Solutions
Product
Pricing Compare
Resources
Request Free Trial

GDPR Compliance: What School Consent Forms Need Now

GDPR Compliance: What School Consent Forms Need Now

If a school’s messaging app, portal, or homework tool collects student accounts through an unverified age gate, that is a GDPR gap today, independent of anything still moving through Brussels. GDPR compliance for student consent forms did not start with any new proposal: schools operating in the EU have carried a verifiable-parental-consent obligation since 25 May 2018, under Article 8 of the GDPR. What changed on 17 September 2026 is that the European Commission proposed a new law, the EU Kids Act, that would sit on top of that existing obligation and add specific, EU-wide age tiers for online accounts. The proposal is specific enough, and the underlying GDPR duty is old enough, that any school still running a self-declared-birthdate signup box on its communication app has two separate reasons to fix that now, not one.

GDPR-Compliant School App Checklist: ClassDojo, Seesaw, or Any Vendor

Whether the tool in question is ClassDojo, Seesaw, ParentSquare, Remind, a WhatsApp parent group, Bloomz, or BeeNet, the questions an administrator should be asking are the same. The brand on the login screen matters less than which categories of answer the vendor can actually give you in writing. The sections below explain the law behind each row.

What to checkWhy it matters
Is student age verified, or just self-declared at signup?Article 8(2) requires “reasonable efforts,” not a checkbox
Where is student data hosted / processed?EU data residency affects transfer risk and audit scope
Does the vendor offer a documented parental-consent workflow?You need evidence of consent, not just a claim of it
Can under-13 accounts be blocked outright?Matches the Kids Act’s proposed floor, ahead of adoption
Is there a no-app option (e.g., SMS) for parents who won’t create an account?Consent and reach shouldn’t require every parent to sign up for a new platform
What does migrating existing accounts cost, in admin hours, not just license fees?Re-collecting consent from an existing student roster is the real cost, not the subscription

What decides it is whether age-gating and consent capture are configurable settings the vendor already ships, or a code change you’d be asking for, regardless of the logo on the login screen. Retrofitting verified consent onto a tool built around self-declared birthdates is a heavier lift than switching to, or configuring, a platform where consent and multilingual parent messaging (Arabic, English, French) were part of the original design. Either path costs staff time; only one of them costs it twice.

What GDPR Compliance Already Requires for Student Data

Article 8 GDPR sets the baseline every EU school and the tools it uses already operate under. For consent-based information-society services, a child can consent for themselves at 16; below that, a parent or legal guardian must give or authorise consent, and member states may lower that floor to as low as 13, which is why the practical age varies by country. Article 8(2) does not let a vendor or a school simply take a typed birthdate at face value: the controller must make “reasonable efforts to verify… that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.” A checkbox that says “I am over 16” is not that.

The EU Kids Act Proposal: What It Adds, and What’s Still Undecided

The European Commission’s EU Kids Act proposal sets three concrete age tiers, confirmed in the Commission’s own FAQ: no accounts under 13; a restricted “mini account” from 13-14, with mandatory parental controls, a one-hour daily cap, and parent approval required for new contacts; and free, independent account creation only from age 15 (not 13, a distinction worth getting right before repeating the headline). Verification would run through a certified EU Age Verification App or the European Digital Identity Wallet, using a zero-knowledge “yes/no” token that, per the FAQ, “cannot identify, locate, track or profile anyone”, with no ID document or biometric data retained.

Two things matter for how a school should read this. First, scope is broader than “social media”: per the Commission’s own release and IAPP’s coverage, it also reaches video-sharing platforms, online games, app stores, and AI chatbots and companions, the last of which the Commission says should be disabled by default for minors “to prevent emotional dependency.” Second, this is a proposal, not a law: it now goes to the European Parliament and Council for negotiation, with no confirmed implementation date. Euronews reports that once rules do take effect, platforms would get six months to identify and deactivate existing under-15 accounts. Member states are split: France, Denmark, Greece, Spain, and Austria back the approach, while the Czech Republic and Estonia have raised concerns about mandatory ID-style verification.

Honest reckoning: this isn’t one law doing the pushing

The real pressure is three things in sequence: Article 8 GDPR (binding since 2018), an earlier tightening of children’s-data rules that already treated minors as “a distinct risk group” (that source’s publication date is unconfirmed, so treat it as directional), and now the Kids Act proposal layering age tiers on top. GDPR already required verification, and the Act may still change in negotiation, so the consent fix stands on the existing law. Privacy group BEUC also cautions that age verification “is not a silver bullet.”

Update the consent form’s verification step. In practice: this is a one-time email plus a form-link update, sent by the school’s admin office to all parents/guardians at the start of a term, triggered by any change to which app collects student data. Sample content: “We’ve updated how [App Name] verifies parental consent for student accounts under 16. Please confirm your consent again here by [date]. It takes two minutes and no new account is required.”

Audit self-declared-age signups across every tool the school uses. In practice: a single internal checklist, reviewed once per term by the IT or admin lead, checking each active platform (messaging app, homework portal, any student-facing game or chatbot) against the six-item table above. Trigger: onboarding a new vendor, or the yearly back-to-school setup.

Tell parents what’s changing, in plain terms. In practice: one short SMS or app notification, sent once, at rollout, not a long policy document. Sample content: “New: [App Name] now verifies parental consent for under-16 student accounts, in line with GDPR. Nothing changes for you unless we ask you to reconfirm.”

Article 8 GDPR has not changed and is not waiting on Brussels. A school auditing its consent flow this term closes a compliance gap that already exists, and arrives at any future Kids Act deadline with a head start instead of a scramble. That’s the practical reading of the timing: fix it while it’s routine, not after it’s mandatory.

A working GDPR-compliant consent flow needs verified parental consent, an auditable record of it, and a way to reach parents who won’t create a new account. Those requirements point toward purpose-built school communication platforms rather than general-purpose consumer apps repurposed for a classroom. Several platforms are built around exactly that requirement set. BeeNet is one of them: it ships documented consent and e-signature workflows, SMS reach for parents without the app, and multilingual Arabic/English/French messaging, alongside the security posture a compliance audit will actually ask about. If you’re evaluating whether your current setup would pass that audit, a demo is a low-effort way to see what a compliant flow looks like end to end.

References

  1. European Commission — Digital Strategy. “EU Kids Act to restrict social media platforms’ access to children in the EU.” 2026-09-17. https://digital-strategy.ec.europa.eu/en/news/eu-kids-act-restrict-social-media-platforms-access-children-eu
  2. Euronews. “EU Kids Act: The EU’s plan to make the internet safer for kids.” 2026-09-22. https://www.euronews.com/my-europe/2026/09/22/eu-kids-act-the-eus-plan-to-make-the-internet-safer-for-kids
  3. European Commission — Shaping Europe’s digital future. “The KIDS Act explained (FAQ).” 2026-09-17. https://digital-strategy.ec.europa.eu/en/faqs/kids-act-explained
  4. European Commission, Directorate-General for Communication. “EU KIDS Act: helping children navigate a safer online world.” 2026-09-17. https://commission.europa.eu/news-and-media/news/eu-kids-act-helping-children-navigate-safer-online-world-2026-09-17_en
  5. IAPP. “European Commission unveils EU KIDS Act.” 2026-09-17. https://iapp.org/news/a/european-commission-unveils-eu-kids-act
  6. GDPR Register. “EU Tightens Rules on Children’s Data Protection.” (Publication date unconfirmed.) https://www.gdprregister.eu/news/eu-tightens-childrens-data-protection/
  7. gdpr-info.eu. “Art. 8 GDPR – Conditions applicable to child’s consent in relation to information society services.” In force since 2018-05-25. https://gdpr-info.eu/art-8-gdpr/

Continue reading

Ready to Transform Your School Communication?

Start saving time and increasing parent engagement with BeeNet.

Request Demo