Data Privacy in Schools: How to Properly Handle Teaching Materials & Personal Data

Last updated:
15.05.2024
Data protection and schools go hand in hand. School operations involve the processing of a significant amount of personal data. This article outlines the applicable laws and regulations.
Data Privacy in Schools: How to Properly Handle Teaching Materials & Personal Data
Key Takeaways
  • Personal data in schools is protected by the GDPR, school laws, and state constitutions.
  • Data protection requires compliance with principles such as transparency, purpose limitation, and data minimization.
  • Photos and videos in schools always require explicit consent.
  • School administrations are responsible for data protection and are supported by data protection officers.
  • Digital media require specific data security measures and appropriate communication tools.

Data protection and schools are inseparable, as school operations involve the processing of numerous personal data. We explain what these are and which legal regulations schools should observe.

With the COVID-19 pandemic, data protection in schools has become increasingly important. Teachers are relying more and more on digital media that can also be used from home. Whether it's apps, online learning platforms, digital class registers, or teaching materials—communication between students, teachers, and parents takes place across a wide variety of channels, creating new data protection challenges that are strictly regulated in daycare centers and schools under the GDPR.

Why does data protection matter in schools?

The use of digital media in schools involves the storage and processing of numerous personal data. This data is protected by the General Data Protection Regulation (GDPR). Furthermore, school laws and state constitutions also contain regulations regarding data protection in schools. Among other things, it is stipulated that interference with the right to informational self-determination is only permitted in the overriding interest of the general public and on the basis of a law. The processing of personal data must not exceed the necessary scope and may only be carried out for the purpose for which the data was collected. In addition, data protection in schools and daycare centers dictates that every data subject has the right to access, rectification, restriction, data portability, and erasure.

In addition, data protection is also an educational task for schools: data protection requirements should not only be met for legal reasons, but also to set a good example for students and to sensitize them to the self-determined and responsible handling of personal data.

What data is processed in schools?

When thinking about "schools and data protection," student data is the first that must be collected and protected. Personal data of schoolchildren includes, for example: 

  • Name
  • Date of birth
  • Address
  • Grades

It should be noted that only data absolutely necessary for school operations may be used, such as name, address, date of birth, and grades. Since grades also count as personal data, they must be communicated privately to comply with data protection in schools and may not be announced aloud in front of the entire class.

However, it is not only the data of schoolchildren that is relevant for data protection in schools, but also the data of parents and teachers. For parents, for example, names, telephone numbers, and addresses are stored so that they can be reached in an emergency. For teachers, caretakers, cleaning staff, and other employees, the following data, among others, is collected and processed as is customary in an employment relationship:

  • Name
  • Date of birth
  • Nationality
  • Employee ID
  • Religion
  • Bank details

Considering that this data is collected, stored, and processed for all students, parents, and every teacher, it becomes clear how important data protection in schools is for these mountains of personal information.

What to keep in mind regarding photos and video recordings at school

Photos and video recordings at school are subject to specific data protection regulations. Their use is generally not necessary for school operations. Therefore, explicit consent for recording is required in these cases. If the photos are to be published, it must also be ensured that written consent is obtained from every person depicted. For minors, this is handled by their parents. In addition to consent, the specific purpose of the recordings should also be stated.

In principle, it should be noted that photo and video recordings always constitute personal data. This applies even if the people depicted are only partially visible and their names are not displayed. Therefore, the provisions of the GDPR apply.

In which areas must data protection be given special attention?

The law allows for the use of personal data insofar as it is necessary for the performance of school duties. Examples of this include recording academic performance or sending out school information. Any use of data that goes beyond the fulfillment of such tasks generally requires the consent of the parents. If the student has already reached the age of majority, they can provide consent themselves.

The use of digital media also requires specific data security measures: access rights and permissions, for example, precisely regulate who has access to the data. Public bodies that process personal data automatically must also appoint a data protection officer. They fulfill the following tasks:

  • Advising the school on the implementation of data protection
  • Data protection oversight in schools
  • Contact for parents and students

When no data protection officer is available, teachers and school administrators are often left to fend for themselves. The resulting responsibility frequently places a significant additional burden on school staff. However, it is not just the selection of appropriate digital media that requires a delicate touch. Ultimately, data protection extends to all areas where personal data is processed.

GDPR and schools: Which legal regulations must be observed?

For public schools to meet the data protection requirements of the GDPR, several points must be considered. Here is a selection:

Principles for the processing of personal data

As in any organization, the principles for processing personal data as set out in Art. 5 of the GDPR also apply to schools. Data processing must be transparent, lawful, and fair; it must be for a specific purpose and limited to what is necessary. Furthermore, storage periods must be observed, and the accuracy and security of the data must be guaranteed.

Email

It is important that schools ensure appropriate encryption when communicating via email to comply with data protection regulations. Ideally, an address with encryption technology should be set up. Under the GDPR, the use of services like Gmail, which exchange data via American servers, is no longer permitted for schools.

School website

If a school operates its own website, the various requirements of the GDPR must be implemented there as well. In short, this includes a complete legal notice (Impressum), a privacy policy, and a GDPR-compliant cookie notice. If the website also features a contact form, it must run over a secure connection.

WhatsApp & Co.

While some teachers may find it practical to communicate with their students via WhatsApp or Facebook, the situation looks different from a data protection perspective: as with Gmail, all information on WhatsApp and Facebook flows through American servers. Furthermore, user contact data is harvested. These services should therefore be strictly avoided. However, there is no need to forgo messenger communication entirely, as there are German and European providers that meet data protection standards for schools. These include, for example, Threema, Signal, SIMSme, or Hoccer.

Who is responsible for data protection in schools?

The school administration is responsible for ensuring that data protection in a public school is maintained and implemented in accordance with the GDPR. They are supported by a school data protection officer. Like other public bodies that process personal data automatically, schools are required to appoint a data protection officer (DPO). This person holds an advisory and oversight role regarding school data protection and acts as a contact person for students, their parents, and teachers.

Digitalization, schools & data protection – do they go together?

It is not new that schools are gradually introducing digital offerings. However, this development was further accelerated by the outbreak of the coronavirus pandemic, which made its necessity obvious. Whether it is digital class registers and teaching materials, e-learning platforms, digital reading support, or holding video conferences while students are homeschooling—there are many ways to integrate digitalization into everyday school life. However, the challenges that arise in the area of data protection are not diminished by this.

Nevertheless, there is nothing to prevent the use of digital tools in the classroom, provided that two points are observed:

  • Whether analog or digital, the data protection principles set out in Art. 5 GDPR and other requirements of the General Data Protection Regulation must be rigorously adhered to by schools.
  • Furthermore, the security of the data used must also be guaranteed. This can be achieved through appropriate data security measures.

All in all, it is clear that a vast amount of data is processed by various parties in everyday school life—and that digitalization only intensifies this fact. Data protection is therefore an extremely important issue for schools. Data protection regulations establish specific rules for schools and parents regarding the handling of personal data. Even though the GDPR provides for some exceptions in data processing with regard to the purpose of data collection, teachers and parents should take the matter seriously. Whenever the use of data is not strictly necessary for school operations, the individuals concerned must consent to the data processing. This often presents teachers with significant challenges and also raises questions for students and parents. Information and support for teachers in this regard are usually provided by the respective state ministries of education.

If you are unsure about implementing data protection and handling personal data correctly at your school, please feel free to contact us. The Proliance team is here to provide you with competent and professional assistance with all your data protection questions.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in