Blog
Data protection · Music school

GDPR for online music schools: what you should know if you run an online music school

Who is responsible when several teachers teach? The practical guide to data protection in private online music schools.

Jonas Weber·Published on October 26, 2026
Team of an online music school managing student data on a laptop

A single teacher has it easier in some respects. They know their students, they decide alone, and they usually have an overview of where each piece of information sits.

As soon as several teachers teach, questions appear that did not exist before.

Who may see which data? What happens when a teacher leaves? And who actually answers an access request when it arrives in the middle of the week?

Strictly speaking, data protection in a music school is less a technical question than an organisational one.

GDPR for online music schools sounds like a large project, but in practice it is a manageable series of decisions.

The good news: a few clear rules solve most of it, and most of them you set up once and then simply maintain.

Why a music school has different questions from a single teacher

For an individual, teaching and organisation sit in one pair of hands. That makes data protection easier, because there is one place and one person with the overview.

In a music school, the same work is spread across several people and several systems.

That creates new questions. Not because different laws suddenly apply, but because responsibility is shared.

An example: a teacher notes an observation about a student’s practice. May the next teacher see it when the student changes teacher? And may administration see it?

Such questions are not complicated, but they need an answer before they come up for the first time.

For solo teachers the situation is clearer. That is covered in detail in GDPR in online music lessons.

Who is actually responsible?

The most important question first. The controller under the GDPR is usually the music school, meaning the organisation that offers the lessons and signs the contracts.

That also applies when the lessons are delivered by freelance teachers, as long as the school sets the framework.

Employed teachers process data under instructions. They are not controllers themselves, but act for the school.

With freelance teachers you have to look more closely. Depending on how the arrangement is set up, they can be their own controllers, joint controllers or processors.

That does not mean you have to settle it in legal detail. It means you should write the role down once, so that it is clear who is responsible when in doubt.

A simple role matrix helps

  • The school is the controller: it defines the purposes and answers data subject rights.
  • Employed teachers process data under instructions.
  • Freelance teachers: clarify the role and set it out in a contract.
  • The platform is a processor with a data processing agreement under Art. 28 GDPR.

Once these roles are clear, many follow-up questions answer themselves.

What data comes together in a music school

More data comes together in a music school than with an individual, and it comes from more directions.

Typically these areas are involved:

  • Student administration with master data, contracts and payments
  • Lessons with appointments, content, goals and progress
  • Communication from chats, emails and enquiries
  • Recordings as audio and video
  • Personnel data of the teachers
  • Website and registration

Three groups deserve particular attention: data of minors, data of the teachers, and health-related notes under Art. 9 GDPR.

On top of that comes the point that is the real risk in practice: the same data often sits in several places at once.

In the admin system, in a shared calendar and in a chat there are then three slightly different versions. Not because anyone is careless, but because the systems do not talk to each other.

It is exactly this spread that a music school should put in order first.

Duties that come with size

Some duties that are hardly relevant for an individual become concrete for a school.

Records of processing activities

Under Art. 30 GDPR every controller must keep a record. The exemption for small organisations rarely applies in practice, because data is processed regularly and therefore not only occasionally.

The record is essentially a table: purpose, data types, data subjects, recipients, deletion deadlines and safeguards. It sounds like bureaucracy, but it is the basis for almost everything else.

Technical and organisational measures

Art. 32 GDPR requires appropriate safeguards. In practice that means clear access rights, encryption, regular backups and strong passwords.

Data protection officer

A data protection officer becomes necessary under § 38 of the German Federal Data Protection Act when at least 20 people are permanently involved in automated data processing. For many music schools that is reached faster than expected once you add up teachers and administration.

Deletion plan

A deletion plan defines when which data is deleted. Invoice data stays for statutory periods, lesson data does not.

These four points sound like a lot of work. But they are set up once and maintained afterwards, and each year gets easier.

Involving teachers

The best documentation is worth little if everyday practice does something else.

That is why a well-organised music school also ensures teachers know what they may and may not do.

  • A confidentiality obligation
  • A short briefing on handling data
  • Clear access rights per role
  • Rules for using personal devices

That sounds like effort, but it is usually one short conversation plus a signature.

Teacher changes

The case where a teacher leaves or a student changes teacher is especially important.

What happens to notes, recordings and goals? Who may see them, and what should stay with the student?

In a system with clear roles this is a matter of minutes. Without such a system it is often a matter of asking around, remembering and guessing.

The experience report 3 months of MUSIRIS with 20 students shows how much such transitions ease everyday work.

Setting up data processing correctly

A music school almost always works with external providers: admin software, video tools, cloud, accounting.

Each of these providers needs a data processing agreement under Art. 28 GDPR. If it is missing, responsibility still stays with the school.

Freelance teachers can be processors too

When a freelance teacher processes data on behalf of the school, that should be set out in a contract, including confidentiality, instructions and deletion.

That is not distrust, but a clear division of labour that protects both sides.

What to look for in providers

  • Where is the data stored? A location in the EU makes many things easier.
  • Is there a data processing agreement, and is it easy to sign?
  • Is there a clear deletion feature?
  • Can the data be exported?

MUSIRIS meets these points, hosts in the Netherlands and offers export and deletion. The details are in the MUSIRIS privacy policy.

You can find an overview of the features under feature comparison.

Organising recordings, minors and consent centrally

In a school with many students, consent for recordings is one of the biggest organisational tasks.

When every teacher does it differently, a patchwork of verbal promises and individual chat messages quickly emerges.

Central instead of on the side

  • One uniform form for all teachers
  • A clear purpose, for example feedback and progress monitoring
  • A defined storage location
  • A fixed deletion deadline
  • The signature of the legal guardians for minor students

For images and video, image-rights law applies on top, specifically §§ 22 and 23 of the German Art Copyright Act. In practice what matters most is that consent is documented and can be withdrawn.

A central place for recordings later makes both deletion and access requests much easier. Strictly speaking, that saves the school more time than it costs.

Data subject rights and data breaches with a clear process

Access requests are rare, but when they come they usually come with a deadline.

That is why a school needs a simple procedure: who receives the request, who collects the data, and who answers?

For an individual this runs in their head. In a school it goes wrong when nobody is responsible at the decisive moment.

Data breaches

In an incident, such as a lost laptop with student data, a report may be required within 72 hours, as set out in Art. 33 GDPR.

A short procedure helps: document the incident, assess the risk, record the decision and inform those affected if necessary.

Writing this routine down once is the best protection against panic in a real case.

A roadmap for the music school

You do not have to change everything at once. This order has proven itself.

  • Clarify roles and write them down.
  • Take stock of data: what sits where?
  • Create records of processing activities.
  • Conclude data processing agreements with all providers and freelance teachers.
  • Organise consent for recordings centrally.
  • Create a deletion plan and review it annually.
  • Define a procedure for data subject rights and data breaches.

Once these seven points are in place, the music school is solidly set up.

Strictly speaking, this is less a project than a habit. And habits are easier to keep when the tools fit.

How MUSIRIS supports music schools

MUSIRIS is built so that many of the organisational points do not stay with you.

Data sits in one place and is hosted in the EU, more precisely in the Netherlands.

There are separate roles for teachers and administration, so that access is clearly regulated and not everyone sees everything.

Data export and a deletion feature are available, which considerably eases access requests and deletion.

If you want to check this for your school, you can get in touch or look at pricing and plans.

For solo teachers, the article GDPR in online music lessons is the right starting point.

Frequently asked questions

From when do we need a data protection officer?

As soon as at least 20 people are permanently involved in automated data processing, as set out in § 38 of the German Federal Data Protection Act. Add up administration and teachers, and that is often reached faster than expected.

Who is responsible when teachers are freelance?

As a rule the school remains the controller if it sets the framework. The exact role should be set out in writing.

Do we need records of processing activities?

Yes. The exemption for small organisations rarely applies, because data is processed regularly and not only occasionally.

Do we need a data processing agreement with every provider?

Yes, as soon as a provider processes personal data for you. With reputable providers it is standard.

What happens during a teacher change?

Notes, goals and recordings stay with the student. With clear roles the new teacher can access them in a targeted way.

How do we organise consent for recordings centrally?

With one uniform form, a defined storage location and a fixed deletion deadline, and with the signature of the legal guardians for minors.

Legal notice

This article provides practical orientation and does not constitute legal advice. In special cases, it is worth looking at the GDPR or seeking advice from a qualified body.

Sources

Jonas Weber

Music educator and editor at MUSIRIS

Jonas has taught music for more than ten years, several of them online, and writes about everyday digital teaching at MUSIRIS.

Register for free

No credit card · Ready in a few minutes