THREAT BRIEFING · 09.09.2026 DEENFRES

Case Studies

DSFA: How Schools Properly Document the Consequences of Data Processing

By Tobias Massow · July 18, 2024 · 7 min read

Data Protection Impact Assessment (DSFA) is a somewhat cumbersome term. However, what the GDPR essentially describes is sensible and necessary: it is about assessing and documenting the possible negative consequences of processing personal data. Schools are particularly challenged in this regard.

TL;DR

The EU-wide data protection law, the General Data Protection Regulation (GDPR), describes in Article 35 the obligation to conduct a Data Protection Impact Assessment if data processing “is likely to result in a high risk to the rights and freedoms of natural persons.” Furthermore, from the explanations to the law (Recital 75), it emerges that the legislator sees such risks, in particular, when data of children are processed.

Students in their teenage years are increasingly active on social media and often voluntarily disclose all kinds of personal data. However, this does not relieve schools and other educational institutions as responsible parties from the obligation to assess, evaluate, and document the risks for the “affected persons” before using software in which student data is processed. The “affected persons” include, among others, the young people to whom the data refers.

DSFA as the Key to Data Protection Compliance

Digitalization is the order of the day in the education sector (Source: Adobe Stock/ Romolo Tavani)

Digitalization is the order of the day. If there was one good thing about the COVID-19 pandemic, it was the wake-up call for the education sector to digitize their processes – that is, to use software to work faster and independently of location. The same applies to the healthcare sector and public administration.

When selecting the “right” software, many aspects play a role. These are usually the suitability for the purpose, user-friendliness, and price. But also the security of the application, the handling of personal data, and the reliability of the provider.

In this regard, it is not only important for educational institutions and other organizations to be technologically up-to-date but also to meet the relevant legal requirements, including those of the GDPR. The DSFA is well suited to examine software-supported processing and also serves as proof of data protection compatibility to authorities and other interest groups, such as parents.

Ubiquitous but Controversial: Microsoft 365

Established products on the market offer the advantage over niche products or “homegrown” solutions that information required for a DSFA is usually already available. Furthermore, the need for adaptation and training often falls lower here. Standard solutions like Microsoft’s Office products are attractive not least because they are known to most people from their private or professional environment.

However, the use of these products also leads to users being accustomed to the brand behind them, which is a lasting point of criticism regarding the use of such solutions in schools. Some data protection supervisory authorities also criticize a lack of transparency regarding data usage by Microsoft and third parties from their perspective.

Nevertheless, the choice often falls on Microsoft 365 because the software offers a variety of functions, runs largely stably, and requires relatively little technical knowledge from the user.

Expertise is in Demand

msecure helps to use Microsoft 365 securely (Source: Adobe Stock/ IB Photography)

To be able to use the extensive functionality in Microsoft 365 securely and with reduced data protection risks, the correct settings must be made. This presents schools with some challenges, as knowledge of data-minimizing configurations is usually not available.

We at msecure have the necessary expertise and offer targeted training and seminars to support the use of Microsoft 365. In a DSFA basic workshop tailored specifically to schools, we provide an overview of the modules and explain what can be sensibly used and what should be deactivated due to potential security risks. In addition, school administrators learn to estimate the effort required for the adjustments and which data processing activities are relevant for the DSFA. Subsequently, they receive a report with recommendations for designing the M365 environment to be able to make the corresponding configurations or commission them from their service provider.

In addition, msecure also offers a tenant check to evaluate, review, and audit the M365 configuration, as well as a comprehensive Data Protection Impact Assessment with all necessary sub-documents and a risk assessment.

Fact: According to Bitkom, 62 percent of German companies see the GDPR as a competitive disadvantage.

Fact: Every third German company has reported at least one data breach since the GDPR came into force, according to Bitkom.

Conclusion

Digitalization in schools is important. To ensure that the concerns of the affected persons are considered when selecting software and designing processes, and no unacceptable risks for them are overlooked, a DSFA is necessary. In particular, with complex software products like Microsoft 365, schools must pay attention to data protection-friendly settings. IT security specialists like msecure help schools with workshops and audits to fulfill their data protection obligations well.

Key Facts at a Glance

Legal Basis: GDPR Article 35 – Data Protection Impact Assessment

Mandatory for: Systematic processing of sensitive data, especially of minors

Affected: All schools using digital tools for data processing

Core Steps: Identify risks → assess → define measures → document

Special Category: Data of minors enjoys the highest GDPR protection

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What is a Data Protection Impact Assessment (DSFA)?

A DSFA is a structured process for evaluating the risks that a planned data processing poses to the rights and freedoms of affected persons. The GDPR requires it if the processing is likely to present a high risk.

When must schools conduct a DSFA?

Whenever personal data of students is processed systematically and extensively – for example, when introducing digital learning platforms, school clouds, digital class registers, or video teaching systems. Since student data is considered particularly worthy of protection, the threshold is low.

What happens if no DSFA is conducted?

Schools and school authorities risk fines under the GDPR. More importantly: in the event of a data protection incident without a prior DSFA, there is no proof that risks were assessed and measures were taken. This significantly increases liability.

What specific risks exist with school data?

Identity theft of minors, unauthorized access to grades and performance data, bullying through leaked personal information, profiling by learning platform providers, and uncontrolled data flow to third countries with cloud services.

Who can support schools with the DSFA?

External data protection consultants, official data protection officers, and specialized consulting firms like msecure offer workshops, sample DSFAs, and audits. The state data protection authorities also provide orientation aids.

Further Reading in the Network

DORA and IT Compliance: DORA in the Financial Sector (securitytoday.com)

Cloud Data Protection for Educational Institutions: cloudmagazin.com

Digitalization and Data Protection in SMEs: mybusinessfuture.com

 

Related Articles

Header Image Source: Adobe Stock / Gorodenkoff

Further reading

Case Studies · July 7, 2026

When a Phone Call Halted Car Production

On 31 August 2025, systems at Jaguar Land Rover began behaving strangely. A few days later, production came to a standstill. For five weeks, …

A magazine by Evernine Media GmbH