Data protection in schools
Guidance for legislators, policy makers and schools
Highlights
The use of data and digital technology in children’s education can be a powerful tool that has the potential to provide access to quality learning through engaging and tailored experiences. However, insufficient safeguards can lead to the processing of personal and sensitive personal data of children and staff by a variety of actors, including the school, government, third parties and private commercial establishments. Reliance on technology to provide and manage education and the scale of data collection therefore holds significant risks that must not be overlooked.
The Data protection in schools: Guidance for legislators, policy makers and schools, intends to serve as a practical guide for schools aiming to implement good practices in data protection and privacy. The guidance includes recommendations for a range of stakeholders and is arranged in four parts:
Part 1: Key obligations in terms of data protection and privacy governing the collection and processing of personal data in education.
Part 2: Key steps and guidance to ensure compliance with data protection and privacy standards.
Part 3: Key considerations in respect of data protection and privacy in tech-enabled teaching and learning.
Part 4: Cybersecurity controls for data protection in schools.
This Guidance aims to support compliance with the European Union's General Data Protection Regulation (GDPR) law, particularly for countries moving toward EU accession, but should be of use to other countries or contexts looking for guidance on data protection in schools.