Analysis

Privacy & data processors

Who is accountable for a pupil's data, which companies actually touch it, and whether the cookie banner tells the truth. This is where the schools diverge most.

Three ways to run a DPO

Every school's data controller must register with the ICO, and that public register names its Data Protection Officer — the authoritative source we've used here. Four use an external specialist firm: SchoolPro TLC covers both Cambridge and U-Maths, Judicium covers Imperial, and Data Protection People covers Leeds's trust. King's names King's College London (the University) itself. The rest keep it in-house — Exeter in its finance office, Aston's trust Operations Director, Lancaster's trust at Cardinal Newman College, Surrey's trust. Liverpool names no DPO on its website, yet the ICO register lists the school as its own DPO. Only the two pre-opening schools aren't ICO-registered at all: Durham operates under Durham Sixth Form Centre's registration, and Nottingham's partner trust (East Midlands Education Trust) is registered but doesn't yet list the school.

The MIS map

The student information system is the database that holds the most sensitive pupil records. Three schools share Bromcom — Exeter, King's and Liverpool — a genuine cluster among otherwise-unconnected institutions. Lancaster runs its admissions on CEDAR instead. And although few privacy policies name it, Applicaa (Admissions+) is the de-facto admissions platform across the network: it's named outright by Imperial and Aston, and visible in the application links of Exeter, Cambridge, Liverpool and Surrey (all *.applicaa.com). 1729 is the exception, testing applicants through Atom Learning.

Aston publishes the most candid processor list of anyone — naming not just Applicaa and Microsoft 365 but the Plaude AI note-taker, ONVU classroom-observation cameras and Flashpark ANPR in its car park. It also, unusually, blocks AI crawlers (GPTBot, Google-Extended, PerplexityBot) in its robots.txt.

When the banner doesn't match the page

This is the most consistent finding across the network: what a site loads is often not what its policy discloses. A handful get it right — Exeter (Cookiebot) and Cambridge (Complianz) genuinely gate analytics behind consent, Aston's trackers are consent-gated, and U-Maths avoids third-party analytics entirely by running the first-party AnalyticsWP. But several don't:

  • Leeds runs no consent banner at all while firing Google Analytics (two properties), Tag Manager and three separate Meta Pixels.
  • Liverpool also has no banner; its generated template policy omits the Meta script that actually loads.
  • Imperial's banner is notice-only — GA4, Tag Manager and a Meta Pixel set cookies before any consent, and the cookies page names none of them.
  • Lancaster has a proper CookieYes banner, but the site loads a Meta Pixel, LinkedIn Insight, an X/Twitter ads pixel and Google Ads remarketing that the cookie policy never mentions.
  • 1729 runs the heaviest stack of all — HubSpot, Meta, Reddit and Google Ads — while its only privacy notice is Mill Hill's group document, which never mentions 1729 or any of these tools.

Consent & tracking, side by side

SchoolConsent toolWhat actually loadsPolicy vs. practice
ExeterCookiebotGoogle Analytics (GA4) — consent-gated behind Cookiebotconsistent
KCLContensis native cookie managerGoogle Tag Manager (GTM-59CCXK66)consistent
Liverpoolno bannerGoogle Analytics (GA4, G-1F1EX01PQR); Meta / Facebook script; Google Translate; LightWidget (Instagram embed)gap
Lancaster (LUSoM)GDPR Cookie ConsentGoogle Analytics; Google Tag Manager (GTM-MXKHR9D); Meta Pixel; LinkedIn Insight Tag; X / Twitter Ads pixel; Google Ads / DoubleClick remarketinggap
CambridgeComplianzGoogle Analytics (GA4, via Site Kit) — consent-gated; Vimeo; Google Mapsconsistent
Imperialcookieconsent — notice-onlyGA4 (G-EGHP5N4GN3); Google Tag Manager (GTM-NGSNSPS); Meta / Facebook Pixel; Google Maps; X / Twitter embedgap
Leeds (LMaS)no bannerGA4 (two properties); Google Tag Manager (GTM-MJDP2XS); Meta / Facebook Pixel (three)gap
SurreyCookie bannerGoogle Tag Manager; GA4; YouTube / Facebook / X embedsconsistent
AstonCookie bannerGoogle Analytics — consent-gated; Meta Pixel; Curator; YouTube; Vimeoconsistent
Durhamno bannernone detectedboilerplate
NottinghamGoDaddy Website Builder built-inGoDaddy first-party traffic analytics onlyno policy
1729CookieScriptGoogle Tag Manager + GA4; Meta / Facebook Pixel; HubSpot analytics; Reddit Ads Pixel; Google Ads / DoubleClick remarketing; Elfsightgap
U-MathsCookieYesAnalyticsWP — self-hosted, first-party (no Google Analytics)consistent
A fair caveat

This is a single-day, homepage-level observation. Tracker behaviour can vary by page, by region and by prior consent state, and a script present in markup isn't proof of unlawful processing. What it does show is a gap between the published policy and the observed page — the kind of gap a data-protection review would flag, and exactly the kind of thing a prospective family can't see from a prospectus. Read the methodology for the limits of this.

See it per school →