The General Data Protection Regulation (GDPR) is a piece of EU-wide legislation which determines how people’s personal data is processed and kept safe, and the legal rights individuals have in relation to their own data. It applied from 25 May 2018 to organisations that process or handle personal data, including schools.
It's similar to the Data Protection Act (DPA) 1998 in many ways. Most of the differences involve the GDPR building on or strengthening the principles of the DPA.
The full General Data Protection Regulation has been published by the Council of the EU.
The UK has implemented the GDPR despite its intention to leave the EU.