Education organisations process data about people who often cannot meaningfully consent, through platforms chosen centrally and used daily. Most regimes treat children's data as requiring additional care, and several restrict profiling or advertising directed at children outright.
The dominant practical issue is supplier control. Learning platforms, assessment tools and communication apps are adopted quickly by individual departments, and each one becomes a processor holding data about minors.
Where personal data flows
- Student records
- Enrolment, attendance, assessment, special educational needs and disciplinary records.
- Learning platforms
- Activity data, submissions, engagement analytics and communications inside third-party systems.
- Safeguarding and welfare
- Highly sensitive records with restricted access and specific retention expectations.
- Parents and guardians
- Contact details, payments, consent records and communications.
- Staff and research
- Employment records and, in higher education, research participant data with ethics oversight.
Priority risks
- Unreviewed edtech adoption
- Free tools adopted by individual teachers or departments, processing student data with no contract or assessment.
- Advertising and profiling
- Platforms monetising engagement data, which is restricted or prohibited for children in several regimes.
- Safeguarding record access
- Sensitive welfare records accessible to more staff than necessary, or retained without a defined schedule.
- Proctoring and monitoring
- Remote proctoring, biometric checks and activity monitoring deployed without impact assessment or alternatives.
- Transparency for young people
- Notices written for institutional readers rather than students, which fails the transparency standard regardless of accuracy.
Practical controls
- Operate a mandatory, fast approval route for any tool that will process student data, with a lightweight assessment.
- Confirm contractually that suppliers will not use student data for advertising, profiling or model training.
- Restrict safeguarding records to named roles with logged access and a defined retention schedule.
- Run an impact assessment for proctoring, monitoring or biometric tools and document the alternative offered.
- Publish age-appropriate privacy information alongside the formal notice.
- Define who exercises rights for students of different ages and record the position.
- Review platform default settings each academic year, since supplier defaults change silently.
Worth measuring
- Proportion of active edtech tools with a completed review and current contract.
- Safeguarding record access reviews completed on schedule.
- Impact assessments completed before deployment of monitoring or biometric tooling.
Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.