3 September 2026 • Cyber security
For a school, the GDPR, known in the Netherlands as the AVG, comes down to one principle: you may only use student data for the purpose you collected it for, you may only keep it as long as you need it, and you have to be able to show that you handle it carefully. That sounds like paperwork, but in daily practice it is mostly about behaviour: who shares which file with whom, over which channel, and who still has access to a system they left behind two years ago.
Below we look at which data schools actually handle, who carries the responsibility, what to arrange with the suppliers of your digital learning tools, how data breaches really happen in a school, and how all of this connects to the Normenkader IBP that schools are working towards.
Which data schools handle, and why it is sensitive
Schools sit on more personal data than most organizations of the same size, and a large part of it concerns minors. That is precisely why the rules are stricter here than in a company with the same headcount.
- Basic student records. Names, addresses, dates of birth, citizen service numbers, the details of parents or guardians. Ordinary in appearance, valuable to anyone building a profile.
- Learning progress and results. Grades, test scores, reports, notes in the student tracking system. Sensitive because they follow a child for years.
- Care and support files. Dyslexia statements, medical notes, reports from support teams. This is special category data and deserves the tightest handling in the building.
- Images and recordings. Photographs on the school website, video from a school trip, recordings of a lesson. Consent here is specific, revocable and often forgotten.
- Communication with parents. Emails and messages about individual pupils, including the conflicts and the difficult situations at home.
What makes this different from a business is the combination: the data is sensitive, the subjects are children who cannot oversee the consequences, and the people handling it are teachers whose job is teaching rather than data protection.
Who is responsible for GDPR at a school?
Formally the school board is the controller. That is the party that determines why and how personal data is processed, and the party the Autoriteit Persoonsgegevens will address if something goes wrong. Many boards appoint a data protection officer, and in education there is usually also an IBP coordinator who keeps information security and privacy running in practice.
The gap that causes most trouble is between that formal responsibility and daily reality. The board carries the accountability, but the actual processing happens in the classroom and the front office: a teacher who exports a class list, an administrator who forwards a care file, a substitute who logs in with a shared account. Policy that never reaches those hands is not compliance, it is documentation.
Processing agreements with your suppliers
Schools run on external tools: the student tracking system, digital learning materials, a communication app for parents, a cloud storage service. Every supplier that handles student data on your behalf is a processor, and that relationship needs a processing agreement setting out what they may do with the data, how they secure it, how long they keep it and what happens when the contract ends.
Two practical points. First, check whether such an agreement actually exists for every tool in use, including the ones a single enthusiastic teacher introduced without telling anyone. Second, remember that signing it does not transfer your responsibility: if a supplier leaks data, the school is still the controller and still has to inform the people affected.
Want your teachers to recognize a privacy risk before it becomes a breach?
Short, recurring training keeps privacy alive in a busy team room, in a few minutes a week and on the device people already carry.
Discover security awareness trainingHow data breaches actually happen at schools
Almost never through a spectacular hack. The reports that reach the Autoriteit Persoonsgegevens from the education sector are overwhelmingly mundane, and that is good news, because mundane causes are the ones you can train away.
- The wrong recipient. A class list, a grade overview or a care report emailed to the wrong address, or to a whole parent group in the To field instead of BCC. The single most common breach in education.
- Shared logins. One account for the student tracking system that the whole team uses, because arranging separate accounts took too long. Nobody can tell afterwards who looked at what.
- Devices and storage that wander off. A laptop in a car, a USB stick with a backup of the results, a private phone with school photos on it.
- Phishing aimed at school accounts. Attackers know that a school mailbox opens the door to a lot of data about minors. A single click on a fake login page is enough.
- Access that was never revoked. The substitute from last spring who still has an active account, the departed colleague whose access to the shared drive nobody switched off.
When something does go wrong, the clock matters. A data breach that poses a risk to the people involved has to be reported to the Autoriteit Persoonsgegevens without undue delay and in principle within 72 hours, and the people affected have to be informed when the risk to them is high. That deadline is only realistic if a teacher who suspects something reports it the same morning, which is a matter of culture rather than procedure. Keeping the subject alive helps: privacy awareness that returns in small doses works better than an annual briefing, and a light format such as GDPR training games gets more participation from a busy team room than a policy document does.
The link with the Normenkader IBP
Privacy and information security arrive at schools as one package. The Normenkader IBP for primary and secondary education brings both together into concrete requirements, and schools are working towards it with 1 January 2027 as the horizon. A good deal of what the framework asks overlaps with what the GDPR already expected: know which data you hold, arrange access properly, make agreements with suppliers, and be able to demonstrate that your staff know what to do.
That overlap is worth using. A school that takes the awareness part of the Normenkader seriously is doing its GDPR homework at the same time, and the other way around. Treating them as two separate projects is how boards end up doing the same work twice with two different sets of paperwork.
How Guardey helps schools with the human side
Guardey’s security awareness training is built for teams that have no time to spare: weekly challenges of about three minutes, gamification with leaderboards and streaks, and content that follows the threats actually circulating. For schools that means recognizable scenarios, from a phishing mail aimed at a school account to the question of which photograph may go on the website.
KONOT, a school organization in education, uses Guardey to improve the security awareness of its teachers, and our security awareness training for schools is set up for that context. Teachers train in the mobile app for iOS and Android or simply in the browser, integrated phishing simulations show whether recognition becomes behaviour, and the reporting gives the board something concrete to show for the Normenkader IBP. Setup takes minutes.
Frequently asked questions about GDPR in education
May a school publish photographs of pupils?
Only with valid consent, which for younger children means consent from the parents or guardians, and that consent has to be specific about where the image will be used and can be withdrawn at any time. In practice the trouble is rarely the consent form itself but keeping track of who said no, and making sure the colleague posting to social media knows it.
How long may a school keep student data?
Only as long as necessary for the purpose, with statutory retention periods for parts of the record. The practical question is not the exact term but whether anyone actually deletes anything: many schools carry years of old files simply because nobody was assigned to clear them out.
Is a teacher personally liable for a data breach?
Almost never. The school board is the controller and carries the responsibility. That is worth saying out loud in the team room, because fear of blame is the main reason a mistake gets reported late, and late reporting is what turns a small incident into a supervisory problem.
Do we need a data protection officer?
Public authorities and bodies must appoint one, and schools generally fall in that category, though how it is organized differs: some boards appoint their own, others share one across a group of schools. What matters more is that the role is actually reachable for the people with the everyday questions.
The schools that have their GDPR in order are rarely the ones with the thickest policy binder. They are the ones where a teacher knows what to do with a suspicious email, where an account is switched off the week someone leaves, and where reporting a mistake is normal rather than awkward. That is a culture, and cultures are built in small steps.
Curious how this works for your school?
Try Guardey for 14 days and let your team do the first challenge this week, with reporting your board can use for the Normenkader IBP.
Try Guardey free for 14 days