- LAWFULNESS: All personal data processing must be lawful, meaning that you must identify valid grounds under the GDPR legal basis for collecting and using personal data. There’s six legal bases described in the GDPR; but in my opinion, the legal basis that makes data processing in Admissions lawful is art. 6.1.c: data processing that needs to take place before entering into a contract (i.e. the school its Admissions Office/Team - must process personal data of a student and his family to decide whether or not to admit and sign an enrollment contract).To get a better idea on how lawfulness works, you simply have to think of the data processing in Admissions (that takes place BEFORE the student is enrolled) and the data processing that takes place AFTER he/she is admitted. Once the student is enrolled and the family has signed an Enrollment Contract, the school will process data with different purposes and thus the legal basis may vary:
- the Enrollment Contract would make lawful the data processing needed to perform the contract (provide educational services)
- a Law can also be the legal basis if the school is processing data to comply with obligations set forth in said Law
- and Consent may be the school’s legal basis if for example the school plans to publish a Directory (if you do use Consent, be sure to meet all GDPR requirements for consent).
- PURPOSE LIMITATION: All personal data collected needs to be done so with a purpose, that needs to be specific, explicit and legitimate. The purpose of data processing in the Admissions Office being whether or not a student should be admitted into the school. Your purpose(s) need to be recorded as part of the School’s (Controller) documentation obligations.
- DATA MINIMIZATION: Personal data shall be adequate (sufficient to properly fulfill your stated purpose), relevant (has a rational link to that purpose) and limited to what is necessary in relation to the purpose (you don’t ask for more than you need for that purpose). Are we collecting the personal data we need to satisfy our purpose?Can that purpose be met collecting less personal data? These are the sort of questions we should ask ourselves in order to understand if we comply with this principle.
- TORAGE LIMITATION: Personal data should not be kept longer than needed in relation to the purpose you are collecting it for and you must be able to justify, document and inform on retention periods. National laws might be a guide here, but in absence of specific laws, Controllers should make a decision and be able to provide solid arguments as to why they have decided for a specific period. In Spain for example, a national law requires that schools store academic information indefinitely, but what happens with personal data that is not academic?What happens with personal data collected by the Admissions Office of students that have not been admitted
- Accountability: In terms of principles, the last one to mention is Accountability, which requires all Controllers and Processors not only to comply with the GDPR but also be able to prove that they are complying. This involves Controllers having to document all decisions made in relation to GDPR compliance, and having appropriate measures and records in place to be able to demonstrate compliance.
About this article
Published October 19, 2018
About the author
Admin Faria Site
Contributing Writer
Recent Posts
The Admissions Digest
Subscribe today to receive our latest resources, events, updates and so much more – specially curated for you, and delivered straight to your inbox.