Nine categories,
and the question against each.
Start with a blank page and the list below. For each category, write three things: what exactly you hold, where it lives — every place, including the ones that are not software — and why you are allowed to hold it. The third column here is a prompt rather than an answer, because the basis and the retention period depend on your jurisdiction and on whether your school sits inside compulsory education.
Two categories deserve separate treatment from the start. Safeguarding records follow their own rules in most countries — often longer retention, tighter access, and specific duties about disclosure — and they should be kept apart from ordinary school records rather than mixed into the student file. Financial records are usually governed by accounting and tax law, which sets a retention period the school does not get to choose and which does not yield to a deletion request; that asymmetry surprises people and is worth knowing before a family asks.
The places a school forgets
until somebody asks.
The inventory is easy for the systems you bought and hard for everything else, and it is everything else that causes the problems. The usual list: a teacher's personal spreadsheet of marks; the shared inbox with three years of enrolment forms attached to emails; a WhatsApp or Telegram group with parents, on someone's personal phone; photographs from the end-of-year show, on a laptop and on social media; paper registers in a drawer; an old cloud folder from the year the school used a different system; the personal device a teacher marks homework on at home.
None of these is unusual and none is automatically wrong, but each one is a place where student data exists outside the school's control, and each has to be findable if a family asks what you hold. The practical fix is consolidation rather than prohibition: move what you can into the systems you control, delete what has no reason to exist, and write down the few exceptions that remain with a reason. A messaging group with parents that lives on a personal phone is the one worth addressing first, because it is the one most likely to contain names, photographs and absence reasons, and the one most likely to leave the school when the person does.
Consent is not the answer
to most of it.
The most common mistake small schools make is to treat consent as the basis for everything, usually via a tick box at enrolment. It creates a trap: if consent is the basis, it can be withdrawn, and a parent could withdraw consent for records the school is obliged to keep. For most of what a school holds, the basis is the contract with the family — you cannot teach a child without holding their name and knowing whether they attended — or a legal obligation, or the school's legitimate interests.
Where consent genuinely belongs is the things that are optional and separable: photographs used in marketing, newsletters to people who are not current families, and often recordings of classes. Those should be asked for separately, be refusable without consequence, and be easy to withdraw. A school that gets this division right also gets a cleaner answer when a parent objects to something: it can distinguish between "that is part of running the school" and "you are right, we will stop."
"For ever, in case"
is not a retention policy.
Most small schools keep everything indefinitely, not by decision but by absence of one. The obligation is to keep personal data only as long as there is a reason, and then to delete it — which means writing a period against each category in the inventory, even a rough one, and then having something that actually enforces it. The periods themselves vary: assessment records supporting a certificate may need years; a marketing mailing list should probably not outlive interest; financial records are set by accounting law; safeguarding by its own rules.
The part worth building carefully is deletion of former students. A school that has never deleted anyone is holding the full records of every child it has ever taught, which is both a legal exposure and a practical one if there is ever a breach. Decide how long after leaving a student's record is kept, write it in the privacy notice, and put a date in the calendar each year to act on it.
On SprintUp, an account an administrator deletes stays restorable rather than vanishing, because schools change their minds and a deletion made in error should be recoverable. Permanent erasure of those deleted accounts after a fixed period is available but deliberately opt-in — it has to be switched on with a retention period chosen, because erasure cannot be undone and how long a school needs to be able to change its mind is the school's decision rather than a default we should impose. If you want that automatic purge, it is worth asking for it as part of setting up.
The cheapest compliance
is not holding it.
Every field on an enrolment form is a commitment: to keep it accurately, secure it, disclose it on request and delete it eventually. Most school enrolment forms contain fields nobody has ever used — a second emergency contact that is always blank, an occupation field inherited from a template, a full postal address for a school that has never posted anything. Removing them is the only compliance activity that costs nothing and reduces risk permanently.
The same applies to access inside the school. A teacher needs the roster, contact details for their own students, attendance and assessment. They rarely need financial records or safeguarding notes about children they do not teach. Where the platform supports roles, use them; where it does not, that is a question for the vendor, and it is in the next article's list.
The inventory
checklist.
None of this is legal advice, and the categories where it matters most — safeguarding, health, anything about children — are the ones where a conversation with someone qualified in your jurisdiction is worth the fee.