GDPR in online music lessons: what you should know if you teach music online
Recordings, WhatsApp, cloud: what actually falls under the GDPR in online music teaching and which five things you should tidy up.
If you are honest, hardly anyone of us chose to deal with data protection.
You wanted to teach music, not fill in forms, and as long as lessons run and students make progress, the topic feels far away.
Strictly speaking, it has not been far away for a long time.
As soon as you organise your teaching online, you store names, contact details, payment information, practice plans and often recordings as well. That means you process personal data on a scale that was simply not possible in a notebook by the piano.
The GDPR in online music teaching is therefore not a topic for lawyers, but for everyday lessons.
That does not mean you have to become a lawyer now. It means that a few basics are enough to set up your teaching properly, and that is exactly what this article is about.
Perhaps you have tried to read up on it before and dropped out after two paragraphs. That is understandable, because most texts on this topic are written for authorities and not for people who teach piano, guitar or singing.
Why data protection in online teaching is closer than it seems
The difference from in-person teaching lies less in the amount of data than in how it is spread out.
Name and phone number used to sit in a card index or a notebook. Today they sit in a calendar, a messenger, a cloud, an invoicing tool and a practice app.
Each of these places is harmless on its own. Together they create a picture that is hard to keep track of, and that is where the problems begin.
On top of that come things that never came up in in-person teaching: video recordings, voice messages, sheet music shared as PDFs and chats about rescheduling.
One point is especially underestimated. Many of your students are minors, and stricter rules apply to them than to adults.
Anyone documenting their practice should also be aware that even keeping a practice journal creates personal data.
That sounds like a lot of effort. In practice, it comes down to a few decisions that make the difference.
What data you actually process
“Personal data” sounds technical, but at first it simply means information that can be linked to a specific person.
In your everyday work, these are mainly the following categories:
- Master data such as name, date of birth and address
- Contact details such as phone number, email address and messenger names
- Payment data for invoices and billing
- Lesson data such as appointments, content and goals
- Practice and progress data
- Recordings as audio or video
- Communication data from chats and emails
Part of this is unremarkable. Another part deserves more attention.
Health-related notes fall under the special categories in Art. 9 GDPR. If you note that a student is pausing because of a hand injury or has a learning difficulty, an apparently harmless note can fall into this group.
That does not mean you are not allowed to store it. It means you need a clear reason and a safe place for it.
The first step is always a simple list
Write down once which data you store where. This list later becomes the basis for everything else, and it might cost you twenty minutes.
If you are already working on making practice visible, it is also worth reading Make practice visible.
The legal bases without legal jargon
The GDPR requires a reason for every processing activity, the so-called legal basis. It sounds bureaucratic, but at its core it is simple.
In practice you almost always need only three of them.
Performance of a contract
Everything needed to carry out lessons rests on Art. 6(1)(b) GDPR. That includes name, contact details, appointments and invoicing data.
For this data you do not need separate consent, because the contract itself is the basis.
Consent
Everything that is added voluntarily requires consent under Art. 6(1)(a) GDPR. This applies above all to recordings and to sharing data with third parties.
Important: consent must be voluntary, it must relate to a specific purpose, and it can be withdrawn at any time.
Legitimate interest
For some things there is neither a contract nor consent, but a comprehensible interest. A typical example is answering an enquiry before the first lesson.
Here you have to briefly weigh whether your interest outweighs the student’s rights. That sounds harder than it is when the purpose is obvious.
With minors there is an extra point. Consent is usually given by the legal guardians, and the younger the child, the more important that is.
Recordings and video: the most sensitive point
Recordings are especially useful in music lessons because you can hear progress. Legally, though, they are the point where the most goes wrong.
A recording is only permitted with consent. For images and video, image-rights law applies on top, specifically §§ 22 and 23 of the German Art Copyright Act.
What good consent looks like
Usable consent answers five questions:
- What is the recording made for?
- Where is it stored?
- How long is it kept?
- How can consent be withdrawn?
- Who signs for minor students?
A single sentence in a chat message is not enough. That is not formalism, it is the difference between a recording you can justify later and one you cannot.
Where recordings are stored matters as much as consent
A recording in a messenger or a cloud folder on US servers is different from a recording in a system with a clear purpose limitation.
Strictly speaking, consent is only half the answer. The other half is the question of where the file actually sits and who can access it.
In practice a simple rule helps: recordings are used only for feedback, deleted after four weeks and not shared.
Example of a short note: “Recording from 3 May, bars 17–32. Purpose: feedback. Deletion after four weeks.”
Tools and providers: what to look for with WhatsApp, Zoom and cloud
Most tools are not forbidden, but they are not equally suitable. Three questions help with every decision.
- Where is the data stored?
- Is there a data processing agreement?
- Is data transferred to the US?
Data processing
As soon as a provider processes data for you, you need a data processing agreement under Art. 28 GDPR. With reputable providers it is standard and usually available online.
If such an agreement is missing, that is no reason to panic, but it is an item for your to-do list.
Transfers to the US
Many well-known services are based in the US. For transfers, the EU-US Data Privacy Framework and the standard contractual clauses provide a framework again.
Things get more reliable when the data sits in the EU. MUSIRIS, for example, hosts in the Netherlands.
That does not mean you have to replace every US service immediately. It means you should know where your data sits.
You can find the details about MUSIRIS in the MUSIRIS privacy policy.
How long may I keep data?
The GDPR requires that data is stored only as long as necessary for the purpose. In practice there are two categories.
- Invoice and accounting data is subject to statutory retention periods, in Germany usually up to ten years.
- Lesson and practice data is kept only as long as the teaching relationship exists and deleted afterwards.
Recordings almost always fall into the second category. They rarely have to be kept for legal reasons.
A simple deletion plan is enough: one deadline per data type, and once a year a look at what can be deleted.
If you are honest, this is the part that is forgotten most often. It is also the part that brings the most order.
Data subject rights and what happens when something goes wrong
Students and parents have rights: access, rectification, erasure, restriction of processing, data portability and objection.
In practice, access is the most common. Anyone asked should be able to compile the stored data.
A system where everything sits in one place makes this much easier than five different folders and chats.
When data goes missing
If something is lost, such as a phone with recordings, a data breach may have to be reported within 72 hours, as set out in Art. 33 GDPR.
That sounds more dramatic than it is in everyday life. What matters most is that you document the case and can assess whether there is a risk to the people affected.
Panic is not a plan. Calm and a short procedure are.
A five-step roadmap
You do not need perfect documentation. Five steps are enough to start.
- List which data you store where.
- Write a short privacy statement for your website or your offering.
- Conclude data processing agreements with your tools.
- Obtain proper consent for recordings, via the legal guardians for minors.
- Set deletion deadlines and review them once a year.
Once these five points are in place, you are further along than most.
Strictly speaking, data protection is nothing more than order. And order is something you establish once and then maintain.
How MUSIRIS helps
Many of these points are easier to implement when the data is not spread across five systems.
MUSIRIS brings teaching, practice and communication together in one place and hosts the data in the EU, more precisely in the Netherlands.
You can export your data on request, and there is a deletion feature.
For music schools with several teachers there are separate roles, so that not everyone has access to everything.
You can find the details in the MUSIRIS privacy policy and an overview of pricing and plans.
If you run a music school, the article Data protection for online music schools is also worth reading, because it covers roles and duties in more detail.
Frequently asked questions
Do I need a data protection officer as a single teacher?
Usually not. A data protection officer only becomes necessary when at least 20 people are permanently involved in automated data processing, as set out in § 38 of the German Federal Data Protection Act. For a single person that is practically never the case.
Am I allowed to record lessons?
Yes, with the consent of those affected and, for minors, their legal guardians. Purpose, storage location and deletion matter.
Do I need a privacy statement?
If you run a website or teach online and process personal data, you should inform people about it. That is the information duty under Art. 13 GDPR.
What about WhatsApp?
WhatsApp is common for quick arrangements. A service that processes data in the EU and offers a data processing agreement is more data-friendly.
How long may I keep student data?
Lesson and practice data for as long as the teaching relationship exists. Invoice data is subject to statutory retention periods and stays longer accordingly.
Legal notice
This article provides practical orientation and does not constitute legal advice. In special cases, it is worth looking at the GDPR or seeking advice from a qualified body.
Sources
Jonas Weber
Music educator and editor at MUSIRIS
Jonas has taught music for more than ten years, several of them online, and writes about everyday digital teaching at MUSIRIS.
No credit card · Ready in a few minutes