GDPR for schools – a useful short guide

In this article on GDPR for schools we will explore:

  • what GDPR is
  • who is responsible for GDPR in schools
  • special protections for children under the GDPR
  • how GDPR rights work for children
  • GDPR and safeguarding
  • Risks to be aware of
  • Our top tips
About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

What is GDPR?

The General Data Protection Regulations (GDPR) is a Europe-wide framework for data protection. The aim was to create a standardised approach to information security and lawful ways to use personal data across the EEA. It was brought into UK law by the Data Protection Act 2018. In short it:

  • describes six key principles that underpin the use of personal data
  • lists the lawful ways personal data can be processed
  • sets out the rights people have to know and control how their data are used
  • defines classes of sensitive personal data that need greater protection
  • defines data breaches and how they should be responded to.

The GDPR applies to all organisations processing personal data, including schools.

GDPR for Schools: Who IS Responsible?

The senior management team in a school is ultimately accountable for data protection in schools, but different people have different responsibilities. In reality, like health and safety or safeguarding, everyone has a role in compliance.

At a minimum every school must have a Data Protection Officer (DPO) who has a certain level of expertise in GDPR. In addition people need specific role based training depending on their roles – a teaching assistant will need different skills to a department head or manager, and in turn staff with responsibilities for human resources or finance will need different skills again.

Our experience: while short courses as part a suite of mandatory training is a good start people need more focussed, role specific support. This is partly because it helps them perform their duties better, but also people value this type of training more.

 

Are there special protections for children under the GDPR?

The GDPR doesn’t have specific provisions for the use of children’s data (children for the purposes of GDPR being anyone under 18). It does recognise the particular needs of children however.

Because children are less likely to be aware of the risks relating to the use of their personal data, and less able to make decisions in their own best interests, additional care must be taken to help them understand how and why their data are being used and ensure they do not come to harm.

In addition people working with children will be more likely to have sensitive personal data such as that relating to health, family life, and other categories of sensitive personal data that has further protections under GDPR.

Schools, and anyone working with children, must be mindful of the first data privacy principle. This says that data processing must be lawful fair and transparent.

The concepts of fairness and transparency are important here because it is harder for children to understand why and how their personal information is being used but as noted below you are responsible for explaining this to children in a way that they will understand.

Our experience: we have found that people sometimes confuse fair and nice. Fair means the appropriate, proportionate use of data to achieve a desired outcome – not necessarily the same as what people want you to do.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Do GDPR rights apply to children?

Children have the same rights under the GDPR as adults. They apply from birth. Clearly this will present a challenge to schools. Unlike adults in general there is a real risk children will not understand how and why their data are being used or the consequences of any action they take in relation to this. This means assessing a child’s competence to control their data is important.

The most important first step you can take when it comes to children’s GDPR rights is providing privacy information in a way that they can understand. This may mean using videos or animations rather than text to help them.

Our experience: people often treat their privacy information as a legal document. They use dense legalistic language to set out their uses of personal data. While a privacy statement is a legal requirement, it does not need to be written like terms and conditions or a contract. Instead it is a great opportunity to explain in the simplest terms what you do with personal data and why.

How does GDPR relate to safeguarding?

GDPR for schools will always need to be mindful of safeguarding. The GDPR recognises there are circumstances where information needs to be used for health, education, social work and safeguarding purposes.

While the rules can feel complex you can share information for safeguarding and the GDPR does not inhibit that. Your DPO will have a key role in supporting this critically important work.

Our experience: we have occasionally seen a reluctance to share information for safeguarding purposes because of data protection concerns. It is never appropriate to put vulnerable people at risk and there are clear grounds under GDPR to share personal data to protect them from harm.

GDPR for Schools: The Risks

There are particular risks when is comes to processing the data of vulnerable people like children. The biggest compliance risks with GDPR for schools are:

  • failing to provide privacy information in a child friendly way
  • not recognising that children have the same rights as adults under the GDPR
  • not recognising and acting on data breaches speedily
  • retaining data for too long and not disposing of data when it is no longer needed
  • not understanding the lawful basis for the data processing being done.

There are also real opportunities for schools when it comes to GDPR compliance, like:

  • engaging with students and parents to help them understand how and why you use personal data
  • enhancing your reputation with all the people you deal with through that engagement
  • reviewing and rationalising your data use to reduce costs and improve efficiency.

Top Tips for improved compliance

  • engagement with students and their families will help you in two ways: you will be able to achieve an approach that takes account of their preferences, and they will understand the approaches you need to take to deliver all of your activities and duties
  • ensure everyone who works in your school knows what a data breach is, how to recognise one, and how to report it
  • explore the need for focussed role based training for people who need particular skills

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial