School software and the GDPR: the questions to settle first
Data protection is the one part of this subject that genuinely does travel. The GDPR is a single regulation across the whole EU and the EEA, and the UK operates a close copy in the UK GDPR, so a school in Dublin, Rotterdam or Munich reads the same articles about school software. What differs underneath is not the framework but three things: which supervisory authority is competent for you, which national or regional law supplements the regulation, and who exactly counts as your data protection officer. This page works through the questions in the order a review actually takes them, and names examples where the answers diverge. One caveat belongs at the top rather than the bottom: if your school is outside the EU, the EEA and the UK, none of the article numbers below bind you. The questions still do – the citations you need are your own country's.
Coming soon
- GDPR-compliant
- Hosted in Germany
- Free for teachers
A product of SavePaper.work
Four questions that should be settled before a rollout
Who is the controller here?
Under the GDPR one body determines the purposes and means of processing, and for school data that is normally the school as an institution – not the individual teacher and not the provider. Everything else follows from that answer.
Which authority supervises you?
The regulation is EU-wide, the supervisor is not. In Germany that is the data protection authority of the federal state; in Ireland the Data Protection Commission; in the UK the Information Commissioner's Office. Find yours before you need it.
Who is your data protection officer?
A school run by a public body must designate one under Article 37(1)(a) GDPR. An independently run school has to test the other grounds in Article 37(1) instead. Either way, the DPO is the person who signs off on a rollout.
Which law sets your retention periods?
The GDPR says data must not be kept longer than necessary, but it never names a number. The number comes from your national or regional education law and differs by category of data. Software should reflect that instead of treating everything alike.
How a data protection review at school works
The review nearly always follows the same order, and the order is the same in every country that has a data protection regime at all: first clarify who is responsible, then describe what is processed, then read the contract, and finally set roles and retention periods.
-
1
Clarify responsibility
Who decides on purposes and means – the school alone, or the body that runs and funds it as well? This question comes first, because it determines who signs the contract, who answers to parents, and whether joint control has to be documented.
-
2
Describe the processing
Which data, for what purpose, visible to whom, for how long? In the EU and the UK these entries belong in the record of processing activities under Article 30, which the school keeps itself; where processing is likely to be high risk, Article 35 adds a data protection impact assessment before rollout rather than after. A provider can supply the building blocks for both.
-
3
Review contract and measures
The processor contract and the description of technical and organisational measures are read together: server location, sub-processors involved, encryption, deletion at the end of the contract, and the route by which the school issues instructions. If any processing sits outside the EU or the UK, this is where the transfer mechanism has to appear.
-
4
Set roles and periods
Configuration comes last: which role sees which detail, and which retention period applies to which category of data? The first is a school decision, the second comes from your education law. Both are set once for the whole school, not per teacher.
The same data, two ways of keeping it
The terms that come up in every review
Processing on behalf, responsibility and instructions
The processor contract under Article 28 GDPR is not a form to fill in but the description of a relationship. The school remains the controller and determines which data is processed for what purpose; the provider processes it solely on instructions and never for its own purposes. The agreement also covers duration and subject matter, the categories of people affected, the protective measures, support with access requests, the reporting of incidents, the handling of sub-processors, and what becomes of the data once the contract ends. Outside the EU and the UK the article number changes but the substance rarely does, because almost every privacy regime needs some way to bind a vendor who holds pupil data. That same division of roles explains why a grade list on a private laptop is the school's problem: the school stays responsible, yet on someone else's device it can neither limit access nor prove what happened to the file.
Grades, sick notes and the special categories
Not all school data is equally sensitive, and the line between them is drawn in similar places almost everywhere. In the EU and the UK the reason given for a sick note is health data and therefore falls into the special categories under Article 9 GDPR, for which stricter requirements apply. In practice this can be defused: for an absence record it is usually enough to know that the absence was due to illness, and a reason can stay voluntary. Grades and assessments do not fall under Article 9, which does not make them harmless: they describe performance over years and shape transitions and qualifications, which is why systems that have no Article 9 at all still protect them – United States federal law treats them as education records under FERPA, with its own consent and disclosure rules. Both point to the same conclusion wherever you are: tie visibility to the task, use free-text fields sparingly, and store sensitive content encrypted instead of spreading it across files and attachments.
Keeping, deleting, giving information
Every review ends with three questions: how long does the data stay, how does it disappear, and what happens when a family asks to see it? Retention is the one point where the GDPR deliberately gives no number – it requires only that data is not kept longer than necessary, and the actual period comes from your education law, differing by category of data as well: attendance in the register, report card data, sick notes and parent communication are kept for very different lengths of time. In Germany those periods are state law and vary between the sixteen federal states; in England they follow the retention schedules that apply to the school's records. A pile of spreadsheets and mailboxes cannot separate any of it, so nothing tends to be deleted there. Articles 15 and 20 add a second duty, mirrored by subject access rights in most other regimes: everything about one person has to be handed over, readable and machine-readable at once. SchuleVernetzt bundles this into a data protection view for the school leadership – a log of access and changes, a configurable period per category of data, and a subject access export per person.
What a school can ask the provider for
Four documents can be requested before deciding: the data processing agreement under Article 28, the description of the technical and organisational measures, a list of the sub-processors involved together with their location, and a processing description the school can feed into its own record of processing activities under Article 30. A provider who only assembles these papers on request delays the review by weeks. SchuleVernetzt keeps them ready, so that whoever runs your school and whoever advises it on data protection do not have to build anything themselves. Application and school data are hosted inside the EU, on servers in Germany, which is the point that matters for a school anywhere in the Union.
Frequently asked questions about school software and data protection
Be there when SchuleVernetzt launches
We're building SchuleVernetzt at full speed. Leave your email and we'll notify you the moment your school can get started – free and with no obligation.
We use your address only to notify you at launch, and you can unsubscribe at any time.