Skip to content

Personal Device Use in Schools: Guidance and Policy

Guidance for safe, secure and GDPR-compliant use of personal digital devices by visiting music teachers in schools, supporting teaching and administration

This document serves as a policy guidance framework and code of practice for Derby & Derbyshire Music Partnership (DDMP) visiting teachers working in school settings, providing clear operational and safeguarding guidance. 


1. The DDMP context 

DDMP coordinates provision but does not supply hardware or digital devices to teachers or support staff. Visiting teachers operate as independent professionals providing their own equipment to fulfil their teaching roles. 

Teachers and support staff routinely visit multiple school sites across the city and county, creating a challenge to align with the digital device expectations of each individual school's device policy. Modern music, instrumental and vocal tuition includes the use of digital technology. Consequently, this document establishes a rigorous, baseline designed to support device use in schools while maintaining safeguarding and GDPR requirements. 

Additionally devices support pupil progress, enabling immediate feedback, accurate modelling, and engagement with high-quality musical resources that enhance learning outcomes. 

  • Lesson administration: Teachers require immediate digital access to secure cloud services to manage pupil registers, track musical progress, and check asset management systems (such as instrument loans). 
  • Pedagogical delivery: Devices act as interactive teaching aids. They are used to play backing tracks, display digital sheet music, utilise tuning and metronome applications, and share specific educational media with pupils. 

Use of school-owned devices: practical limitations and exceptions

Where requested by the host school, teachers may access cloud-based platforms via school-owned devices as a temporary measure. However: 

  • the routine transfer of resources via email is not recommended due to security and version-control risks; 
  • the use of removable media (e.g. USB memory sticks) is strongly discouraged due to the risk of loss, unauthorised access, or malware transmission. 

This framework therefore maintains personal device use as the primary and most secure operational model, when managed in accordance with the safeguards set out in this document.

The role of smartphones and connected devices

Smartphones and connected devices are fully capable computers compressed into a highly portable format. For visiting teachers, navigating multiple school sites daily, smartphones represent a practical, convenient, and cost-effective method of accessing teaching materials.

Note for school leadership: DDMP recognises that schools increasingly foster strict "no phone" cultures. This policy ensures that necessary staff device use respects, protects, and reinforces that school culture 


2. Risk acknowledgment and safeguarding 

DDMP and its associated teachers and support staff are fully committed to upholding the highest standards of child protection and data security. We openly acknowledge that the presence of personal devices in a learning environment presents specific safeguarding risks that must be proactively mitigated. 


3. Code of practice for safe device use

Teachers and support staff are expected to strictly adhere to the following when teaching in schools: 
Teachers should activate Do Not Disturb (DND) or an equivalent on all active devices prior to entering the teaching space. This setting should be configured to entirely suppress and hide personal notification pop-ups, text alerts, and incoming call previews.

Devices will only be used to access resources, platforms, or applications directly relevant to their teaching.


4. Technical security and data protection 

Visiting teachers and support staff should implement technical safeguards to secure the pupil data they handle as part of their mobile administrative duties.

Biometric and passcode protection

Devices should be protected by a secure alphanumeric passcode or strong biometric lock (FaceID/Fingerprint). Devices should never be left unlocked or unattended. 

Cloud and secure local storage

Pupil registers, timetables, and lesson notes should ideally be accessed and processed within secure, browser-based cloud portals or authorised apps. Where local storage is required for offline access, any downloaded student files, names, or identifiable details should be kept within a secure, encrypted local drive or password-protected local storage area. 

Media restriction

Under normal circumstances, personal device cameras should not be used to take photographs or videos of students.

In some cases, such as formal examination submissions or externally moderated assessments, video recording may be permitted only where explicit prior approval has been granted by the host school, and where this aligns with the school’s consent, safeguarding, and data protection procedures. Wherever feasible, school-owned equipment could be used for this purpose. 

Controlled use of audio recording for pedagogy 

In specific instructional contexts, short audio recordings of a pupil’s performance may be used as a recognised pedagogical tool to support progress and reflective learning. Where such recordings are made, they should be: 

  • strictly limited to educational purpose 
  • stored and shared only via secure, approved methods 
  • aligned with existing contractual agreements between teachers and families regarding lesson support materials. 

These recordings should not be retained longer than necessary and should not be stored within unsecured personal media libraries. 

Data protection and GDPR compliance

All handling of pupil data, including names, lesson records, and any authorised audio or video materials, must comply with UK GDPR and Data Protection Act principles. In particular, teachers should ensure that: 

  • only the minimum necessary personal data is accessed and processed 
  • any sharing of pupil-related materials is conducted through secure, approved channels 
  • data is not duplicated unnecessarily across multiple platforms or personal storage areas 
  • any temporary data held on personal devices is deleted promptly once no longer required. 

Teachers remain responsible for ensuring that their practices align with both DDMP expectations and the host school’s data protection policies.