How are you addressing DPA issues with these?
We are starting to introduce iPads in the classroom but our Infosec Officer is keen that they are encrypted and restriction policies applied via some sort of MDM solution (our ICT department have committed to having an MDM solution in place fairly soon). I think they're going to be looking at staff devices having a complex password policy applied and therefore encrypted. This should keep the ICO happy!
We are also labelling them as being for "Staff use only - not to be used by pupils". Likewise, we are labelling pupil devices as "Pupil use only - Do not remove from school". This should be a sufficient "procedural measure" (to use ICO speak) to ensure that personal sensitive data is kept safe.
We're keen that schools are able to manage their app purchases locally, but think the LA might want to keep control for audit purposes.
I'd be interested what others are doing to ensure they comply with the Information Commissioners Office and the like....