Skip to Content

Part 4: The Student Data Lifecycle: From Admission to Graduation and Secure Disposal

August 12, 2026 by
Mindful Clicks Africa, Athena Morgan

In Part 3 of this series, we discussed why resilient infrastructure matters more than software. We looked at how offline first architectures, hybrid systems, and structured NEMIS integration can help schools remain functional under real world connectivity constraints.

However, once an institution deploys the infrastructure to collect, store, and transmit information, a critical governance question arises: What happens to that data over time? 

Many schools operate on the assumption that once information has been collected, there is little reason to delete it. After all, “you never know when you might need it.” 

However, under the Kenya Data Protection Act, 2019, indefinite data retention is an explicit statutory breach. Data retained without an active, lawful purpose ceases to be an asset and becomes a severe legal and regulatory liability. 

Schools must actively manage personal data through a strict lifecycle from collection, use, and sharing, to archiving and final destruction. Every piece of student data must have a legally justified reason for collection, defined usage boundaries, strict access controls, and a mandatory expiration date at which it is either retained for a verified statutory purpose or permanently and securely destroyed. 

The Student Data Lifecycle

A student's digital footprint does not begin when they graduate. It begins much earlier, often with the information collected during the admission process.

From that point, information moves through different stages of the learner's journey. It is collected, used, sometimes shared with third parties, stored and eventually either retained for a legitimate long term purpose or securely disposed of.

Collection → Use → Sharing → Retention and Archiving → Secure Disposal

Each stage creates different responsibilities for the school.

Collection: Start With What You Actually Need

Before collecting information, schools should ask themselves; "What information do we actually need, and why?"

This is the statutory  principle of data minimisation (the legal requirement to collect, use, and retain only the absolute minimum amount of personal data necessary to achieve a clear, specified purpose.). 

Schools often collect more information than they immediately need because they believe it might become useful later. An admission form can gradually become a repository for everything from family details and employment information to photographs, emergency contacts and other personal information.

However, every additional piece of information collected creates another responsibility for the school. For example, a parent's telephone number may be necessary for communication or fee related purposes. But does the school genuinely need detailed information about a parent's employer or salary bracket?

The point is not that schools should know less about their learners, but that they should be deliberate about what they collect and why they collect it.

Use: Who Actually Needs to See the Data?

Once information enters a School ERP or Student Information System, access control must be strictly enforced. Under data protection law, administrative positioning does not grant blanket data access; information exposure must be governed by the principle of least privilege through Role-Based Access Control (RBAC); access to information should be determined by a person's responsibilities, not simply by their position within the institution. 

An accountant may need access to fee balances and payment records, but there is no operational reason for that person to access a learner's medical history.

A class teacher may need attendance records and academic assessments, but should not automatically have access to a family's financial history.

Schools must conduct mandatory, regular reviews of user permissions, particularly during staff transfers, promotions, or exit procedures.

Having system access does not constitute a legal right to view all institutional data. 

Sharing: Once Data Leaves the School, Control Becomes More Difficult

Schools do not operate in isolation. They routinely share data with transport providers, payment platforms, school trip organisers, extracurricular vendors, examination bodies, and cloud technology companies.  

Schools should therefore first assess: Why is the information being shared, what information is necessary, who is receiving it, and what will happen to it afterwards?

The principle of purpose limitation strictly dictates that data collected by schools for a specific objective cannot automatically be diverted or repurposed for unrelated processing activities. Under the KDPA, 2019, third-party vendors operating as Data Processors must be bound by robust Data Protection Agreements (DPAs). Where a vendor processes personal data on behalf of the school, the relationship should clearly define the responsibilities of both parties and how the information will be protected.

As we discussed in Part 1, the fact that a third party is processing the information does not mean the school can simply step away from its responsibility as a data controller..

Sending data to another organisation does not mean sending away the school's responsibility for that data.

Retention and Archiving: Breaking the "Permanent Record" Myth 

Schools must fundamentally restructure their approach to data archiving. When a learner graduates or transfers, their legal relationship with the institution changes, meaning the legal justification for holding their entire file expires. 

Some records have a legitimate long term value. A student's academic transcript, examination records, admission history, and certificates may need to be preserved because they form part of the learner's educational history and may be required for future verification.

Other information has a much shorter useful life. Daily attendance records, temporary visitor records, routine communication logs, transport location information, certain operational records, and other temporary data cannot legally be retained indefinitely.

The important distinction is between records that need to be preserved and information that has simply been left behind.

A school should therefore have a clear data retention schedule that defines how different categories of information are handled.

The exact retention period should not simply be guessed. It should be based on legal requirements, regulatory obligations, the purpose for which the information was collected, contractual requirements, and the school's legitimate operational needs.

Secure Disposal: Deleting Data is a Core Part of Data Governance

Eventually, all personal data surpasses its mandatory statutory retention period or loses its lawful basis for processing. 

Deleting an email, moving a file to the recycle bin, or disposing of an old computer does not constitute secure destruction. Schools need processes for the secure disposal of both physical and digital records.

Physical Records: Paper documents containing personal, financial, or medical information must be cross-cut shredded or incinerated, rather than discarded in ordinary waste.

Digital Records: Schools must audit how their ERP platforms and cloud vendors execute hard deletions, overwrite backup cycles, and sanitise archived environments.

Hardware Lifecycle: When decommissioning or donating old computers, tablets, or servers, schools must utilize certified data-wiping software to ensure all storage sectors are completely unrecoverable.

Data protection does not end when a record is no longer needed. It includes making sure that the record cannot simply resurface later.

The Regulatory Liability of Alumni Databases 

Alumni networks provide strategic value for fundraising, mentorship, and community engagement. However, transitioning from a student to an alumnus does not grant a school an automatic lawful basis to maintain historical data points in an active repository. 

Under data protection law, schools must strictly segregate active alumni engagement data from legacy student records. Any personal information that no longer serves a verified, statutory purpose must be purged or anonymised, leaving only the minimal data required for ongoing alumni relations.

This strict segregation applies explicitly to sensitive historical information, including photographs, contact details, and disciplinary records. A former student's administrative file cannot legally be repurposed into a permanent marketing database. 

Utilizing historical data for new processing activities, such as marketing or fundraising, constitutes a change of purpose. Since the original legal basis for holding the data has expired, schools are legally required to establish a fresh lawful basis, such as explicit consent, before initiating any alumni outreach.

What Should Schools Do?

Compliance does not require schools to wipe their servers at the end of every academic calendar. It requires absolute clarity regarding what data they hold, why they hold it, how long they are legally permitted to keep it, and how it will be destroyed. 

This begins with a clear data retention schedule. Schools should map the major categories of information they hold and establish how long each category should be retained, taking into account applicable legal and regulatory requirements rather than relying on arbitrary time periods.

Having a policy however is not enough. Schools also need to have institutionalized data audits and  conduct regular reviews of the information they hold. They should not wait until a server is full or a vendor contract is ending to ask what information remains in their systems.

Schools should also audit the supply chain to understand what happens to their data once it leaves their own systems. A school may delete a record from its own platform while copies remain with its software provider, cloud storage provider, backup system, or another third party.

Schools should inquire of their vendors; “Where is our data stored? How long is it retained? What happens to backups? What happens when our contract ends? And how do you verify that data has been deleted?”

These supply-chain questions form the foundation of Part 5, where we will dissect the strategy behind school technology contracts. The agreements you sign today dictate who controls, owns, and profits from your institutional data tomorrow. 

The Strategic Takeaway: Responsible Stewardship 

The student data lifecycle is ultimately about responsible stewardship, not just deletion. Schools are entrusted with some of the most sensitive information about children and their families. 

That responsibility does not disappear simply because the information has been entered into a digital system. From the moment a learner's information is collected at admission to the moment a record is archived or securely destroyed, every stage of that journey requires thought, accountability, and appropriate safeguards. Schools must aim to keep the right data, for the right reason, for the right amount of time.

In Part 5, we turn our attention to the strategy behind school technology contracts. What happens when your school wants to change software providers? Who owns the data? Can you take it with you? And what happens to your information when the contract ends?

About the Author

Athena Mwarwakamori Morgan is the Founder of Mindful Clicks Africa, where she advises schools, organisations, and policymakers on digital governance, child online safety, data protection, and responsible technology use. She has worked across Africa on child protection, technology policy, and safeguarding, helping institutions create safer and more resilient digital environments.