When a school enters students in your league, student-data processing becomes part of the platform-buying decision, alongside brackets and match chat. Ask any platform to show you what it holds, who decides how it's used, who can see it and when it goes. Your data-protection lead should check the arrangement for your competition.

Does the GDPR apply to a school esports league?

The EU GDPR covers processing in the context of an EU establishment's activities. It can also cover non-EU processing connected with offering goods or services to people in the EU, or monitoring their behaviour there (European Commission). Citizenship alone doesn't settle it. The UK GDPR is separate; check the current ICO children guidance for UK requirements.

Who is responsible for student data: the school, the league or the platform?

Controllers decide why and how data is processed; processors act on their instructions and have responsibilities too. Joint decisions can create joint controllers. Roles follow actual decisions for each purpose. The EDPB explains the required controller–processor contract, covering instructions, security, sub-processors, rights assistance and return or deletion.

School Esports' provider policy normally describes the customer as controller and School Esports as processor, with separate provider-controlled purposes. Compare your signed agreement and data processing addendum with actual processing. Its main-site policy and demo documents conflict on consent, under-13 participation and termination timing. Have the supplier reconcile these before relying on their promises.

Imagine a parent emailing mid-season about where their child's details came from, who has seen them and what happens after the final. If everyone expects someone else to reply, the email sits there. Agree a school–league–platform responsibility matrix before the season starts.

Do you need parental consent for every student?

Not automatically. Under the EU GDPR, consent is one of six lawful bases, each with conditions (EDPB lawful-processing guide). Article 8 applies to consent-based information society services offered directly to children. Below the applicable national age, parental authorisation is required for that processing. The default is 16; Member States can lower it to no younger than 13 (EDPB consent guidelines, section 7.1).

Participation permission, publisher account rules and the processing legal basis are separate questions. Your data-protection lead should assess each use alongside school, game and competition requirements. The conflicting published age rules don't establish an under-13 participation route.

What should you ask a platform to show you?

Ask for a demonstration and supporting documents, then work through these questions.

  • What's collected, and why? Map rosters, usernames, chat, results, moderation, billing and public profiles to purpose, source and recipient. A linked username can identify a student; pseudonymised data remains personal data while re-identification is possible.
  • Who sees what? The privacy support guide says emails, surnames and student IDs are excluded from standard opponent/public rosters. The demo notice also lists school/team in opponent views and usernames in public results. Ask to see these views, staff/organiser/support access and optional profiles. Obtain your actual tenant notice and security evidence; the demo notice has illustrative customer details.
  • Where does data travel? The subprocessor register lists Sydney, US and French processing. New Zealand's EU adequacy status doesn't settle onward transfers. Check safeguards for each flow, including support, backups and integrations, against actual agreements.
  • Who tells families, and who answers them? Under the EU GDPR, indirect collection generally requires notice within a month, or earlier at first communication or disclosure, unless an exception applies. Rights requests generally need a response within a month; qualifying extensions require timely notice. Erasure and portability have conditions (EDPB rights guidance). Assign requests and processor assistance. A personal download doesn't establish a complete organisation export or cover records needing separate privacy review.
  • When does each kind of data go? The provider schedule states routine-chat cleanup 48 hours after match/round end and removal of specified roster fields 24 months after competition end, with separate evidence retention and dormant-account review. Check each trigger, surviving records and code-set periods. Resolve the conflicting termination wording into one answer about export, deletion, anonymisation, exceptions and backups. A published schedule doesn't verify execution.
  • Do you need a data protection impact assessment? One is required where processing is likely to be high risk. Check the EDPB criteria, including vulnerable people's data, and your national regulator's list before rollout. Assess your actual processing.

When should you reassess a platform's student-data processing?

Revisit the assessment when a new game, public profile, sponsor, broadcast or integration changes data uses. If you're considering School Esports, its live demo gives you views and documents to examine before discussing your agreement and tenant notice.