Schools hold some of the most sensitive data there is, and under GDPR the responsibility does not transfer to the supplier. What that means in practice.
A school holds more sensitive information about a child than almost any other organisation they will meet: attendance, behaviour, medical needs, safeguarding notes, family circumstances, academic history. Much of it now sits inside software the school does not own and cannot see into. That is normal, and largely fine - but the responsibility for it has not moved.
Under GDPR the school is the data controller: it decides what is collected and why. The software supplier is the processor, acting on the school's instructions and nothing more. The practical consequence is that if a supplier is careless with student data, it is still the school explaining it to parents and to the regulator. Choosing a processor is a safeguarding decision, not only a procurement one.
The document that formalises this is a data processing agreement, and every supplier holding student data should have one you can read without asking twice. It should say what they do with the data, who they pass it to, where it is stored, how long they keep it, and what happens on the day you leave. A supplier who does not publish one, or who sends a sales contract instead, has answered the question.
Breaches come with a clock. A personal data breach has to be reported to the supervisory authority within 72 hours of the school becoming aware of it - which means your supplier must tell you fast enough to make that possible. Ask, before signing, how quickly they commit to notifying you. 'As soon as practicable' is not something you can build a process around.
A parent can also ask what you hold about their child, and you have a month to give them all of it. If student data is spread across six systems and three of them are spreadsheets on somebody's laptop, that month gets uncomfortable. The subject access request is the honest audit of whether a school really knows where its data is.
The practical minimum - and it genuinely is a minimum - is a single list: every system holding student data, what it holds, who the supplier is, and who at the school owns that relationship. Most schools do not have this, and writing it is usually the moment two or three forgotten systems surface.
None of this needs a lawyer to begin. It needs someone to be responsible for the list, and for that person to be allowed to say no to a tool that cannot answer the questions above.
Bring SuperExams to your school
Set work, mark it with AI, and track every student in one place. See it in a short call.
Book a call →