Pupil data is not used to train general-purpose AI models. The school or ministry remains the data controller and retains ownership, with full export available at any time including at termination.
The legal framework
| Instrument | What it does |
|---|---|
| Nigeria Data Protection Act 2023 | Principal data protection legislation, establishing the Nigeria Data Protection Commission and setting obligations for controllers and processors |
| NDPR 2019 | The earlier Nigeria Data Protection Regulation, which established the initial framework |
| Sector guidance | Guidance and directives issued by the Commission, which continue to develop |
| Child data | Heightened obligations around personal data of children, which is nearly the entire dataset in a school |
A great many Nigerian school vendors still reference only the NDPR. That is a reasonable signal about how closely they have followed the position.
Who is responsible for what
This is the part schools most often misunderstand, and it matters.
- The school is the data controller. It decides what pupil data is collected and why. That responsibility does not move to a software vendor.
- Edves is a data processor, acting on the school’s documented instructions.
- Obligations to parents and pupils — notice, lawful basis, access requests, correction — remain the school’s.
A vendor saying “we are compliant, so you are covered” has told you they do not understand the allocation, or is hoping you do not.
How Edves handles pupil data
- Role-scoped access down to the field. A class teacher sees their own pupils. A bursar sees fee data, not medical records. A subject teacher does not see another arm’s behaviour notes. Access follows role, not seniority.
- Audit logging. Every access to a pupil record is logged with user, time and record. This is what turns an access policy into something enforceable, and it is the control most Nigerian school systems entirely lack.
- Configurable retention set to the school’s policy and applicable record-keeping requirements, not a vendor default.
- Data minimisation — the school decides what is collected, and fields it does not need are not forced on it.
- Parent access through the parent app, which is also the practical mechanism for meeting access obligations without a manual process.
AI and pupil data — the specific commitments
Stated plainly, because this is where a school should press any AI vendor hardest:
- Pupil data is not used to train general-purpose AI models.
- Pupil data is not sold, and not used for advertising or profiling.
- Data used to personalise teaching stays within the school’s tenant.
- Sub-processors are disclosed, with processing locations identified.
- Contractual terms confirming the above are provided during procurement, not referenced on a marketing page.
Ask for the contract clause, not the claim. A vendor unwilling to put a training-data restriction in writing has answered the question.
The bigger practical risk
In most Nigerian schools the realistic data protection failure is not the procured system. It is:
- Pupil records held in a WhatsApp group with former staff still in it.
- Score sheets and biodata on personal laptops and phones that leave with the teacher.
- A staff member pasting pupil names and results into a consumer AI tool.
- Photographs of pupils published without any record of parental consent.
- A departed bursar retaining the only complete fee record.
A school system helps with all of these — access ends when employment ends, records stay in the system rather than on devices, and a sanctioned AI tool removes the reason to use an unsanctioned one. But policy has to arrive alongside the software.
Photographs and publicity
Schools routinely publish pupil photographs for marketing without a defensible consent record. Consent status is held against the pupil record and respected across every output, so a pupil whose parents have not consented does not appear in a school’s publicity by accident.
Data ownership and exit
| Question | Position |
|---|---|
| Who owns the data? | The school or ministry, stated in contract |
| Can we export everything? | Yes, including full academic and financial history, in a usable format, at any time |
| What does export cost? | Nothing, including at termination |
| What happens at termination? | Export delivered, then deletion on the school’s instruction and schedule |
| Is data withheld to force renewal? | No. Access to your data is not contingent on renewal |
That last row deserves particular attention during procurement. It is the only leverage a school retains after signature, and it is where locally sold school software has the worst record.
Questions to ask every vendor
- Are you a controller or a processor in this arrangement? If they say controller, stop.
- Show me your clause on AI model training.
- Where is our data hosted, and who are your sub-processors?
- Who at your company can see our pupil data, and is that logged?
- What does full export cost at termination, and in what format?
- What is your breach notification commitment to us?
Note that the NDPA framework and Commission guidance continue to develop. Confirm current obligations with the Nigeria Data Protection Commission or your own legal adviser; this page describes Edves’s posture and is not legal advice.