Education

Safeguarding & Pupil Data Standard

Technology work in schools, MATs, colleges and other education settings must respect the institution's safeguarding responsibilities. Raeburn's role is normally technology, operations, data or AI consulting—not taking over the client's statutory safeguarding function.

Minimise access

Access to pupil, family or safeguarding information is avoided unless genuinely necessary for the agreed scope. Where access is required, it must be authorised, purpose-limited, least-privilege and subject to appropriate privacy/security controls.

Client safeguarding procedures

Personnel working in education environments must follow applicable client safeguarding, visitor, access and escalation requirements. Any role-specific vetting requirement is established before the relevant activity; no DBS or other vetting status is claimed unless actually held and applicable.

AI and children

AI should not be treated as an autonomous safeguarding decision-maker. High-impact decisions involving pupils require appropriate accountable human judgement. Sensitive information should not be exposed to unapproved AI/model providers.

Escalation

If Raeburn personnel encounter a safeguarding concern during an engagement, they should preserve confidentiality and promptly follow the client's designated safeguarding/escalation process rather than conducting an unauthorised investigation.

Engagement-specific safeguarding, DPIA, DPA, access and security requirements take precedence where stronger. Last reviewed: 27 August 2026.