Blog

School data protection checklist

A practical data protection checklist for international schools: roles, retention, backups, subprocessors, parent consent, and GDPR-ready posture.

Schools hold sensitive data by default: child identities, guardian contacts, fee status, medical notes, assessment results, safeguarding logs. A data protection checklist is not legal advice — it is an operational tool so registrars, IT leads, and principals agree on what you store, who can see it, and how you recover when something goes wrong.

International schools face extra complexity: expat families, cloud vendors in multiple countries, and boards asking about GDPR while local law also applies.

Governance and roles

  • Named data protection lead (can be registrar or IT, not “everyone”)
  • Written privacy notice for parents at admission (privacy policy as school publication)
  • Staff acceptable use policy signed annually
  • Vendor list with contracts (SIS, email, WhatsApp Business, LMS)

Document decisions. Auditors and angry parents both ask “who approved this?”

Data minimisation

Collect only fields you use operationally:

  • Do you need both passport number and national ID?
  • Is medical data restricted to nurse role?
  • Are WhatsApp numbers separate from emergency contact?

Admissions forms often over-collect because a old PDF said so.

Access control

  • Role-based permissions in the SIS (no shared admin password)
  • Principal can see school-wide; teacher sees own classes
  • Finance sees fees; teachers do not browse guardian credit notes
  • Audit log for sensitive edits (marks, balances, medical notes)

Ask vendors: “Show me the log when a mark changed after report cards published.” Choosing an SMS includes security questions.

Encryption and hosting

  • HTTPS everywhere for portals
  • Encryption at rest on provider infrastructure
  • Understand primary hosting region (security page for Edument on Cloudflare)

Schools in EU/UK often ask about GDPR; schools in Pakistan or GCC ask about local guidance — map questions to your counsel.

Backups and restore

Backups that never restore are theatre.

  • Automated backups with retention policy
  • Restore test at least annually (tabletop: “SIS gone Friday 4pm”)
  • Tenant-level export if you leave a vendor

Edument OS includes tenant backup/restore controls on supported plans — verify your tier.

Subprocessors and WhatsApp

Cloud SIS uses subprocessors: hosting, email, analytics, payment (Paddle for pricing checkout). Maintain a register:

ServicePurposeData touched
SIS hostApplicationStudent/staff records
EmailNoticesGuardian email, attachments
WhatsApp BusinessFee noticesMobile, template content, PDF
Payment MoRSubscriptionsBilling contact, card via provider

WhatsApp fee notices must use business accounts — personal forwards fail compliance and audit.

  • Consent for photography separate from data processing consent
  • Opt-in documented for marketing vs transactional messages
  • Clear boundary: WhatsApp groups are not official records (parent portal vs WhatsApp)

Portal terms should match what staff actually do.

Retention and deletion

Define retention for:

  • Alumni transcripts (often years)
  • Financial records (tax dependent)
  • Safeguarding files (often longer, restricted)
  • CCTV if applicable (usually not in SIS)

When families leave, know whether you anonymise, archive, or delete — and how long.

Student and parent rights

Processes for subject access requests:

  • Who verifies identity before sending exports?
  • SLA (e.g. 30 days)
  • Format (PDF portal export vs CSV)

Train front office not to email full files to unverified addresses because “they sound upset.”

Incidents

Prepare before breach headlines:

  • Incident contact list (lead, head, legal, vendor support)
  • Template parent communication
  • Preserving logs without destroying evidence
  • Regulator notification criteria (jurisdiction-specific — involve counsel)

Tabletop a lost laptop with an exported CSV once a year.

Cross-border transfers

International school groups may store EU students on non-EU infrastructure. Standard contractual clauses or adequacy decisions may apply. Software choice does not replace legal review; /security and vendor DPA help counsel decide.

Multi-campus consistency

Multi-campus operations need one DPA with vendor, campus-level role templates, and no “Dubai spreadsheet of passport scans because IT said so.”

Day-one technical checklist for new SIS

  1. Disable default demo accounts in production
  2. Enforce strong passwords or SSO (Google Workspace SSO)
  3. Turn on audit logging
  4. Restrict export permissions
  5. Configure backup retention
  6. Review integration scopes (Classroom, Moodle)

Migrate from spreadsheets — do not upload legacy files with PII to personal drives during import.

Culture beats checkbox

Checklists fail when staff photograph screens into WhatsApp. Leadership must model portal-first, official-notice channels, and no shadow exports.

Closing

Data protection for schools is child protection and financial integrity dressed as compliance. Use this list with your counsel, publish honest privacy terms, and pick systems that log access instead of scattering truth across chats and tabs.

International school SIS checklist overlaps on vendor questions; features and demo for Edument OS security walkthrough.

DPIA and LIA basics for schools

Data Protection Impact Assessments matter when you add biometrics, large-scale CCTV analytics, or new cloud regions — counsel guides timing. Legitimate Interest Assessments may apply to some direct parent communication. Software does not replace legal templates; it should support export and deletion workflows counsel defines.

Safeguarding overlap

Child protection records may live outside the SIS — but attendance anomalies, guardian change requests, and pickup authorisations often touch it. Define which safeguarding notes are never visible to general teachers. Restrict medical fields to nurse roles. Log access when sensitive profiles are viewed.

Yearbook and social media consent should be separate flags on the student record. Do not infer consent from generic admission terms. Staff photographing events need quick lookup — “can we publish this student’s image?” — without browsing paper files.

Vendor due diligence questions

Send suppliers a short questionnaire:

  1. Where is production data hosted?
  2. Encryption at rest algorithm and key management?
  3. Subprocessor list updated how often?
  4. Incident notification SLA?
  5. Customer data export format on exit?
  6. Pen test or SOC report summary available?

Store responses with contract renewals.

Staff offboarding

When registrars or teachers leave:

  • Disable accounts same day
  • Rotate shared integration credentials they touched
  • Review export permissions they held
  • Confirm no school data on personal devices (policy + spot check)

Leaver process is data protection process.

Parent trust communications

After you improve systems, tell parents what changed in plain language: “Fee notices now come from the official school WhatsApp; balances live in the portal; we no longer discuss individual fees in class groups.” Transparency reduces conspiracy theories when channels shift.

Annual review calendar

MonthActivity
JanuaryAccess permission audit
AprilRestore drill
JuneRetention cleanup for leavers
SeptemberStaff AUP re-sign
NovemberVendor subprocessor review

Small recurring tasks beat panic before accreditation visits.

Summary

School data protection is operational: named owners, minimal collection, role access, tested backups, subprocessors documented, parent consent aligned with channels you actually use, and staff offboarding same-day. Software should log sensitive changes; culture should stop exporting rows to personal WhatsApp — checklist plus enforcement, not checklist alone.

Try Edument OS with your workflows

14-day card-required trial — demo students, fees, attendance, and WhatsApp notices included.

Your card will not be charged during the 14-day trial. Cancel anytime before day 14 — you will not be billed.