Skip to content
All articles
OperationsBy Ilian Azz

GDPR for private tutors: protecting student data

A plain guide to GDPR for private tutors in France: which student data you hold, how long to keep it, and the habits that keep you compliant.

GDPR for private tutors: protecting student data
Summarize with AI

The GDPR is the European regulation that governs how you collect, store and use the personal data of your students and their families. A private tutor handles it from the very first message: a name, a phone number, sometimes a home address, and soon after, a child's grades and academic difficulties. This data has been protected by law across the EU since 25 May 2018, and a self-employed tutor is bound by it like any other business.

Many tutors assume the topic only concerns large companies. In practice, France's data protection authority, the CNIL, applies the same principles to a one-person activity. The reassuring part: for a small operation, compliance comes down to a handful of simple habits.

What data do you actually hold?

Write the list out; it runs longer than most people expect:

  • Identity and contact: the student's and parent's name, phone, email, and a home address for in-person lessons.
  • Academic data: level, subject, report cards, grades, comments, goals.
  • Billing data: amounts, payment methods, sometimes bank details for a direct debit.
  • Conversations: WhatsApp messages, texts, lesson notes.

Some of this deserves extra care. A learning accommodation for a dyslexic student, or any mention of a medical follow-up, counts as sensitive data under the GDPR: keep it only if the lesson genuinely needs it, never "just in case."

Your obligations, plainly

Collect only what you need, and say so

Ask only for what the lesson and the invoice require. At first contact, a single sentence informs the family: what you keep, why, and for how long. That is the transparency principle, and it heads off most disputes before they start.

Secure access

A password on your phone and laptop, a mailbox the rest of the household does not share, and a backup are the bare minimum. If data leaks (a lost notebook, a hacked account) and the breach puts people at risk, you have 72 hours to report it to the CNIL.

Keep data no longer than needed

A student file does not live forever. Two concrete markers:

  • Data for a student who has stopped: about 3 years after the last lesson, in case they come back, then deletion.
  • Invoices and accounting records: 10 years, a commercial-law duty separate from the GDPR.
A simple rule you follow beats a perfect policy you never apply. Pick a retention period, write it down, and clear out old files once a year.

Keep a short record

Even on your own, you should be able to state what data you process and why. The CNIL offers a one-page record template. For a tutoring activity, a single line reading "student management and billing" already covers the essentials.

What families can ask of you

A parent can ask to see their child's data, correct it, or delete it once it is no longer needed. You have one month to answer. Such requests are rare in tutoring, but a clear, quick response protects your reputation as much as the law requires it. If you already track your students' progress in a structured way, pulling up and exporting a file takes minutes.

The spreadsheet is GDPR's blind spot

An Excel file sitting on a shared laptop is the riskiest setup: no access control, stray copies buried in email threads, no record of who saw what. Leaving the spreadsheet for a single tool, where students, lessons and invoices live in one place, solves part of the problem by design. A student-management software centralizes the information, guards it behind an account, and spares you the scattered duplicates.

Where to start this week

  1. List the data you hold and delete what no longer serves a purpose.
  2. Put a password on your devices and your mailbox.
  3. Draft the sentence you will read to the next parent who signs up.
  4. Set a retention period and note it down.

None of these steps needs a lawyer. They turn data protection into a habit rather than one more burden.

Sources

Ilian Azz
Written by
Ilian Azz · Head of Content

A senior software engineer, he founds and runs several tech companies. He builds products around messaging APIs, automation and AI integration, and shares here what he learns while building.

  • rgpd
  • donnees personnelles
  • gestion des eleves
  • conformite

Spend your Sundays teaching, not chasing payments.

Free to start, set up in minutes. No card.

Start for free
GDPR for private tutors: protecting student data · Kadrella