Enrollment and records
Collection limited to what is necessary, with clear information on purpose and retention. Health and religious data are sensitive and require extra care.
Schools · data protection
A school processes children's data every day: enrollment, health, performance, photos and platform access. Brazil's data protection law requires every use to have a legal basis, a clear purpose and, in many cases, specific parental consent.
The LGPD requires that children's data be processed in their best interest and, as a rule, with specific and prominent consent from at least one parent or guardian. There are exceptions: data needed to contact guardians, to protect the child or to perform the educational contract and comply with legal obligations may be processed without consent. Image use on social media, sending data to third-party platforms for non-essential purposes and marketing communications require consent, which may be withdrawn at any time.
This page is for sponsoring entities, principals, technology coordinators and data protection officers of Brazilian schools and educational institutions. We serve companies throughout the State of São Paulo, Brazil, with meetings at our Paulista or Tatuapé offices or by video call, and act before the São Paulo courts (TJSP), the labor courts (TRT-2, TRT-15), the federal court (TRF-3) and administrative bodies.
Collection limited to what is necessary, with clear information on purpose and retention. Health and religious data are sensitive and require extra care.
Photos and videos on social media and in advertising depend on specific consent, with the option to refuse without any harm to the student.
Third-party apps receive students' data. The contract must define the school as controller and the supplier as processor, with security and deletion rules.
Sending data to school transport, insurers, canteens and education systems requires a legal basis and a record. Sharing through messaging apps is the most common incident.
Parents may request access, correction and deletion. The school needs a channel and a deadline to respond, and must record requests.
Leaks of lists, photos or grades must be assessed and, when relevant, reported to the ANPD and the data subjects. The school must appoint a data protection officer.
Broad, permanent authorizations signed at enrollment do not meet the requirement of specific, prominent consent.
Students' photos and information in teacher and family groups are uncontrolled sharing. Usage rules and official channels reduce the risk.
Platforms contracted by online sign-up, without data protection clauses, leave the school liable for incidents it does not control.
Inventory of data processed, systems and sharing flows.
Review of forms, privacy policy, supplier contracts and appointment of an officer.
Staff training, a channel for data subjects and an incident response protocol.
Before publishing any student photo, check that there is specific, current consent for that purpose. A single student without authorization in a class photo already makes it irregular.
Only with specific consent from the guardians of each student shown. Students without authorization must be excluded from the image or have their faces protected.
Yes. The LGPD requires the controller to appoint an officer, who may be an employee or a third party, with published contact details.
Contain the leak, record what happened, assess the risk to data subjects and, if the risk is relevant, notify the ANPD and the families within a reasonable time. Omission aggravates liability.
Brazilian rules of reference for students' data. ANPD guidance on children and adolescents complements the interpretation.
Describe the systems and forms in use through the secure channel. The screening identifies the gaps and the compliance plan.