Update - WisePay
We are aware that many schools have been affected by the large data breach that WisePay suffered between 2nd – 5th October. From the communications that many of you have received and shared with us, WisePay have requested schools to help determine who has been affected by the breach and to assist WisePay to reach out to those affected parents.
We have spoken to WisePay about this approach as we feel that, where possible, they should be the organisation to contact those affected and remedy the data breach. Whilst schools can of course assist WisePay, on occasion it appears the level of support they have requested was excessive.
Whilst we have had communication with WisePay their position remains that they are unable to contact those individuals affected. We have queried this position and given some suggestions to assist them in remedying the breach but have not received a satisfactory response.
In the meantime we thought it best just to give some practical guidance to assist those schools affected: -
- WisePay (and not the school) are ultimately responsible for the data breach. Whilst schools can assist them (as they have requested), if this would involve a disproportionate amount of time, you are well within your rights to refuse to assist further.
- Should you refuse to assist, I would suggest communicating this to WisePay. We can assist with this communication.
- You do not need to contact the ICO directly. WisePay have already contacted the ICO and you do not have a separate obligation to do so.
- If you have any queries/questions about this data breach do contact us in the first instance and we will do our best to assist (and where necessary contact WisePay on the school’s behalf).
Related content
Over the coming months, we’ll unpack key changes, timelines, and practical steps your HR or leadership team in a school or multi-academy trust (MAT) should take now to be ready. In this post, we explain the key employment changes coming into force in April 2026.
This is a summary taken from Judicium’s DPO ‘Sofa Session’ from the 11th February, with our Data Protection consultant, Shaafah Mohamed. This session explored the use of CCTV within school settings and its link to data protection. Why CCTV is considered privacy intrusive, the legal basis for its use under UK GDPR, and practical steps schools should take to ensure compliance.
This blog is based on Judicium’s Safeguarding ‘Sofa Session’ from the 4th February 2026, with our resident experts Joanne Bocko and Sarah Cook.
This blog is based on Judicium’s Health and Safety ‘Sofa Session’ from the 28th January 2026, with our resident expert Alice Campbell.
The latest ERA implementation explains the imminent changes to trade union legislation, and several things that schools, trusts and colleges should do now to prepare.
This blog is based on Judicium’s Facilities ‘Sofa Session’ from the 14th January 2026, with our resident expert Joanne Fisher and Neil Merry. This session focused on premises safety, planning day-to-day, and contingency plans for when your caretaker is absent. Practical tips for auditing and ensuring correct regulations and training are in place.
Whats New | HR