Joining the Dots: The DfE's New EdTech Procurement Guidance

The DfE published new EdTech procurement guidance on July 9. It is the first DfE document to reference the ICO's Edtech Examined findings, and it tells schools to treat procurement as a connected governance decision, not an isolated IT one. Read it before September.

Share
Joining the Dots: The DfE's New EdTech Procurement Guidance

The 60-second Briefing

  • On July 9, the DfE published new guidance called Procuring educational technology (EdTech) as part of its wider Data Protection in Schools guidance.
  • It is the first DfE guidance to directly reference the ICO's Edtech Examined audit report and its findings.
  • Schools are directed to consult their Data Protection Officer at the start of procurement, not after a tool has already been chosen or trialled.
  • The guidance sets out specific questions schools must ask about AI features in tools, including whether pupil data is used to train the AI, how outputs are moderated, and whether the school retains meaningful controls.
  • Procurement is now positioned as a connected governance decision involving IT, data protection, safeguarding, AI oversight, cybersecurity, contracts, and ongoing monitoring.

There is a specific piece of DfE guidance that landed two weeks ago, and if you have not read it yet, it is worth your Sunday. On July 9, the department published new procurement guidance that ties the ICO's Edtech Examined findings to school procurement processes and makes them something schools are expected to act on.

Two weeks in, the mainstream trade press has barely covered it. The specialist safeguarding and data protection press has, and their reading is worth borrowing. This is the piece of DfE guidance that turns "the ICO said suppliers have problems" into "your school needs a procurement process that finds those problems before you sign."

Let me walk through what is actually in it.

The guidance sits inside the DfE's existing Data Protection in Schools framework as a new section called Procuring educational technology (EdTech). It does not create new legal obligations. Schools have always needed to understand what personal data an EdTech tool processes, why it is processed, who the vendor is, whether a DPIA is required, what contract terms apply, and how children are protected. What the new guidance does is bring those obligations together in one school-facing document and make explicit the connections between them.

The single most significant sentence in the guidance is the one directing schools to Edtech Examined. It tells schools to take the ICO's findings into consideration when they procure EdTech tools. That is the first time a DfE document has done that. It matters because until July 9, the ICO's audit was analysis. From July 9, it is something schools are expected to build into their procurement process. As I wrote in The ICO Has Just Audited 28 EdTech Providers, the audit itself gave school leaders the argument. The DfE has now given them the authority.

The second significant beat is the direction to involve the Data Protection Officer at the start of procurement and throughout implementation. That is not where DPO involvement usually sits. Most schools bring the DPO in at the point they need a DPIA signed off, which is usually well after a tool has been chosen, sometimes after it has been trialled, and occasionally after it has already been deployed. The DfE is saying that if the DPO is only ever involved to sign off, the process is broken. The DPO is part of deciding what to buy, not just confirming that what has been bought is legal.

The AI-specific parts of the guidance are where the language sharpens most. Suppliers must be able to explain how their AI features work, including how AI outputs are moderated, whether pupil data is used to train the AI model, how inaccuracies and bias are mitigated, and what controls and restrictions schools have. The guidance uses a case study of an AI writing tool where the school established that pupil data was used to develop AI functionality, the function could not be turned off, and data was stored outside the UK. The school decided the supplier did not meet its internal policy requirements and did not proceed with the tool. That example is in the DfE document as an illustration of good governance. It reads as a straightforward application of the procurement filter I wrote about in The Pioneer Group Confession.

The connection to safeguarding is also more explicit than before. Where children may access a tool, the guidance says the Designated Safeguarding Lead should be involved in the procurement decision, appropriate filtering and monitoring must be in place, and tools should include an audit trail that lets safeguarding leads monitor and review pupil usage. This is procurement being asked to sit alongside safeguarding in a way it usually does not, and it lines up with the direction of travel in KCSIE 2026, which comes into force on September 1.

The arc across the past six weeks is worth pausing on. On June 24, the ICO published Edtech Examined and mapped the supplier-side gaps. On the weekend that followed, this blog set out what the audit meant for procurement and released the Generative AI Procurement Policy template as a subscriber deliverable, mapping the questions to Section 4.4 of the template that dealt with data protection, safeguarding and security. On July 9, the DfE published guidance that tells schools to base their procurement process on exactly those questions, and to make the connections between data protection, safeguarding, AI oversight, and cyber security explicit rather than assumed. Three weeks. Three positions that were separately defensible in June are now one position that is officially expected in July.

The practical work between now and September is short.

Read the DfE guidance alongside the Edtech Examined report. Look at the existing procurement process. Ask whether the DPO is involved from the start, whether the DSL is included where children will access the tool, whether AI functionality is being reviewed for training-data use and for storage location, and whether the review of a tool continues after it has been deployed. If the answers are anything other than yes, that is the summer work.

The direction is clear. Procurement of technology in schools is no longer a decision that IT makes on its own, or that finance signs off in isolation, or that a Head can wave through on the strength of a demo. It is a connected governance decision that has to bring the DPO, the DSL, the IT lead, the SLT and the school's own procurement policy into a single conversation. The DfE is not asking. It is directing.

Get the process right before September, and inspection risk falls sharply. Leave it until October, and every subject access request, every safeguarding disclosure, and every DPIA audit becomes a moment where the school explains why the process was not what the DfE said it should be.

The summer is short. The guidance is not long. Read it now.

See you in the digital staffroom.