Edudata.io blog

10 Key Terms for School Leaders: Get Ready for Back to School

Written by Edudata.io | Jul 28, 2026 7:00:00 AM

While you are enjoying a well-earned summer break, this is a good moment for a quick refresher on the terms that often shape conversations when school starts again.

Whether you are discussing digital tools, student data, or new AI features, the same concepts tend to come up in meetings with IT, vendors, and municipality leadership. Knowing what they mean makes those conversations easier to lead.

This is a simple top 10 checklist for school leaders. It is quick to read and easy to return to when things pick up again. If you want a more detailed reference to share with your team, you can find Edudata’s full glossary available here.

1) Privacy by design and privacy by default

Privacy by design means that data protection is built into the core of the system from the start — not added as an afterthought. Privacy by default means that the tool collects and shares only the minimum data necessary by default, without requiring users to adjust any settings themselves. If broader data processing is needed, that should be a deliberate choice, not the starting point.

Together, these principles reveal whether a vendor has proactively designed the service to protect learners' data, or whether that responsibility has been left to the users.

Practical question to ask: Is this tool built to protect student data automatically, or does it depend on teachers or administrators to adjust settings to make it safe?

2) NIS2 (Network and Information Security Directive)

NIS2 is an EU directive that raises expectations for cybersecurity and preparedness in important public services, including education. In practice, it leads to tighter requirements for vendors, clearer routines for access control, and stronger expectations around how schools handle digital incidents.

Practical question to ask: If an important school system goes down, do we know who to call and what our communication plan is for the first hour?

3) EU AI Act

The EU AI Act sets rules for how AI systems are built, sold, and used, with stricter requirements when AI can significantly affect people's rights or opportunities. In schools, this becomes relevant when a tool uses AI for student risk flags, automated feedback, recommendations, or decision support features.

Practical question to ask: What does the AI actually do, what data does it use, and who is responsible for checking that the results are correct and fair?

4) Data controller

The data controller decides why personal data is used and how it will be used. In many school settings, the controller is the school owner or municipality, and the school operates within the framework set by the data controller.

Practical question to ask: Can we clearly explain why we are using this student data, and who is accountable for that decision?

5) Data processor

A data processor handles personal data on behalf of the controller. This is typically the vendor that provides the platform, hosting, support, or analytics. The processor must follow the controller's instructions on how that data is managed.

Practical question to ask: Which parts of the data handling are managed by the vendor, and which parts remain our responsibility?

6) DPA (Data Processing Agreement)

A DPA is the contract that legally binds a vendor to follow your security and privacy rules. It covers security measures, how incidents are handled, which sub-processors are involved, and what happens when the service ends.

Practical question to ask: Do we have a signed DPA that matches how this service is actually used in the school, not only how it is described in marketing material?

7) Lawful basis

A lawful basis is the legal reason for processing personal data under GDPR. Every time the school uses student data, there must be a clear and documented reason for doing so. Without it, the processing is not compliant.

Practical question to ask: What is our legal reason for using this student data, and where is that reason documented?

8) Risk assessments and DPIA (Data Protection Impact Assessment)

A risk assessment should be carried out for every digital learning tool. It helps the school identify what could go wrong, how likely it is, what the consequences could be, and which safeguards are needed. A DPIA is more specific and is needed when the planned use of personal data may create high risk to the rights and freedoms of students. In practice, the risk assessment often helps the school recognise when the privacy risk is high enough that a DPIA is required.

Practical question to ask: Have we assessed the risks of this digital tool, and does that assessment show a level of privacy risk that means a DPIA is needed?

9) Incident vs personal data breach

An incident is a security event that affects, or could affect, the availability, integrity, or confidentiality of systems or data. A personal data breach is a specific GDPR term and refers to an incident that involves personal data. The distinction matters because a breach can trigger a legal duty to notify authorities and those affected.

Practical question to ask: If an event occurs, who decides whether it is a personal data breach, and what is our timeline for action and communication?

10) Access control and least privilege

Access control defines who can access which data and systems. Least privilege means that staff and students only get the access they need for their specific role, and that access is removed when the role changes. In schools, this matters because roles change often and temporary access is common.

Practical question to ask: How do we ensure that access to sensitive student data is removed when a staff member changes roles or leaves?

Preparing for the new term

Being familiar with these ten terms makes it easier to lead digital projects, ask the right questions in vendor meetings, and communicate clearly with both IT teams and parents.

These ten terms are just a starting point. If you want to go deeper, Edudata's full glossary covers a wider set of terms you can bookmark and share with your team.

You can see Edudata’s full glossary here.