School and After-School Registration: What Personal Data Can Be Collected?


At the beginning of each school year, local authorities and educational institutions collect a large amount of information about children and their legal guardians: school registration, school meals, childcare, transport, leisure activities and other after-school activities.
This process is necessary for the proper management of public services, but it must comply with the principles of the GDPR and the recommendations of the CNIL, the French data protection authority.
The processing of data relating to minors requires particular vigilance. Public-sector organisations must ensure that they only collect information that is strictly necessary for the purpose pursued and that they guarantee its confidentiality.
The GDPR requires data controllers to collect and process only the data that is necessary.
In practice, a local authority or educational institution may only request information that is strictly useful for managing the child’s registration and participation in the relevant service.
The CNIL states that, in order to organise children’s attendance at school, school canteens, school transport or after-school activities, only information necessary for their care and management may be requested.
As part of school and after-school registrations, organisations may notably request:
This information must always have a direct connection with the organisation of the relevant service.
The CNIL notably states that dietary information may be collected where necessary for the service, but must not directly reveal the child’s racial, ethnic or religious origins.
Conversely, certain information should not be requested where it is not necessary for managing the service.
This notably includes the social security number, the parents’ marital status, and information revealing the racial or ethnic origin, religious beliefs or political opinions of the individuals concerned.
The CNIL specifically states that a local authority must not record a child’s social security number or use it as the pupil’s identifier. It may not request a copy of the social security certificate as part of school registration either.
The principle is straightforward: personal data should only be collected where it is genuinely necessary for the purpose pursued.
Local authorities should therefore regularly review the information requested in registration forms to prevent excessive data collection.
The CNIL recommends considering whether each piece of information requested is genuinely necessary and what purpose the collection serves.
Only supporting documents that are necessary may be collected.
For example, tax assessment or non-assessment notices or family quotient information may be requested for billing after-school activities.
However, if a document is not strictly necessary for the child’s registration, or if a visual confirmation is sufficient, it should not be collected.
The CNIL also points out that certain documents, such as school insurance certificates, may only be required in situations where they are actually necessary.
Particular attention must be paid to health data.
Local authorities and educational institutions often collect information relating to food allergies, intolerances or specific support arrangements for children.
The CNIL states that only data strictly necessary for protecting the child and organising the service should be collected. The objective is to ensure appropriate care without collecting more medical information than necessary.
In certain circumstances, collecting this type of data may require the consent of the individuals concerned.
The CNIL notably states that certain information relating to the child’s medical or psychological care may be collected, under the conditions provided by applicable rules, where necessary for the child’s care.
Where a specific support arrangement is required, the objective should remain to collect only the information necessary for the child’s care.
For example, in the context of certain arrangements such as an individualised reception plan (PAI) or personalised schooling project (PPS), the CNIL states that only the necessary indication may be collected, without specifying the nature of the disability or medical condition where such information is not necessary.
Finally, this data must be subject to enhanced security measures and only be accessible to individuals who genuinely need it to perform their duties.
The child’s registration is also a key opportunity to inform parents about how their personal data will be used.
Data controllers must be able to explain transparently:
This information can be included in registration forms, family portals or service regulations.
For local authorities, this transparency should also form part of a broader GDPR compliance and processing documentation framework. The CNIL notably stresses the importance of maintaining an up-to-date record of processing activities and regularly checking the relevance and necessity of the data collected.
Data relating to minors requires particular protection, especially where sensitive data is involved.
Appropriate technical and organisational measures must therefore be implemented to prevent unauthorised access, loss or disclosure of the information collected.
This applies equally to paper records, business software, family portals and information exchanged with service providers involved in school catering, transport or after-school activities.
The CNIL also reminds local authorities that security measures must be adapted to the specific risks associated with the data being processed.
Particular attention should also be paid to access rights management, so that each employee can only access the data necessary for their duties.
This principle is particularly important when several departments within a local authority are involved in managing school registrations, catering, transport or after-school activities.
Access rights should therefore be defined according to each employee’s responsibilities and regularly reviewed.
Data protection also applies to business software, family portals and service providers acting on behalf of the local authority.
When a local authority entrusts processing activities to a service provider, it must ensure that the relationship is properly governed under the GDPR and that an appropriate level of security is guaranteed. The CNIL sets out specific requirements for local authorities working with processors.
School and after-school registration perfectly illustrates the specific challenges faced by local authorities: multiple processing activities, children’s data, health data, digital portals, service providers and numerous authorised employees.
DPO Consulting’s Public Sector and Associations division supports local authorities, inter-municipal structures and public institutions with their compliance with data protection regulations. Its expertise notably covers education, family protection and video surveillance.
Discover DPO Consulting’s Public Sector and Associations division
A GDPR compliance audit can also help identify gaps relating to school and after-school processing activities, registration forms, retention periods, access rights and relationships with service providers. DPO Consulting offers audits designed to assess compliance and establish an appropriate action plan.
Discover DPO Consulting’s GDPR compliance audit
School and after-school registration involves the daily processing of personal data relating to minors.
For local authorities and public institutions, the challenge is to find the right balance between the operational needs of the service and respect for families’ privacy.
The approach is straightforward:
Protecting children’s personal data therefore requires a particularly rigorous approach based on the principles of data minimisation, transparency, confidentiality and security.
For local authorities, this approach can be incorporated into a broader GDPR compliance programme, notably with the support of a DPO and regular monitoring of processing activities.
Would you like to strengthen your local authority or public institution’s GDPR compliance?
Discover DPO Consulting’s solutions for the public sector or book a consultation with a GDPR expert.