GDPR FAQs for Schools
1.What personal data does Classroom 42 collect and process?
Classroom 42 processes the personal data needed to provide and operate the platform. Depending on how the platform is being used, this can include names, email addresses, account details, school and class information, quiz and exam responses, marks and feedback, progress and activity records, and technical information such as IP address, browser and device information.
For pupils at subscribing schools, Classroom 42 processes this information on behalf of the school.
We do not ask users to provide special-category personal data, such as health information or information about ethnicity, religion or political beliefs, and answer fields should only be used for educational responses.
2. Is Classroom 42 GDPR compliant?
Classroom 42 complies with the UK GDPR, Data Protection Act 2018, and other relevant data protection laws.
We are also registered with the Information Commissioner’s Office (ICO) under registration number ZB259604.
3. Who is the data controller and data processor?
For a school subscription, the school is the Data Controller for its pupil, teacher and school data, because the school determines why that data is used. GCSE Classroom Ltd, trading as Classroom 42, acts as the Data Processor and processes that data on the school's documented instructions.
There are circumstances where Classroom 42 acts as the Data Controller itself, including for website visitors, people who contact us, marketing recipients and individuals who purchase a membership directly from us.
4. How does Classroom 42 protect personal data?
We use industry-standard encryption, access controls, and secure servers to protect data. Additionally, our staff receive data protection training, and we conduct regular security audits to maintain compliance.
5. Where is personal data stored?
As with most online platforms used by schools, personal data is stored across multiple secure data centres, some of which may be located outside the UK. However, all data transfers comply with Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) to ensure full GDPR compliance.
6. Do you share personal data with third parties?
Like almost all educational platforms, we work with trusted third-party providers (e.g., hosting services, analytics tools, and payment processors) to deliver our services effectively. All subcontractors comply with GDPR regulations and implement appropriate safeguards. We do not sell or misuse personal data.
7. How long do you retain personal data?
We retain data for 30 days after a membership expires, after which it is securely deleted. Schools can also request earlier deletion if needed.
8. Can teaches or pupils request their data to be deleted?
Yes. Schools, as the Data Controller, can request pupil or teacher data deletion at any time. Individual users (teachers/pupils) should contact their school to request data removal.
9. How does Classroom 42 deal with data breaches?
If a data breach occurs, we will:
Notify the affected school promptly.
Report it to the Information Commissioner’s Office (ICO) if legally required.
Take immediate steps to mitigate risks and prevent further breaches.
10. Can schools request a Data Protection Agreement (DPA)?
Yes, we provide a DPA upon request, outlining how we process and protect personal data on behalf of schools.
11. Do you conduct a Data Protection Impact Assessment (DPIA)?
Yes, we have conducted a Data Protection Impact Assessment (DPIA) to assess and mitigate risks related to data processing. If required, we can provide general details about our approach upon request.
12. How do we contact Classroom 42 about data protection?
For any GDPR-related inquiries, please contact our Data Protection Officer (DPO):
support@classroom42.com
01789 569299