Data Management Policy

An official document regulating the collection, storage, and maintenance of students' personal and academic data. It defines security standards, access permissions, and cloud backup mechanisms to protect information and prevent digital breaches.

1. Introduction and Policy Objective

This policy defines the regulatory framework that International Generation School adheres to in collecting, storing, managing, and restricting access to personal data, to safeguard the privacy of students, their parents, and staff, and in compliance with applicable regulations and legislation. This policy applies to all parties who handle the school's data, including employees, teachers, and external contractors.

2. Student Data Retention

First: Types of Data Retained

a. Personal Data
Parent/Guardian data and contact information.
All personal student data provided by the student during school registration.
b. Academic Data
Registered subjects and study plans
Grades, reports, attendance, and absence records
c. Activity Data on the Learning Management System (LMS) platform.
Login records and daily activity
Submitted assignments, tests, and evaluation results
Audio and video recordings of classes

Second: Data Retention Period

Data Type

Retention Period

Action Upon Expiry

Active Student Data

Throughout the registration period

Review upon registration expiry

Graduated Student Data

7 years

Secure deletion or archiving

Login Records

1 year

Secure deletion or archiving

Audio/Video Recordings

1 year

Archiving

Third: Storage Location and Data Security

All academic data is stored on cloud storage approved by the administration.
It is prohibited to store student data on personal devices or unauthorized applications.
All sensitive data is encrypted during transit and at rest.

3. Data Access Permissions

First: Access Levels

Level

Party

Scope of Authority

Level One

Senior Management

Full access to all data

Level Two

Administration and Teachers

Data of their registered students only (grades, attendance, assignments)

Level Three

Administration and Students

Their personal data and academic performance only

Level Four

Administration and Parents

Their children's data only via the parent account on the learning platform

Second: Access Rules

Sharing passwords or login credentials between users is prohibited.
Permissions are reviewed and updated at the beginning of each academic semester.
Upon termination of any employee's contract, their permissions are immediately revoked within 48 hours of the service end date.
All access to sensitive data is recorded in the audit log and reviewed periodically.

4. Data Sharing with Third Parties

International Generation School does not share any personal data of students or their parents with external parties except in the following cases:
Official educational bodies or competent government authorities upon legal request.
Service providers bound by contracts ensuring adherence to the same privacy standards.
Medical emergencies requiring disclosure to protect student safety.
In all cases, the school maintains a record documenting each data sharing operation, specifying the recipient, purpose, and timeframe.

5. Backup Policy

Backup is a fundamental pillar to ensure business continuity and data protection.

First: Backup Schedule

Backup Type

Frequency

Responsible Party

Daily Automatic Backup

Daily

IT Admin

Weekly Full Backup

Every Saturday

IT Admin

Monthly Archive Copy

First of every month

Senior Management + IT

Second: Backup Requirements

A backup copy must be stored outside the learning platform (external server or approved local server).
Backup integrity is tested monthly to verify restorability.
Backups must be encrypted with a standard no less than AES-256.

Third: Disaster Recovery Plan

In case of platform failure, data will be restored within a maximum of 24 hours.
All teachers, students, and parents will be immediately notified via email of any service interruption.
Every data-related incident is documented in the official incident log.

6. Data Breach Procedure

In case of suspected data breach or leak, the following procedures apply immediately:

Phase

Action

Timeline

Detection and Containment

Isolate affected system and prevent breach spread

Immediately upon detection

Assessment

Determine scope and nature of affected data

Within 6 hours

Internal Notification

Notify senior management and IT administrator

Within 12 hours

Notify Affected Parties

Inform relevant parents and students

Within 48 hours

Documentation and Review

Submit official report and root cause analysis

Within 7 days

7. Rights of Parents and Students

The school guarantees parents and students the following rights regarding their personal data:
Right to Access: Request to view their stored data at any time.
Right to Rectification: Request correction of any inaccurate or incomplete data.
Right to Erasure: Request deletion of data when its purpose is no longer valid, subject to applicable legal restrictions.
Right to Object: Object to the processing of their data in specific cases.
To exercise any of these rights, a written request must be sent to the school administration and will be processed within a maximum of 15 business days.

8. Compliance and Review

This policy is reviewed at least once annually, or immediately upon any significant change in regulations or legislation.
All affiliates are required to sign an acknowledgment of this policy upon appointment and at each annual review.
Periodic awareness sessions are held for all staff on information security and data protection.