I suspect they can, but who do you inform if something's happened? I work in the public sector and am aware that swingeing fines can be meted out to organisations that are careless with sensitive info, but is it the same with schools?
I ask because a kid at my DS's school got sent a letter informing them that they'd been suspended. It was obvious it was a cock-up because the details of the incident were quite distinctive and easy to disprove, and there'd been no lead-up as you might expect. It turned out that they'd been mixed up with another kid with the same name (think common name with unusual spelling).
Now obviously the parents are entitled to, at least, a grovelling apology. But the identifiability of this situation and the sensitivity of the info has created a breach of confidentiality (I have been deliberately vague about details and changed a fair few, just to be careful). So what are the potential repercussions for the school? Are they obliged to tell the Information Commissioner about this? And is anyone likely to get sacked for misconduct?