🔗 The M2W platform connects overseas and Vietnamese schools →🔗 Connect international and Vietnamese schools → 🎓 International recruitment — overseas schools, join now →🎓 International recruitment for schools → 🤝 School-to-school cooperation: student & teacher exchange, summer camps →🤝 School cooperation & joint programs → 🏫 Vietnamese schools — international cooperation, summer camps, joint programs →🏫 Vietnamese schools go international →

Protecting student data when sharing it with partners

May 26, 2026 18 min read By My Second World
Protecting student data when sharing it with partners

Protecting student data is a responsibility that a school cannot outsource, even when the collection and processing is carried out by an admissions partner.

In international admissions, personal data passes through many hands: from the student to the partner, from the partner to the school, and sometimes through a third party such as a translation provider or a document verification provider. Each transfer is a point where risk can arise.

This article covers the underlying principles, what should be included in the agreement, and how to respond when an incident occurs.

It should be stated clearly upfront: personal data protection regulations differ between countries and are updated over time. This article is presented at the level of general principles. Before applying them, a school should check the regulations currently in effect in Vietnam and in the partner’s country, and should obtain specialized legal advice.

What data needs to be protected

The scope is much broader than most people think.

Identifying information. Full name, date of birth, ID document number, photo, address.

Contact information. Phone number, email address, social media account if collected.

Academic information. Transcripts, exam results, certificates, letters of recommendation.

Thông tin tài chính. Financial proof documents and information about ability to pay.

Family information. Parents’ occupation, family income, sponsor information.

Sensitive information. Health status, if collected for support purposes.

The last two groups require the highest level of protection, and they are also the two groups most often collected beyond what is actually necessary.

Six underlying principles

Principle one: minimal collection. Collect only what is truly necessary for evaluating applications and providing support. Every additional data field is an added risk without a corresponding benefit.

One way to check: for each field in the form, ask whether the admission decision would change if that field were removed. If not, it should be removed.

Principle two: state the purpose clearly. Students must know what their data is used for, who has access to it, and how long it is kept.

Principle three: obtain consent. Sharing data with a third party requires the student’s consent, and for a student who is not yet of legal age, the consent of a guardian is required.

Consent must be expressed clearly, not buried in general terms that no one reads.

Principle four: limit the purpose of use. Data collected for admissions purposes must not be used for other purposes, such as marketing unrelated services.

Principle five: security in storage and transfer. Do not send sensitive documents over unprotected channels, do not store them on personal devices, and do not share them through personal accounts.

Principle six: delete once the purpose has been served. Data belonging to people who did not enroll does not need to be kept indefinitely.

Protecting student data in agreements with partners

The six principles above only take effect once they are put into writing. The seven items below should be included in the contract or in a separate appendix.

A list of data permitted to be collected, specified concretely rather than described in general terms.

Purpose of use, together with a commitment not to use it for any other purpose.

How consent is obtained, including the consent-form template that the partner must use.

How it is stored and secured. Where it is stored, who has access, and whether there is an access-control mechanism.

Rules on transfer to a fourth party. If the partner needs to transfer data to a translation provider or another entity, what conditions must be met.

Retention period and the obligation to delete, including the case where the partnership ends.

Obligation to notify in the event of an incident, with a specific deadline.

This last item is especially important, because without it a school may only learn of a data leak after the damage has already spread.

Cross-border data transfer

This is a distinctive feature of international admissions and the most legally complex part.

Data belonging to a Vietnamese student is transferred to an educational institution in another country, which has its own data protection regulations, sometimes considerably different.

Three things a school should do.

Clearly identify which data needs to be transferred abroad and limit it to the minimum necessary for the admissions evaluation.

Notify the student where the data will be transferred to and which regulations will govern it.

Check the regulations on both sides before setting up the data flow, and record the result of that check along with the date.

This is an area where guessing is very risky. For data flows that are frequent and large in scale, specialized legal advice should be obtained rather than relying on a general understanding.

Students’ rights

Students are not only subjects to be protected but also hold specific rights that must be respected.

The right to know. What data is being stored, what it is used for, and who has access to it.

The right to access. To be given a copy of their own data upon request.

The right to correction. To request that inaccurate information be corrected.

The right to withdraw consent. For purposes not mandatory for the admissions evaluation.

The right to request deletion when the data is no longer needed for the stated purpose.

A school should have a clear channel for receiving these requests, and should state that channel right in the initial data collection materials.

Publicizing students’ rights does not increase workload as much as many people fear. In practice, the number of such requests is usually very small, but the mere existence of the mechanism builds considerable trust.

When a leak incident occurs

How it is handled in the first hours determines the extent of the damage.

Step one: determine the scope. What data was exposed, how many people it affects, and through which channel.

Step two: cut off the source. Revoke access, take down content if it has been posted publicly, and lock related accounts.

Step three: notify. Notify those whose data was affected, stating clearly what happened, what data was exposed, and what they should do. Notifying early and honestly causes far less damage than letting people discover it themselves.

Step four: fulfill the reporting obligation under the regulations currently in effect, if applicable.

Step five: fix the root cause. Identify the vulnerability and fix it, rather than only dealing with the aftermath.

This process needs to be prepared in advance. In a real situation, no one has time to figure out a response from scratch.

Training and real-world checks

Rules on paper do not protect data by themselves. The people who handle applications day to day are where the risk actually arises.

Include this content in partner training programs. It does not need to be long, but it must be concrete: what is collected, which channel it is sent through, where it is stored, and when it is deleted. Use real examples rather than abstract principles.

Periodically check actual practices. At least once a year, ask the partner three questions: where student records are currently stored, who can access them, and whether data belonging to people who did not enroll two years ago is still being kept.

The third question usually reveals the problem most clearly, because deleting data once it has served its purpose is almost never done unless someone is reminded to do it.

Review your own internal practices before reviewing your partner’s. Many schools require partners to comply strictly while their own admissions department is still sending documents through personal messaging. Reviewing internally first is both fair and shows that the school takes its own rules seriously.

The cost of doing it right

A common worry is that full compliance will slow down the process and increase costs. In reality, most of the measures above cost almost nothing.

Shortening the form costs nothing. Switching from personal messages to an organizational mailbox costs nothing. Creating a separate account for each person instead of sharing one is the same. Deleting data once it has served its purpose even reduces storage costs.

The real cost only appears when an incident occurs: time spent handling it, reputational damage, and in some cases legal liability. Comparing the two, investing in preventive processes is almost always cheaper.

Three common mistakes in practice

Sending documents through personal messages. Very common because it is convenient, but the data stays on personal devices and outside the organization’s control.

Sharing one account across an entire department. There is no way to tell who accessed which data, and revoking access when someone leaves becomes practically impossible.

Keeping data indefinitely. Records of people who never enrolled, from years ago, still sit in the system, creating risk without providing any value.

All three errors stem from short-term convenience, and all can be fixed through process rather than technology investment.

When you need to benchmark data governance practices in education across systems, the policy report of the Organisation for Economic Co-operation and Development (OECD) provide useful reference context.

For content related to exchanging academic records between education systems, the framework of The United Nations Educational, Scientific and Cultural Organization (UNESCO) is the reference worth using.

Summary

Protecting student data is a non-transferable responsibility of the school, based on six principles, the most important of which are data minimization and purpose limitation.

These principles only take effect once translated into seven specific provisions in the agreement with the partner, with the breach-notification obligation being the item most often left out.

And the three most common errors in practice all stem from short-term convenience, and all can be fixed through process.

Next Steps

Take the information-collection form your partner is currently using and check each item against one question: if this item were removed, would the admission decision change.

Items where the answer is no should be removed, and this is the fastest way to reduce risk at no cost.

After trimming the form, cross-check it against the existing agreement: does the list of data permitted for collection in the contract match the new form. A mismatch between the two documents is a common situation, and it leaves both sides unclear on which standard applies in a dispute.

Related articles

Need advice on the right immigration pathway?

Leave your details and an M2W specialist will contact you for a free consultation within 24 working hours.

Join the platform