GDPR for Online Tutors: What You Actually Need to Do

Derek Cowan··8 min read
A woman rests a protective hand on her half-closed laptop beside a small locked drawer

Most solo tutors need exactly four things to handle GDPR properly: a lawful basis note in your terms, sensible storage, a deletion answer you actually honour, and consent for marketing emails. That is the whole list. GDPR is about handling personal data carefully, and a one-person tutoring business can do that without a compliance department.

GDPR follows your students' location, not yours

GDPR applies to you if you teach students in the EU or UK, regardless of where you live — it governs how anyone collects, stores and uses personal data, which means any information that identifies a person. The UK GDPR is near-identical in practice, so one careful setup covers both. Technically you are a "data controller" — the person who decides why and how the data is used — even if your entire database is a spreadsheet and a calendar. The spirit of the law fits in a sentence: collect only what you need, keep it safe, be able to say what you hold and why, and delete it when asked. Headline fines make the news, but for a solo tutor the realistic stakes are smaller: a student asking an awkward question, a payment platform audit, or losing the trust that keeps renewals coming.

Everything that identifies a student counts as personal data

Personal data is anything that identifies a student, and tutors hold more of it than they realise. Names and emails are the obvious items. Also covered: payment details, lesson notes ("lacks confidence in calls"), chat history, progress reports, recordings, and even a booking calendar entry tied to a name. A useful test: if a file would embarrass you if it leaked, treat it as personal data and store it accordingly.

Different data types carry different levels of risk

Different data types carry different risk, and the table below is the practical map: where each usually lives, what can go wrong, and the minimum handling rule.

Data type Where it usually lives Risk What to do
Names, emails CRM, spreadsheet, inbox Low Keep in one system; protect the account with 2FA
Payment details Stripe or PayPal, invoices Medium Never store card numbers; keep references only
Lesson notes Docs app, notebook Medium Keep them factual; delete on request
Recordings Cloud storage, platform High Consent, one locked location, 30–90 day window
Chat history WhatsApp, platform messages Medium Keep it professional; export and delete on request
Marketing list Email tool Low Double opt-in and one-click unsubscribe

Four duties cover almost everything a solo tutor needs

The four duties below are what "GDPR compliant" means in practice for a tutor working alone. Each takes minutes to set up and almost no time to maintain — which is the point.

1. Collect only what you use — and say why in your terms

Every field you collect should earn its place. A sensible minimum for teaching online: name, email, timezone, lesson notes, and the payment records your accountant requires. Skip postal addresses, birthdays and family details unless there is a genuine reason to hold them.

The "say why" half is the lawful basis note. One sentence in your terms does it: I collect your name, email and lesson notes to deliver your lessons; I send marketing emails only with your consent. If your contract needs updating anyway, the guide to writing a tutoring contract shows where that line fits alongside payment and cancellation terms.

2. Store sensibly: password manager, 2FA, no card spreadsheets

Use a password manager and switch on two-factor authentication on every account that touches student data — email first, because whoever controls your email can reset everything else. That single habit removes most of the realistic risk. Then fix the classic tutor failure mode: a spreadsheet of names, emails and card numbers sitting on the desktop. Card numbers should never be stored by you at all — let Stripe or PayPal handle the payment and keep only the reference. Cloud services with 2FA beat a laptop's Documents folder, because a stolen laptop then becomes an inconvenience instead of a data breach. A dedicated tutoring platform shrinks the surface further: Tuton, for example, keeps notes, messages and materials behind one protected login. The record-keeping side overlaps with tax, and the online tutor finances guide covers what you must keep and for how long.

3. Know your deletion answer — and honour it

Deletion requests are the duty tutors fear, and the answer is one sentence you decide in advance: "Email me and I'll delete your data within 30 days." Then honour it — remove the student from your CRM, lesson notes, chat history and marketing list. Two honest caveats, both fine to state plainly: automated backups may retain data until they rotate, and financial records you are legally required to keep for tax stay until the law says otherwise. Saying that openly is compliance. Deleting nothing and hoping they forget is not.

Marketing emails need consent; transactional ones do not. A lesson reminder is transactional. A "new course launching!" blast is marketing, and it needs the recipient to have opted in. The safe pattern is double opt-in: they enter their email on your site, they confirm via a link, and only then are they on the list. Never add students to a newsletter automatically because they booked a lesson — that is the mistake that most often gets solo tutors reported, and it costs you goodwill with exactly the people most likely to recommend you.

Recordings are the special case you must handle explicitly

Recordings are the most sensitive data most tutors hold, because video identifies someone completely. Three rules cover it. Get explicit consent before recording — a line in your terms plus a spoken confirmation at the start of the lesson ("I'll be recording for your notes — happy to switch it off"). Keep recordings in one place with access control, not scattered across cloud folders and chat apps. Set a retention window — 30 to 90 days is typical and defensible — then delete on schedule. If a student asks you to stop recording, stop; lesson notes are the gentler cousin, and they deserve the same discipline: keep them factual and professional, because a student can request to see what you have written about them.

Registration is rare below scale — but check your country

Most solo tutors below a modest scale do not need to register with a data protection authority, but thresholds vary by country and there is no universal rule. In the UK, the Information Commissioner's Office asks most organisations to pay a small annual data protection fee, with exemptions for some sole traders who only process data for accounts and records — the ICO's own guidance tells you in two minutes whether you are one of them. Elsewhere in Europe, registration duties usually attach to organisation size or to sensitive data types rather than to tutoring itself. When in doubt, an hour with your country authority's website settles the question for good.

A 30-minute checklist gets you compliant

Everything above compresses into six actions you can finish before your next lesson:

  1. Add the data sentence to your terms.
  2. Turn on 2FA for email, cloud storage and any CRM you use.
  3. Move card details out of any spreadsheet today; keep references only.
  4. Write your deletion script and save it as a message template.
  5. Set your recording consent line and retention window.
  6. Check your email tool for double opt-in and switch it on.

None of this requires a lawyer, a policy document or a weekend of work. It requires an hour, a password manager and the habit of collecting less than you think you need.

Frequently asked questions

Do I need GDPR compliance if I don't live in the EU?

Yes, if you teach students in the EU or UK. GDPR follows the student's location, not yours — a tutor in Brazil teaching a student in Berlin is handling EU residents' personal data.

What is a lawful basis, and which one applies to me?

It is your stated reason for holding data. For delivering lessons it is "contract" — you need the details to teach. For marketing emails it is "consent". One sentence in your terms covering both is enough for a solo tutor.

How long can I keep student data?

Keep what you are using; delete what you are not. Active students' data stays. Ex-students' notes and contact details go after a reasonable window — 12 to 24 months is common — while payment records you legally need for tax stay as long as tax law requires.

Can I record online lessons under GDPR?

Yes, with explicit consent before you record, a stated retention window of 30–90 days, and actual deletion afterwards. A student can refuse, and if they do, you do not record.

Do I need to register with a data protection authority?

Usually not as a solo tutor below a modest scale, but thresholds vary by country. UK tutors should check the data protection fee rules at ico.org.uk — some sole traders are exempt where they only process data for accounts and records.