Education
Data protection for
schools and educational centres
Educational centres process data on minors with enhanced protection: academic records, photographs and special needs data. The appointment of a Data Protection Officer is mandatory for all centres delivering regulated education — public, private and state-subsidised — under art. 34.1.f) of the LOPDGDD.
art. 34.1.f)
LOPDGDD — DPO mandatory
14 years
digital consent threshold
Art. 9
GDPR — special category SEN data
24 h
personalised proposal
Sector challenges
Data protection obligations in educational centres
Minor pupils — enhanced protection
Under-18 pupils are a particularly vulnerable category. The processing of their academic records is grounded in the applicable legal basis for the centre (public interest or performance of contract). Parental or guardian authorisation may be required only for additional or specific processing activities. Each case must be assessed individually.
Photographs and videos of pupils
Images of pupils taken during school activities, trips and events are personal data. Publishing them on social media or the school website requires specific parental consent.
CCTV on school premises
Installing cameras in an educational centre requires a specific proportionality analysis, an information notice, and documentation in the RoPA (Record of Processing Activities). The AEPD has published criteria on this type of installation which should be consulted for each specific case.
Health data and special needs
Special educational needs reports, medical diagnoses and medication data are health data with enhanced protection. Only authorised staff may access them.
Communications with families
The messaging system used with families (educational platforms, email, school apps) involves processing the personal data of legal guardians and must be documented.
Digital educational platforms
Providers of school management platforms, family messaging apps and digital learning environments may act as data processors when they handle pupil data on the centre's instructions. The precise legal relationship depends on each provider's terms and must be verified and documented.
Legal obligation
The DPO is mandatory in educational centres
The art. 34.1.f) of the LOPDGDD establishes the express obligation to appoint a Data Protection Officer (DPO) for all centres delivering education at any level of the regulated school system — schools, secondary schools, universities and vocational training centres — whether publicly or privately owned. This is not a discretionary decision: it is a direct legal requirement.
The centre's DPO supervises regulatory compliance, manages family consent, advises on the use of educational platforms and acts as the point of contact with the AEPD. Certix fulfils this role as an independent service, including registration in the AEPD's DPO Register.
Most common legal bases
Art. 6.1.e GDPR
Public interest task — the primary basis for processing academic data.
Art. 9 GDPR
Special categories (SEN, educational psychology reports) — processing requires a detailed study of the applicable legal basis in each specific case.
Art. 6.1.a GDPR
Consent — pupil photographs, voluntary application use.
Art. 6.1.c GDPR
Legal obligation — communications with the education authority.
Art. 6.1.b GDPR
Contract — the centre's relationship with teaching and non-teaching staff.
The service
What the service includes for your educational centre
RoPA (Record of Processing Activities)
Tailored record: pupils, families, employees, CCTV and educational platforms.
Information clauses and consent
Enrolment documents, image authorisations and extracurricular activity forms.
Privacy policy and legal notice
Documentation for the centre's website.
Data Processing Agreements (DPA)
DPAs for educational platforms, family messaging apps and school management providers.
Data breach protocol
Response procedure with 72-hour notification.
Data subject rights management
Procedure for requests from families and employees, with specific provisions for minors.
Document management platform
Access to a private platform with documents and electronic signature.
Ongoing support
Unlimited queries. Updates in response to regulatory changes.
External DPO
Mandatory appointment under art. 34.1.f) LOPDGDD for all centres with regulated education. Certix fulfils this role under an independent contract, including registration in the AEPD's DPO Register.
Do you need a proposal for your centre?
Tell us the type of centre and number of pupils. Proposal within 24 hours.
FAQ
Frequently asked questions about data protection in educational centres
Are educational centres required to appoint a Data Protection Officer?
Yes. Art. 34.1.f) of the LOPDGDD establishes the express obligation to appoint a Data Protection Officer (DPO) for all centres delivering education at any level of the regulated school system, whether public, private, or state-subsidised. The obligation does not depend on the size of the centre or the volume of data processed.
Can photographs of pupils be published on social media or the school website?
In general, the publication of images of minors requires explicit consent. The specific conditions should be verified on a case-by-case basis with specialist advice.
Can CCTV be installed in a school?
CCTV in educational centres requires a rigorous proportionality analysis and is subject to specific criteria published by the AEPD. In general, its installation in teaching areas and pupil rest spaces raises serious proportionality concerns. Each case must be assessed individually before any installation proceeds.
How should communications with separated or divorced families be managed?
The centre must communicate with both parents who hold parental responsibility, unless a court order restricts this. Information about the pupil may not be shared with a parent where a court judgment prevents it. In cases of contentious separation, the centre must be especially cautious about the data it shares and must document its internal procedures.
Is data relating to special educational needs (SEN) classified as health data?
Yes. Educational psychology reports, special educational needs diagnoses, disability data, and medical reports submitted to the centre are health data (a special category under art. 9 GDPR). Access must be restricted to staff with a direct role in the pupil's care.
Can the parents' association (AMPA) access the school's pupil data?
Not directly. The parents' association is an entity independent of the educational centre. The centre may not provide the association with all pupils' data without the consent of their families. The association may collect data from members who voluntarily join, but it does not have automatic access to the centre's database.
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Education
GDPR compliance
for your educational centre.
An expert analyses your activity and proposes the right solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.