As I've got some responsibility for our Academy Trust website content and policy, I often have a browse around other academy chains to see if there are any good ideas or anything I might have missed. It's not unusual to see websites that don't have everything I'd expect to see for Data Protection and GDPR. My question is, who actually cares? Does the ICO? Is it only when something happens that they might take a look? Is it up to parents to say something?
Take this as an example - I can't see anything there that suggests GDPR has even been considered in the recent past either in policy or on the website, even the DPA content looks c+p from elsewhere. Ok, it's not the greatest site in the world but not even having the bare bones of GDPR seems reckless to me.
Maybe I just have to get over it, keep our own house in order, and accept that some decide to chance it and get away with it...