Skip to main content

Trust · School Data Compliance

Compliance for school data

GDPR-oriented workflows, FERPA-aware access scoping, and retention guidance for schools using Schoolyi internationally.

https://compliance.schoolyi.com · Schoolyi - Cloud School Management System (SMS)

Overlapping regimes, one roster

International schools often answer to GDPR for EU families, FERPA-style expectations from US expats, and local ministry rules simultaneously. Schoolyi does not replace your DPO or legal counsel - it gives operational tools that align with common requests: export, restrict access, document approvals.

Data subject and family requests

When a parent asks for a copy of their child’s records, registrars need a coherent export - attendance, fees, grades - not six CSVs from six modules. Workflows support structured export with role approval. Deletion or anonymization requests are handled with school legal guidance; some records must be retained for statutory periods.

  • Export packages for transfer and subject access requests
  • Role scoping limits unnecessary staff exposure to PII
  • Guardian linkage controls parent portal visibility
  • Audit trail on sensitive record changes

FERPA-oriented access patterns

US-facing schools typically restrict grade and discipline visibility to staff with legitimate educational interest. Schoolyi’s role matrix and class assignments implement that pattern operationally - counselors see caseload, substitute teachers see today’s periods only.

GDPR-oriented patterns

Lawful basis and purpose documentation remain the school’s responsibility. Schoolyi supports data minimization in daily use - collect fields admissions actually needs, hide staff-only notes from parent portals, and log consent where your policy requires it for optional communications.

Retention and archival

Schools define how long leaver records stay active vs archived. Finance may need fee history longer than athletics photos. Configuration guidance helps admins align module retention with policy without deleting data required for audits.

Cross-border transfers

Subprocessor and region documentation in the trust center supports transfer impact assessments. Enterprise agreements can include regional hosting preferences where available.

Working with your DPO

Provide your DPO the trust center, security summary, and this compliance mapping early. Pilot with a single campus and document which modules process special category data - health notes, counseling - before enabling them network-wide.

  • Role-based access - teachers, finance, admissions, and families see scoped workspaces
  • One academic calendar drives attendance, exams, fees, and leave
  • Phased rollout: admissions, roster, and fees first - expand when teams are ready

schoolyi.com · full sitemap

Frequently asked questions

Common questions about school data compliance with Schoolyi - Cloud School Management System (SMS).

Is Schoolyi GDPR compliant?+

Schoolyi provides tools and contractual terms schools need for GDPR-aligned operations. Compliance status depends on how your school configures modules, lawful basis, and subprocessors - legal review is required.

Can parents delete all data on request?+

Schools must balance erasure requests with legal retention for transcripts and tax records. Schoolyi supports deletion or anonymization workflows where policy and law permit.

Where are regional addenda?+

Published alongside trust documentation and updated when regulatory guidance affects product behavior or subprocessors.

Students walking together on a school campus

See school data compliance in a live SMS walkthrough

We show how this capability fits your cloud school management system - and which teams should go live first.

Already using Schoolyi? Sign in