Schools hold some of the most sensitive data there is: information about children. Names, dates of birth, addresses, phone numbers, photos, health records, marks, fee details, and staff salaries and bank details. A data leak can harm families and staff and damage a school’s reputation built over decades.
Security can sound technical, but most of what protects a school is basic discipline. This checklist covers practical steps any school can take. It complements, but doesn’t replace, legal advice on obligations such as those under India’s Digital Personal Data Protection Act.
1. Know what data you have
- List the personal data you collect and why.
- Note where it lives: registers, spreadsheets, software, email, phones, WhatsApp.
- Remove what you don’t need — fewer copies means less risk.
2. Control who can see what
- Give each person access only to what their role needs. Teachers see their classes; accountants see fees; the librarian sees the library.
- Use individual accounts — never shared logins.
- Remove access promptly when staff leave or change roles.
- Review access every term.
3. Strong passwords and sign-in
- Require passwords that aren’t easy to guess, and never reuse the school’s passwords elsewhere.
- Don’t write passwords on sticky notes or share them on chat.
- Prefer systems that store passwords securely (hashed), limit repeated failed sign-in attempts, and offer one-time-code sign-in where appropriate.
- Change passwords if you suspect they’ve been seen; good systems sign out old sessions when a password changes.
4. Protect devices
- Lock office computers when unattended.
- Keep operating systems and browsers updated.
- Use antivirus software on office computers.
- Don’t store student data on personal USB drives or personal phones.
- Encrypt laptops that leave the campus.
5. Be careful with spreadsheets and email
- Avoid emailing spreadsheets of student data. If you must, share only what’s needed with only who needs it.
- Don’t keep sensitive files in public or widely shared folders.
- Delete old exports you no longer need.
6. WhatsApp and social media hygiene
- Class WhatsApp groups expose every parent’s number to every member. Prefer communication inside a school-controlled system.
- Don’t post student photos publicly without consent according to your policy.
- Don’t share marks, fee dues or health information in group chats.
7. Check your vendors
Any software company that handles your data should answer clearly:
- Is all traffic encrypted (HTTPS)?
- How are passwords stored?
- How is our school’s data kept separate from other schools’?
- Is access role-based? Is there an audit log?
- Do you sell data or show ads?
- Who owns the data, and can we export it?
- How would you tell us about a breach?
Write the answers into your agreement.
8. Keep an audit trail
Choose systems that record important actions — who changed a fee, reverted a receipt or edited a student record, and when. An audit trail deters misuse and helps you investigate quickly.
9. Plan for incidents
- Decide who is responsible if data is lost, leaked or a device is stolen.
- Know how you would find out, what you’d do first, and whom you’d inform — families, authorities as required, your vendor.
- Write it down on one page and share it with the people involved.
10. Train people
Most incidents start with people, not technology: a password shared, a file sent to the wrong group, a phishing link clicked. A short session each year — with real examples from schools — goes a long way.
A one-page summary for staff
- Use your own login; never share it.
- See only what your role needs.
- Don’t send student data on WhatsApp or personal email.
- Lock your screen when you step away.
- Report anything unusual immediately.
More questions
Is cloud software less secure than files on our own computer? Not inherently. Files on an office computer or USB drive are often less protected than data in a well-run system with encryption, access control and logs. What matters is how the system is built and operated — ask your vendor specific questions.
How often should we review access? At least once a term, and whenever staff join, leave or change roles. Remove access the day someone leaves.
What should we do first if a phone with school data is lost? Change the passwords of accounts used on the phone, inform your software vendor so sessions can be checked, and follow your incident plan for informing those affected where required.
Do small schools really need all this? Small schools hold the same kind of sensitive data as large ones. Most of the checklist is about habits — individual logins, sensible sharing, prompt removal of access — which cost little to adopt.
Key takeaways
- Know what data you hold and remove what you don’t need.
- Give individual logins with role-based access.
- Move official communication off personal phones.
- Ask vendors specific security questions and write the answers into the contract.
- Write a one-page incident plan.
How CampusConnect helps
CampusConnect is built with these safeguards: role-based access for admins, staff, students, parents and drivers; passwords stored only as bcrypt hashes; limits on failed login and OTP attempts; HTTPS everywhere; each school’s data kept separate, with automated tests for that isolation; an audit log of important actions; and no ads or data selling. Read the details in our trust centre.
Book a free demo and bring your security questions.
