Skip to content
Visit Prembly
Protecting Students’ Personal Data: Understanding Data Protection Obligations in Education

Protecting Students’ Personal Data: Understanding Data Protection Obligations in Education

Misturat Alausa Misturat Alausa Regulatory Series 4 min read 25 Aug 2026 19 views

Educational institutions collect and manage large amounts of personal information every day.   From students’ names and contact details to identification documents, academic records, financial information, and other sensitive data, these institutions are trusted with information that can have significant implications for students if it is misused or not properly protected.

As digital technology becomes more integrated into education, greater attention is being placed on how students’ personal data is collected, processed, and shared. Institutions may work with banks, technology providers, government agencies, and other third parties to provide services to students. Although such partnerships can offer greater convenience and access, they also raise important questions about how students’ personal data is being used.

This is because the Nigeria Data Protection Act (NDPA) 2023 places responsibilities on organizations that process personal data, including how such information is collected, used, shared, stored, and protected. Therefore, educational institutions need to understand these responsibilities when engaging with third parties.

Understanding Lawful Data Processing Under the NDPA

One of the fundamental principles of data protection is that organizations must have a lawful basis for processing personal data. This means that having access to an individual’s information does not automatically mean that the information can be used for any purpose. Educational institutions may collect students’ data for specific reasons, such as admission, academic administration, communication, or student support. However, using that data for a different purpose may require institutions to consider whether the new processing is lawful and appropriate.

This is particularly important when student data is shared with external parties. For example, if an institution provides students’ information to a financial institution to facilitate access to a financial service, there should be a clear understanding of why the data is being shared, what information is necessary, who will process it, and the legal basis for doing so. Transparency is another key aspect of responsible data processing. Students should be informed about how their personal data is being collected and used. This can be communicated through privacy notices, which explain the purposes of processing and the parties that may have access to the information.

The principle of purpose limitation is also important. Personal data should be collected for clear and specific purposes and not simply because it may be useful later. Any further use should be consistent with the original purpose.

Data Sharing and Responsible Use of Students’ Personal Data

Institutions need to understand that when they share a student’s data with another organization, the risks do not end there. In some cases, student information may be combined with other data to create a profile, assess an individual’s financial position, or determine their eligibility for a service. For example, information collected by an educational institution could potentially be used alongside other data to assess a student’s eligibility for a bank account or financial product. This raises questions about what information is being used, how it affects decisions, and whether students understand how their data is being used.

A recent case involving the University of Lagos (UNILAG), Lotus Bank, and Hackerbella Ltd highlights these concerns. The Nigeria Data Protection Commission (NDPC) began an investigation after complaints that students’ personal data had allegedly been used to open bank accounts without a lawful basis. The investigation also considers how students’ data may have been used to assess their financial profiles and make decisions about their access to financial services. This shows the need for organizations to consider not only how student data is collected and shared, but also what happens to that data afterwards and how it may affect the students involved. In situations where student data could pose significant risks, organizations should assess those risks and put appropriate safeguards in place, using a Data Protection Impact Assessment (DPIA) to identify and address potential risks before processing begins.

Follow Prembly Insights for more insights on data protection, compliance, and responsible data use.

Building Stronger Data Protection Practices in Education

Protecting students’ personal data should go beyond one-time compliance. It should be incorporated into the way institutions design their systems, establish partnerships, and manage information throughout its lifecycle. Educational institutions should also ensure that clear policies are in place to define who can access student data, when it can be shared, and what safeguards should be applied. When third parties are involved, appropriate agreements and responsibilities should be established to ensure that personal data continues to receive adequate protection.

Technical safeguards such as access controls, secure data handling, monitoring, and other security measures are also important in reducing the risk of unauthorized access or misuse. For businesses that provide services to educational institutions, data protection should be considered from the start. Products and systems that collect or process student data should be designed with privacy and security in mind.