Trusted by over half a million customers

Our service is rated 'Excellent' on Feefo

Over 2,000 experts ready to help

Steps to protect parent and child data

Mom making childs hairstyle

Running a nursery means spinning several plates at once. You’re managing a business, children and parent queries, often all at the same time.

Not only are parents trusting you with their children but also with deeply personal information about their lives and payment details. While nurseries must comply with General Data Protection Regulation (GDPR) and the Data Protection Act 2018 to keep all data safe, protecting data isn’t just about being lawful. It’s an essential part of building trust with families and supporting your team.

With cybercrime continuing to present a risk for nurseries and early years educational providers, it’s essential to consider appropriate training, procedures and insurance in place.

Why cybersecurity matters in nurseries

Nurseries handle a lot of sensitive personal information. This includes children’s names, dates of birth, home addresses, parents’ contact details, and in some cases, bank information and medical notes. When a family chooses your nursery, they’re placing a great deal of trust in you to make sure their data is safe.

This isn’t a theoretical risk, either. In 2025, nursery group Kido International reported that they fell victim to a cyberattack resulting in the personal data of 8,000 children being stolen and exposed.¹ The criminals then proceeded to post profiles of the children online, as well as the private information of dozens of employees, including their National Insurance numbers.²  This highlights just how much damage one data breach can have.

If personal data falls into the wrong hands, it can be misused for identity theft and fraud, causing significant distress for the families involved. A data breach can also result in parents quickly losing confidence in your team, putting pressure on them to manage the concerns and questions from families.

Cybersecurity doesn’t need to involve complex systems or technical language. At its heart, it’s about protecting the people in your care.

Why personal data is so valuable to criminals

Personally identifiable information (also known as PII) is highly valuable to cybercriminals because it can be used in many different ways. This can include selling it on to other criminals, committing identity theft and open bank accounts in the victim’s name, holding victims to ransom, and carrying out various other crimes.

Children’s personal data can be particularly attractive to cybercriminals because misuse may go undetected for long periods³. In some cases, they can build up debt and even apply for loans in the children’s name⁴.

It’s easy to see why nurseries are becoming bigger targets of cyberattacks. If successful, they get access to the children’s information which is “clean” and the parent’s payment information which may mean they can get access to their money.

Being a smaller organisation doesn’t mean you’re less of a target. Cybercriminals can often focus on busy teams who might not have enough time or resources to invest in cyber awareness training⁵.

Practical steps to keep data safe

It doesn’t need to be complicated to protect your staff and families’ data. Implementing a few small changes, as below, can make a meaningful difference:

tick iconUse strong passwords – Encourage your team to use strong, unique passwords for email accounts, systems and databases logins. Make sure colleagues are not sharing logins.

tick iconLock your devices when not in use – If a device is unattended, even for a short time, it could pose a risk. Your teams should lock screens to prevent unauthorised access.

tick iconReduce access to information – Limit access so that staff can only see what they need to see for their role. For example, a nursery worker doesn’t need to have access to a family’s payment history.

tick iconBack up your data regularly – Doing routine backups of your data can make it easier to recover information if something goes wrong.

tick iconStore hard copies securely – If you have any printed documents, make sure that you have somewhere secure to store it. Avoid leaving files unattended.

tick iconHelp your team spot phishing scams – Make sure that staff understand the risks of phishing emails and that they know how to recognise suspicious messages. Encourage them to be cautious when clicking links or opening any attachments, especially if the email asks for urgent action, payment details or login information. If they're not sure, they should reach out to the sender of the message using trusted contact details rather than replying directly to the email.

Helping staff feel confident and involved

When it comes to cybersecurity, your team is your first line of defence. That’s why offering regular training sessions is an important investment.

Your team don’t need to be experts, but having a basic understanding of the common cyber threats could help prevent incidents before they happen. Encourage open conversations so that your team feels comfortable asking questions and confident that they have your support if they need to report a mistake.

Think about creating simple checklists, posters or reminders during team meetings to keep cybersecurity front of mind for your team without overwhelming them. Where possible, use real-life examples so it feels more relevant and easier to apply to their role.

For data that matters

Parents want a nursery that they can trust. Every piece of data matters, and by taking proactive steps to protect all the data you hold, you’re showing families and employees that you understand that responsibility.

Having a good cybersecurity strategy in place can help reduce the risk of a successful cyberattack, but no nursery is immune. That’s why it’s important to review your insurance and consider whether protection against cyber-related risks is appropriate for your organisation.

At Everywhen, we can help arrange nursery insurance as well as reviewing the cyber options available to you. To find out more, speak to a member of our team at newcare@everywhen.co.uk or 0330 123 5357 and discover how we can help support your nursery.

Let's talk

If you’ve added new services recently, or you’re expecting to, it’s worth having a quick chat.

Want to know more? Get in touch today on: 

newcare@everywhen.co.uk

0330 123 5357

jason-brown

Jason Brown

Head of Product - Care, Charity and Medical Malpractice

Jason Brown is a respected leader in the care insurance industry with over 15 years’ experience. He works across a number of insurance areas including commercial insurance and medical malpractice.

His current role is Head of Product - Care, Charity and Medical Malpractice at Everywhen. Everywhen combines regional care with national reach, deep sector knowledge and strong insurer relationships to deliver tailored solutions across 55+ schemes. We help our clients navigate everyday and emerging risks with confidence, always and at all times.

Sources:

Children's names, pictures and addresses stolen in nursery hack - BBC News

Nursery hackers threaten to publish more children's profiles - BBC News

Safeguard against child identity theft | Equifax UK

What is Child Identity Theft?

Why Cyber Criminals Target Small Businesses More

This information contained in this article is for general information purposes only. It does not constitute legal or other professional advice and cannot be relied upon as such. Should you have any queries, we recommend that you consult the appropriate professional adviser. The links provided in this document are for reference only. Please note that we are not responsible for the content of any linked site.