jump to content

Video Conferencing in Schools and Colleges

Why Data Privacy Is Especially Important Here

  • Secure Communication
A person wearing red headphones is sitting at a laptop and moderating a video conference, pointing to a screen showing six participants and speech bubbles. The openVisavid logo is in the lower right corner.

Lutz Hasse, the former Thuringian State Data Protection Commissioner, announced in 2020 that he would investigate potential data protection violations by teachers conducting remote instruction. He stated that fines of up to 1,000 euros could be imposed for the use of tools that did not comply with data protection regulations or had not been approved—Zoom and Microsoft Teams, among others, were mentioned in this context. In fact, however, according to his later statement, no fines were imposed on teachers. Nevertheless, this case serves as a prime example of how the responsibility for ensuring a data-protection-compliant video conferencing solution in the education sector does not lie solely with the school as an institution, but can extend to the individual teacher in specific cases.

Why Data on Children and Adolescents Requires Special Protection

Video conferences in a school setting typically involve the processing of extensive amounts of personal data: video and audio recordings, names, and in some cases, special categories of personal data—such as in the context of special education support. The GDPR explicitly recognizes that children require special protection. Recital 75 identifies the processing of personal data of vulnerable individuals, particularly children, as a circumstance that may give rise to a high risk to the rights and freedoms of natural persons. Article 8 of the GDPR also sets forth specific requirements for consent-based processing in connection with information society services directly offered to children.

In practice, this means that for a video conferencing solution used in schools, the selection criteria tend to be stricter than in many other areas of application because the data subjects are often unable to fully exercise their rights on their own and are particularly vulnerable.

Who Is Liable: The School, the School Authority, or the Teacher

According to the prevailing view of the state data protection commissioners, individual schools are separate data controllers under data protection law within the meaning of the GDPR. The state school laws permit the processing of personal data of students, parents, and teachers in the context of video conferencing systems, provided that this is necessary for the respective purpose.

In practice, this results in a multi-tiered chain of responsibility: The school authority or the responsible ministry often makes the fundamental decision regarding a system; the individual school is responsible for its specific implementation; and the teacher is responsible for its day-to-day use.

What the State Data Protection Commissioners Are Calling For

In 2020, the Conference of Independent Data Protection Supervisory Authorities of the Federal Government and the States (DSK) published guidance on video conferencing systems and supplemented it with a checklist summarizing the key legal and technical requirements. State data protection authorities have specified these requirements for schools, including in Baden-Württemberg, Lower Saxony, and North Rhine-Westphalia. These include, in particular:

  • encryption appropriate to the risk
  • privacy-friendly default settings: such as disabled recording functions and camera and
  • microphone access turned off by default
  • transparent information about roles and involved service providers
  • contractual safeguards for data processors
  • appropriate deletion and retention policies
  • a sound legal basis for the respective processing operations

These requirements apply regardless of whether a video conferencing solution is used as on-premises software or as an online service (Software as a Service). In the case of online services provided by non-European providers, the question of the legal basis for international data transfers often arises as well.

Special Considerations at Universities

At universities, the initial situation is sometimes different: Students are generally of legal age, so the special requirements for minors do not apply. At the same time, other factors come into play, such as lecture recordings that are permanently stored and reused, as well as the framework conditions for university teaching, which are shaped by academic freedom. Here, too, the following applies: A video conferencing solution for universities should have a clear privacy policy, transparent retention periods for recordings, and documented data processing arrangements.

What Educational Institutions Should Consider When Making a Selection

The following criteria can be used to evaluate a video conferencing solution in an educational setting:

  • Legal Basis and Data Processing on Behalf of a Third Party: Is there an agreement in place for data processing on behalf of a third party, and is the legal basis for any international data transfers documented?
  • Encryption and technical safeguards in accordance with the guidelines of the DSK
    Software Transparency: Is it possible to trace how data is processed, and can this transparency be documented for school supervisory authorities and state data protection officers?
  • Operating model: Can the solution be hosted by the school district, a state media center, or a university itself, rather than being tied to a single external provider?

The operating model is becoming increasingly important in this context because many school districts and state media centers want to retain control over the infrastructure they use themselves, rather than relying entirely on the assurances of an external cloud provider. Open-source video conferencing solutions such as openVisavid can be operated directly by school districts or state media centers, ensuring that responsibility for children’s data remains entirely in the hands of the educational institution or its governing body, rather than being dependent on the assurances of a non-European provider.

Due to the particular vulnerability of children and adolescents, video conferencing in an educational context is subject to stricter requirements than in many other fields of application. Schools, school authorities, and universities would be well advised to base their selection of a video conferencing solution not only on technical considerations but also on data protection principles, and to follow the guidelines provided by state data protection commissioners. Self-hosted open-source solutions offer a practical way to maintain long-term control over sensitive data within one’s own organization.