FIELD GUIDE / EVIDENCE FIRST
School Data Ownership, Export and Deletion Questions
Before adopting a school platform, obtain written, product-specific answers about the data in scope, contractual control, authorised access, export content and format, retention triggers, deletion handling, backups, exceptions and end-of-service handover. Then test the promised export path and record how completeness and deletion evidence will be checked.
Reviewed draft · 14 September 2026
KEY TAKEAWAYS
What should the reader carry into the decision?
- Replace the vague question ‘Who owns the data?’ with separate questions about contractual rights, access, use, export and exit.
- Test an export before contract commitment and check records, attachments, identifiers, timestamps and excluded fields.
- Keep live data, archives and backups separate when asking about retention and deletion.
- Name the approval, evidence and exception for every deletion or end-of-service step.
- Use Malaysian regulatory material as general context and seek advice for the actual arrangement.
Method and scope. Prepared from the cited public sources and the verified client facts available for this article.
Which school data is actually in scope?
Start with the proposed use, not the platform's full catalogue. List each data category the school expects to place in the system: learner identity, parent or guardian contact, staff information, attendance, assessment, messages, attachments, support records and technical logs where relevant. For each category, record the purpose, source, accountable school owner and people who need access.
Include derived and copied data. A dashboard total, notification, synchronised field or backup may come from an original record but follow a different path. Draw one sample record from collection through use, correction, sharing, export, retention and disposal. Unknown steps remain open questions for the vendor.
What should ‘data ownership’ mean in the contract?
Ask the vendor to separate contractual ownership from operational control. The school needs to know who may access data, for which purposes, what instructions apply, whether information is used for any secondary purpose, which subcontractors or services are involved and what rights continue after the agreement ends. A general statement that ‘the school owns its data’ does not answer these questions.
Ask where each answer appears in the contract, privacy notice, product documentation or proposal. Record conflicts between documents and require a written resolution. Do not assign legal labels to the school or vendor from a generic template; roles and obligations depend on the real arrangement and should be reviewed with appropriate advice.
What must a test export prove?
Ask an authorised administrator to export a defined sample. Before the test, write down what should be present: record counts, identifiers, field names, timestamps, status history, attachments and relationships between files. After the export, compare the result with the source records, open the files using tools available to the school and document missing or transformed information.
Record the available formats, scope limits, permissions, preparation time, delivery method, encryption or password handling, frequency and cost. Google's administrator documentation provides one example of a provider documenting an organisation-level export process. It does not establish what another platform exports, so the school must test the exact proposed product.
How should retention, deletion, archives and backups be separated?
Ask what event starts each retention period: record creation, last activity, account closure, student departure or contract end. Then ask what is deleted from the live system, what remains archived, what remains in backups, when backup copies age out and what exceptions may delay or prevent deletion. Require the answer for each important data category rather than one broad period for the whole platform.
Define completion evidence. It might be an administrator status, a service record or a written confirmation tied to a request identifier, depending on the system and arrangement. Ask who can approve a deletion, how mistakes are prevented, whether the action can be reversed and how the school is informed about an exception. Do not promise a deletion outcome that the vendor has not documented.
Who can access school data, and how is that access reviewed?
Map access for school users, vendor personnel and any other party named in the proposed arrangement. For each group, ask which data categories it can access, the purpose, approval, authentication path, duration and record of access. Include support access, emergency access and bulk export rather than reviewing only ordinary classroom views.
Google for Education describes its own tools with the line, “Retain full control over your data with tools that help you manage how, when, and where data can be accessed.” Treat that as a product-specific example of the kind of statement a school should test, not as a claim about another vendor. Ask the provider under review to show its actual controls and the evidence available during a periodic review.
How should Malaysian personal-data material be used?
Malaysia's Personal Data Protection Department publishes seven principles under Act 709 and six data-subject rights in its FAQ. Act 709 places the principles in sections 6 through 12. These verified facts provide a reason to ask precise questions about purpose, disclosure, security, retention, access and correction; they do not by themselves decide what a school or vendor must do in a specific arrangement.
Put unanswered legal or contractual questions into a separate advice list. Give the adviser the proposed data inventory, data-flow map, contract wording, user groups and vendor answers. This avoids asking a general article to make a compliance conclusion it cannot support.
What should the school test before signing and during service?
Before commitment, run the sample export and document ownership, access, retention, deletion, backup and exit answers. Mark the contractual document and clause for each important answer. If the vendor cannot demonstrate an item before contract, record the reason, responsible person, due date and consequence for the decision.
Repeat a smaller export and access review at an agreed interval and after major changes. The aim is to detect drift while the school can still correct it, rather than discovering at exit that the promised handover is incomplete. Keep the result with the contract record and name who will decide whether an exception remains acceptable.
QUICK ANSWERS
Frequently asked questions
Does ‘the school owns the data’ guarantee a complete export?
No. Ownership wording does not specify export scope, format, metadata, attachments, timing, cost or excluded information. Ask for those terms in writing and test a representative export before commitment.
Does deleting a live record also delete backups?
Do not assume it does. Ask how live data, archives and backups are handled, what schedule applies to each, what exceptions exist and what evidence the provider supplies when a request is complete.
Who should verify the export?
Use an authorised school owner who understands the source records and can open the delivered formats. The check should compare counts, identifiers, relationships, attachments, timestamps and any exclusions against the agreed scope.
See every guide in the insights index →
EXTERNAL CONTEXT
- Principles of Personal Data Protection
- Google Workspace Admin Help — Export All Your Organization's Data
- Google for Education — Privacy and Security Centre
- Personal Data Protection Department — Principles and FAQ
- Personal Data Protection Act 2010 (Act 709)
External sources explain category or evaluation context. They do not endorse Easy Edu or prove its product capabilities.
NEXT MOVE
Choose the next check
Use the related guide and verify the exact facts that apply.
Send Easy Edu a written evidence request