Blog · Legal obligations

The AEPD's ten-point guide for schools, translated into what needs to be done

Schools handle an enormous amount of personal information every day: academic records, reports, photographs, addresses, family phone numbers, communications with teachers, learning platforms and apps used directly by pupils. A large share of that data also belongs to minors, which calls for special care.

What this guide is and why the ten-point list is a good place to start

The Spanish Data Protection Agency (AEPD) devotes a guide of its own to schools, the ‘Guía para centros educativos’ (guide for schools), which opens with a ‘Decálogo para un correcto uso de los datos de carácter personal en los centros educativos’ (ten-point guide to the proper use of personal data in schools). The guide deals mainly with the data of pupils and their families, the main groups affected ‘both in number, with more than eight million pupils, and by the categories and nature of the data’ (our translation).

The ten points are fairly clear, but when they are applied to the day-to-day running of a school, the important questions arise: who can consult which information, what happens with the apps a teacher uses, how families should communicate with the school or what to do with the photographs from a school activity.

One point in the interest of honesty before going further. The Agency still has the document marked as under review, and the guide itself warns that it is not ‘a static and unalterable document, but a dynamic one that can be reviewed and updated’ (our translation). That does not invalidate it: it is still the published position of the authority that carries out inspections, and a good basis for reviewing how a school is working.

1. A pupil's data should not be available to everyone

The first of the ten points notes that senior leadership teams, teachers and administrative and support staff need to process the data of pupils and their families, and that they must do so ‘with due diligence and respect for their privacy and private life, keeping in mind the interests and protection of minors’ (our translation). The list of who processes data does not match the list of who has an office.

The practical consequence is simple: having an account on a school system should not mean being able to consult all the information in it. A teacher needs access to the data of the pupils they teach, while the school office may need other information and the educational psychology and guidance team something else entirely. The guide spells this out when it discusses security: anyone under the school's authority ‘may only process such data in the exercise of the functions assigned to them’ (our translation).

That is why permissions matter as much as passwords. If every member of the teaching staff has exactly the same access profile, they are probably being allowed to consult more information than necessary. And the duty of confidentiality does not disappear when someone stops working at the school: Article 5(3) of the LOPDGDD (Spain's data protection act) states that these obligations ‘shall remain in force even after the relationship between the person bound by them and the controller or processor has ended’ (our translation).

An example makes this clear quickly. Can a teacher consult the educational psychology report of a pupil they do not teach and for whom they have no responsibility? If they technically can, it is worth reviewing how permissions are defined.

2. The school remains the controller even when it uses outside providers

The second point says two things in one line: the education authorities and schools ‘are the controllers of the data’ and ‘must provide training on its basic principles and on how to process it correctly’ (our translation). The guide also specifies that ‘in the case of publicly funded private schools (concertados) and private schools, the controllers will be the schools themselves’ (our translation).

This does not mean the provider has no obligations. Depending on its role, it may act as a processor and take on specific responsibilities. But contracting a learning platform, a management system, a cloud service or an IT provider does not automatically transfer all of the school's obligations to the provider. Responsibility cannot be outsourced.

The same point in the guide also talks about training. And this is where a very common problem appears: a session is held at the start of the year to explain certain rules, but weeks later cover teachers, new staff or external staff arrive who never received that information.

Data protection training should not, therefore, be seen as something done once a year and then ticked off. The procedure should also cover what information someone receives when they join the school in November, February or April, and from whom.

3. Consent is not always needed, but information always is

The third point lifts one burden and adds another. It lifts this one: ‘as a general rule, schools do not need the consent of data subjects to process their data, which will be justified by the exercise of the educational function and by the relationship arising from pupils' enrolment’ (our translation). It adds this one: the school must provide information ‘using clear and plain language’ (our translation), and the same form on which the data is collected will do.

The school must explain who is responsible for the data, what it is used for, what the lawful basis for processing it is, whether providing it is compulsory and what happens if it is not provided, to whom it may be disclosed and how to exercise the rights. The ten-point guide adds that the European Regulation extends that information to include ‘the contact details of the data protection officer and the retention period or the criteria used to determine it’ (our translation).

In practice, the problem is not usually that the school has no data protection clause at all. More often it is carrying one drafted years ago that has been reused ever since without checking whether it still reflects current apps, services and processing, and that mentions neither the data protection officer nor the retention periods. A fairly simple check is to take the enrolment form families are using this year and see whether the information in it still matches what the school actually does.

4. Consenting to a photograph for one purpose does not mean consenting to it for all

Some processing is not strictly part of the educational function and may need consent. When that happens, the ten-point guide asks that, ‘as these are purposes other than the educational function, clear information must be given about each of them, allowing data subjects to object to those they wish’ (our translation). The deciding words are ‘each of them’.

This particularly affects the use of images. A family may be happy for their child's photograph to appear in the end-of-year class photo and, at the same time, not want it published on Instagram. They may also accept photographs in an internal magazine but not in an advertising campaign.

That is why a single tick box saying ‘I consent to the use of the pupil's images’ can be too broad if those images are then used for different purposes. But the real challenge is not just the form: it is making sure that decision reaches the person who publishes the photographs. There is little point in collecting consent perfectly if, months later, the teacher or the person in charge of communications cannot easily check which pupils may appear on each channel.

5. An app should not reach the classroom before you know what it does with the data

This is one of the points that most directly affects technology. The guide recognises that ‘ICT tools are fundamental’ in education and sets the rule: schools ‘must know the apps they are going to use, their privacy policy and their terms of use before using them, and must reject those that do not provide information on the processing of personal data they carry out’ (our translation).

The ‘before’ is the part that gets skipped. In a school it is very easy for things to happen the other way round: a teacher discovers an interesting app for a subject, creates accounts for the pupils and starts using it. The tool works well and nobody thinks any more about it until months later, when someone asks what data it collects, where it is stored or what happens to the accounts at the end of the year. The guide adds that using them from the teacher's mobile phone ‘must uphold the privacy policy defined by the school’ (our translation).

The point is not to hinder innovation or stop teachers discovering new tools. It is to have a simple procedure so that an app can be reviewed before pupils' personal data is entered into it. A good exercise for any school would be to try to answer this question today: can we list every external app that uses pupils' data, and do we know who authorised each one?

6. Technology rules also have to change with age

The sixth point says that schools ‘must have protocols, instructions, guides, guidelines or recommendations for the use of ICT by teachers’, and adds a particularly important condition that tends to be overlooked: ‘their teaching and use must be adapted to the child's stage of development’ (our translation).

It makes little sense to apply exactly the same technology policy to a primary pupil (ages 6–12) as to a Bachillerato student (ages 16–18). The level of autonomy, the type of browsing, the apps available and the restrictions should evolve with age and with the school's educational approach. A single device profile and the same filtering for early years (Infantil, ages 0–6), primary, ESO (compulsory secondary education, ages 12–16) and Bachillerato fails the criterion by definition.

This is where data protection ends up having a very specific consequence for how devices and the network are configured. A mobile device management (MDM) system that allows policies by phase of education, or a filtering system that tells users and ages apart, is not just a technical convenience: it allows technology to reflect the school's educational decisions.

It is also important for those rules to be written down, and they carry more weight than they appear to: the guide makes sensitive actions, such as accessing a pupil's device in a case of cyberbullying, conditional on that protocol. A teacher who has just joined should be able to find out which tools they can use with a particular year group without having to ask a colleague informally.

7. Communication with families should use the school's channels

The seventh point is short: communication between teachers and parents ‘should preferably take place through the means made available to both by the school (learning platforms, school email)’ (our translation). With pupils, the guide points in the same direction.

This recommendation has a consequence that is sometimes forgotten: the official channel has to work well. If checking a notification takes too many steps, the app does not send alerts properly or families struggle to use it, alternative routes will end up appearing and no letter home will prevent it.

So it is not enough to send out a letter saying the school platform must be used. You need to check that it works well on the devices families actually use, that notifications arrive when they should and how many families have them switched on. Data protection is also made easier when the official channels are convenient enough that nobody feels the need to replace them.

8. WhatsApp should not become the usual channel between teachers and families

The eighth point says that ‘the use of instant messaging apps (such as WhatsApp) between teachers and parents or between teachers and pupils is not recommended’, with one exception: if the best interests of the child are at stake, ‘as in the case of an accident or illness on a school trip’ (our translation), images could be taken and sent to the parents.

It is not an absolute ban, but the direction is clear. The point is to prevent messaging from systematically becoming the teacher's official channel of communication with families.

Class groups are a good example. When a form tutor creates and runs them, families' personal numbers can be exposed, and the teacher ends up managing communication that could be organised differently. The guide accepts that they may exceptionally be created with the parents' consent, and points out that ‘it would be preferable for the groups to be managed by the parents themselves’ (our translation).

Once again, the solution often does not lie in simply banning something. It lies in offering an official alternative that is simple and effective enough.

9. Publishing classwork on the internet also means making decisions about privacy

The ninth point has two halves. The first is aimed at teachers: ‘Teachers must be careful about the classwork content they upload to the internet’ (our translation). The second is aimed at the classroom: pupils must be taught that ‘they may not take photos or videos of other pupils or of school staff without their consent’ (our translation), to prevent cyberbullying, grooming or sexting.

On the first half, the guide is specific: recordings of a school activity ‘should only be accessible to the pupils involved in that activity, their parents or guardians and the teacher concerned’, and for families to see the images it describes a secure environment ‘requiring prior identification and authentication’ (our translation).

This marks an important difference between sharing and publishing openly. A video of a class project can perfectly well be shared with the families taking part through a private platform, without making it publicly accessible on the internet. Is the video of the last class project open to all, or behind a login?

And there is an educational side that no tool replaces. Teaching pupils to respect their classmates' privacy and to understand that not everything they can record should be published is part of digital education, and it is work for tutor time.

10. At school shows and events, people must be informed before things start

The last point deals with something as everyday as a Christmas show, an end-of-year celebration or a sports event. Families inevitably take photographs and record videos, and the guide states that ‘it is good practice to inform them, for example when asking for their consent to take part or through notices or posters, that they may record images for their personal and household use only’ (our translation).

As long as that material stays within the personal, family or friendship sphere, it falls outside the ordinary application of data protection law. The situation changes if a family later decides to share it publicly: the guide makes clear that in that case ‘the family members would assume responsibility’ (our translation), and that the school must warn them of this beforehand. The same guide also settles a frequent question: a family's refusal to have images taken does not oblige the school to cancel the event.

The notice therefore has to be given beforehand, through the sign-up form, a message to families or suitable signage. There is no need to wait for an argument over a photograph to decide what information should have been given: has the notice for the next event on the calendar already been drafted, or will it be improvised on the day once again?

What can be reviewed this week without spending money

One of the interesting things about the ten-point guide is that many of the improvements do not start with buying technology, but with reviewing procedures. All it takes is half a morning, well organised, and a decision on who takes charge of each item. Note down anything that does not add up: that list is the conversation to have with the data protection officer, who is mandatory in all schools under Article 34 of Organic Law 3/2018 and to whom, according to the guide, questions must be referred.

  • Reread the clause on the enrolment form against the list of information in point 3.
  • Check that the data protection officer's contact details are published and correct.
  • Write down on one sheet which apps process pupils' data and who approved each one.
  • Ask at a staff meeting who runs messaging groups with families or pupils.
  • Check whether filtering and device policies distinguish between phases of education.

Data protection is also designed into the infrastructure

Reviewing those procedures will bring up issues that do require technological changes, but by then the investment will respond to a specific need: changing a platform's permissions, introducing an MDM, improving filtering, removing a shared password or reviewing how teachers authenticate. Technology makes sense when it helps apply a policy the school has defined beforehand.

Legal decisions are for the school and its data protection officer. But many of them then need a technical translation. Deciding that a teacher should not access certain data is only useful if the platform allows permissions to be restricted. Setting different policies for primary and Bachillerato requires the ability to apply them on devices and to browsing. Recommending official communication channels requires those channels to be reliable and easy to use.

That is where PenwinEdu comes in. Our experience in schools allows us to turn many of those decisions into configurations, policies and technical procedures that can be maintained throughout the school year. We work with device management, content filtering, identity and network access, security and support, always starting from how each school really works.

In device management and filtering, this means usage policies that differ by group or educational level, web filtering by category and a managed app store that lets in only what the school authorises, which is exactly what point 5 asks for. PenwinSafe covers a different part: DNS filtering that goes with the device on any Wi-Fi network, alerts for form tutors and remote lock from the dashboard.

Compliance is not about having a folder of documents

Data protection in a school is not settled just with clauses, consents and policies kept in a folder. It shows in everyday decisions: who can open a pupil's file, which app comes into a classroom, where a photograph is published, which channel a teacher uses to write to a family or what restrictions are placed on a device used in primary.

Sources

  1. Agencia Española de Protección de Datos, «Guía para centros educativos» (documento en revisión) (in Spanish)
  2. Reglamento (UE) 2016/679, General de Protección de Datos (RGPD) (in Spanish)
  3. Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD), artículos 5 y 34 (in Spanish)

None of this replaces your data protection officer: the DPO helps the school define the framework, and our job at PenwinEdu is to make sure the technology can put it into practice. Our specialist experience with schools allows us to design infrastructures that are fast and reliable and that also help protect the information of pupils, families and staff throughout the school year. If you want to review how your school's data protection decisions currently carry through to the network, the devices and the systems it uses, we can study your infrastructure free of charge and with no obligation.