By the middle of September, the transfer window should be closed. Pupils have moved, receiving settings have been identified and Child Protection Files should have followed them. For most DSLs, it will be months before transfer becomes a significant part of the safeguarding workload again.
Perhaps that is part of the problem.
In my final year as a DSL, I used the preparation of Child Protection Files for transfer as part of the handover to the colleague who would take over the role. I chose one pupil deliberately. In five years at the school there had been no safeguarding concerns: no referrals, no Early Help, no social care or police involvement, no home visits, no unexplained poor attendance, no concerns about parental engagement and none of the financial, uniform or packed-lunch concerns that can sometimes provide the first indication that something is wrong.
We used the function on our electronic safeguarding platform specifically designed to generate a Child Protection File for transfer.
It produced a 244-page document, with a cover sheet for the receiving DSL to sign.
A 244-page Child Protection File to transfer contained no child protection information.
At the time, I wanted to illustrate to the incoming DSL the difference between recording information and sharing it. I now think the 244 pages expose something more fundamental: electronic systems have changed the relationship between the DSL and the information recorded about a child. I would argue that our language, and some of our practice, have not kept pace with that change.
Most schools now use an electronic safeguarding system. This means that most children now have an electronic safeguarding profile. But not every pupil has safeguarding information recorded about them, and not all safeguarding information will become a child protection matter. Those distinctions matter, but our everyday professional language does not always preserve them particularly well.
We even turn the names of safeguarding systems into verbs. It is wonderfully efficient professional shorthand, but what exactly has the verb replaced: reported, recorded, referred, assessed? The language is convenient. The distinctions it conceals are not.
Throughout this Insight, I use Child Protection File for the record that Keeping Children Safe in Education tells schools and colleges to transfer when a child moves to another setting.[1] That choice is deliberate, because the terminology becomes less settled as national guidance filters through local procedures, trust and school policies, safeguarding systems and everyday professional language. Child Protection File becomes safeguarding file, safeguarding record, safeguarding information or simply the name of the electronic system a school subscribes to.
Those differences might appear merely semantic. I think they matter because safeguarding and child protection are related concepts, but they are not interchangeable. Working Together to Safeguard Children describes child protection as part of the wider work of safeguarding and promoting children’s welfare. Child protection concerns activity undertaken to protect specific children who are suspected to be suffering, or likely to suffer, significant harm. Safeguarding is much broader.[2]
It would be tempting, therefore, to conclude that a Child Protection File should contain only information concerned with that narrower child protection activity. The guidance does not allow such a simple conclusion. Information can properly need to be shared to safeguard a child without having crossed a child protection threshold. The new statutory guidance on information sharing, published in advance of the Information Sharing Duty coming into force on 30 September 2026, makes that particularly clear. Schools may hold information about behaviour, attendance, health or presentation that indicates emerging vulnerability or unmet welfare need, while apparently minor information may acquire greater significance when considered alongside information held elsewhere.[3]
That does not make the terminology unimportant. It makes it more interesting. If child protection and safeguarding have different meanings, but the thing national guidance calls a Child Protection File may legitimately contain information arising from the wider safeguarding function, then the name alone cannot tell us where the boundaries of the file lie.
Education has form for this. We routinely say teaching and learning so closely and so frequently that teachingandlearning can begin to feel like a single concept. It isn’t. One can happen without the other. I wonder whether something similar has happened with safeguarding and child protection. Habitual conjunction can disguise conceptual difference.
The same problem appears with reporting and recording. They are often treated as though they describe the same act. They do not. A member of staff reports something they have seen, heard, been told or become concerned about. The school records information about that report and the response to it. Between those two acts sits professional judgement: what has been reported, what is known, what remains uncertain, what action is required and how the information should be understood.
The threshold for reporting should be low. I never wanted a teaching assistant deciding whether something was sufficiently “safeguarding” before telling me about it. I wanted the information. That was one of the reasons we, like many schools, used the same electronic system to record behaviour, medical, pastoral and safeguarding information. As DSL, I valued having that intelligence in one place. A behaviour incident might mean nothing in isolation but look very different alongside a change in attendance, a visit to the medical room or something another member of staff had noticed. Just as importantly, the system did not require the person entering each piece of information to decide whether it was a safeguarding concern before recording it. That judgement could then be made where necessary, with a wider view of what was known about the child. But it did not follow that everything recorded on the system subsequently became safeguarding information, still less that it became part of an enduring Child Protection File.
For those of us who worked with paper Child Protection Files, the distinction was once much more physical.
The Child Protection File was an actual thing. In my early career, when I was a teacher rather than a DSL, it was almost a mythical thing. I don’t think I saw one in the wild for at least my first five years in teaching. The Child Protection File was separate from the main pupil record. It lived in a locked cabinet or drawer. Access was restricted. In my setting, even as DSL, I wasn’t allowed to look after the key to the cabinet. The Child Protection Files were kept under lock and key, and so, rather wonderfully, was the key. There was something almost ceremonial about the process. Find the key holder. Get the key. Open the drawer. Take out the file. Read what was already there. Add the new record. Update the chronology at the front. Put the file back. Lock the drawer. Return the key and watch it be locked away again.
I don’t want to romanticise that system. Paper files could be incomplete, badly organised and difficult to search. Information could remain elsewhere in school without ever being connected. A chronology was only useful if somebody maintained it properly. Access depended upon being physically present in the building.
For many schools, Covid accelerated the move to electronic safeguarding systems. I am profoundly grateful that my school had already made that move. When schools closed, pupils and staff worked from home, bubbles were created and children isolated, safeguarding did not stop. DSLs still needed to receive concerns, understand children’s circumstances and respond to them. A Child Protection File securely locked in a school office could suddenly become secure to the point of being inaccessible. Electronic systems allowed safeguarding work to continue across physical boundaries. Staff could report concerns without walking into the DSL’s office; DSLs could access previous information remotely; colleagues in different places could contribute to the same developing record.
I would not want the locked drawer back.
But its physicality did perform a function that was easy to overlook. Opening the file was an intentional act. Adding something to it was another. Updating the chronology required the new information to be placed, however briefly, alongside what was already known. The physical separation between the Child Protection File and other school records made a conceptual separation visible.
If something went into the Child Protection File, somebody had to decide to put it there.
That did not guarantee good judgement, but it made the decision difficult to avoid. By the time a pupil left, the file had been built incrementally through years of such decisions. An instruction to transfer the Child Protection File therefore operated on something whose boundaries had already, to a significant extent, been determined.
The locked drawer was not simply where we kept the file. In a fundamental way, it helped to tell us what the file was.
Electronic systems have removed many of those physical boundaries, mostly for very good reasons. Reporting is quicker. Records are searchable. Chronologies can be constructed more easily. Patterns can be identified across information that might previously have remained disconnected. Several professionals can contribute without needing simultaneous access to a physical folder.
But the paper file was created in response to something. And the electronic profile is created in anticipation of anything.
The relationship between the DSL and the information within that profile is therefore different.
The advantages of aggregation have a consequence. In the system as we used it, a behaviour incident could be recorded and remain a behaviour incident without the DSL ever seeing it. Attendance, pastoral and other information could sit within the same electronic environment as safeguarding records without having passed through safeguarding decision-making at all. Some information would acquire safeguarding significance. Some might contribute to a child protection concern. Some would remain exactly what it was when it entered the system.
Bringing information together does not make it all the same kind of information. If I keep golf balls in an egg box, it doesn’t mean I can eat them for breakfast. The absurdity illustrates a simple category error — a form of container-content conflation in which the character of the container is attributed to its contents. In an electronic safeguarding system, the same error is much easier to miss. Information does not become safeguarding information merely because it is stored in a system we describe as a safeguarding system.
This matters because an electronic safeguarding system can now perform several functions that were once more visibly separate. It can receive information, store it, connect it, categorise it, construct a chronology and generate documents from it. The fact that information sits in the same electronic container does not mean that it has the same professional status. Nor does its presence on a system used for safeguarding mean that the DSL has considered it.
The difficulty becomes easier to see if we distinguish four related things: the electronic pupil profile; the safeguarding record held within it; the Child Protection File constituted through safeguarding decisions; and the information disclosed when the child moves. Depending upon the system and the circumstances, those four things may overlap considerably. They should not simply be assumed to be identical.
The distinction becomes particularly important when the child leaves.
Consider a simple example I used when training my successor. A member of staff reports that a 12-year-old pupil is going out with a 14-year-old. I would want that reported. Age, developmental difference, consent, coercion, exploitation and power all require consideration. Imagine that those questions are explored appropriately, there are no additional concerns and the relationship subsequently ends.
Four years later, the young person is leaving for college.
The fact that the information was appropriately reported when the child was 12 does not answer whether it needs to be shared when they are 16. It may have been safeguarding information then. It does not follow that it remains necessary safeguarding information to share now.
One useful test is to imagine explaining the decision to the young person: We told your new college who you went out with when you were twelve.
Their entirely reasonable question would be: Why?
That question does not give the young person a veto over necessary safeguarding information. There will be circumstances in which information must be shared despite objection. But if our answer is simply because it was on the system, we have not given a safeguarding rationale. We have described where the information was stored. The new statutory guidance itself expects practitioners, where appropriate, to explain the purpose of sharing, what will be shared and with whom, while recognising that safeguarding information sometimes has to be shared without consent.[4]
Information does not acquire permanent safeguarding significance merely because it once required safeguarding attention. Children change. Circumstances change. Risk changes. The significance of information changes with them. Equally, old information is not necessarily irrelevant information. A historical incident may become crucial when considered alongside something that happens years later. The professional question is not how old the information is, but what significance it has now.
And if that judgement is necessary for information that genuinely required safeguarding consideration, the problem is clearer still for information that never crossed that threshold.
Return to the pupil with the 244 pages. Now imagine that, during those five years, there had been one genuine safeguarding concern. Would the existence of that concern suddenly turn the other 243 pages into the Child Protection File? If not, where would the file begin and end?
That question matters because Keeping Children Safe in Education instructs schools and colleges to transfer the Child Protection File separately from the main pupil file. The newer statutory guidance on information sharing asks a related but different question: what information is relevant to safeguarding and welfare, and what is necessary and proportionate to share for that purpose?[1][3] Those instructions do not need to be contradictory. But they can operate coherently only if we know what constitutes the Child Protection File in the first place.
The prior question is therefore not whether a DSL should remove two hundred pages from a Child Protection File before sending it. It is whether those pages became part of the Child Protection File merely because an electronic system included them in an export bearing that name.
This is where transfer itself becomes a more interesting word than I initially realised. It comes ultimately from the Latin transferre: to carry across. In the paper world, that description was remarkably literal. The file was here. It was carried across to another institution. Then it was there.
The transfer changed custody.
We did not ordinarily photocopy the entire Child Protection File, send the original to the next school and put the copy back into the locked drawer. The physical file moved. When the receiving DSL took possession of it, the originating school no longer held that file.
An electronic transfer is different.
If a school generates a PDF from an electronic safeguarding system and sends it securely to another institution, the underlying electronic record has not moved. The information has been reproduced and disclosed. Unless the originating record is subsequently deleted, School A still possesses it and School B now possesses information copied from it.
The old language describes an operation the technology no longer necessarily performs.
That matters beyond semantics because retaining information and sharing information are both forms of processing personal data. The fact that information has been disclosed to another institution does not, by itself, answer whether the originating school should continue to retain it. DfE data-protection guidance explicitly asks schools, when setting retention policy, to consider whether information still needs to be retained after it has been passed on.[5] Equally, the fact that the originating school has a lawful reason to retain a record does not mean that everything within that record necessarily needs to be disclosed to the receiving institution.
The paper model allowed several different ideas to sit comfortably inside the single word transfer: moving the file, changing custody of the record and giving the receiving DSL access to the information it contained. Digitisation has pulled those acts apart.
The electronic profile, the school’s safeguarding record, the Child Protection File and the information disclosed when a child moves may therefore be related without necessarily being identical.
That distinction helps to square an otherwise difficult circle. The record a school retains and the information it shares are not necessarily the same thing.
The new statutory guidance on information sharing makes that distinction particularly important. It says that where documentation such as a case file or access to a system is requested, but sharing that documentation is not necessary and proportionate, practitioners should consider providing the relevant information extracted from it instead. Its explanation to children and families is similarly clear that information should be limited to what is necessary rather than the entirety being shared by default.[3]
That is difficult to reconcile with any process in which the answer to what should we share? is determined simply by what an electronic system can export.
It also exposes a tension within the wider operational landscape. Some local safeguarding procedures tell schools to transfer safeguarding or child protection files in their entirety. Devon, for example, describes the safeguarding file as the record of all safeguarding concerns and says the information within it must pass in its entirety to the next setting. Plymouth goes further in addressing electronic systems directly: where a system contains information beyond immediate safeguarding concerns, including behaviour information, its current guidance nevertheless says the file should still be shared in its entirety.[6]
There may be sound reasons for preserving complete records in particular circumstances, especially where apparently minor historical information later contributes to an important pattern. But retain the complete history, consider the complete history and disclose the complete history are not the same instruction.
That distinction matters because the strength of electronic systems lies precisely in their capacity to accumulate and connect information.
The problem is not unique to safeguarding. I have seen something similar repeatedly through EHCP annual reviews. A child arrives in Year 7 with descriptions of significant dysregulation, physical outbursts or violence. At the time, those descriptions may be entirely accurate and essential to understanding need. Support works. The young person develops. By Years 10 and 11, those behaviours may have disappeared, sometimes for several years, while the language describing them remains embedded in the record.
Then somebody reads the document as though it describes the young person standing in front of them now.
The original information was not necessarily wrong. The young person changed; the record did not.
There is an important difference between preserving history and allowing history to impersonate the present. A statement such as “X assaulted members of staff” may remain historically true, but without a date, context, subsequent history or account of what changed, it can become functionally misleading.
KCSIE 2026 now addresses precisely this distinction. Safeguarding records should distinguish observed concerns, professional opinion and historic information. When a Child Protection File is transferred, the exporting setting should provide a structured summary identifying current concerns, relevant context and ongoing support needs. Particular care should be taken to distinguish current concerns from historic information and to give past issues appropriate context. The guidance goes on to say that safeguarding information should be used to support, not disadvantage, the child.[7]
That considerably strengthens the point. Accuracy is not simply a question of whether something once happened. It is also a question of whether the information, as presented now, allows its recipient to understand its current significance.
Safeguarding records accumulate childhood. Friendships, relationships, arguments, anxieties, mistakes, family difficulties, disclosures, suspicions, professional concerns and moments of vulnerability can remain long after the circumstances that gave them meaning have changed. Some of that history may be crucial to understanding current or future risk. Some may not. Remembering history is not the same as making every historical detail permanently portable.
That matters particularly at transition. A receiving college or training provider may be given historic information about behaviour, attendance, health, family relationships, parental conflict, friendships or allegations that were never substantiated. Some of it may need to be shared through safeguarding, SEND, medical or other appropriate processes. Some may be essential to keeping the young person safe. But the fact that information is accurate does not necessarily make it relevant to every later professional decision in which it might be encountered.
Information does not have to be inaccurate to become prejudicial. Accurate but irrelevant information can still influence the decision in which it is subsequently used.
The purpose of transfer cannot simply be to reproduce everything one institution has ever recorded about a young person in another institution. Its safeguarding purpose is to ensure that the professionals who will now be responsible for that young person have the information they need to safeguard and promote their welfare.
That sounds obvious, but even the grammar of our procedures can pull us away from it. We talk about transferring the file, sending the record, exporting the chronology. The file becomes the object of the sentence and the child can almost disappear from it. The professional task is not really to decide what to do with a file. It is to decide what another professional needs to know about a young person’s life in order to safeguard them.
There are two related frameworks here and they should not be collapsed into one. The new safeguarding information-sharing guidance repeatedly uses necessity, relevance and proportionality in determining what information should be shared. Data-protection law separately requires personal data to be adequate, relevant and limited to what is necessary for its purpose, alongside requirements concerning accuracy and storage limitation.[3][8] Both require us to know why information is being processed rather than assuming that possession alone justifies further disclosure.
Accuracy deserves particular attention because electronic records preserve information so efficiently. Something can remain factually accurate as a historical statement while becoming misleading as a description of the present. Good safeguarding recording therefore needs to preserve both the event and its subsequent significance: what happened, what was thought at the time, what action followed, what was learned and what is known now.
This is not a new problem created by software. More than twenty years ago, Eileen Munro examined the introduction of information and communication technology into child protection. Her conclusion was strikingly relevant to the present problem: the key difficulties in information sharing did not lie simply in the technical process of moving data between professionals, but in professionals’ ability to collect the necessary information, interpret it accurately and communicate it clearly.[9]
Technology has become vastly better at storing, connecting and moving information since Munro wrote that in 2005. Those professional tasks have not disappeared.
The same lesson continues to appear in national safeguarding review material. Working Together to Safeguard Children 2026 notes that rapid reviews and Child Safeguarding Practice Reviews have identified missed opportunities not merely to share information, but to record it and understand its significance. The Child Safeguarding Practice Review Panel has similarly continued to identify information-sharing difficulties, including failures of information to move between services and differences in the interpretation of policies, procedures and protocols.[10]
The problem is not simply that professionals fail to share enough information. Sometimes information is not sought. Sometimes it is partial or inaccurate. Sometimes it is recorded but its significance is not recognised. Sometimes fragments remain disconnected. Information does not protect children simply because somebody, somewhere, possesses it.
A computer can complete a technical transfer perfectly if everything sent from one system arrives intact in another. Safeguarding demands a different test of success. Did the information that needed to cross the boundary arrive, and did it arrive with enough context for another professional to understand its significance?
That requires professional judgement throughout the life of the record, and professional review at the point of disclosure.
The distinction matters. Review at transition should not mean rewriting the historic record, sanitising it, removing uncomfortable history or withholding information that a receiving DSL needs. The originating school’s record and the information shared from it are different questions. The task at the boundary between institutions is to understand the accumulated record well enough to decide what another institution needs to receive and to ensure that the information arrives with the context necessary to understand it.
Nor does this mean retrospectively applying a high threshold to what staff should report. The low reporting threshold remains important precisely because patterns can emerge from information that appears insignificant in isolation. The strength of the electronic system is that it can preserve those fragments and allow them to be considered together. The question at transfer is different from the question at recording.
Nor can review be reduced to redaction. There will be occasions when information must be restricted because sharing it would itself create a safeguarding risk. The new information-sharing guidance expressly recognises that adverse consequences may sometimes be mitigated by limiting what is shared, while also making clear that relevant information should not normally be withheld simply because it is sensitive.[3] Removing every third-party name does not necessarily make information safer or more useful. Sometimes the identity of another person is essential to understanding the risk. The question is not simply whose name is this? but does the receiving professional need this information to understand and safeguard the child, and could disclosing it create additional risk?
These are professional decisions, and professional decisions take time.
For some DSLs, this argument may produce a rather uncomfortable moment of recognition. They have transferred the Child Protection File their electronic system generated because that was what the system appeared to be designed to do. Press the appropriate button, generate the document, send it securely, obtain confirmation of receipt. Nothing about that sequence necessarily looks careless. Indeed, it may appear to follow both the language of the guidance and the workflow designed by the software. The difficulty is that successful completion of the process does not, by itself, answer whether the information produced by that process was the information that needed to be shared.
If that description feels familiar, the answer is not to begin tomorrow morning with a retrospective review of every electronic safeguarding record in school. It is to understand what the system currently does, decide what professional decisions need to sit around it, and begin to capture those decisions more deliberately as the record develops.
Other DSLs will recognise the problem immediately because they have spent years solving it retrospectively. They are the heroes of the transfer window: the DSLs who reach the end of the academic year and work backwards through hundreds, sometimes thousands, of entries, reconstructing the child’s safeguarding history, separating information that matters from information that merely happens to be there, checking context, considering third-party information, writing summaries and trying to produce something genuinely useful for the next setting.
Their professional judgement is not the problem. The timing of it is.
There will also be schools where the electronic system and the practice surrounding it already allow the transferable safeguarding record to develop as the child’s history develops. Even there, there is a useful question to ask. Does a marker created earlier in the child’s history prompt a fresh judgement at transition, or has it quietly become an instruction to disclose? Moving the automation one stage earlier does not solve the problem if the professional decision disappears with it.
The three starting points are different, but they lead towards the same question: where, in our process, does a human being make the final decision about what another setting needs to know?
For schools reconstructing the Child Protection File retrospectively, there is a more useful question than how to review electronic records more efficiently in July: how can we design our systems so that we do not have to reconstruct the Child Protection File retrospectively at all?
DSLs already make professional judgements about the information reported to them. They triage concerns, categorise them, consider them alongside what is already known, record actions and outcomes, and decide what happens next. We do not need to invent another safeguarding process. We need to capture one additional judgement at the point when the DSL is already considering the information:
This should be considered for transfer.
The wording matters. Considered for transfer is not the same as transfer. A concern recorded in Year 7 may be highly significant at the time and have little continuing relevance when the young person leaves in Year 11. Conversely, something apparently minor may acquire greater significance when later information reveals a pattern. The final decision about disclosure must still be made in the circumstances that exist when the child moves. The tag records a judgement for future consideration; it does not settle that future judgement.
It should function as a prompt to review, not an instruction to disclose.
The paper system did this almost accidentally. Putting something into the Child Protection File was itself a form of tagging. Its physical location recorded a professional judgement that this information belonged within the child’s enduring safeguarding record. Nobody needed to add a label saying consider this when the child leaves. The fact that it was in that particular folder did the job.
An electronic system needs us to decide how we will achieve the same thing.
How that works will depend upon the platform. It may be possible to use a category, tag, flag, status, custom field or another feature already available within the system. Schools should explore the settings and functionality of the platform they use rather than assuming that its default configuration determines good safeguarding practice. The important question is whether there is a practical way, when the DSL is already triaging and responding to information, to mark material that should form part of the eventual consideration at transition.
The aim is to recreate the decision, not the drawer.
That does not mean restricting what staff report. The broad electronic profile can remain broad. Staff should continue to report information without having to determine its eventual safeguarding significance. Behaviour, attendance, medical and pastoral information can continue to contribute to the wider intelligence available to the DSL. The golf balls can stay in the egg box. What matters is that their presence there does not make us forget which ones are eggs.
Over time, a consider for transfer marker would allow a potential transfer record to develop alongside the much wider electronic profile. When circumstances change, the judgement can change too. A later entry can provide context. A concern can be resolved. Something previously unmarked can become significant because of a developing pattern. The electronic record retains the history while also retaining evidence of the professional judgements made about that history.
Tagging reduces search. It does not replace judgement.
At transition, the task then becomes one of review rather than reconstruction. The DSL starts with information that has already been identified for consideration because colleagues made those judgements while the circumstances were live and understood. They can review it against what is known now, consider whether anything else has acquired significance, decide what remains relevant and necessary to share, and provide the receiving DSL with the context needed to understand it.
This does not remove the need for professional judgement at transfer. It puts that judgement in a much better position.
Nor is this simply a solution to the annual pressure of the summer transfer window. Children do not always move conveniently in July. A change of placement, a family move or another change of setting can happen with little notice. KCSIE explicitly requires appropriate arrangements for safeguarding information to be transferred, reviewed and actioned at all transition points, including in-year moves.[7] A transfer record that develops alongside the safeguarding record therefore leaves the DSL better placed whenever responsibility for safeguarding the child passes to another institution.
There is an obvious piece of quality assurance that follows. Schools should test what their electronic system actually does before the transfer window arrives. Take a pupil with no safeguarding history but substantial other information and generate whatever the platform describes as its Child Protection File or transfer record. Do the same with a pupil with a historic, resolved concern and, appropriately and securely, with a more complex safeguarding history. Look at what the system produces.
Does it correspond with what the school believes a Child Protection File to be? Does it include information that has never been considered by the DSL? Are categories preserved in the output? Does it provide context or simply chronology? Can particular records be marked for later consideration? Can those decisions be revisited? Can the transfer output be constructed from those markers rather than from everything attached to the pupil? What happens to third-party information? What remains on the originating system afterwards?
Those questions are not solely for the DSL.
A headteacher might reasonably ask whether all Child Protection Files have been transferred. A trust safeguarding lead might reasonably seek assurance that every school has completed the process within the required timescale. Those are necessary questions, but they establish that a process has occurred. They do not establish that everyone means the same thing by Child Protection File, or that the quality of the professional decisions sitting behind the process is consistent.
A useful leadership exercise is therefore disarmingly simple: show me what you transfer.
Then ask: show me how it became the Child Protection File.
Those questions can be asked without being an expert in the particular safeguarding platform. They move assurance away from policy and completion rates and towards actual practice. What information does the system hold? What does the DSL see? How is safeguarding significance determined? What does the transfer function produce? What professional review takes place before it is sent? What does the receiving setting receive? What remains afterwards?
Across a trust, those questions acquire another significance. Every school may report that 100 per cent of Child Protection Files were transferred within the required timescale while the underlying practice differs considerably. One school may transfer everything the platform generates. Another may undertake extensive retrospective review. Another may have developed a system for identifying potential transfer material as concerns are considered. Completion may be consistent while practice is not.
That is not an argument for imposing identical technical processes across every school. Platforms, settings and safeguarding contexts differ. It is an argument for being clear about the professional principles that should remain consistent beneath them.
If the answers are unsatisfactory, July is the wrong time to discover them. Explore the platform’s settings and features. Speak to the provider where necessary. Adjust categories, permissions, workflows or local procedures where the platform allows it. Where it does not, design a manageable professional process around that limitation. The software should support the school’s safeguarding practice; the school’s safeguarding practice should not be determined by whatever the software happens to export.
Crucially, this should not become another task handed to the DSL because somebody has identified a new safeguarding problem. If the issue concerns the configuration of a whole-school system, the time available for professional review, the consistency of practice across settings, data retention, information governance and the quality of leadership assurance, then responsibility sits more widely than the DSL’s office.
The question for leaders is therefore not simply whether the DSL has transferred the files. It is whether the organisation has created the conditions in which the DSL can make good decisions about them.
That may require a headteacher to sit beside the DSL and look at what the system actually produces. It may require a DPO to help distinguish questions of retention from questions of disclosure. At trust level, it may require comparing practice across schools rather than assuming that a common policy produces common practice. It may require protected time, changes to system configuration or a conversation with the software provider.
There remains a workload implication. Even a well-designed system will not remove the need to review a child’s safeguarding history at transition. Nor should it. Circumstances change, relevance changes and the receiving setting may need information that could not have been anticipated years earlier. But there is a considerable difference between reviewing a transfer record that has developed through contemporaneous professional judgement and conducting an archaeological excavation of five years of electronic data in the final weeks of the summer term.
The software can produce the PDF in seconds. It cannot decide what another DSL needs to know. But it can be configured and used so that the judgements DSLs make throughout the child’s time in school are not lost when that PDF is eventually required.
There is therefore a practical sequence underneath all of this. Staff should be encouraged to report with a low threshold. Information should be recorded accurately. DSLs should triage, categorise and record their actions and outcomes. Where appropriate, information should be marked for consideration at transfer while its significance and context are understood. At transition, that developing record should be reviewed against the child’s current circumstances. Relevant information that needs to be shared can then be disclosed purposefully and proportionately. Finally, the originating school should be clear about what it continues to retain, for how long and why.
Those verbs describe different professional acts. Electronic systems make it very easy for them to blur into one another.
There is a simple test that might reveal quite a lot. Ask a DSL to show you the Child Protection File for a pupil on their electronic safeguarding system.
Where is it?
If the pupil has never had a safeguarding concern, is there one? If a single safeguarding concern is added tomorrow, does a Child Protection File suddenly come into existence? If it does, which of the information already held on the system becomes part of it? If it does not, what determines what does? Is the Child Protection File the electronic profile, the safeguarding record within it, a collection of particular records constituted through professional decisions, the document produced when Export is pressed, or the information selected for disclosure to the next setting?
And after that information has been “transferred”, what remains behind?
Those are semantic questions, but they are not merely semantic questions. The answers determine what information follows a child from one institution to another, what information remains with the institution they have left, and what professional decisions are made about both.
Perhaps we have been asking them too late. In the paper world, many of the decisions that constituted the Child Protection File were made as the file developed. The physical record itself maintained a boundary between what was in the file and what was elsewhere, and transfer physically moved that record from one institution to another.
Electronic systems have changed both parts of that process. They allow the boundaries within the record to remain less visible, and they allow information to cross an institutional boundary without leaving the institution that sends it. The technology has changed what it means to record, what it means to hold, and what it means to transfer.
Our language has remained remarkably stable.
Which brings us back to the transfer window.
By September it may be closed. The files have gone — except, in the digital world, they may not actually have gone anywhere.
The more useful time to ask what we mean by a Child Protection File is not when a child is leaving.
It is when we start to construct it.
Notes and sources
[1] Department for Education, Keeping Children Safe in Education 2026, September 2026, paras 150–152 and Annex B, pp. 185–186. KCSIE requires the DSL to ensure the Child Protection File is transferred to the new school or college promptly, separately from the main pupil file for schools, with secure transit and confirmation of receipt. Annex B provides further requirements for managing and transferring the file.
[2] Department for Education, Working Together to Safeguard Children 2026, March 2026, p. 9. The guidance defines safeguarding and promoting children’s welfare broadly and states expressly that child protection forms part of safeguarding, defining it as activity undertaken to protect specific children suspected to be suffering, or likely to suffer, significant harm.
[3] Department for Education, Information Sharing to Safeguard Children and Young People, statutory guidance, September 2026, particularly paras 25 and 32–33 and the practice guidance on explaining information sharing. The guidance recognises the relevance of information held by schools about behaviour, attendance, health and presentation; requires relevant safeguarding information to be shared; says that where provision of an entire case file or system access is not necessary and proportionate, relevant information may instead be extracted or summarised; and states that information is not to be shared in its entirety by default. The statutory Information Sharing Duty under section 16LA of the Children Act 2004 comes into force on 30 September 2026.
[4] Department for Education, Information Sharing to Safeguard Children and Young People, September 2026, pp. 26–27. The practice guidance says practitioners should explain, where appropriate, the purpose of sharing, what information will be shared and with whom; acknowledge children’s and parents’ concerns; and avoid presenting information sharing as optional where consent is not required.
[5] Department for Education, Data Protection in Schools: Record Keeping and Management, updated 9 July 2026. DfE advises schools to retain personal data only for as long as needed and says retention policies should consider whether information still needs to be kept after it has been passed to another organisation.
[6] Devon County Council, Transfer safeguarding information and files, and Plymouth Safeguarding Children Partnership, Guidance on the Transfer of Child Protection and Safeguarding Files. Devon describes the safeguarding file as the record of safeguarding concerns held by the DSL and advises that it be passed to the next educational setting in its entirety. Plymouth similarly states that all information in the file should be transferred and specifically says that where an electronic system also records matters beyond immediate child protection and safeguarding concerns, such as behaviour, the file should still be shared in its entirety. These are local operational procedures rather than national statutory guidance.
[7] Department for Education, Keeping Children Safe in Education 2026, Annex B, pp. 185–186. KCSIE states that safeguarding records should distinguish observed concerns, professional opinion and historic information. At transfer, the exporting setting should provide a clear structured summary of current safeguarding concerns, relevant context and ongoing support needs; historic information should be appropriately contextualised; and safeguarding information should be used to support rather than disadvantage the child. It also requires arrangements for safeguarding information to be transferred, reviewed and actioned at all transition points, including in-year moves.
[8] Information Commissioner’s Office, Principle (c): Data Minimisation and A Guide to the Data Protection Principles. Article 5 UK GDPR requires personal data to be adequate, relevant and limited to what is necessary for the purposes for which it is processed. Separate principles address accuracy and storage limitation.
[9] Munro, E. (2005), “What tools do we need to improve identification of child abuse?”, Child Abuse Review, 14(6), pp. 374–388. DOI: 10.1002/car.921. Munro argues that key information-sharing difficulties do not lie primarily in the technical transmission of data but in professionals’ ability to collect necessary information, interpret it accurately and communicate it clearly.
[10] Department for Education, Working Together to Safeguard Children 2026, para. 29; Child Safeguarding Practice Review Panel, Annual Report 2023 to 2024, paras 5.35–5.38. Working Together notes that safeguarding reviews have identified missed opportunities to record information, understand its significance and share it in a timely way. The Panel’s annual report identifies continuing information-sharing problems between services and notes that differing interpretations of policy, procedure and protocol can contribute to them.