Student data privacy means schools must collect only what they need, secure it proportionately, document why they hold it, and act quickly if it is exposed. That's the whole obligation in one sentence. The practical starting point is simple: pull up your current privacy notice today, and if you're buying new software this term, start a data protection impact assessment before you sign anything, especially before purchasing new software.
TL;DR:
- Schools must restrict data collection to what is necessary, secure it appropriately, and document its purpose to comply with legal frameworks like FERPA and GDPR.
- Regularly review staff access permissions, enforce multi-factor authentication, and encrypt data to prevent breaches and minimize security risks.
- Maintain updated privacy notices, processing records, and retention schedules to demonstrate accountability and prepare for information requests within legal timeframes.
- Conduct a data protection impact assessment before purchasing new edtech to identify risks, verify vendor security, and include clear data deletion and audit rights clauses in contracts.
- In the event of a breach, quickly contain access, identify affected records, notify authorities or families per jurisdiction rules, and revise policies and training accordingly.
Table of Contents
- What legal frameworks govern student data privacy?
- How should schools protect student data day to day?
- What policies and records does a school need?
- How should schools manage edtech vendors and contracts?
- What should schools do when a data breach happens?
- Ten actions to take this term
- Balancing protection with a usable classroom
- Where to check the rules for your jurisdiction
- Sources
What legal frameworks govern student data privacy?
Three sets of rules shape most school obligations, and which ones apply depends on where a school sits. American schools work primarily under the Family Educational Rights and Privacy Act. FERPA gives parents and eligible students the right to inspect education records, and agencies must respond to access requests within a reasonable period and never more than 45 days. The statute also restricts disclosure without consent and requires schools to keep a record of who accessed what, spelled out in the underlying federal statute.
UK schools answer to UK GDPR and the Data Protection Act 2018. The core duties are transparency about what's collected and why, a documented lawful basis for processing, and a Data Protection Impact Assessment whenever processing is likely to pose a high risk to individuals, which almost always includes new edtech. Retention limits and stronger protections for children's data sit alongside these duties.
Beyond national law, the Council of Europe's Convention 108+ guidance frames children's data as inherently higher risk, because decisions made about a child's record can follow them for life. That's a useful lens even outside Europe.
None of these frameworks are interchangeable, so check your own jurisdiction:
- FERPA applies to US schools receiving federal funding
- UK GDPR and the Data Protection Act 2018 apply to schools operating in the UK
- Convention 108+ informs national law across Council of Europe member states
- When in doubt, follow your national regulator's published guidance rather than general online advice
How should schools protect student data day to day?
Good student information security rests on a handful of controls that most schools can implement without a specialist IT department. The order below reflects priority, not just chronology.
- Minimise what you collect. Every data field should have a clear purpose. Commentators studying edtech adoption describe a widening 'privacy-security gap' where schools gather far more than they use, which only expands the damage if something goes wrong.
- Apply least privilege access. Not every staff member needs to see every record. Role-based permissions and automatic session timeouts stop routine access turning into routine oversharing.
- Require multi-factor authentication for any account touching administrative systems or sensitive records, alongside reasonable identity checks before disclosing information to anyone requesting it.
- Encrypt data at rest and in transit, and keep backups encrypted and tested, not just present.
- Set device and email rules. Never send unencrypted personal information by email, and require passcodes or remote wipe on any device that holds student records.
- Patch systems on a schedule rather than reactively, and log access so unusual activity is visible.
- Run periodic security reviews. PTAC's data security checklist treats audits as a standing requirement, not a one-off exercise, and that repetition is what actually catches drift in permissions over time.
Pro Tip: Review staff access permissions every term, not just when someone joins or leaves. Role creep, where a teacher who once covered admin duties keeps that access years later, is one of the most common gaps auditors find.
What policies and records does a school need?
Accountability under most frameworks means being able to show your working, not just doing the right thing quietly. A published privacy notice should explain what data you collect, why, how long you keep it, and who it's shared with. GOV.UK guidance for schools treats this as a baseline expectation, published somewhere parents can actually find it, not buried in a policy PDF nobody opens.
Behind that notice sits a record of processing activities and a retention schedule that says when data gets deleted, not just that it eventually will be. When a parent or eligible student submits a subject access request, someone needs to know the timeline and the process for responding, and FERPA's 45 day ceiling is a useful benchmark even where it isn't the governing law.
Practical governance essentials:
- A named data lead or DPO who owns these decisions
- Staff training records showing who's been briefed and when
- Audit logs kept as evidence, not just as a technical byproduct
- Supplier documentation filed somewhere retrievable, not scattered across email threads
How should schools manage edtech vendors and contracts?
A DPIA belongs before procurement, not after. Treating it as a box to tick once software is already live creates retroactive compliance risk instead of the risk management it's meant to be. The assessment should cover what data the tool touches, who can access it, where it's stored, and what happens if the vendor is breached or goes under.
A working vendor checklist looks like this:
- Security certifications and evidence, not just a claim on the sales page
- A clear list of sub processors and where data is actually stored
- Written commitments on data deletion at contract end
- Audit rights, so you can verify claims rather than take them on faith
- A written data protection agreement, not a verbal assurance from a sales call
Pro Tip: If drafting bespoke contracts feels out of reach, use a regulator's own DPIA template rather than building one from scratch. Both PTAC and the ICO publish templates designed for exactly this situation, and using one is far cheaper than commissioning legal advice for every renewal.
What should schools do when a data breach happens?
Speed matters more than perfection in the first hour. Work through these steps in order:
- Contain access immediately and preserve logs before anyone starts "fixing" things.
- Identify precisely which records and which students are affected.
- Notify according to your jurisdiction's rules. Some require regulator notification within a fixed window; others focus on informing affected families directly. Check local rules rather than assuming.
- Reset credentials, patch the exploited weakness, and add monitoring for related accounts.
- After the dust settles, update your DPIA and policies, retrain relevant staff, and consider an external review if the breach was serious.
Ten actions to take this term
Educational data protection improves fastest when schools work through a short, concrete list rather than a sprawling policy rewrite:
- Refresh your privacy notice and retention schedule if either is over a year old.
- Run a DPIA before signing any new edtech contract.
- Enforce MFA on every administrative account.
- Review staff role permissions against actual job needs.
- Run a tabletop breach exercise and write down what it exposed.
- Audit existing vendor contracts for missing data protection clauses.
- Confirm backups are encrypted and restore-tested, not just scheduled.
- Check your subject access request process against your jurisdiction's deadline.
- Brief staff on email and device handling rules for student records.
- Diarise a quarterly review of everything above.
Balancing protection with a usable classroom
Locking everything down sounds simple until a teacher can't pull up a student's attendance record during a lesson because permissions were set too tightly. The trade-off is real, and pretending otherwise just pushes staff toward workarounds that undo the controls anyway. What works better is a rhythm: quarterly permission reviews, vendor checks timed to contract renewal rather than left to memory, and effort spent first on the datasets that would cause the most harm if exposed, like safeguarding notes or medical information, rather than spreading attention evenly across everything. Templates from regulators exist precisely so schools don't have to reinvent this from scratch.
— Package
Where to check the rules for your jurisdiction
For US schools, studentprivacy.ed.gov covers FERPA detail; UK schools should use GOV.UK's data protection guidance; the Council of Europe covers child-centred principles.
A platform like DojangHub illustrates the same discipline on a smaller scale: any system holding student or family records needs the same minimisation and access controls applied deliberately rather than left to default settings.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Protecting Student Privacy — Frequently asked questions
- Data protection in schools — procuring educational technology (edtech)
- Data security checklist — Privacy Technical Assistance Center (PTAC)
- As surveillance grows, student privacy protections lag
- Children's data protection in an education setting — Council of Europe
