DPDP Rules, 2025 are now in effect. See where your business stands, in 3–5 minutes.Find out — free →
Where your data travels · Schools & Colleges

One student. Many systems. One institution's responsibility.

Follow one student's information through enquiry, admission, the school ERP, classroom platforms, attendance, cameras, transport, hostels, health and counselling records, examinations, fees, board submissions, placements, public photographs and long-term archives - and count every place it ends up, and where you lose control of it.

Show the journey for:
12 stages
  1. 1

    Enquiry, prospectus & campus visit

    +5 places · 5 so far

    A parent calls, fills in a website form, messages on WhatsApp, walks in on an open day or arrives through an education portal. A child's name, age and current school are recorded - along with the family's address and the parents' occupations - before anyone has applied for anything.

    Moving hereStudent identity (new at this stage)Contact & address details (new at this stage)Parent, guardian & family details (new at this stage)Academic record & admission history (new at this stage)Photographs, video & messages (new at this stage)Household segments & institutional analytics· inferred (new at this stage)

    DPDPAGive notice at the first point of contact, not at admission. An enquiry needs far less than an application does: a child's full date of birth, sibling details and a parent's occupation are not required to answer a question about fees. Keep enquiries in systems you can search, restrict and delete from, and set a retention rule for families who never enrol.

  2. 2

    Application, documents & guardian authorisation control breaks

    +5 places · 10 so far

    The application is submitted with birth certificates, identity documents, previous school records and a health declaration. One parent signs one form - and that signature is subsequently treated as permission for the school app, the photographs, the CCTV, the bus tracker and the marketing, for as long as the student stays.

    Where control breaks: One signature at admission is treated as permission for everything

    Moving hereIdentity & eligibility documents (new at this stage)Health, counselling & special support (high-impact student data) (new at this stage)Student identityContact & address detailsParent, guardian & family detailsAcademic record & admission history+1 more

    DPDPASeparate what admission genuinely requires from what is optional, and record each optional use as its own choice that can be refused without affecting the admission. Record which guardian is authorised for what, keep the notice version and timestamp with the record, and define how long a rejected application is kept.

  3. 3

    Student identity, ERP & account creation control breaks

    +5 places · 15 so far

    The student becomes a record: an admission number, a roll number, a class and section, a parent login, a student email, an ID card and an entry in every system the institution runs. The same person is created several times over, and the link to the right adult is made by hand.

    Where control breaks: One student, several records - and the wrong adult attached

    Moving hereCCTV, biometric & campus-access records (new at this stage)Fees, scholarships & family finances (new at this stage)Learning-platform & exam activity (new at this stage)Student identityContact & address detailsParent, guardian & family details+3 more

    DPDPADefine one master student identifier that every other system derives from, verify the guardian relationship rather than assuming it, and provision and de-provision accounts through a controlled workflow. Duplicate students and stale parent logins are how the wrong adult ends up receiving a child's records.

  4. 4

    Classroom, LMS & EdTech activity control breaks

    +5 places · 20 so far

    Teaching generates data continuously: attendance in a register, work submitted to a portal, reading levels, participation notes, quiz scores, device activity, and free-text comments about a child written by an adult who will not be there in three years.

    Where control breaks: Student work goes into tools the institution never approved

    Moving hereAttendance & behaviour records (new at this stage)Learner profiles & tool-generated judgements· inferred (new at this stage)Student identityParent, guardian & family detailsAcademic record & admission historyHealth, counselling & special support (high-impact student data)+2 more

    DPDPAKeep an approved-tool register and check what each vendor does with student work before a class uses it. Teacher observations become part of a child's record: keep them factual, keep them in institutional systems rather than personal devices, and make sure a parent can see and challenge what has been written.

  5. 5

    Attendance, CCTV, biometrics & campus access control breaks

    +5 places · 25 so far

    Cameras record corridors and classrooms, a fingerprint or face marks attendance, an RFID card logs each gate crossing, and a visitor book links an adult to a child. Together these produce a continuous, timestamped record of where a child was and who they were with.

    Where control breaks: Cameras, fingerprints and card taps build a continuous record of a child

    Moving hereStudent identityParent, guardian & family detailsAttendance & behaviour recordsHealth, counselling & special support (high-impact student data)CCTV, biometric & campus-access records

    DPDPAUse the least intrusive method that achieves the safety purpose, and be able to state that purpose per system. A biometric template needs a genuine necessity case and a deletion path on exit; CCTV needs defined camera placement, a retention limit, named access and a viewing log. Convenience is not a purpose.

  6. 6

    School transport & live location

    +4 places · 29 so far

    A child's name, home address, pickup stop, timings and a parent's mobile number are handed to a transport office, a driver and an attendant - and a GPS unit begins producing a live location trail that a parent app can watch.

    Moving hereTransport & location data (new at this stage)Student identityParent, guardian & family detailsCCTV, biometric & campus-access records

    DPDPAThis is the point where a child's home address and daily routine leave your buildings. Minimise what a driver can see, use masked contact numbers where the route allows, limit how long location history is kept, make sure a parent sees only their own child, and revoke access the day a driver or attendant stops working for you.

  7. 7

    Health, counselling & special support control breaks

    +2 places · 31 so far

    Allergies, medication, a disability, a learning-support plan, an infirmary visit, a counselling session or a safeguarding concern is recorded - very often in a notebook, a personal drive or a message to a staff group rather than a controlled system.

    Where control breaks: The most sensitive record is kept in the least controlled place

    Moving hereStudent identityParent, guardian & family detailsHealth, counselling & special support (high-impact student data)Learner profiles & tool-generated judgements· inferred

    DPDPAThis is the highest-impact data an institution holds about a young person. Restrict it to the staff who genuinely need it, keep counselling records separate from the academic file, never disclose a condition in a class or staff group, share only the classroom support a teacher must know about rather than the diagnosis, and give the family a way to correct it.

  8. 8

    Examinations, proctoring & results

    +3 places · 34 so far

    Marks begin life in a teacher's own spreadsheet, move into the examination system, become a report card or a transcript, and - where exams are online - are accompanied by a webcam recording, browser activity and an automatically raised suspicion flag.

    Moving hereStudent identityAcademic record & admission historyAttendance & behaviour recordsLearning-platform & exam activityLearner profiles & tool-generated judgements· inferred

    DPDPAKeep one authoritative version of a result with an auditable correction history, and delete the working copies that were never meant to persist. Where a tool monitors a student during an exam or flags them automatically, define how long the recording is kept, require a human decision before any consequence, and give the student a route to challenge it.

  9. 9

    Fees, scholarships & financial aid control breaks

    +4 places · 38 so far

    Payment history, outstanding dues, bank details, a family's income certificate, a category certificate and a loan or scholarship file are processed - and the list of families who have not paid tends to circulate far more widely than the finance office.

    Where control breaks: What a family could not pay becomes known to the classroom

    Moving hereStudent identityParent, guardian & family detailsIdentity & eligibility documentsAcademic record & admission historyFees, scholarships & family financesHousehold segments & institutional analytics· inferred

    DPDPARestrict financial records to finance roles, and treat a family's income documents as high-impact data rather than routine paperwork. Share the minimum a scholarship body needs, never publish or circulate a defaulters list, keep fee reminders private to the family, and hold financial records under their own retention rule.

  10. 10

    Boards, universities & regulator submissions

    +2 places · 40 so far

    Student identity, attendance, marks, category and eligibility data are submitted to an education board, an affiliating university, a scholarship authority or an inspection body - usually as a spreadsheet exported from the ERP and emailed or uploaded by hand.

    Moving hereStudent identityIdentity & eligibility documentsAcademic record & admission historyAttendance & behaviour records

    DPDPAKeep a register of what is disclosed, to which authority and under what obligation. Validate an export before it is submitted rather than after a correction is needed, restrict who holds portal credentials, delete the working files afterwards, and have a route to push a correction through to every authority that already received the wrong version.

  11. 11

    Communication, photographs & public content control breaks

    +4 places · 44 so far

    Announcements, fee reminders, results and event invitations go out through parent groups, apps and bulk messaging - and photographs, videos, award lists and toppers' marks go out onto the website and social media, where they stay.

    Where control breaks: The child's face is the institution's marketing asset

    Moving hereStudent identityContact & address detailsParent, guardian & family detailsAcademic record & admission historyAttendance & behaviour recordsHealth, counselling & special support (high-impact student data)+3 more

    DPDPATreat publication as a separate, specific and revocable choice per channel, not part of the admission form. Keep a working removal route for a family that changes its mind, avoid publishing a child's full name alongside their results or a location and routine, control what an event photographer keeps, and review what is still visible from previous years.

  12. 12

    Transfer, graduation, alumni & archive control breaks

    +4 places · 48 so far

    The student leaves with a transfer certificate or a degree - and stays behind in the ERP, the LMS, the parent app, the photo library, the CCTV archive, the transport system, the board's records, the alumni database, the vendor platforms, the backups and a physical record room.

    Where control breaks: The student leaves. The record does not.

    Moving herePlacement, internship & alumni records (new at this stage)Student identityContact & address detailsParent, guardian & family detailsIdentity & eligibility documentsAcademic record & admission history+6 more

    DPDPAWrite a retention rule per record type and separate what you are genuinely required to keep - an academic transcript - from what is merely never deleted. Close student and parent accounts, remove optional marketing and analytics profiles, chase vendor deletion, review what is still public, and record honestly where an erasure cannot reach and why.

In this reference model, one student's data ends up in 48 distinct places across 12 stages, with 8 places where control breaks.

Top risk hotspots - where control usually breaks

The 8 places student data most often slips out of your control. Each links to the matching check in the readiness assessment.

  1. Hotspot 1 Critical risk

    Event photographs, classroom videos, prize-day footage and toppers' names with their marks go onto the website, Instagram and YouTube - and into admission advertising. The permission for it was a line on an admission form signed years earlier by one parent, there is usually no working way to ask for removal, and material stays up long after the student has left.

    Why this matters

    No other kind of business publishes its data principals' faces and names as a matter of routine. A named child, in uniform, at an identifiable place, on a known daily schedule, is visible to anyone - and their academic results are frequently published beside them. Unlike almost everything else on this map, a family that changes its mind cannot undo it: the image has been copied, cached and indexed.

    Fix: Make publication a specific, separate and withdrawable choice per channel rather than part of the admission form, run a removal route that actually works and tell families it exists, stop publishing a full name next to results or alongside a location and routine, put in writing what an event photographer may keep, and review and prune what is still visible from previous years.

    Check this in the assessment
  2. Hotspot 2 Critical risk

    A parent signs the admission form. That signature is subsequently relied on for the parent app, the classroom photographs, the CCTV, the biometric attendance, the bus tracker, every third-party learning platform the institution later adopts, and the marketing - for as long as the student stays.

    Why this matters

    None of those uses was separately explained, none can be refused without appearing to jeopardise the admission, and several did not exist when the form was signed. There is usually no record of which guardian signed, what they were shown, or what they agreed to - so if a family asks the institution to stop one of these things, it has nothing to act on and no way to prove what was permitted.

    Fix: Separate what admission genuinely requires from what is optional, capture each optional use as its own choice that can be declined without consequence and withdrawn later, record the notice version, the date and which guardian gave it, and re-confirm directly with the student once they are an adult.

    Check this in the assessment
  3. Hotspot 3 Critical risk

    CCTV records corridors, gates and - in many institutions - classrooms. A fingerprint or face marks attendance. An RFID card logs every gate crossing, and a visitor book links an adult to a child. Retention is whatever the recorder defaults to, access is an app on several personal phones, and clips get shared into staff groups when something happens.

    Why this matters

    Separately each looks like a safety measure; together they are a timestamped record of where a named child was, when, and who they were with, held indefinitely because nobody set a limit. A biometric template taken from a child cannot be reissued if it leaks, is usually collected because it was convenient rather than necessary, and is almost never deleted when the student leaves.

    Fix: Write down the purpose of each camera and each reader and remove the ones that fail it, justify biometrics against a less intrusive alternative and offer a non-biometric option, set and enforce a retention period, restrict viewing to named individuals with a log, ban sharing footage into messaging groups, and delete templates and access records when a student leaves.

    Check this in the assessment
  4. Hotspot 4 Critical risk

    Allergies, medication, a disability, a learning-support plan, counselling sessions and safeguarding concerns are recorded in a notebook, a personal drive folder or an email thread. The emergency medical sheet is pinned up where staff - and anyone walking past - can read it, and conditions get mentioned in staff and class groups.

    Why this matters

    This is the highest-impact data an institution holds about a young person, and it is held with less control than the fee ledger. A support need becomes a label that follows the child through every subsequent year, a diagnosis reaches people who only needed to know what to do in an emergency, and a family that disagrees with what was written has no way to see it or have it corrected.

    Fix: Move counselling and support records into a system with named, restricted access and an audit trail, give teachers the classroom action rather than the underlying diagnosis, never disclose a condition in a staff or parent group, reduce the posted emergency sheet to the minimum needed to act, set a retention rule, and give families a route to see and correct what is held.

    Check this in the assessment
  5. Hotspot 5 Critical risk

    A teacher pastes a child's essay into a public chatbot to draft feedback or a report-card comment, along with their name and sometimes their support needs. Elsewhere a department has signed up to a learning app on its own, and the institution cannot produce a list of every platform holding student data.

    Why this matters

    A child's work and name are disclosed to a service the institution has no contract with, no notice covers and no deletion route reaches. There is no record it happened, so it cannot be told to a parent, included in an access response, or stopped afterwards. The adopted platforms are barely better: each holds a profile of what the child is judged to be weak at, built by a model nobody has reviewed.

    Fix: State plainly which tools may and may not be used on student work and provide an approved alternative so the need does not go underground, keep a register of approved learning platforms with an owner for each, check what a vendor retains and whether student work trains their models before a class uses it, and require deletion when a contract ends.

    Check this in the assessment
  6. Hotspot 6 Critical risk

    The same child is created separately in the ERP, the LMS, the parent app, the transport list and the exam system, and the records are reconciled by eye. A sibling's details, a shared family mobile number or a mis-keyed date of birth quietly links a child to the wrong adult, and a separated parent's login is almost never removed.

    Why this matters

    This is how a report card, an attendance alert, a counselling outcome or a live bus location reaches someone who should not have it - including, in the worst cases, a parent a court has restricted. It is also why a correction made in one system never reaches the others, and why nobody can answer confidently when a family asks what the institution holds.

    Fix: Define one master student identifier that every other system derives from, verify and record the guardian relationship rather than inferring it from a phone number, support more than one guardian with different scopes, provision and remove accounts through a controlled workflow, run duplicate detection, and audit every record merge.

    Check this in the assessment
  7. Hotspot 7 Critical risk

    A dues report is exported at the start of every reminder round and forwarded to class teachers to chase. Names get read out in class, pinned to notice boards or circulated in staff and parent groups, and a report card is held back until the fee is cleared. Alongside this, income and category certificates submitted for a scholarship sit in the finance folder indefinitely.

    Why this matters

    A child is identified to their classmates by their family's financial position - something they did not choose, cannot change, and will carry socially for the rest of the year. The underlying documents are among the most consequential a family ever hands over, and they are handled as routine paperwork rather than as high-impact data.

    Fix: Restrict fee records to finance roles and never publish or circulate a defaulters list in any form, send teachers an action rather than a household's financial circumstances, keep reminders private to the family and out of class-level channels, handle income and category documents through named staff only and delete local copies once processed, and set a retention rule for financial records.

    Check this in the assessment
  8. Hotspot 8 Critical risk

    A transfer certificate or a degree is issued and the student is marked inactive. They remain in the ERP, the LMS, the parent app, the photo library, the camera archive, the transport system, the alumni list, the board's records, every vendor platform, the nightly backups and a paper file in a store room - and are carried into alumni outreach without anyone asking.

    Why this matters

    This is the question the whole map exists to answer. If a former student asked tomorrow for every copy of their data, most institutions could not produce the list - and of the places they could name, most they cannot reach. An education record is one of the few that genuinely must be kept in part, which makes it all the more important to know which part that actually is.

    Fix: List every place student data lands and write a retention rule for each, separate what you are genuinely required to keep - a transcript - from what is merely never deleted, close student and parent accounts as a defined exit step, make alumni participation something a leaver chooses rather than a default, ask every vendor in writing what they retain and how deletion works, and record honestly where an erasure cannot reach and why.

    Check this in the assessment

What happens when someone asks

The map above shows where student data ends up. This is what that means the day someone asks you to find it, fix it or remove it - including the places a request realistically cannot reach.

Who asks: A parent or guardian of a current student - or, once the student is 18, the student themselves.

Where you have to look

  • School ERP / Student Information SystemYour institution
  • Admissions CRM & enquiry registerYour institution
  • Admission document storeYour institution
  • Learning management systemYour institution
  • Attendance register & ERP attendanceYour institution
  • Infirmary & health recordYour institution
  • Examination & result processingYour institution
  • Fee & payment portalYour institution
  • Parent & student mobile appYour institution
  • Physical admission filesYour institution

Where this usually cannot reach

  • Reception & counsellor WhatsAppYour institution
  • Teacher's own laptop & phoneYour institution
  • Parent & class WhatsApp groupsYour institution
  • Public AI assistant used on student workOthers who receive it
  • Backups & vendor copiesEdTech & service vendors
  • Event photographer & yearbook vendorEdTech & service vendors
  • Board, university & regulator portalBoards, universities & regulators

What has to happen

  1. Verify who is asking and confirm they are the authorised guardian for that student - not simply the number on the record.
  2. Pull the master record from the ERP, and the linked records from the LMS, attendance, examinations, health and fees.
  3. Retrieve the admission file and the documents that were uploaded, including the ones you no longer had a reason to keep.
  4. Include what the institution created rather than collected: teacher observations, ability bands, support plans and any score a platform generated.
  5. Name the third parties the data has been shared with - the board or university, the learning platforms, the photographer, the messaging and payment vendors.
  6. Say plainly which places you could not search, and why.

The part that usually fails: The parts nobody can search. A year of WhatsApp messages on a counsellor's phone, marks and photographs on a teacher's personal laptop, a class group containing every family's number, and whatever a public AI tool retained - none of these can be queried, so the answer is either incomplete or silently pretends they do not exist.

Check whether you could answer this today

When it has already gone wrong

An operational response reference for the incidents this sector actually has - what to do in the first hour, what to put right afterwards, and the control that stops a repeat. Whether an incident needs to be reported is a decision to take with your own advisers.

Serious

How you find out: A parent calls to say they received another child's report - or, more seriously, a separated parent received a record they were not supposed to have.

Systems involved

  • Report cards & transcriptsYour institution
  • School ERP / Student Information SystemYour institution
  • Parent & student mobile appYour institution
  • SMS & email broadcast platformEdTech & service vendors

First - stop it spreading

  1. Ask the recipient to delete it and confirm they have, and stop any remaining sends in the same batch.
  2. Suspend the parent app login that is wrongly attached until the relationship is verified.
  3. Check whether the same wrong link has sent anything else - attendance alerts, fee notices, bus location.

Then - correct it and record it

  1. Find out whether the cause was a duplicate student record, a shared mobile number or a stale login, and fix the master record.
  2. Verify and record the guardian relationship properly rather than re-typing the number.
  3. Tell the family whose data was disclosed what was sent, to whom, and what you have done.
  4. Log it as an incident with a cause, an owner and a closure date - not as an administrative slip.

The control that prevents a repeat: One master student identifier with verified, recorded guardian relationships and scoped access per guardian, plus duplicate detection - so a shared phone number can never resolve to the wrong adult.

How to read this journey

Pick your model

Switch between School - K-12, College / higher education and Integrated multi-campus institution to see the journey each kind of institution actually runs. This is not a filter over one journey - a school runs bus routes and has no placement cell, a college runs hostels, online proctoring and placements and no school transport, and a multi-campus group runs both and adds central analytics over every branch. The stage count and the place-counter recalculate for the model you choose.

When it leaves you

A violet left edge and a tag mark everything outside your institution - EdTech and ERP vendors, the camera and attendance suppliers, the transport contractor and their drivers, the examination board or affiliating university, scholarship authorities, employers receiving CVs, event photographers, ad platforms, and anything published where the public can see it. Once data lands there your control is indirect: it runs through your contract and instructions, not your admin panel. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and a teacher's own laptop can be one of the worst things on the page.

Where control breaks

Red flags mark the hotspots - the eight places schools and colleges most often lose control of student data, from one admission signature standing in for a decade of permissions, to a child's photograph becoming marketing, to a student who left years ago still sitting in every system. Tap any system to see what it holds and how to fix it.

Now check whether your controls hold up

The map shows where student and parent data travels in a typical school or college. The 3-minute readiness scan checks whether your institution has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.

Educational reference model - not legal advice, and not a scan of your actual systems.