Data protection for school leaders: questions to ask any EdTech vendor

The Saudi Personal Data Protection Law (PDPL) makes schools responsible for how staff and student data is handled. These questions help you choose systems with confidence.

Why it matters now

The Saudi Personal Data Protection Law (PDPL), overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA), applies to organisations that process personal data in the Kingdom, including schools. When a school uses an online system for staff or student information, the school remains responsible for that data, and the vendor processes it on the school’s behalf.

Teacher portfolios contain more personal data than people expect: names and emails, appraisal comments, and sometimes students’ names, photos or marks inside work samples.

Ten questions to ask

  1. Who is the controller and who is the processor? Is there a data processing agreement?
  2. Where is data stored? In which country, and on what legal basis is it transferred if outside the Kingdom?
  3. Which sub-processors are used? Hosting, email, backups, payments, and will you be told about changes?
  4. Who can see what? Is access limited by role, and is support access logged?
  5. How do people sign in? Is two-step sign-in available, and required for leaders?
  6. How is data protected? Encryption in transit, secure sessions, upload checks, backups?
  7. How long is data kept? Can the school set retention, and is it applied automatically?
  8. Can we get our data out, and delete it? Per person and for the whole school?
  9. What happens after a breach? How quickly will the school be told?
  10. What about students’ data in work samples? Is there guidance for teachers?

This is a checklist, not legal advice. Review contracts with your legal adviser.

How TeachFolio answers them

  • Data processing terms with TeachFolio as processor, and a published sub-processor list.
  • Hosting location stated plainly, with transfers only as the PDPL allows; schools needing hosting in the Kingdom can ask us.
  • Role-based access, logged support access that ends after 30 minutes, and two-step sign-in required for leaders.
  • HTTPS, strict security headers, upload checks, encrypted sessions and nightly encrypted backups.
  • Retention per school, data export and deletion for individuals and whole schools, and a breach notification commitment.
  • Upload guidance reminding teachers to remove students’ personal details unless the school allows them.
Put this into practice

See how TeachFolio does it with your own folders and standards.

Speak to an expert

Want to see it with your school’s folders?

We’ll set up a department the way your school works and show you the results.