← Back to School Blog

Student Data Protection Across Borders: GDPR, UAE PDPL, Saudi PDPL, Kenya DPA, Nigeria NDPA and Malaysia PDPA

Which data protection laws apply to international schools using EdTech: a side-by-side comparison of the GDPR, UAE and Saudi PDPL, Kenya's Data Protection Act, Nigeria's NDPA and Malaysia's amended PDPA on children's data, DPOs, breach notification and cross-border transfers.

Last reviewed:

student data protection international schoolsedtech data protection checklistpdpl schoolsgdpr international schoolscross-border student data transfer

International schools must follow the data protection law of the country they operate in, not the law of their curriculum. In the EU it is the GDPR. In the UAE, Saudi Arabia, Kenya, Nigeria and Malaysia, national laws now set comparable rules on children’s data, breach notification and transfers abroad. EdTech hosting student data abroad is a cross-border transfer.

This is a comparison of the laws’ texts for school leaders, not legal advice.

Which law applies to an international school?

The law where the school processes the data, and sometimes more than one. A British school in Dubai follows UAE law, not the UK GDPR. A school in a free zone may follow the zone’s own regime instead: the UAE law excludes “companies and establishments located in free zones” that have “special legislations regarding Personal Data protection” (Article 2). When a school uses an EdTech platform hosted in another country, student data crosses a border. Each law has its own rules for that.

How do the six laws compare?

EU GDPRUAE PDPLSaudi PDPLKenya DPANigeria NDPAMalaysia PDPA
InstrumentRegulation (EU) 2016/679Federal Decree-Law No. 45 of 2021Royal Decree M/19 (1443H), amended M/148 (1444H)Data Protection Act No. 24 of 2019Nigeria Data Protection Act 2023Act 709 (2010), amended by Act A1727 (2024)
In force25 May 20182 January 2022720 days after publication25 November 2019Assented 12 June 2023Amendments in force 1 January, 1 April and 1 June 2025
RegulatorNational supervisory authoritiesUAE Data BureauCompetent authority; SDAIA issues the regulationsOffice of the Data Protection CommissionerNigeria Data Protection CommissionPersonal Data Protection Commissioner
ChildrenConsent age 16; member states may lower to 13 (Art. 8)No child-specific provisionsLegal guardian consent and rights for those lacking capacityParent or guardian consent; age verification (s.33)Parent or guardian consent; age verification (s.31)Parent acts for under-18s (s.4)
DPOPublic bodies; large-scale monitoring or special data (Art. 37)High-risk or large-scale sensitive processing (Art. 10)Public entities at scale; systematic monitoring; sensitive dataOptional: controllers “may designate” (s.24)Required for controllers “of major importance” (s.32)Required (s.12A)
Breach notice72 hours where feasible (Art. 33)As set by executive regulations (Art. 9)72 hours (Implementing Regulation Art. 24)Within 72 hours (s.43)Within 72 hours (s.40)“As soon as practicable”; guideline: 72 hours
Transfers abroadChapter V conditions (Art. 44)Adequate law or agreement, as approved (Arts. 22–23)Adequate protection and data minimisation; SCCs, binding rules, certificationProof of safeguards to the Commissioner (s.48)Adequacy mechanisms (s.41)Whitelist removed; adequate or similar law (s.129)
Government bodiesCoveredExcludedCoveredCoveredCoveredExcluded

Sources are listed at the end. Where a law leaves detail to regulations, check the current regulations.

What do the laws say about children?

All but one set rules for consent on a child’s behalf. Kenya’s Act bars processing a child’s data “unless (a) consent is given by the child’s parent or guardian; and (b) … protects and advances the rights and best interests of the child”. Controllers “shall incorporate appropriate mechanisms for age verification and consent”. Nigeria’s Act requires controllers to “obtain the consent of the parent or legal guardian” and to “verify age and consent”. It exempts processing “for purposes of education, medical, or social care” by a professional under a duty of confidentiality. Malaysia treats a parent or guardian as the “relevant person” for “a data subject who is below the age of eighteen years”. Saudi Arabia’s Implementing Regulation says that where a data subject lacks legal capacity, “their legal guardian shall exercise their rights on their behalf”. The UAE law has no child-specific provisions.

Which laws make schools appoint a DPO?

Depending on scale, most of them. Malaysia’s amended Act says “a data controller shall appoint one or more data protection officers”. Its DPO guideline triggers this above 20,000 data subjects, 10,000 for sensitive data, or where there is “regular and systematic monitoring”. In Nigeria, the NDPC’s 2025 guidance lists “Primary and Secondary Schools” as data controllers of major importance, which must register and “designate a Data Protection Officer”. Kenya’s is discretionary: a controller “may designate or appoint” one. Under the GDPR, a DPO is required for public authorities and for large-scale monitoring or special-category data.

How fast must a breach be reported?

Usually within 72 hours. The GDPR requires notification “without undue delay and, where feasible, not later than 72 hours after having become aware of it”. Kenya, Nigeria and Saudi Arabia also set 72 hours, subject to their risk thresholds. Malaysia’s Act says “as soon as practicable”, and its guideline says “no later than seventy-two (72) hours”. Affected individuals must be told within 7 days where there is “significant harm”. The UAE law leaves timing to its executive regulations. A school’s incident plan should assume 72 hours everywhere and should require vendors to alert the school fast enough to meet it.

What does this mean for EdTech contracts?

That every platform is a data transfer question. Before signing, ask each vendor:

  1. Where is student data hosted, and which subprocessors are used?
  2. What transfer mechanism does the vendor rely on under your country’s law: adequacy, contractual clauses or consent?
  3. How quickly will they notify you of a breach, in hours?
  4. How do they handle children’s data, including parental consent and age checks?
  5. Will they sign a data processing agreement naming the law that applies?
  6. Can data be exported or deleted at the end of the contract? Malaysia’s Act now gives data subjects portability “subject to technical feasibility”.

See the EdTech procurement checklist and understanding DPIAs.

How schools do this with AI Buddy

Schools evaluating AI Buddy should put the same six questions to us as to any vendor, in writing, before rollout. That covers hosting location, subprocessors, breach notification, children’s data and the data processing agreement for your country. Tutopiya’s public privacy policy is the starting point. Your data protection lead should confirm the terms against your local law.

Frequently asked questions

Does GDPR apply to international schools outside Europe?

Not automatically. A school follows the data protection law of the country where it operates. The GDPR applies to schools in the EU, and, under Article 3(2), can reach schools and vendors outside the EU that offer services to people in the EU.

How quickly must a school report a data breach?

Within 72 hours under the GDPR and the Kenyan, Nigerian and Saudi rules, subject to risk thresholds. Malaysia’s guideline also sets 72 hours. The UAE leaves timing to its executive regulations.

In Kenya and Nigeria, generally yes, with age verification. Nigeria exempts some education processing by professionals under a duty of confidentiality. Malaysia treats parents as acting for under-18s.

Is using a foreign EdTech platform a cross-border transfer?

Yes, if student data is stored or accessed outside the country. Each law sets conditions, such as adequate protection, contractual safeguards or proof of safeguards to the regulator.

Discover how AI Buddy helps schools strengthen teaching, learning and evidence-informed school improvement. Or start a short consultation with our schools team using the form below — we will get back to you directly.

Sources

Explore how AI Buddy supports international school implementation.

View case studies
See AI Buddy in action Request a Demo
Book a Tutor