡ Vendor + school breach together if the school relies on false claims.

Parent Summary

Councils and vendors often breach multiple laws together when data is shared without lawful basis, contracts are hidden, or systems are misrepresented.

⭐ FINAL PARENT MESSAGE

If these behaviours are happening — blanket phone bans, all‑day confiscation, forced digital systems, hidden vendors, excessive data collection, multi‑agency pipelines — then schools, trusts, councils, and vendors may be breaching multiple laws at the same time. Your letters work because they cite the exact law, the exact section, and the exact behaviour that triggers a breach.

bottom of page