Policy context: suspicious emails and protection of school information

Information
Your school’s acceptable use and information security policies require staff to treat unexpected messages, links, and attachments with caution, especially where they refer to pupil attendance, safeguarding, SEND, medical, or staff records. Under UK GDPR, personal data must be processed securely and protected against unauthorised access or disclosure, so a convincing email can still create a data protection risk if it leads you to reveal credentials or open malicious content. In practice, suspicious messages must be checked through a trusted route rather than acted on at face value.