Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Sector

Data protection at schools

A school is a controller like any other body. It keeps health data of minors for years and runs the whole of its teaching through platforms. No staffing plan provides a post for data protection. The task goes to a teacher with a full teaching load. The supervisory authority audits without a trigger all the same. What an infringement costs depends on whether the school is a state school or one with a private governing body.

The same duties as a company, but no post for them

Whether a school can meet its data protection duties is rarely settled by knowledge and mostly by the time available.

A school keeps pupil files for years, processes health data of minors and runs its teaching through platforms. The duties arising from that are the same as those of a company holding the same data. A state school designates a data protection officer under Art. 37(1)(a) GDPR without exception. For a school with a private governing body, § 38(1) BDSG applies from twenty persons constantly engaged in automated processing.

No staffing plan provides a post for it. The task goes to a teacher who also teaches. The supervisory authority recorded this during its audit.

The schools do know their duty to appoint a data protection officer, but the teachers feel out of their depth both professionally and in terms of time. One school’s attempt to tie the task to a new established post was blocked by the regional state office.

LfD Lower Saxony, final report on the audit of fifty schools carried out without a trigger, 5 May 2023

The designation therefore stands beside the task rather than covering it. Art. 38(2) GDPR requires the controller to provide the resources necessary to carry out those tasks. Where these are absent, the duty is formally met and the work is not done.

The supervisory authority does not wait for a trigger

When a school has to reckon with an audit does not depend on whether anyone has complained. Art. 58(1)(b) GDPR permits the supervisory authority to carry out investigations in the form of data protection audits, without any incident being required.

In 2022 the Lower Saxony data protection authority wrote to fifty randomly selected schools. In 2023 four on-site audits followed.

50schools audited without a trigger, selected at random
50of them showed shortcomings in at least one area
1produced a deletion record that drew no objection

The authority has announced that it will audit the use of intelligent tutoring systems separately. Anyone adding a diagnostic tool to a learning platform today should have the documents ready.

What an infringement costs depends on the governing body

Whether a fine follows is not settled by the gravity of the infringement but first of all by who runs the school.

The same set of duties, two different consequences

State schoolMerkmalPrivate governing body
Practically ruled outUnder § 20(5) NDSG the authority holds that power against public bodies only in so far as they take part in competition as undertakings. The basis is the opening clause in Art. 83(7) GDPR.Administrative fineIn fullAs a non-public body, Art. 83(4) and (5) GDPR applies unabridged, so up to 10 or 20 million euros.
In fullArt. 83(7) GDPR expressly leaves the corrective powers under Art. 58(2) GDPR untouched. These include a ban on processing as well as an order to bring processing operations into compliance.Orders by the authorityIn full
§ 31 NSchGThe provision names the permitted purposes, the routes of transmission and, in subsection 10, a closed catalogue for special categories.Legal basis for processingArt. 6 GDPR and Art. 9 GDPR§ 141(1) NSchG lists which provisions of the school act apply to substitute schools by analogy. § 31 NSchG is not among them.
Through the state officesThe regional state offices for schools and education provide templates and advise. The authority expressly recommends using them.Ready-made templates and a contact pointNo comparable bodyA private governing body sits outside that structure and obtains its documents itself.

For a school with a private governing body both disadvantages therefore coincide. It carries the full exposure to fines while having no access to the documents available to the state school system.

For the state school this is no all-clear. A ban under Art. 58(2)(f) GDPR hits a learning platform in the middle of the school year just as it hits any other operation.

The questions that actually come up at a school

Which of a school’s own processing operations is the risky one is hard to judge from the inside. What gets dealt with is usually whatever is pressing.

Three of them take a particular shape at a school. Under § 31(5) NSchG the use of a learning platform requires the consent of the school management alongside its lawfulness. The authority also lists the processing of pupil data through a central processor among the operations requiring an impact assessment. Health data are permitted under § 31(10) NSchG only for a closed catalogue of purposes, from establishing fitness for school to infection control. On a change of school § 31(7) NSchG limits the transmission to the core data. What the authority found in pupil files instead were complete primary school files including school entry examinations.

How we support you at your school

Which route fits depends on what is missing. Where time is missing, we take on the function of the data protection officer from outside. The teaching staff then stay with their teaching. Where an overview is missing, an audit with a written result comes first and sorts the open points by urgency. Where a single decision is pending, ahead of introducing a platform for instance, an assessment in day-to-day operation is often enough.

Frequently asked questions

Must every school designate a data protection officer?

A state school yes, without exception. Art. 37(1)(a) GDPR attaches solely to the processing being carried out by a public authority or body. For a school with a private governing body § 38(1) BDSG applies as soon as at least twenty persons are constantly engaged in automated processing. That is likely to be true of any staff working with a learning platform.

Is designating a teacher enough?

The designation satisfies the duty under Art. 37 GDPR. It does not satisfy Art. 38(2) GDPR, which requires the resources necessary to carry out those tasks. Without hours of relief the work is left undone. The school owes the records regardless. An external designation is expressly permitted under Art. 37(6) GDPR.

As a small school, are we exempt from the record of processing activities?

In all likelihood not. The exemption in Art. 30(5) GDPR falls away as soon as the processing is not occasional or concerns special categories under Art. 9(1) GDPR. Both are likely to be true at any school. The supervisory authority encountered precisely this misconception during its audit.

We are a school with a private governing body. May we use the state templates?

Only after review. The templates of the regional state offices base the processing on § 31 NSchG. § 141(1) NSchG does not extend that provision to substitute schools, so the legal basis stated there is unlikely to hold. Structure and layout remain usable. The legal bases have to be replaced.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.