The general data protection regulations (GDPR) aren’t just for schools; they apply to every European organisation that handles personal data.
The aim of the new law is to return control to individuals by allowing them to request deletion or disclosure of their data: and the onus is on organisations to provide evidence of their data storage activities.
There isn’t any detailed specific guidance available for anybody (it would be impossible to document every possible scenario), so organisations must decide how best to apply the generic GDPR rules to themselves before the deadline of May 25.
So what are schools meant to do?
