Certix

GDPR at driving schools: basic information and mandatory documentation from the first student

Certix
Certix®
· 2 Jun 2026 · 7 min read

Informative article. It does not replace individualised professional advice.

A driving school is a controller of personal data from its first enrolled student. Identifying data, financial data, academic process data, a file submitted to the DGT (Spain's General Traffic Directorate) and, in many cases, recordings from cameras in practice vehicles. The GDPR applies to all of it, regardless of the size of the school or the number of students per year.

This guide explains the proportionate minimum documentation any driving school should have available, under the GDPR (Regulation (EU) 2016/679), the LOPDGDD (Spain's Organic Law 3/2018), the LSSICE (Spain's Law 34/2002) where there is an online presence and Spanish Royal Decree 818/2009, the General Drivers Regulation, in relation to the file processing with the DGT.

Typical processing operations at a driving school

Almost any driving school can be summarised in five or six perfectly identifiable processing operations:

Processing Typical data Legal basis
Registration and file Identifying data, contact, official photos, academic data. Contract performance (6(1)(b))
DGT processing Licence application, psychotechnical report, exam presentation. Legal obligation (6(1)(c)) + RD 818/2009
Billing and financing Payment data, financing, discounts. Legal obligation (6(1)(c)) + contract
Vehicle cameras Student and instructor image during practice. Legitimate interest (6(1)(f)) + safety
Marketing and former students Subscribers, leads, former students. Consent or legitimate interest + art. 21 LSSICE
Teaching staff Labour data, payroll, training, qualifications. Employment contract + legal obligation

Proportionate minimum documentation

A small or medium driving school reasonably complies with these documentary blocks, without overengineering:

  • Record of Processing Activities (RoPA): one page, five or six entries, with the art. 30(1) GDPR information.
  • Information notices: one for an adult student, another for a minor student (delivered to parents or guardians), one for candidates for teaching staff and the website privacy policy.
  • Differentiated consent sheet at registration for optional processing: student image on social media and website, future commercial communications, transfers to third parties (recommended to avoid; if any exist, they must be documented).
  • Art. 28 GDPR contracts with relevant technology providers: driving school management platform, payment gateway, simulator system, vehicle camera system where applicable, external accountant.
  • Operational security policy: one or two pages with real measures (individual passwords, two-factor authentication, encrypted backup, management of staff system access additions and removals, screen locks, physical archiving under lock and key).
  • Breach protocol: two paragraphs with who assesses, in which cases notification to the AEPD (the Spanish Data Protection Authority) within 72 hours is required and how.
  • Cookie policy on the website, if the driving school has an online presence, with banner compliant with the LSSICE.

The registration information notice: the most overlooked document

The art. 13 GDPR notice is delivered at registration, ideally integrated into the enrolment document itself or as a signed annex by the student (or by parents or guardians for minors). Minimum content:

  • Identity of the controller (the driving school, with CIF and address) and contact details of the Data Protection Officer if appointed.
  • Specific purposes: management of the student's training file, DGT processing, billing, course administrative communications, where applicable practice vehicle cameras.
  • Legal bases: performance of the teaching contract for academic management, legal obligation under Spanish Royal Decree 818/2009 for communication with the DGT, fiscal legal obligation for billing, legitimate interest for vehicle cameras, consent for optional uses.
  • Usual recipients: DGT, psychotechnical centre (when the driving school works with a specific one), external accountant, management platform, tax authorities where applicable.
  • International transfers if the tools used operate outside the EEA (typically yes when using Google Workspace, Microsoft 365, international payment platforms).
  • Retention periods by block (administrative file, tax, civil).
  • Student rights (or parents' rights for minors) and route to exercise them.
  • Reference to the right to lodge a complaint with the AEPD.

Relationship with the DGT: two controllers, not a processor arrangement

A point frequently misunderstood: the driving school and the DGT do not sign an art. 28 GDPR contract between themselves. They are two independent controllers:

  • The driving school is the controller of the student's file while it is under its management.
  • The DGT is the controller of the drivers' register and the administrative process for obtaining the licence under Spanish Royal Decree 818/2009.
  • Communication between them is covered by legal obligation on the driving school's side: student consent is not needed for the administrative file flow.
  • The information notice must clearly state the flow: which data are sent to the DGT, for what purpose, at what point in the process.

Art. 28 GDPR contracts with technology providers

The modern driving school typically depends on several SaaS tools that process student data: integrated management platform, simulator software, vehicle camera system where storage is outsourced, payment platform, student communication tool, cloud storage of materials. Each is a processor and requires an art. 28 GDPR contract.

Critical points when contracting:

  • Signed and stored DPA.
  • Verification of international transfers (Data Privacy Framework for US providers).
  • Data return procedure when the provider's service ends, before destruction.
  • Provider commitment not to reuse data for its own purposes.
  • Breach notification to the controller and notice periods.

"At a driving school, data protection documentation fits in one folder. Registration information notice, optional consents sheet, contracts with providers and an operational policy that is respected every day. Nothing more is needed, but this is needed. Without this, there is no system."

Mario P. Talamillo · Managing Partner, Certix®

Operational security policy for a driving school

Day-to-day life at a driving school has very specific components the security policy must address without overengineering:

  • Physical archiving of the file under lock and key in an area not accessible to students.
  • Digital access with individual passwords and two-factor authentication on the management platform.
  • Locked screens when staff leave their position, especially at reception where students may be waiting.
  • Communication with the student via controlled channels (corporate email, platform, SMS from system): do not use the instructor's personal WhatsApp to send results or documents.
  • Staff system access additions and removals: when an instructor or assistant leaves the driving school, access is revoked the same day.
  • Encrypted backup and tested restoration procedure.
  • Secure destruction of paper documentation (appropriate-grade shredder) and digital media at end of life.

Driving school minimum checklist

  • RoPA with real processing operations.
  • Information notices for adult student, minor student (to parents) and teaching staff.
  • Differentiated consent sheet at registration.
  • Art. 28 GDPR contracts with management platform, payment gateway, simulator, camera system, external accountant.
  • Operational security policy adapted to size.
  • Breach protocol and AEPD notification template.
  • Website privacy and cookie policy with correct LSSICE banner.
  • Student image management protocol with exclusion list and revocation procedure.
  • Retention policy by block and secure destruction procedure.
  • Documented procedure for rights exercises (access, rectification, erasure, objection, restriction, portability).

Frequently asked questions

What minimum data protection documentation does a driving school need?

RoPA with identified processing operations, art. 13 GDPR information notice delivered at registration referencing the DGT, differentiated consent sheet, art. 28 contracts with technology providers, operational security policy, breach protocol and website cookie policy.

Are the driving school and the DGT joint controllers?

No. They are independent controllers. The driving school is the controller of the student's file while it is under its management; the DGT is the controller of the drivers' register and the administrative process under RD 818/2009. Communication between them is covered by legal obligation, not an art. 28 arrangement.

What must the registration information notice contain?

Controller and DPO if any, specific purposes (file, DGT, billing, where applicable cameras), legal bases, recipients (especially the DGT), international transfers, retention periods by block, student rights and right to lodge a complaint with the AEPD.

What provider contracts does the driving school need to sign?

Art. 28 GDPR contract with each provider processing data on behalf of the driving school: management platform, payment gateway, simulator, camera system, external accountant, labour adviser. International transfer verification with Data Privacy Framework where applicable, and return of data before destruction at the close of service.

This content is for informational and educational purposes only and does not constitute legal advice. Applying the regulation to each specific case requires individual analysis. Regional sectoral regulations may extend or modify time limits and requirements.

Want to organise your driving school's GDPR compliance without overengineering it?

At Certix we assign you a compliance expert specialised in driver training. No commercial intermediaries, no generic templates.

Talk to an expert

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →