GDPR duties in education extend to children’s data, lawful processing, transparency, automated decisions, security and international transfers.
Accountability begins with each processing purpose
Education processing is not lawful merely because it supports teaching, safeguarding or administration. The controller needs a defined purpose, a valid legal basis, transparent information, proportionate data use and controls matched to risk. Processor contracts and product settings cannot displace the controller’s accountability.[S1]
Education organisations commonly process data for admission, attendance, learning, assessment, safeguarding, support, employment and research. These purposes cannot be merged into one general claim of educational necessity. Each operation needs a defined purpose, data set, affected person, legal basis, retention position and allocation of controller or processor responsibility. The accountability record follows the operation, including when a platform supplier performs it.[S1]
The GDPR provisions most relevant to education
Article 5 establishes the core processing principles and accountability. The Regulation separately addresses children’s consent in specified information-society contexts, data-subject rights, automated decision-making, privacy by design, processor terms, security, impact assessment and restricted international transfers. A review record can trace each processing operation to these distinct legal questions rather than using one undifferentiated privacy checklist.[S1]
The cited provisions create a connected control structure. Articles 5 and 6 govern principles and lawful basis; Articles 12 to 22 concern information and individual rights; Articles 24 to 35 address accountability, design, processors, security and impact assessment; and Articles 44 to 49 govern restricted transfers. Evidence is strongest when the processing inventory, notices, contracts, settings, rights cases, incident records and transfer mechanism describe the same actual operation.[S1]
High-risk processing benefits from a traceable impact-assessment record that begins before deployment and follows material changes. The record identifies necessity, proportionality, risks to individuals, safeguards, consultation and residual risk acceptance. Rights requests and incidents provide operational evidence: response times, recurring causes and corrective action reveal whether the documented governance works when a person actually relies on it.[S1]
Mapping data roles across an education service
The Regulation’s territorial provisions, controller–processor allocation and special-category rules determine its reach. Education records can involve learners, parents, employees and prospective applicants, each with different purposes and retention needs. National education and employment law can add further requirements.[S1]
Territorial reach and role allocation require a factual analysis. A provider may be a controller for admissions, a joint controller for a partnership and a processor for another institution in the same technical environment. Learners, parents, employees and applicants can also be subject to different legal bases. Special-category data and decisions affecting children introduce additional risk but do not automatically determine the legal result.[S1]
What privacy documentation cannot establish alone
Consent is not the default answer for every education relationship, and a privacy notice is not proof that actual processing matches its description. A security certification may contribute evidence without resolving purpose limitation, fairness, rights handling or transfer law.[S1]
A signed consent form does not cure an unsuitable legal basis, and a processor agreement does not prove compliance in operation. Security testing addresses confidentiality, integrity and availability but not necessarily fairness, transparency or purpose limitation. Certification evidence also cannot decide questions reserved to courts or supervisory authorities. Any legal conclusion needs the current facts and the law applicable to the processing.[S1]
GDPR evidence and ICEQC certification
ICEQC classifies the GDPR as external law. This article explains an evidence structure; it does not issue a legal determination or imply that ICEQC certification substitutes for supervisory-authority oversight. No later ICEQC provision is applied to the historical publication record.
ICEQC can examine data-governance evidence that is relevant to a declared certification scope without assuming the role of a data-protection authority. GDPR compliance and ICEQC conformity remain separate determinations. This historical page does not apply provisions from a later ICEQC standards edition.