Policy Template

School Data Protection Policy Template

Schools collect and process large volumes of personal data about students, parents, and staff — including names, addresses, health information, academic records, disciplinary history, and financial details. A data protection policy establishes how the school collects, stores, uses, shares, protects, and disposes of this personal data in a lawful and ethical manner. Many African countries have enacted or are in the process of enacting data protection legislation (including Ghana's Data Protection Act 2012, Nigeria's NDPA 2023, Kenya's Data Protection Act 2019, and South Africa's POPIA 2013), and this policy template is designed to help schools comply with these frameworks. It provides a practical governance foundation for schools using digital school management systems, which are among the most significant processors of personal data in the school environment.

This is a template for reference purposes. Review and adapt with appropriate legal or governance advisors before official adoption.

Purpose

This policy exists to ensure that all personal data held by the school is processed lawfully, fairly, and transparently; collected for specified, explicit, and legitimate purposes; adequate, relevant, and limited to what is necessary; accurate and kept up to date; retained only for as long as necessary; and protected against unauthorised access, loss, or destruction.

Scope

This policy applies to all personal data processed by the school in any format — digital or physical — and covers all staff, contractors, volunteers, and third-party service providers who handle personal data on behalf of the school. It covers data about current and former students, parents and guardians, school employees, and any other individuals whose data the school holds.

1. 1. Data Controller Responsibilities

The school is the data controller for all personal data it collects and processes. The Head of School is the designated Data Controller Representative and bears overall responsibility for the school's compliance with applicable data protection law. The school appoints a Data Protection Officer (DPO) — or designates an existing senior staff member with equivalent responsibilities — who is the first point of contact for data protection queries, complaints, and regulatory correspondence. The DPO's contact details are published on the school's website. Any staff member who processes personal data is responsible for ensuring they do so in accordance with this policy and will receive training to that effect.

2. 2. Types of Personal Data Collected

The school collects and processes the following categories of personal data: for students — full name, date of birth, gender, nationality, home address, parent/guardian contact details, medical and health information (including allergies and disabilities), academic records, attendance records, examination results, disciplinary records, and photographs; for parents and guardians — names, contact details, emergency contact information, and financial information related to fee payment; for staff — names, contact details, national identification numbers, academic and professional qualifications, employment history, payroll information, disciplinary and performance records, and health information relevant to occupational health. The school processes certain categories of special or sensitive personal data (health, disability, religion, ethnicity) only where strictly necessary and with appropriate safeguards in place.

3. 3. Lawful Basis for Processing

The school relies on the following lawful bases for processing personal data: the performance of a contract (enrolment agreement between school and parent); compliance with a legal obligation (e.g., submission of examination candidate data to examination bodies, reporting to government education authorities); protection of vital interests (emergency medical situations); and the legitimate interests of the school in operating a safe and effective educational environment. Where the school processes sensitive personal data — particularly health data — it relies on explicit consent from the parent or guardian (or from the student where they are of sufficient age and maturity), or on the grounds that processing is necessary for the provision of health care. Consent where relied upon is recorded and can be withdrawn at any time.

4. 4. Data Storage and Security

All digital personal data is stored on the school management system (RedeemOS), which employs industry-standard encryption, access controls, and regular security audits. Physical records containing personal data — including paper admission forms, medical records, and staff files — are stored in locked cabinets in designated secure areas. Access to physical records is restricted to authorised personnel. The school performs regular data backups. Staff must not store personal data on personal USB drives, personal email accounts, or personal cloud storage services. When transmitting personal data electronically, staff must use the school's official systems and not personal email addresses.

5. 5. Data Sharing and Third Parties

The school does not sell personal data or share it with third parties for commercial purposes. Personal data may be shared with: examination bodies (e.g., WAEC, NECO, BECE) for the registration and administration of national examinations; government education authorities (e.g., GES, UBEC, state ministries of education) where legally required; approved educational software providers who have entered into data processing agreements with the school and who process data only on the school's instructions; and healthcare providers in emergencies. Any third-party service provider that processes personal data on behalf of the school must have a written data processing agreement in place and must demonstrate adequate data security measures. The school reviews its third-party relationships annually.

6. 6. Rights of Data Subjects

Students (and parents acting on their behalf), parents, and staff have the following rights in relation to their personal data: the right to access a copy of the personal data the school holds about them; the right to correct inaccurate or incomplete data; the right to request deletion of personal data where it is no longer necessary for the purpose for which it was collected (subject to legal retention requirements); the right to restrict processing in certain circumstances; and the right to lodge a complaint with the national data protection authority. Requests to exercise these rights must be submitted in writing to the Data Protection Officer. The school will respond to all requests within 30 days.

7. 7. Data Retention

The school retains personal data only for as long as necessary for the purpose for which it was collected, or as required by law. Student academic records are retained for a minimum of 10 years after the student leaves the school to support future requests for certified transcripts. Financial records are retained for a minimum of 7 years in line with tax and audit requirements. Staff employment records are retained for 7 years after the end of employment. CCTV footage (where applicable) is retained for a maximum of 30 days unless required for an ongoing investigation. Physical records due for disposal are shredded. Digital data is securely deleted. The school maintains a Data Retention Schedule that specifies retention periods for all categories of data held.

8. 8. Data Breaches

A personal data breach is any event that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Any staff member who discovers or suspects a data breach must report it to the Data Protection Officer immediately. The DPO will assess the breach, contain it, and determine whether notification to the national data protection authority or to affected individuals is required. Where notification is required by law, the school will notify the relevant authority within 72 hours of becoming aware of the breach. The school maintains a data breach register in which all breaches — including minor ones — are logged for accountability and improvement purposes.

Related Resources

Enforce policies with RedeemOS

RedeemOS helps schools implement attendance, fee, and data policies with automated workflows and audit trails.

Book a Free Demo