Article · June 17, 2026
PDPL: What tutoring and test prep centers must do with student data
Guide for tutoring/test prep centers on student, parent data and admissions marketing under PDPL, with practical examples.
Quick answer
What is PDPL student data at tutoring and test prep centers?
This covers all personal data the center creates or receives during admissions, class management, student care, and marketing activities. For a tutoring, test prep, or vocational training model, this dataset typically includes: full name, date of birth, phone number, class, mock test scores, class schedule, classroom photos, lecture videos, parent information, and sometimes sensitive data such as health conditions or special learning needs.
Note that if students are children, the data protection obligations are generally higher. Centers should not treat admissions data as “simple administrative data,” because using it for promotional messages, posting student photos, sharing with part-time instructors, or passing it to a CRM platform already triggers compliance requirements.
What consents must the center obtain when collecting student data?
You should separate each processing purpose rather than lumping everything into a single “agree to let the center use data.” For example, parents may agree to:
- class registration;
- tuition consultation contacts;
- receiving class schedule notifications;
- using photos/videos for communications;
- receiving marketing messages for upcoming courses.
Each purpose should have its own status to simplify proof. For children’s data, check the consent process of parents or guardians as required. If the center uses online forms, retain consent evidence: timestamp, policy version, IP, source of submission, and the content of the checkboxes displayed.
List data sources:
Identify whether data comes from registration forms, Zalo, hotline, Facebook lead forms, classroom cameras, or teacher manual entries.
Split by purpose:
Separate admissions, student management, class care, communications, and record retention.
Attach legal bases:
For each purpose, specify whether it requires consent, is necessary to perform a contract, or serves a statutory obligation.
Design forms correctly:
Registration forms should include separate checkboxes for marketing, photos/videos, and a parent confirmation if the student is a child.
Keep evidence:
Store consent logs, edit history, who accessed the data, and when data is deleted.
Standardize deletion/correction requests:
Create a process to receive requests from parents or students, with a clear internal response timeline.
Can tutoring and test prep centers use class photos and videos for marketing?
They can, but should not assume they are permitted by default. Class photos and videos are personal data if students can be identified; with children, a higher level of caution is needed. The center should clearly inform about the purpose of using images, where they will be posted, retention periods, and when consent can be withdrawn.
Practical example: the center records a “top 10 high-scoring students” video for TikTok. If the video includes a student’s face, name, class, or voice, you should obtain separate consent for communications. If you only need general classroom scenes, consider camera angles that avoid unnecessary identification.
What should the center watch out for in admissions marketing?
Admissions marketing is a high-risk area because data often comes from multiple sources: parents filling out forms, leaving phone numbers at seminars, messaging the fanpage, or staff entering data into a CRM. Under the regulations, the center must be transparent about the source of collection, the purposes of use, and how to opt out of marketing messages.
If running ads via third-party platforms, check the data processing terms with the provider. When using tracking tools, pixels, chatbots, or lead forms, do not rush to label them “legal” or “illegal”; the key is that such tools trigger obligations around notices, third-party control, purpose limitation, and keeping consent evidence.
| Activity | Data commonly generated | What to do | |
|---|---|---|---|
| Class registration | Full name, phone number, date of birth, parents | Inform purposes, keep consent evidence | |
| Class management | Attendance, learning outcomes, class schedule | Restrict access, implement internal role-based permissions | |
| Run admissions ads | Phone numbers, email, lead source | Record collection source, allow marketing opt-out | |
| Post photos/videos | Images, voice, name | Obtain separate consent for communications | |
| Online teaching | Accounts, learning logs, recordings | Notify in advance, configure secure storage |
What should the center do if student data is leaked?
If a data leak is detected, the center must activate its incident response process immediately and file a data breach notice within 72 hours of discovery as required. The response should include: isolating systems, resetting passwords, revoking access rights, checking logs, determining the scope of impact, and assessing whether parents/students need to be notified.
For small centers, common risks come from Excel files sent to the wrong Zalo contact, publicly shared drives, or departing staff retaining CRM access. A simple, ready-to-use response process is more important than a beautifully written policy that no one follows.
Minimum templates to have for tutoring and test prep centers
You should prepare at least five internal documents:
- Personal data protection policy;
- Consent form for parents/students;
- Process for responding to data correction/deletion requests;
- Process for managing photos/videos and communications;
- Access logs and data sharing records for teachers, collaborators, and vendors.
If the center uses a website or admissions landing page, consent.vn can help you implement a cookie banner, store consent evidence, and manage DSAR more efficiently, especially when multiple admissions channels run in parallel.
- Yes, when the student is a child or when the data requires consent under the regulations. It’s best to separate the parent’s consent for admissions, contact, and marketing.
- Only when you’ve clearly informed about the marketing purpose and provided an opt-out. Keep consent evidence to demonstrate compliance if needed.
- Usually you should obtain separate consent, especially if the photos/videos identify the student or involve children. Don’t bundle this with the class registration form.
- Contain the risk immediately, revoke access rights, determine the scope of impact, and prepare a data breach notice within 72 hours of discovery as required.
Conclusion for tutoring and test prep centers
For non-public education models, PDPL is not just a “legal” matter, but a way to manage student data, protect children, and avoid risks from admissions marketing. Doing things right—from registration forms and internal permissions to keeping consent evidence—will prevent many operational errors later.
Source: the Personal Data Protection Law (Law 91/2025/QH15) and Decree 13/2023/ND-CP on thuvienphapluat.vn; enforcement authority: the Ministry of Public Security (A05) at bocongan.gov.vn.
Get started — set up in 5 minutes.
Deploy PDPL solutions for your business?