Essential Steps for Execution
-
1
Appoint a
Post-Closure CustodianEnsure a legal entity (such as SDS or a local authority) is legally named to handle future Subject Access Requests (SARs) or litigation inquiries
-
2
Execute a
Data AuditCatalogue every filing cabinet, local server, and cloud application before physical decommissioning begins
-
3
Obtain
Transfer ReceiptsTake receipt of a legally binding, signed Transfer of Custody receipt, which will document exactly what was handed over to the custodian
Identifying the risks
-
Data Protection & Safeguarding Risks
Loss, breach, or unauthorised access to safeguarding or personal data
-
Commercial Lettings Risks
Disruption to commercial lettings operations
-
Estate Compliance & Safety Risks
Failure to maintain statutory compliance (fire, water, asbestos, electrical, insurance)
-
Operational Transition Risks
Failure to decommission educational operations safely and cleanly
-
Financial Risks
Financial instability during post-closure period
-
Governance & Oversight Risks
Insufficient oversight of archive integrity, compliance, and lettings performance
-
Reputational Risks
Reputational damage from poor communications or mishandling of legacy
-
Staffing & HR Risks
Production of a Risk Register
A Risk Register is a often-used method of identifying, assessing, and tracking potential threats and uncertainties that could affect a project or organization. It lists the likelihood of each risk, its potential impact, and the plan to manage or fix it. With our expertise and experience, SDS can help you create a Risk Register to ensure any potential risks are mitigated and you can conclude the school’s operations professionally and responsibly. An example is provided in the table below.
| Risk Description | Category | Impact Level | Risk Owner | Mitigating Action / Response Plan |
|---|---|---|---|---|
|
Loss or delayed transfer of Safeguarding & Child Protection files prevents continuity of care at the pupil’s new setting. |
Compliance / Safeguarding |
Critical
Severe legal and safety impact |
Designated Safeguarding Lead (DSL) |
Audit all active child protection files. Securely transfer files to the child’s new educational setting immediately upon closure via a signed, tracked delivery system.) |
|
Breach of UK GDPR / Data Protection Act due to insecure disposal or abandonment of physical/digital personal data. |
Legal / Regulatory |
High
Substantial fines from the ICO |
Data Protection Officer (DPO) |
Cross-reference all holdings against a formal data retention schedule. Hire an accredited secure shredding vendor (such as SDS) for physical assets and perform certified data wiping for digital servers. |
|
Failure to archive mandatory statutory registers (e.g., Admission and Attendance Registers) which must be kept for specified legal periods. |
Statutory Compliance |
Medium
Breach of education regulations |
School Business Manager / Headteacher |
Identify and package Admission Registers (required for 30+ years) and Attendance Registers. Formally transfer them to the Local Authority Archive Service or SDS. |
|
Destruction of financial, tax, and employment records prior to their statutory expiry timeline. |
Financial / Legal |
High
Breach of HMRC / Companies House rules |
Chair of Governors / Trust CFO |
Centralise all financial records (retained for 6 years after financial year-end) and staff training/HR files. Secure them with the remaining Local Authority or other custodian such as SDS. |
|
Loss of historic ‘School History’ artifacts causing a breach of local community trust and heritage guidelines. |
Reputational |
Low
Local complaint risk |
School Archivist / Clerk to Governors |
Identify logbooks, signed governor minutes, and historical photographs. Transfer ownership directly to the local county records office or SDS for permanent preservation. |
Production of a Closure Plan
The Production of a Closure Plan establishes a structured roadmap to manage the operational, financial, and legal complexities of winding down the school’s operations. This document outlines the critical governance steps required to maintain regulatory compliance, secure data assets, and manage stakeholder transitions responsibly.