International schools must follow the data protection law of the country they operate in, not the law of their curriculum. In the EU it is the GDPR. In the UAE, Saudi Arabia, Kenya, Nigeria and Malaysia, national laws now set comparable rules on children’s data, breach notification and transfers abroad. EdTech hosting student data abroad is a cross-border transfer.
This is a comparison of the laws’ texts for school leaders, not legal advice.
Which law applies to an international school?
The law where the school processes the data, and sometimes more than one. A British school in Dubai follows UAE law, not the UK GDPR. A school in a free zone may follow the zone’s own regime instead: the UAE law excludes “companies and establishments located in free zones” that have “special legislations regarding Personal Data protection” (Article 2). When a school uses an EdTech platform hosted in another country, student data crosses a border. Each law has its own rules for that.
How do the six laws compare?
| EU GDPR | UAE PDPL | Saudi PDPL | Kenya DPA | Nigeria NDPA | Malaysia PDPA | |
|---|---|---|---|---|---|---|
| Instrument | Regulation (EU) 2016/679 | Federal Decree-Law No. 45 of 2021 | Royal Decree M/19 (1443H), amended M/148 (1444H) | Data Protection Act No. 24 of 2019 | Nigeria Data Protection Act 2023 | Act 709 (2010), amended by Act A1727 (2024) |
| In force | 25 May 2018 | 2 January 2022 | 720 days after publication | 25 November 2019 | Assented 12 June 2023 | Amendments in force 1 January, 1 April and 1 June 2025 |
| Regulator | National supervisory authorities | UAE Data Bureau | Competent authority; SDAIA issues the regulations | Office of the Data Protection Commissioner | Nigeria Data Protection Commission | Personal Data Protection Commissioner |
| Children | Consent age 16; member states may lower to 13 (Art. 8) | No child-specific provisions | Legal guardian consent and rights for those lacking capacity | Parent or guardian consent; age verification (s.33) | Parent or guardian consent; age verification (s.31) | Parent acts for under-18s (s.4) |
| DPO | Public bodies; large-scale monitoring or special data (Art. 37) | High-risk or large-scale sensitive processing (Art. 10) | Public entities at scale; systematic monitoring; sensitive data | Optional: controllers “may designate” (s.24) | Required for controllers “of major importance” (s.32) | Required (s.12A) |
| Breach notice | 72 hours where feasible (Art. 33) | As set by executive regulations (Art. 9) | 72 hours (Implementing Regulation Art. 24) | Within 72 hours (s.43) | Within 72 hours (s.40) | “As soon as practicable”; guideline: 72 hours |
| Transfers abroad | Chapter V conditions (Art. 44) | Adequate law or agreement, as approved (Arts. 22–23) | Adequate protection and data minimisation; SCCs, binding rules, certification | Proof of safeguards to the Commissioner (s.48) | Adequacy mechanisms (s.41) | Whitelist removed; adequate or similar law (s.129) |
| Government bodies | Covered | Excluded | Covered | Covered | Covered | Excluded |
Sources are listed at the end. Where a law leaves detail to regulations, check the current regulations.
What do the laws say about children?
All but one set rules for consent on a child’s behalf. Kenya’s Act bars processing a child’s data “unless (a) consent is given by the child’s parent or guardian; and (b) … protects and advances the rights and best interests of the child”. Controllers “shall incorporate appropriate mechanisms for age verification and consent”. Nigeria’s Act requires controllers to “obtain the consent of the parent or legal guardian” and to “verify age and consent”. It exempts processing “for purposes of education, medical, or social care” by a professional under a duty of confidentiality. Malaysia treats a parent or guardian as the “relevant person” for “a data subject who is below the age of eighteen years”. Saudi Arabia’s Implementing Regulation says that where a data subject lacks legal capacity, “their legal guardian shall exercise their rights on their behalf”. The UAE law has no child-specific provisions.
Which laws make schools appoint a DPO?
Depending on scale, most of them. Malaysia’s amended Act says “a data controller shall appoint one or more data protection officers”. Its DPO guideline triggers this above 20,000 data subjects, 10,000 for sensitive data, or where there is “regular and systematic monitoring”. In Nigeria, the NDPC’s 2025 guidance lists “Primary and Secondary Schools” as data controllers of major importance, which must register and “designate a Data Protection Officer”. Kenya’s is discretionary: a controller “may designate or appoint” one. Under the GDPR, a DPO is required for public authorities and for large-scale monitoring or special-category data.
How fast must a breach be reported?
Usually within 72 hours. The GDPR requires notification “without undue delay and, where feasible, not later than 72 hours after having become aware of it”. Kenya, Nigeria and Saudi Arabia also set 72 hours, subject to their risk thresholds. Malaysia’s Act says “as soon as practicable”, and its guideline says “no later than seventy-two (72) hours”. Affected individuals must be told within 7 days where there is “significant harm”. The UAE law leaves timing to its executive regulations. A school’s incident plan should assume 72 hours everywhere and should require vendors to alert the school fast enough to meet it.
What does this mean for EdTech contracts?
That every platform is a data transfer question. Before signing, ask each vendor:
- Where is student data hosted, and which subprocessors are used?
- What transfer mechanism does the vendor rely on under your country’s law: adequacy, contractual clauses or consent?
- How quickly will they notify you of a breach, in hours?
- How do they handle children’s data, including parental consent and age checks?
- Will they sign a data processing agreement naming the law that applies?
- Can data be exported or deleted at the end of the contract? Malaysia’s Act now gives data subjects portability “subject to technical feasibility”.
See the EdTech procurement checklist and understanding DPIAs.
How schools do this with AI Buddy
Schools evaluating AI Buddy should put the same six questions to us as to any vendor, in writing, before rollout. That covers hosting location, subprocessors, breach notification, children’s data and the data processing agreement for your country. Tutopiya’s public privacy policy is the starting point. Your data protection lead should confirm the terms against your local law.
Frequently asked questions
Does GDPR apply to international schools outside Europe?
Not automatically. A school follows the data protection law of the country where it operates. The GDPR applies to schools in the EU, and, under Article 3(2), can reach schools and vendors outside the EU that offer services to people in the EU.
How quickly must a school report a data breach?
Within 72 hours under the GDPR and the Kenyan, Nigerian and Saudi rules, subject to risk thresholds. Malaysia’s guideline also sets 72 hours. The UAE leaves timing to its executive regulations.
Do schools need parental consent to process children’s data?
In Kenya and Nigeria, generally yes, with age verification. Nigeria exempts some education processing by professionals under a duty of confidentiality. Malaysia treats parents as acting for under-18s.
Is using a foreign EdTech platform a cross-border transfer?
Yes, if student data is stored or accessed outside the country. Each law sets conditions, such as adequate protection, contractual safeguards or proof of safeguards to the regulator.
Discover how AI Buddy helps schools strengthen teaching, learning and evidence-informed school improvement. Or start a short consultation with our schools team using the form below — we will get back to you directly.
Sources
- European Union, Regulation (EU) 2016/679 (GDPR)
- UAE Legislation, Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data
- SDAIA, Personal Data Protection Law, Implementing Regulation and Transfer Regulation
- Office of the Data Protection Commissioner, The Data Protection Act, No. 24 of 2019
- Nigeria Data Protection Act, 2023; NDPC, General Application and Implementation Directive 2025
- PDP Malaysia, Act A1727, Commencement order, DPO guideline and Data breach notification guideline