Skip to content

Sector guidance

Privacy for education

Children's data, third-party learning platforms and safeguarding records — a sector where transparency and vendor control matter more than documentation volume.

Education organisations process data about people who often cannot meaningfully consent, through platforms chosen centrally and used daily. Most regimes treat children's data as requiring additional care, and several restrict profiling or advertising directed at children outright.

The dominant practical issue is supplier control. Learning platforms, assessment tools and communication apps are adopted quickly by individual departments, and each one becomes a processor holding data about minors.

Where personal data flows

Student records
Enrolment, attendance, assessment, special educational needs and disciplinary records.
Learning platforms
Activity data, submissions, engagement analytics and communications inside third-party systems.
Safeguarding and welfare
Highly sensitive records with restricted access and specific retention expectations.
Parents and guardians
Contact details, payments, consent records and communications.
Staff and research
Employment records and, in higher education, research participant data with ethics oversight.

Priority risks

Unreviewed edtech adoption
Free tools adopted by individual teachers or departments, processing student data with no contract or assessment.
Advertising and profiling
Platforms monetising engagement data, which is restricted or prohibited for children in several regimes.
Safeguarding record access
Sensitive welfare records accessible to more staff than necessary, or retained without a defined schedule.
Proctoring and monitoring
Remote proctoring, biometric checks and activity monitoring deployed without impact assessment or alternatives.
Transparency for young people
Notices written for institutional readers rather than students, which fails the transparency standard regardless of accuracy.

Practical controls

  • Operate a mandatory, fast approval route for any tool that will process student data, with a lightweight assessment.
  • Confirm contractually that suppliers will not use student data for advertising, profiling or model training.
  • Restrict safeguarding records to named roles with logged access and a defined retention schedule.
  • Run an impact assessment for proctoring, monitoring or biometric tools and document the alternative offered.
  • Publish age-appropriate privacy information alongside the formal notice.
  • Define who exercises rights for students of different ages and record the position.
  • Review platform default settings each academic year, since supplier defaults change silently.

Worth measuring

  • Proportion of active edtech tools with a completed review and current contract.
  • Safeguarding record access reviews completed on schedule.
  • Impact assessments completed before deployment of monitoring or biometric tooling.

Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.