How School Websites Stay GDPR Compliant

Many school websites collect a lot of personal data from parents, pupils and staff of the school. Because of the GDPR rules and regulations above, school websites need to be GDPR compliant and that’s not something you can opt out of.

Publish a Clear Privacy Notice

The Privacy Notice for a school’s website must clearly explain what data a website will collect about a user of a website, the purpose(s) for which the data will be used, the period for which time personal data will be stored, and who will be given access to the personal data of users to a website. The said Privacy Notice must be worded in simple English and linked to from the home page’s footer of a website. A Privacy Notice must be reviewed by the provider of a website on a regular basis. It shall also need to be updated whenever there is a change in how personal data of users of a website is to be used by the provider of a website.

Get Your Cookie Banner Right

By simply stating that using the website implies acceptance of the cookies, a cookie banner does not meet the required standards. A genuine opt-in for non-essential use of cookies must be provided. Here, non-essential cookies are switched off by default and the visitor is able to choose to accept them for use on the website. The banner must actually block tracking scripts until consent is given for their use.

Handle Contact Forms Carefully

Every contact form on a website is a point at which data will be collected from a user of a website. Information needs to be provided to users of websites as to what information will be collected using contact forms on school websites and what this information will be used for. Furthermore only information that is needed to be collected using contact forms on school websites should be requested for use on the website.

Manage Pupil Photos With Consent Records

For any images (photos or videos) of pupils on your website, you will need to keep a signed copy of the consent that was given for publication for each individual. There must be a process for removal of images should consent be withdrawn at a future date and records must be kept to allow for their removal promptly.

Appoint a DPO and List Their Contact Details

A DPO (Data Protection Officer) must be appointed for a School. The Name and Contact Email of the DPO must be clearly stated on the School Website. This can be done on a dedicated page or as part of the School Website’s Privacy Notice. Further guidance can be found on the ICO’s UK GDPR guidance for organisations.

Review and Remove Outdated Data

Old information is frequently left online for long periods of time, and this can often include old personal information. Checking for old personal information is one of the main tasks for ensuring school websites are up to date and remain compliant.

If you are looking for Websites for schools, see https://www.fsedesign.co.uk/websites-for-schools.

This is a summary of key good practice points. Most of these will form part of normal practice for the website rather than representing significant changes.

Tony Jimenez

Learn More →

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.