Data Protection in Schools and Education Institutions
Introduction
Swiss schools and education institutions process sensitive data on minors: learning and performance data, special-needs diagnostics, school-psychology reports, disciplinary files, photographs and video, behaviour observations. The legal landscape is federally complex: public schools are governed by the relevant cantonal information and data-protection act (IDG, ÖDSG, KDSG depending on canton), private schools fall under the federal Federal Act on Data Protection (DSG). Layered on top are school acts, secondary and higher-education law, EDK recommendations on cloud use and the ever-present question of Microsoft 365 and Google Workspace in education. Generative AI in classrooms has further intensified the debate in 2026.
What this article delivers:
- Which legal sources actually apply to schools – cantonal or federal
- How to obtain valid parental consent for under-16s
- What to watch for with Microsoft 365, Google Workspace and learning analytics
- How to handle photo and video publication cleanly
- Which TOMs match EDK recommendations and cantonal practice
Federal or cantonal framework
The dividing line is organisational: public schools (compulsory education, cantonal upper-secondary schools, vocational schools, universities of teacher education) are public bodies of the canton or municipality and are governed by the relevant cantonal data-protection act. Oversight rests with the cantonal data-protection commissioners (e.g. Zurich Data Protection Commissioner, Vaud/Geneva cantonal commissioners). Since 2023/2024 most cantons have aligned their IDG/KDSG to the DSG level – but each canton retains its specifics, e.g. on retention periods, statutory disclosure rights and municipal school boards.
Private schools (private gymnasiums, international schools, corporate education providers) are governed by the federal DSG. They are subject to the familiar duties under Art. 12 (processing register), Art. 19 (information), Art. 22 (data-protection impact assessment), Art. 24 (breach notification), Art. 25 (access). For higher-education institutions the situation is hybrid: cantonal universities under cantonal law, the ETH domain (ETH Zurich, EPFL, PSI, WSL, Empa, Eawag) under federal law. International students and EU research projects pull GDPR into the picture – Horizon Europe and Erasmus+ specifically require GDPR-compliant processing.
Consent of minors
The DSG does not set a rigid age threshold for consent capacity (unlike GDPR Art. 8 with the 16-year threshold). The decisive criterion is capacity of judgement under Art. 16 CC: relative, depending on maturity and complexity of the decision. The following three-tier approach has emerged in practice:
- Under 12: consent by legal guardians, information to the child in age-appropriate language.
- 12-15: consent jointly with guardians; for simple, low-risk everyday processing the pupil may consent alone, but for more complex or publication-related processing (photo/video publication, learning analytics with profiling) parental participation is required.
- From 16: capacity of judgement on data-protection matters is regularly presumed; the pupil consents personally, parents are informed but not required to co-consent.
Consent must be freely given, informed and revocable. Schools should avoid consent constructs for basic school processing, which is legally grounded anyway (compulsory education, cantonal school acts) – consent is limited to genuinely voluntary additional services: class photos, school website, sponsor images, optional learning apps, voluntary learning analytics. A "bundled" start-of-year consent is not free enough – every processing with meaningful risk needs its own, separated consent.
Microsoft 365 and Google Workspace in schools
The use of Microsoft 365 (Education A3/A5) and Google Workspace for Education in Swiss schools has been commented on by several cantonal data-protection commissioners (notably Zurich, Schwyz, Bern, Basel-Stadt) and the EDK in multiple statements. The 2026 consensus: both platforms can be operated lawfully where configuration is restrictive and TOMs apply.
Concretely: 1. vendor contract with a clean DPA, tenant location in the EU/EEA, Swiss supervision accepted; 2. restrictive tenant configuration: telemetry minimised, no advertising, Connected Experiences disabled where possible, no automatic LinkedIn/M365 Copilot logging for minors; 3. transparent pupil/parent information with concrete fact sheets; 4. an internal school data-protection lead reviews configuration annually; 5. no use of US cloud AI features without a risk assessment; 6. clearly regulated data return and erasure on transfer or graduation. Use of Copilot, Gemini for Education, ChatGPT EDU or local LLM solutions mandatorily requires an impact assessment under cantonal IDG or Art. 22 DSG – vendors increasingly document their position, some configurations meet requirements, others do not.
Learning analytics and observation
Learning analytics, adaptive learning platforms (Mathletics, Lernpass+, publisher-provided tools, higher-education LMS such as Moodle, Ilias and Canvas with analytics modules) and online exam tools are data-protection-intensive applications. They produce profiles of considerable granularity: time on task, click sequences, error profiles, attention-proxy data. Such profiling regularly meets the Art. 5(f) DSG definition of "profiling" and may qualify as "high-risk profiling" under Art. 5(g) DSG.
Three measures are non-negotiable: first, a data-protection impact assessment for every analytics application identifying risks (stigmatisation, privileging, effects on academic trajectory), mitigations (aggregation, pseudonymisation, narrow retention) and residual risk. Second, transparent information to parents and pupils about purpose, logic and consequences of the analysis – generic statements do not suffice. Third, continuous teacher training in interpretation: an analytics dashboard is an indicator, not a verdict, and never the sole basis for an academic decision. The Art. 21 DSG ban on automated individual decisions bites where recommendations with academic consequences are generated without human involvement. Video surveillance in school buildings is additionally tightly regulated by cantonal law; surveillance inside classrooms is regularly impermissible.
Photo, video and school communications
Publication of images and videos on the school website, social media and yearbooks is one of the most frequent conflict areas. Legally, data-protection law is overlaid with the right to one's own image (Art. 28 CC) and the photographer's copyright. Practical rules:
- Differentiated consent: per publication channel (school website internal, school website public, social media, print, press). An "all or nothing" approach is not free.
- Granularity: class photos with name lists are more sensitive than context images without identification. Group photos with first names are better than with full names.
- Retention and erasure: images are removed after a fixed period (often 5 years); former pupils can request removal at any time.
- Clear negative list: swimming lessons, changing situations, sensitive moments (special-needs support, school crises) are categorically excluded from publication, even with consent.
- Teacher and third-party images: separate consent because protection needs differ.
- Events with press: prior information, programme notice, opt-out option (e.g. sticker).
School chats via WhatsApp are problematic: WhatsApp Business processes metadata outside the EU/EEA. Swiss alternatives such as Threema for Education, class chats via M365 Teams or Edupage are increasingly recommended.
Breaches and incident response
In 2026 schools are routinely targeted with phishing against teacher accounts, ransomware encrypting school-administration systems and occasional targeted doxxing of high-profile pupils. Notification duties depend on the legal framework: public schools report under cantonal IDG (e.g. §25 IDG ZH with notice to the data-protection commissioner of the competent body), private schools report under Art. 24 DSG to the FDPIC. In both cases: information of the affected persons where the risk requires – with child and youth data this is in practice always.
A productive incident response follows: 1. immediate containment (account lock, system isolation), 2. coordination with IT provider and where needed an external forensicator, 3. risk assessment with the data-protection lead, 4. notification to the competent supervisor (cantonal or FDPIC), 5. information of school leadership, school board, where relevant the cantonal education department and parents, 6. BACS/NCSC notification under Art. 74b ISG for schools with critical function, 7. police complaint where a criminal offence is involved, 8. lessons-learned, TOM adjustment, awareness reinforcement. Schools without a documented incident plan lose trust with parents and authorities in the first hours. An annual tabletop training including teachers is the single most effective measure.
How SIDD supports you
SIDD supports Swiss schools at every level – compulsory schools, gymnasiums, vocational schools, private schools, universities – as external data-protection adviser and security partner. We deliver the processing register, pupil/parent privacy notices, consent templates with correct age tiering, data-protection impact assessments for Microsoft 365, Google Workspace and learning analytics, DPA templates for EdTech vendors, and a school-grade incident handbook. Our data-protection adviser mandate for education institutions is tuned to federal diversity and parent communication. For the technical side many schools combine the adviser mandate with a vulnerability scan of the school infrastructure and – for larger school operators – an ISO 27001 implementation. Our data-protection workshops for teachers and school leadership are a proven entry point. Speak with us via our contact form or request a quote – we factor in cantonal specifics and EDK recommendations.
