BCSABritish Cycle & Scooter Association
Book a Demo
CouncilsSchoolsOrganisations
ProgrammeFunding & PolicyHow It WorksReportingPricingBlogAbout
BCSA
BCSA

Independent UK cycle and scooter safety certification for councils, schools, and organisations.

Solutions

  • Councils
  • Schools
  • Organisations
  • Pricing

Programme

  • Programme Overview
  • How It Works
  • Reporting
  • Funding & Policy
  • Blog

Company

  • About
  • Contact
  • FAQs

Legal

  • Privacy Policy
  • Learner Privacy
  • Cookie Policy
  • Terms of Service
  • Accessibility
  • Safeguarding

© 2026 BCSA TRAINING PORTAL LTD. All rights reserved.

Company No: 16878317

UK Hosted|WCAG 2.1 AA|GDPR Compliant

BCSA safety materials cover responsible micromobility awareness. Private e-scooters are currently illegal on public roads and pavements in the UK. BCSA does not encourage or endorse illegal e-scooter use.

  1. Home
  2. Blog
  3. Keeping Children Safe Online: Data Protection in E-Learning Platforms
Safeguarding20 March 2026

Keeping Children Safe Online: Data Protection in E-Learning Platforms

What schools should ask e-learning providers about children's data protection, from GDPR compliance to the ICO Children's Code.

BCSA Training

As more schools adopt e-learning platforms for curriculum delivery, one question should sit at the top of every safeguarding lead's agenda: how is my students' data being protected?

Online learning brings real benefits -- students learn at their own pace, teachers get instant progress reports, and schools can deliver specialist content like road safety education efficiently. But every platform that processes children's data carries responsibilities under UK GDPR, the Data Protection Act 2018, and the ICO's Children's Code. Here is what you need to know.

Why Children's Data Needs Higher Protection

Under UK GDPR, children are recognised as vulnerable data subjects who deserve specific protection. The ICO is clear: children may be less aware of the risks and consequences of data processing, and organisations handling their information must design their services with this in mind.

The ICO's Age Appropriate Design Code (commonly known as the Children's Code) sets out 15 standards that online services must follow when processing children's data. These include data minimisation, high privacy by default, and ensuring the best interests of the child are a primary consideration.

With the Data (Use and Access) Act 2025 now in force, the regulatory landscape is tightening further. The ICO is developing a new statutory code specifically covering children's data in educational technology. Schools and providers that are not already taking compliance seriously will find themselves under increasing scrutiny.

What "Age-Appropriate Design" Means for E-Learning

The Children's Code does not apply to schools directly. But it can apply to the edtech providers schools use, particularly where a provider processes data beyond the school's direct instructions or offers a service accessed on a direct-to-consumer basis.

Even where the Code does not formally apply, the ICO has stated that organisations should not use processor status to avoid child-centred design. E-learning providers working with children should still apply the Code's key principles:

  • Data minimisation -- collect only what is genuinely needed
  • High privacy defaults -- no unnecessary tracking or profiling switched on by default
  • Transparency -- privacy information written in language children and parents can understand
  • No detrimental use -- data must never be used in ways that could harm children
  • No behavioural profiling -- beyond what is strictly necessary (such as pass/fail scoring)

The DPIA: A Non-Negotiable for Children's Data

A Data Protection Impact Assessment is not optional when processing children's data at scale through a technology platform. Under Article 35 of UK GDPR, a DPIA is mandatory when processing is likely to result in a high risk to individuals' rights and freedoms.

Processing children's data through an e-learning platform typically triggers multiple DPIA criteria: vulnerable data subjects, systematic monitoring, cloud-based technology, and processing across multiple schools.

A thorough DPIA should identify every data category collected, map where it flows (including sub-processors and international transfers), assess risks, and document mitigations. If your e-learning provider cannot show you a completed DPIA, that is a significant red flag.

Data Minimisation: Less Is More

One of the clearest indicators of a responsible provider is what data they do not collect. A platform delivering cycling safety training to Year 7 students does not need home addresses, phone numbers, or dates of birth.

Schools should ask providers to confirm exactly which data fields are collected, both during onboarding and automatically during platform use. Technical data like IP addresses may be necessary for security, but it should be justified and documented. Ask: Can you show me a data inventory listing every field collected, its purpose, and its retention period?

Parental Consent vs Public Task: Getting the Lawful Basis Right

A common misconception is that schools need parental consent to share student data with e-learning providers. In most cases, they do not.

For state schools, the appropriate lawful basis is typically Article 6(1)(e) -- public task. Delivering curriculum-aligned education, including road safety, falls within the school's statutory function under the Education Act 1996. The school is the data controller; the e-learning provider is the data processor, acting on the school's instructions.

This distinction matters. The ICO advises against using consent in education settings because of the inherent power imbalance between schools and families. If consent were withdrawn, the school would have to stop processing entirely -- impractical for a programme embedded in the curriculum.

What schools must do is inform parents. A clear information letter explaining the programme, what data is collected, who processes it, and how to raise concerns satisfies transparency obligations under Articles 13 and 14. This is an information notice, not a consent form.

Five Questions Every School Should Ask an E-Learning Provider

Before signing a contract with any platform that will process student data, safeguarding leads and DPOs should ask:

  1. Do you have a signed Data Processing Agreement? An Article 28-compliant DPA must be in place before any student data is transferred, covering sub-processor controls, breach notification timelines, and deletion obligations.
  2. Where is our students' data hosted? If data is hosted outside the UK, appropriate safeguards such as the UK International Data Transfer Agreement must be in place, with encryption at rest and in transit.
  3. What is your data retention policy? Children's data should not be kept indefinitely. Look for defined retention periods: accounts deleted within months of completion, progress data cleared promptly, assessment records retained only where legally justified.
  4. Have you completed a DPIA? A provider that has done the compliance work properly will show you a risk register, data flow maps, and documented mitigations.
  5. Are AI features disabled for student accounts? Many platforms include AI features by default. If these send student data to third-party AI services, they must be explicitly disabled for children's accounts.

What BCSA Training Does Differently

At BCSA Training, we built our compliance framework before onboarding our first school, not after.

Our approach to children's data protection includes:

  • A completed DPIA mapping every data flow, assessing risks across ten categories, and documenting mitigations -- available to any school DPO on request
  • A two-layer privacy notice with a child-friendly version for learners aged 9-16 and a full notice for parents covering lawful basis, data sharing, retention, and rights
  • Defined retention periods aligned to ICO guidance and the Limitation Act: accounts deleted within 12 months of completion, progress data cleared within 3 months, assessment records retained only where legally justified
  • An Article 28 Data Processing Agreement signed before any student data changes hands
  • A school onboarding pack with parental information letter template, data summary sheet, and implementation checklist
  • Branch isolation ensuring one school's data is invisible to another
  • AI features disabled with no student data processed by third-party AI services
  • No marketing, no profiling, no secondary use of children's data

We collect only name, school, year group, and a login identifier. No home addresses, phone numbers, personal emails, or dates of birth.

The Regulatory Direction Is Clear

The ICO's December 2025 strategy update confirmed that edtech remains a priority enforcement area. The Data (Use and Access) Act 2025 introduces strengthened obligations for online services accessed by children, and the ICO is developing a dedicated statutory EdTech code. Schools that choose providers with strong compliance foundations now will not need to scramble when new requirements arrive.

Next Steps

If you are a safeguarding lead, DPO, or headteacher evaluating e-learning platforms, data protection compliance should be part of your procurement checklist alongside pedagogy and price.

We are happy to share our DPIA, Data Processing Agreement, retention policy, or any other compliance documentation with your school's data protection lead.

Learn more about our safeguarding approach or get in touch to discuss how we protect your students' data.

Ready to get started?

Book a demo with our team or request pricing for your organisation.

Book a DemoRequest Pricing