Over the first four parts of this series, we have mapped out the modern school technology ecosystem. We have explored the high cost of regulatory non-compliance, analyzed the core software pillars, adjusted for Kenya’s infrastructure realities, and tracked the student data lifecycle from admission to secure disposal.
But there is one final, critical business risk that school boards and owners frequently overlook until it is too late: The Vendor Lock-In Trap.
Imagine your institution has spent three years using a specific School ERP or Learning Management System. Over time, the software's performance degrades, customer support becomes non-existent, or the vendor suddenly introduces a massive price hike. You decide it is time to switch to a modern, more efficient competitor.
When you ask your current vendor for your historical student, financial, and academic data, they drop a bombshell: They will charge you an exorbitant fee to release it, or worse, they deliver the files in an unreadable, proprietary format that no other system can import.
Suddenly, your school’s entire institutional history is being held hostage.
Understanding the Legal Dynamics: Controller vs. Processor
To protect your institution from this trap, school boards must master a foundational legal concept established under the Kenya Data Protection Act (DPA), 2019: the distinction between a Data Controller and a Data Processor.
The School is the Data Controller: Your institution determines why the data is collected (to educate and manage students) and how it should be handled. You bear the ultimate legal responsibility toward parents and the ODPC. Crucially, the school owns the data.
The Software Vendor is the Data Processor: The software company merely provides the pipeline and storage space to hold that data on your instructions. They have zero ownership rights over your student grades, parent phone numbers, or M-Pesa transaction histories.
Any contract clause that implies a vendor can restrict your access to your data or charge you to retrieve your own records is a major corporate governance failure.
The Right to Data Portability
Under Section 34 of the Data Protection Act, data subjects (parents and students) have a legal right to Data Portability. This means they have the right to receive their personal data in a structured, commonly used, and machine-readable format, and have the right to transmit that data to another controller without hindrance.
If a parent transfers their child to another school, your system must be able to seamlessly hand over their digital transcript. By extension, if your school decides to transfer its entire student body to a new software vendor, your current processor must facilitate this migration.
Preventing a school from easily exporting its data is not just bad business practice, it actively interferes with the school’s ability to comply with statutory data portability obligations.
Necessary Contract Clauses
Before signing a service level agreement (SLA) with any EdTech provider, ERP company, or cloud vendor, your legal counsel must ensure the contract explicitly includes the following protections:
The Immediate Export Clause
The contract must state that the school can export its complete database at any time, without prior vendor approval, and at no additional cost. The system should feature a self-service dashboard allowing the school’s ICT manager to download all academic, demographic, and financial tables.
Universal, Non-Proprietary Formats
If a vendor promises to give your data back, but delivers it in an encrypted or proprietary format that only their software can open, you are still locked in. The contract must stipulate that data exports will be provided in universal formats such as CSV, JSON, or structured SQL databases that can be easily read by any modern system.
The Post-Termination Destruction Clause
What happens to your data on the vendor's servers after you leave them? To prevent data leaks and maintain compliance, the contract must bind the vendor to permanently and securely delete all copies of your school's data from their primary cloud storage and backup servers within a strict timeframe (e.g., 30 to 60 days) after the contract terminates. They must provide a formal Certificate of Data Destruction.
Steps to Protect Your School's Autonomy
Modernizing your school’s tech stack should give you operational freedom, not trap you in a digital monopoly. To protect your institution, adopt these ongoing contract governance steps:
Run an Annual Data Export Drill: Do not wait until you want to quit a vendor to find out if your data can be extracted. Once a year, have your ICT head perform a full system backup export into CSV files to test data integrity and portability.
Audit Existing Contracts: Review your current software contracts today. Look closely at the termination clauses. Are there hidden "migration assistance" fees or restrictions on data retrieval?
Prioritize Open Architecture: When vetting new software, ask the sales team directly: "Show me the export button. If I leave your platform tomorrow, exactly what format does my historical financial and grade data come out in?"
Series Conclusion.
Digital transformation is a journey, not a single software purchase. By building a tech stack that respects data privacy (Part 1), eliminates software overlap (Part 2), adapts to local infrastructure (Part 3), respects the data lifecycle (Part 4), and safeguards data ownership (Part 5), your institution will achieve true operational resilience.
You will protect your school from regulatory fines, drastically reduce administrative workloads for your teachers, and ensure your school remains agile, modern, and completely in control of its digital future.
About the Author
Athena Mwarwakamori Morgan is the Founder of Mindful Clicks Africa, where she advises schools, organisations, and policymakers on digital governance, child online safety, data protection, and responsible technology use. She has worked across Africa on child protection, technology policy, and safeguarding, helping institutions create safer and more resilient digital environments.