Skip to content
PERINGER Data Solutions, back to home

Back

← All articles

Private schools: which law protects pupil data?

Published · updated

The head of a private school bases her IT contract on a template a neighbouring municipality supplied. The intention is sound and the document is solid. But its legal basis can’t simply be copied. A private school usually acts as a private organisation, while staying subject to cantonal education oversight and, in some cases, to rules that govern a public task.

The confusion is understandable. Both kinds of school educate children, operate under cantonal supervision and sometimes process sensitive personal data. But the competent authority depends on the organisation, the purpose and the task in which the processing takes place.

Two frameworks that must work together

I take these cases in the same order every time: the school’s status first, the canton second, the supplier last. The reverse order produces a solid contract that rests on the wrong basis.

A private school is supervised by the canton, including aspects of its teaching, its authorisation and its organisation. In the canton of Vaud, the private education act gives the department oversight of the organisation and the curriculum of establishments that take pupils of compulsory school age.

For its private processing, the school is generally subject to the revised Federal Act on Data Protection (revised FADP) and to the Federal Data Protection and Information Commissioner. That doesn’t displace the cantonal oversight. A subsidised or recognised school, or one that performs a delegated public task, may fall within a cantonal or mixed regime for some processing. The scopes need to be mapped, not opposed.

The practical conclusion is less dramatic and more useful: don’t copy a municipal contract, and don’t copy a standard commercial contract either, without analysis. First identify the controller, the task, the canton, any public funding or delegation, and the competent authority. The revised FADP already requires a private controller to select and to govern its providers properly.

Some pupil data is legally sensitive

A school processes contact details, results, assessments, educational measures, psycho-educational reports, disciplinary records, medical certificates and photographs. All of that is personal data. But it isn’t all sensitive personal data as a matter of law. Health data, certain social-assistance information and high-risk profiles ask for particular care.

Nor does being a minor mean that a pupil can never consent independently. The pupil’s capacity, age and maturity, the purpose and the legal basis, and the parental authority all count. And consent isn’t necessarily the right basis for ordinary school activities in the first place.

That shifts two obligations many small organisations believe they escape.

The register of processing activities

The exemption for organisations with fewer than 250 employees doesn’t apply if they process sensitive personal data on a large scale or run high-risk profiling. A school should document the actual categories and the actual scale before deciding whether the statutory register is mandatory. And even when the register isn’t mandatory, a proportionate processing inventory stays an excellent management tool.

Breach notification

Article 24 revised FADP requires security breaches likely to lead to a high risk for the people concerned to be reported to the federal commissioner as soon as possible. That isn’t the GDPR’s 72-hour deadline, quoted so often by reflex: the European deadline applies only if the GDPR itself applies, for example through an EU establishment or an activity covered by Article 3. The presence or the nationality of EU pupils and parents isn’t sufficient on its own.

The parent portal is the sensitive point

A big share of the risk sits in the wider ecosystem: parent portals, grading platforms, class messaging, document sharing, video conferencing, school photography, identity systems and backups. The school’s own server is only one part of that chain.

Each provider has to be classified by the decisions it actually makes. Some are processors; others may be independent or joint controllers. All of them have processing locations, subprocessors, retention periods and terms that need to be checked. Some consumer services even exclude the categories of data that staff place in them.

Three questions are enough to sort them:

  1. What pupil data does this tool actually see, and how long does it keep it?
  2. Where is it processed, who can access it, and which jurisdictions and subprocessors are involved?
  3. What does the school get back if it changes tool, and in what format?

The points the accreditation and the insurer look at

Depending on their rules and on the policy wording, two parties may ask detailed questions before an authority does: an accreditation body, and the cyber insurer at renewal.

Their requirements aren’t universal. But a prepared school can produce evidence such as:

  • an inventory of processing activities
  • signed processing agreements
  • backups whose restoration has been tested
  • an incident notification procedure
  • traceability of access to pupil files

A school that prepared these for the revised FADP already has a strong basis to answer those requests.

That’s the best order of work in any case: treat compliance as tidying up what exists, not as a separate file. The tool inventory, the data locations and the exit clause each earn their keep three times over.

I checked the framework described here on 14 August 2026. This article offers a decision framework, not legal advice. The school’s status, its canton, its funding, its recognition or a delegated public task may change the applicable regime.

A first conversation, no commitment

A few lines about your project or your question are enough: I reply directly, usually within one working day.

Get in touch