What every school needs to know about GDPR in family communication: what the law says, risks, and how to comply easily.
The GDPR requires any organisation processing personal data to comply with principles of minimisation, purpose limitation and integrity. In the educational context, this directly affects how the school communicates with families. Every time a school uses a channel that requires the recipient's phone number, email or name, it is processing personal data. This means:
Data protection authorities have issued multiple resolutions indicating that WhatsApp groups in schools pose a risk to data protection: It's not that WhatsApp is bad. It's that it wasn't designed for institutional communication.
Article 25 of the GDPR establishes the principle of Privacy by Design: designing systems so that privacy is built in. Konvoko applies this principle radically: the app works with anonymous subscriptions. The recipient downloads the app, subscribes to a channel and receives notifications. The school doesn't know who the recipient is because they were never asked to identify themselves. Without personal data, there are no consents to manage, no contracts to sign, no breaches to report. More information on our GDPR compliance page.
Review these points: If any answer is "no" or "I don't know", it's time to review your strategy. We can help.