Resources

GDPR in music schools: how to handle the data of underage students without risking penalties

Student data protection at a music school

A music school handles one of the most protected types of data in existence on a daily basis: personal data of minors. Names, family phone numbers, bank details, assessments, photos from the Christmas recital, the violin class WhatsApp group… All of that is data processing subject to the GDPR and Spain's LOPDGDD, and the AEPD (Spanish Data Protection Agency) is especially strict when minors are involved. The good news is that compliance does not require a legal department: it requires being clear about a few concepts and putting your processes in order. This guide goes through them one by one with the specific cases of a music center.

Note: this article is informative and does not replace professional legal advice for your specific case.

Why the GDPR fully applies to your music school

The GDPR applies to any entity that processes personal data, with no minimum size: an academy with 40 students is just as bound as a university. A typical music center processes, at a minimum:

  • Identifying data of minors — name, date of birth, year, instrument.
  • Families' contact and bank details — needed for enrollment and fee collection.
  • Academic data — assessments, attendance, the teacher's notes in the class diary.
  • Images and recordings — recitals, concerts, photos for social media.
  • Occasional health data — allergies, special educational needs — which are a special category and require reinforced protection.

The "minors + bank details + images" combination makes the sector a sensitive case: mistakes that would be minor in another business tend to escalate when minors are involved. And complaints do not come from routine inspections, but from where you least expect: a disgruntled family after a withdrawal or a dispute over a published photo.

The age-14 rule: who consents and for what

In Spain, the LOPDGDD sets 14 as the age from which a minor can consent to the processing of their own data. Below that age, consent belongs to the holders of parental authority or guardianship. In your center's day-to-day practice:

  • Under 14 — all consent is signed by parents or guardians. If the parents are separated with shared parental authority, significant decisions (such as publishing images) may require the agreement of both — a real point of friction worth anticipating in the form.
  • Ages 14 to 17 — the student can consent to the processing of their own data, although the enrollment contract (a financial obligation) is still signed by the adult.

Just as important: not everything needs consent. Managing enrollment, schedules, attendance or fee collection is covered by the performance of the contract — you do not have to ask permission for what is essential to provide the service. Consent is reserved for the extras: images, marketing communications, transfers to third parties. Bundling it all into a single "I accept" checkbox is precisely one of the classic mistakes, because consent must be specific to each purpose and as easy to withdraw as it is to give.

Photos and videos of recitals and concerts: the minefield

This is where most music schools stumble, because the activity begs for it: the end-of-year concert exists to be photographed. The rules for doing it right:

  • Separate consent per channel — using the photo in the center's internal yearbook is one thing, publishing it on the website is another, and uploading it to Instagram is yet another. The enrollment form must allow each use to be ticked separately, not a "yes to everything".
  • A family's "no" is managed, not ignored — at every recital you need to know which students cannot appear. If that information lives on a piece of paper from September, nobody remembers it in March: it must be accessible on the student's profile.
  • Families recording from the audience — domestic use is free and the center is not liable for it, but it is wise to warn (a sign or the printed program) that publicly sharing images of other minors is the responsibility of whoever does it.
  • External photographers — if you hire one, they are a data processor and need a contract under art. 28 GDPR.
  • Withdrawal of consent — if a family revokes it, the images must be removed from the center's channels. Knowing exactly where each photo was published stops being optional.
Nicolás Gálvez, Founder of Amadeus

Amadeus: the digital baton for your music school.

Nicolás Gálvez
Founder of Amadeus
Reply in under 24h

Shall we talk directly?

The fastest way is to talk. Tell us about your school and we’ll show you how Amadeus adapts to your needs. No strings attached.

WhatsApp, email and communication with families

Day-to-day communication is the sector's silent GDPR hole. The risk patterns are highly recognizable:

  • The class WhatsApp group — it exposes every family's personal phone number to everyone else (a data disclosure nobody consented to) and takes academic information out of the center's control.
  • The teacher's personal phone — when a teacher writes to families from their own number, minors' data ends up on a private device the center does not control. If the teacher leaves (or leaves on bad terms), the conversations go with them.
  • Emails with visible recipients — the classic CC with sixty family addresses is a textbook data breach, and one of the most reported.
  • Lists on the notice board — posting grades, groups or unpaid fees with full names on the corkboard at the entrance (or in an open PDF on the website) is another common source of complaints.

The underlying solution is for the center's official communication to run through its own channel with access control, where each user sees only what concerns them and the center keeps the audit trail — not through each teacher's personal contact list.

Your center’s 6 basic obligations

  1. Record of processing activities — the internal document describing what data you process, for what purpose, on what legal basis and for how long you keep it (art. 30 GDPR). It is the first thing the AEPD asks for.
  2. Duty of information — clear clauses in enrollment forms, other forms and the website: who the controller is, the purposes, the rights and how to exercise them.
  3. Contracts with data processors — accounting firm, software provider, hosting, photographer: every third party that accesses data on the center's behalf needs an art. 28 contract. Ask your providers for it; the serious ones have it ready.
  4. Proportionate security measures — access control by user and role, backups, encryption. The student Excel file on a passwordless laptop shared by the whole faculty violates this on its own.
  5. Handling data subject rights — access, rectification, erasure, objection. You must be able to respond within one month, which requires knowing where every piece of data is.
  6. Breach notification — if you lose data (stolen laptop, unauthorized access, mass email with CC), you have 72 hours to assess and, where applicable, notify the AEPD, in addition to documenting it internally.

Conservatories and authorized centers providing official curricula must also consider appointing a data protection officer (DPO), mandatory for educational institutions under the LOPDGDD; for non-official academies it will depend on the volume and type of processing — check with your advisor.

Real mistakes that end in an AEPD penalty

The AEPD's rulings against educational and children's leisure centers repeat the same patterns:

  • Publishing images of minors without consent (or with generic consent that did not cover social media).
  • Sending mass communications with addresses in visible copy.
  • Continuing to use data after the student has left (greetings, enrollment advertising) without a legal basis for it.
  • Failing to act on an erasure request from a family — silence turns a two-day task into a formal proceeding.
  • Poorly signposted video surveillance or cameras pointed at areas that do not justify it.

Although GDPR fines can in theory reach figures in the millions, for an SME the usual range goes from hundreds to tens of thousands of euros — enough to jeopardize an academy's school year. And the reputational damage with families, in a business built on trust involving minors, usually costs more than the fine itself.

How Amadeus Magister helps you comply

The GDPR is not fulfilled with a tool, but with processes — yet the right tool makes the right processes the easy path. Amadeus Magister is designed for centers that process minors' data:

  • Roles and permissions per user type — each teacher sees only their students; administration sees the financial data; families see only what is theirs. Access minimization comes as standard.
  • Communication inside the platform — announcements, chat and emails go out through the center's official channel, without exposing personal phone numbers or using the teacher's own phone.
  • Encrypted cloud storage in the EU — records stop living on laptops and USB sticks, with backups and traceable access control.
  • Student profile with their authorizations — consents (images, communications) are checked right where they are needed: on the profile the teacher opens before the recital.
  • Data processing agreement included — as a provider, Amadeus signs the art. 28 contract with your center and supports you on the technical side of compliance. You can see the full approach on our legal management page.

If you want to review what your center's data circuit would look like — from enrollment to the recital photo — request a free demo and we will go through it together on your real case.

100% Free · No Commitment

Want a personalized demo?

See first-hand how Amadeus can transform the management of your music school. Free and with no commitment.