Data protection guide
How should a school protect student, family and staff data?
Practical principles for limiting access, isolating institutions, protecting accounts and separating production from testing.
- Written by
- Raqeem content team
- Product review
- Raqeem product team
Direct answer
Protection is not established by the word secure. It starts with institution isolation, least-privilege access, showing sensitive fields only when needed, reviewing accounts when responsibilities change and using fictional data for testing and demonstrations.
Guide method and boundaries
This guide reflects capabilities reviewed in Raqeem at the stated revision date. It separates available functionality from planned work and does not claim external certification, integration or synchronisation without published evidence.
Limit access to the real need
Teachers do not need all financial data, and parents see only their linked children.
Restrictions should protect the operation and data, not merely hide an interface element.
Protect accounts and files
Passwords and verification codes are not shared, and access is removed when staff responsibilities change or employment ends.
Attachments follow the same institution and role boundaries as other data.
Separate production and testing
Demos and tests use clearly fictional data rather than real school records.
A suspected incident should be documented, reviewed and handled according to impact.
Protection checklist
- Least privilege for every role.
- Institution-isolated data.
- Account review when staff change.
- Restricted files and sensitive fields.
- Fictional data in testing.
Related questions
Does every school employee see the same data?
No. Access depends on role, capability, scope and genuine need.
Can real data be used in a demo?
The standard approach is test data that does not expose a real school or person.
More guides on governance and security
Guides on institutional data isolation, permissions, information protection and timetable conflicts.
How does Raqeem isolate each school’s data?
A clear explanation of institution separation, permissions and the rule against transferring one school’s methods to another.
Who can do what? Roles, permissions and sensitive actions
Understand role, capability and data scope, then control viewing, creation, editing, deletion, review and approval.
How should a school build a timetable and review conflicts before publishing?
A journey from setup and draft to teacher, class and room conflict checks, then review and publication.
