Key takeaways:
- The General Data Protection Regulation (GDPR) is an EU law that dictates how organizations collect, use, store, and protect personal data.
- The seven principles of the GDPR apply in any situation where personal data is processed.
- GDPR can apply to businesses outside of Europe if they handle the personal data of people in the EU.
- GDPR is a highly important consideration for tutoring organizations and online educators in terms of choosing technology and managing student information.
What is GDPR?
The General Data Protection Regulation, or GDPR, is a data privacy law introduced by the European Union (EU) in 2018. It was created to give individuals greater control over the collection, usage, storage, and sharing of their data. Upon introduction, it established a single set of rules that organizations must follow when handling individuals’ personal data.
As the EU’s Guide to GDPR Compliance explains, the regulation doesn’t solely apply to organizations within the EU. It also applies to non-European organizations that offer goods or services to people in the EU or monitor their behavior. This means you don’t need to be based in Europe in order for GDPR to apply to your business.
Educators in particular need to be especially mindful of GDPR. Whether you’re teaching through a school, running your own tutoring business, or managing an online tutoring organization, you will almost certainly collect personal information of some kind. Students’ names, email addresses, lesson recordings, attendance records, assessments, and even chat messages could all potentially qualify as personal data under the GDPR.
If you’re an educator, understanding the regulation will help you treat your students’ information with the care it deserves. More importantly, it gives both your students and their parents greater confidence in your handling of their data.
What are the GDPR principles?

If you’ve ever signed up for a website and been greeted by a cookie banner, then the chances are that you’ve already encountered the GDPR before.
Although the GDPR itself is a lengthy piece of legislation, everything it requires is built on a relatively small set of core ideas. These are known as the GDPR principles, and they’re set out in Article 5 of the regulation.
Rather than listing dozens of disconnected rules, the GDPR establishes seven tenets that guide every decision that an organization will have to make about personal data. Together, they form the foundation of GDPR compliance, regardless of the size of your organization or the industry you work in:
- Lawfulness, fairness, and transparency: Organizations should only collect personal data when they have a lawful reason to do so. They need to explain clearly why they’re collecting it, and they should avoid using said data in ways that those who provided it wouldn’t expect it to be used.
- Purpose limitation: Personal data should only be collected for specific and legitimate purposes, and it shouldn’t later be used for reasons other than these.
- Data minimization: Organizations should only collect the data that they need in order to properly provide their goods or services
- Accuracy: Individuals’ personal information should always be kept as accurate and up to date as possible.
- Storage limitation: Individuals’ personal data should not be stored indefinitely, and should be deleted once it’s no longer needed.
- Integrity and confidentiality (security): Organizations must protect their users’ personal information against unauthorized access, accidental loss, or misuse.
- Accountability: Organizations must be able to demonstrate that they operate in accordance with the above six principles at all times.
What is GDPR compliance?

Getting familiar with the GDPR principles is the first step. Ensuring GDPR compliance means putting those principles into practice within your business.
It’s important to understand that GDPR compliance isn’t a certificate that you can earn once-off. In reality, your company needs to make a continuous commitment to protecting personal data throughout its entire lifecycle, from the second it’s collected until it’s eventually securely deleted.
What GDPR compliance looks like exactly usually varies from one organization to the next. Overarchingly, however, it usually includes:
- Collecting no more personal information than what’s actually needed
- Being transparent about how your business will use that information
- Keeping personal data secure through the appropriate technical and organizational measures
- Giving individuals full ability to exercise their rights under the GDPR (e.g., requesting access to or deletion of their data)
- Regularly reviewing your policies, procedures, and technology to ensure that they’re always as effective as can be
For schools and tutoring organizations, a significant part of GDPR compliance is choosing the right technology. Every virtual classroom platform that stores student records, lesson recordings, attendance data, or assessment results needs to be carefully vetted for its ability to responsibly handle student data.
At Pencil Spaces, privacy and security are built into the platform from the ground up. Pencil Spaces is GDPR-compliant by default, and also meets FERPA, COPPA, SOC 2 Type II, and HIPAA standards. This offers schools, tutoring organizations, and independent tutors full confidence that their students’ information will be handled with the utmost care and responsibility.
How does GDPR apply to online tutoring and education?
Regardless of whether you’re teaching one student a week or managing hundreds of tutors across multiple countries, it’s more than likely that you’re processing some form of personal data every workday.
Most online tutoring platforms, for instance, tend to collect:
- Student and parent names
- Email addresses and contact details
- Attendance records
- Lesson notes and assessments
- Lesson recordings
- Messages exchanged through the platform
- Payment information
Virtually all of this information qualifies as personal data under the GDPR. As such, educators have a responsibility to handle it thoughtfully and securely.
How to follow GDPR as an online tutor
Thankfully, for many tutors, GDPR for online tutoring doesn’t require a drastic change in terms of how they teach. Generally, it just comes down to developing good habits:
- Only collect the information you need.
- Explain why you’re collecting it.
- Store it securely.
- Delete it when it’s no longer necessary.
- Work with virtual classroom platforms that take your students’ privacy as seriously as you do.
These same principles apply to GDPR for education in a broader sense. Schools, colleges, universities, and large tutoring organizations all need to process significant amounts of student data. Just as it does for independent tutors, following the GDPR principles protects learners’ privacy while simultaneously earning trust among students, parents, and educational partners.
Frequently asked questions
What does GDPR stand for?
GDPR stands for the General Data Protection Regulation. It is a data privacy law that was first introduced by the European Union in 2018.
Does GDPR apply outside of Europe?
Yes, in many cases. Even though the GDPR is a European regulation, it will also apply to organizations outside of Europe that offer goods/services to people in the EU. This means an online tutoring business based elsewhere will still have to comply with the GDPR if it extends its services to students who live in the EU.
Does GDPR apply to independent tutors?
It can. If you’re an independent tutor who collects or processes the personal data of European students, then the GDPR most likely applies to your business. The specific obligations will depend on factors such as where exactly your students are located, what information you collect, and how you use it.
What GDPR principles must online tutors follow?
All seven GDPR principles apply whenever personal data is processed. This means organizations must only collect the information they genuinely need, be transparent about how they’ll use it, keep it accurate and secure, delete the data when it’s no longer required, and demonstrate that their privacy practices comply with the regulation.
How does GDPR differ from FERPA and COPPA?
The GDPR is a broad data protection law that governs how organizations handle personal data, particularly for people in the European Union. FERPA is a U.S. law that protects students’ education records at schools and educational institutions that receive funding from the U.S. Department of Education. COPPA is another U.S. law that focuses specifically on how websites, apps, and online services collect personal information from children under the age of 13.
Pencil Spaces is certified as GDPR, COPPA, FERPA, SOC 2, and HIPAA-compliant. It never sells user data, and it maintains the level of accountability that schools and parents expect from any platform young students use. Visit our Privacy page to learn more, or sign up for a free demo today.
This article is for general informational purposes and isn’t legal advice. Tutoring organizations should consult an attorney to confirm their specific GDPR obligations.

.png)








