Certix

Education

Data protection for
schools and educational centres

Educational centres process data on minors with enhanced protection: academic records, photographs and special needs data. The appointment of a Data Protection Officer is mandatory for all centres delivering regulated education — public, private and state-subsidised — under art. 34.1.f) of the LOPDGDD.

art. 34.1.f)

LOPDGDD — DPO mandatory

14 years

digital consent threshold

Art. 9

GDPR — special category SEN data

24 h

personalised proposal

Sector challenges

Data protection obligations in educational centres

Minor pupils — enhanced protection

Under-18 pupils are a particularly vulnerable category. The processing of their academic records is grounded in the applicable legal basis for the centre (public interest or performance of contract). Parental or guardian authorisation may be required only for additional or specific processing activities. Each case must be assessed individually.

Photographs and videos of pupils

Images of pupils taken during school activities, trips and events are personal data. Publishing them on social media or the school website requires specific parental consent.

CCTV on school premises

Installing cameras in an educational centre requires a specific proportionality analysis, an information notice, and documentation in the RoPA (Record of Processing Activities). The AEPD has published criteria on this type of installation which should be consulted for each specific case.

Health data and special needs

Special educational needs reports, medical diagnoses and medication data are health data with enhanced protection. Only authorised staff may access them.

Communications with families

The messaging system used with families (educational platforms, email, school apps) involves processing the personal data of legal guardians and must be documented.

Digital educational platforms

Providers of school management platforms, family messaging apps and digital learning environments may act as data processors when they handle pupil data on the centre's instructions. The precise legal relationship depends on each provider's terms and must be verified and documented.

Legal obligation

The DPO is mandatory in educational centres

The art. 34.1.f) of the LOPDGDD establishes the express obligation to appoint a Data Protection Officer (DPO) for all centres delivering education at any level of the regulated school system — schools, secondary schools, universities and vocational training centres — whether publicly or privately owned. This is not a discretionary decision: it is a direct legal requirement.

The centre's DPO supervises regulatory compliance, manages family consent, advises on the use of educational platforms and acts as the point of contact with the AEPD. Certix fulfils this role as an independent service, including registration in the AEPD's DPO Register.

Most common legal bases

Art. 6.1.e GDPR

Public interest task — the primary basis for processing academic data.

Art. 9 GDPR

Special categories (SEN, educational psychology reports) — processing requires a detailed study of the applicable legal basis in each specific case.

Art. 6.1.a GDPR

Consent — pupil photographs, voluntary application use.

Art. 6.1.c GDPR

Legal obligation — communications with the education authority.

Art. 6.1.b GDPR

Contract — the centre's relationship with teaching and non-teaching staff.

The service

What the service includes for your educational centre

RoPA (Record of Processing Activities)

Tailored record: pupils, families, employees, CCTV and educational platforms.

Information clauses and consent

Enrolment documents, image authorisations and extracurricular activity forms.

Privacy policy and legal notice

Documentation for the centre's website.

Data Processing Agreements (DPA)

DPAs for educational platforms, family messaging apps and school management providers.

Data breach protocol

Response procedure with 72-hour notification.

Data subject rights management

Procedure for requests from families and employees, with specific provisions for minors.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited queries. Updates in response to regulatory changes.

External DPO

Mandatory appointment under art. 34.1.f) LOPDGDD for all centres with regulated education. Certix fulfils this role under an independent contract, including registration in the AEPD's DPO Register.

Do you need a proposal for your centre?

Tell us the type of centre and number of pupils. Proposal within 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in educational centres

Are educational centres required to appoint a Data Protection Officer?

Yes. Art. 34.1.f) of the LOPDGDD establishes the express obligation to appoint a Data Protection Officer (DPO) for all centres delivering education at any level of the regulated school system, whether public, private, or state-subsidised. The obligation does not depend on the size of the centre or the volume of data processed.

Can photographs of pupils be published on social media or the school website?

In general, the publication of images of minors requires explicit consent. The specific conditions should be verified on a case-by-case basis with specialist advice.

Can CCTV be installed in a school?

CCTV in educational centres requires a rigorous proportionality analysis and is subject to specific criteria published by the AEPD. In general, its installation in teaching areas and pupil rest spaces raises serious proportionality concerns. Each case must be assessed individually before any installation proceeds.

How should communications with separated or divorced families be managed?

The centre must communicate with both parents who hold parental responsibility, unless a court order restricts this. Information about the pupil may not be shared with a parent where a court judgment prevents it. In cases of contentious separation, the centre must be especially cautious about the data it shares and must document its internal procedures.

Is data relating to special educational needs (SEN) classified as health data?

Yes. Educational psychology reports, special educational needs diagnoses, disability data, and medical reports submitted to the centre are health data (a special category under art. 9 GDPR). Access must be restricted to staff with a direct role in the pupil's care.

Can the parents' association (AMPA) access the school's pupil data?

Not directly. The parents' association is an entity independent of the educational centre. The centre may not provide the association with all pupils' data without the consent of their families. The association may collect data from members who voluntarily join, but it does not have automatic access to the centre's database.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Education

GDPR compliance
for your educational centre.

An expert analyses your activity and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.