
Is Your School’s EdTech Really GDPR Compliant? Five Questions Every School Should Ask Before September
- Gerard Strong
- Jul 13
- 4 min read
I would actually pivot the article slightly. Rather than making it sound like it’s reporting “news”, make it a practical guide that uses the ICO’s guidance as the authority. That way it remains relevant for years and avoids becoming dated.
Is Your School’s EdTech Really GDPR Compliant?
Five Questions Every School Should Ask Before Approving or Renewing Education Technology
Every school now relies on technology.
From Management Information Systems (MIS) and safeguarding platforms to online learning tools, parent communication apps and artificial intelligence, schools are processing more personal information than ever before.
But one of the biggest misconceptions I encounter when working with schools is this:
“The supplier says they’re GDPR compliant, so we’re covered.”
Unfortunately, it doesn’t work like that.
Under UK GDPR, your school remains accountable for the personal information it decides to collect and the digital systems it chooses to use. The Information Commissioner’s Office (ICO) is clear that organisations must understand how children’s information is processed, ensure appropriate contractual arrangements are in place with suppliers, and assess privacy risks before introducing online services likely to be used by children.
Whether you’re introducing a new homework platform, renewing your MIS contract or trialling an AI-powered classroom tool, asking the right questions before signing the contract could save your school significant problems later.
Why this matters
Schools process some of the most sensitive personal information there is.
That includes:
-pupil records
-SEND information
-safeguarding concerns
-attendance
-behaviour
-assessment data
-photographs
-health information
-staff records
-parent contact details.
When this information is shared with a third-party supplier, the school doesn’t transfer its legal responsibility.
The ICO expects organisations to understand what data is being processed, why it is needed and how risks to children’s privacy are managed. The Children’s Code also makes clear that online services likely to be accessed by children should consider children’s best interests and carry out appropriate risk assessments.
Five Questions Every School Should Ask
1. What personal data does this product actually collect?
Don’t assume it’s just names and email addresses.
Ask whether it processes:
attendance
behaviour
SEND information
safeguarding records
medical information
photographs
location data
device information
analytics.
Schools should be able to explain exactly what information is collected and why it is necessary.
2. Where is our data stored?
Ask your supplier:
Is the data hosted in the UK?
Is it transferred overseas?
Which countries can access it?
What safeguards are in place?
International transfers remain an important GDPR consideration.
3. Who can access our information?
Clarify:
subcontractors
overseas support teams
third-party integrations
consultants
AI providers.
Many schools know where their data is stored but have never asked who else can access it.
4. Does the system use Artificial Intelligence?
Increasingly, education technology includes AI features.
Schools should understand:
whether AI is used
whether school data trains AI models
whether AI can be switched off
how decisions are reviewed by humans
whether pupils are informed when AI is involved.
These questions are becoming increasingly important as AI becomes embedded within education software.
5. What happens when we leave?
Ask every supplier:
Can we export our data?
How long is information retained?
Are backups deleted?
Will deletion be confirmed in writing?
Exit planning should happen before signing a contract—not after deciding to move suppliers.
What would the ICO expect?
The ICO doesn’t expect schools to become technical experts.
However, it would expect you to demonstrate that you have exercised appropriate due diligence before trusting a supplier with children’s personal information.
That includes being able to show:
-supplier checks
-appropriate contracts
-privacy information
-security considerations
-risk assessments where required
-ongoing governance.
Where processing is likely to result in a high risk to individuals’ rights and freedoms, the ICO expects organisations to carry out a Data Protection Impact Assessment (DPIA) before processing begins.
Five Practical Actions Before September
Before the new academic year, I recommend every school should:
1. Review your ten most important software suppliers.
2. Check your contracts include appropriate UK GDPR clauses.
3. Update your privacy notices if new systems are being introduced.
4. Consider whether a DPIA is required for higher-risk systems, particularly those involving children or AI.
5. Ask governors or trustees to review digital risk as part of their governance responsibilities.
Key Takeaways
Schools remain accountable for the personal data processed by third-party suppliers.
A supplier claiming to be “GDPR compliant” is not enough on its own.
Contracts, privacy information and security should all be reviewed before approval.
AI features require additional scrutiny.
Due diligence is far easier before implementation than after a data breach.
Need Help Reviewing Your EdTech Suppliers?
Choosing education technology is no longer just an IT decision—it’s a governance, safeguarding and data protection decision.
At SchoolDPO.com, we support schools, academies and trusts with:
Independent Data Protection Officer (DPO) services
GDPR compliance audits
Supplier due diligence
Data Protection Impact Assessments
AI governance
Policy reviews
Staff training
If you’re reviewing systems before September or simply want reassurance that your school is meeting its data protection obligations, we’d be happy to help.
Useful Resources
Information Commissioner’s Office – Children’s Code Guidance
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/
Department for Education – Data Protection in Schools


Comments