School and After-School Registration: What Personal Data Can Be Collected?

This is some text inside of a div block.
4
September 23, 2026

Table of contents

Introduction

At the beginning of each school year, local authorities and educational institutions collect a large amount of information about children and their legal guardians: school registration, school meals, childcare, transport, leisure activities and other after-school activities.

This process is necessary for the proper management of public services, but it must comply with the principles of the GDPR and the recommendations of the CNIL, the French data protection authority.

The processing of data relating to minors requires particular vigilance. Public-sector organisations must ensure that they only collect information that is strictly necessary for the purpose pursued and that they guarantee its confidentiality.

What Personal Data Can Be Collected for School and After-School Registration?

The GDPR requires data controllers to collect and process only the data that is necessary.

In practice, a local authority or educational institution may only request information that is strictly useful for managing the child’s registration and participation in the relevant service.

The CNIL states that, in order to organise children’s attendance at school, school canteens, school transport or after-school activities, only information necessary for their care and management may be requested.

Data That Can Generally Be Justified

As part of school and after-school registrations, organisations may notably request:

  • the child’s identity;
  • the contact details of the legal guardians;
  • the identity and contact details of persons authorised to collect the child;
  • information required for billing purposes;
  • information concerning the child’s dietary requirements, provided that this data is not processed in a way that reveals the child’s racial, ethnic or religious origins.

This information must always have a direct connection with the organisation of the relevant service.

The CNIL notably states that dietary information may be collected where necessary for the service, but must not directly reveal the child’s racial, ethnic or religious origins.

What Personal Data Should Be Avoided or Prohibited?

Conversely, certain information should not be requested where it is not necessary for managing the service.

This notably includes the social security number, the parents’ marital status, and information revealing the racial or ethnic origin, religious beliefs or political opinions of the individuals concerned.

The CNIL specifically states that a local authority must not record a child’s social security number or use it as the pupil’s identifier. It may not request a copy of the social security certificate as part of school registration either.

The Data Minimisation Principle

The principle is straightforward: personal data should only be collected where it is genuinely necessary for the purpose pursued.

Local authorities should therefore regularly review the information requested in registration forms to prevent excessive data collection.

The CNIL recommends considering whether each piece of information requested is genuinely necessary and what purpose the collection serves.

What Supporting Documents Can Be Requested?

Only supporting documents that are necessary may be collected.

For example, tax assessment or non-assessment notices or family quotient information may be requested for billing after-school activities.

However, if a document is not strictly necessary for the child’s registration, or if a visual confirmation is sufficient, it should not be collected.

The CNIL also points out that certain documents, such as school insurance certificates, may only be required in situations where they are actually necessary.

Children’s Health Data: Enhanced Vigilance Is Required

Particular attention must be paid to health data.

Local authorities and educational institutions often collect information relating to food allergies, intolerances or specific support arrangements for children.

The CNIL states that only data strictly necessary for protecting the child and organising the service should be collected. The objective is to ensure appropriate care without collecting more medical information than necessary.

In certain circumstances, collecting this type of data may require the consent of the individuals concerned.

The CNIL notably states that certain information relating to the child’s medical or psychological care may be collected, under the conditions provided by applicable rules, where necessary for the child’s care.

Limit Medical Information to What Is Strictly Necessary

Where a specific support arrangement is required, the objective should remain to collect only the information necessary for the child’s care.

For example, in the context of certain arrangements such as an individualised reception plan (PAI) or personalised schooling project (PPS), the CNIL states that only the necessary indication may be collected, without specifying the nature of the disability or medical condition where such information is not necessary.

Finally, this data must be subject to enhanced security measures and only be accessible to individuals who genuinely need it to perform their duties.

Informing Parents and Legal Guardians: An Essential Requirement

The child’s registration is also a key opportunity to inform parents about how their personal data will be used.

Data controllers must be able to explain transparently:

  • what data is collected;
  • for what purposes;
  • who has access to it;
  • how long it will be retained;
  • what rights data subjects have.

This information can be included in registration forms, family portals or service regulations.

For local authorities, this transparency should also form part of a broader GDPR compliance and processing documentation framework. The CNIL notably stresses the importance of maintaining an up-to-date record of processing activities and regularly checking the relevance and necessity of the data collected.

How Should Children’s Personal Data Be Secured?

Data relating to minors requires particular protection, especially where sensitive data is involved.

Appropriate technical and organisational measures must therefore be implemented to prevent unauthorised access, loss or disclosure of the information collected.

This applies equally to paper records, business software, family portals and information exchanged with service providers involved in school catering, transport or after-school activities.

The CNIL also reminds local authorities that security measures must be adapted to the specific risks associated with the data being processed.

Managing Authorisations and Access Rights

Particular attention should also be paid to access rights management, so that each employee can only access the data necessary for their duties.

This principle is particularly important when several departments within a local authority are involved in managing school registrations, catering, transport or after-school activities.

Access rights should therefore be defined according to each employee’s responsibilities and regularly reviewed.

Managing Service Providers and Digital Tools

Data protection also applies to business software, family portals and service providers acting on behalf of the local authority.

When a local authority entrusts processing activities to a service provider, it must ensure that the relationship is properly governed under the GDPR and that an appropriate level of security is guaranteed. The CNIL sets out specific requirements for local authorities working with processors.

GDPR and Local Authorities: Adapting Compliance to School and After-School Activities

School and after-school registration perfectly illustrates the specific challenges faced by local authorities: multiple processing activities, children’s data, health data, digital portals, service providers and numerous authorised employees.

DPO Consulting’s Public Sector and Associations division supports local authorities, inter-municipal structures and public institutions with their compliance with data protection regulations. Its expertise notably covers education, family protection and video surveillance.

Discover DPO Consulting’s Public Sector and Associations division

A GDPR compliance audit can also help identify gaps relating to school and after-school processing activities, registration forms, retention periods, access rights and relationships with service providers. DPO Consulting offers audits designed to assess compliance and establish an appropriate action plan.

Discover DPO Consulting’s GDPR compliance audit

Conclusion: Key GDPR Good Practices for School Registration

School and after-school registration involves the daily processing of personal data relating to minors.

For local authorities and public institutions, the challenge is to find the right balance between the operational needs of the service and respect for families’ privacy.

The approach is straightforward:

  • only collect information that is genuinely necessary;
  • limit access to data;
  • clearly inform parents;
  • properly manage service providers;
  • define appropriate retention periods;
  • ensure a level of security proportionate to the risks.

Protecting children’s personal data therefore requires a particularly rigorous approach based on the principles of data minimisation, transparency, confidentiality and security.

For local authorities, this approach can be incorporated into a broader GDPR compliance programme, notably with the support of a DPO and regular monitoring of processing activities.

Would you like to strengthen your local authority or public institution’s GDPR compliance?

Discover DPO Consulting’s solutions for the public sector or book a consultation with a GDPR expert.

Read this next

See all