Skooly
Blog · Compliance

PDPA Basics for Tuition Centre Owners: A Practical Guide

Your centre holds more personal data than most small businesses — children's names, parents' phone numbers, payment details, sometimes health notes. Singapore's PDPA applies to all of it. Here's what that means in practice, without the legalese.

Disclaimer: this article is general information, not legal advice. PDPA obligations depend on your specific circumstances. For authoritative guidance, consult the Personal Data Protection Commission’s website (pdpc.gov.sg) or a qualified professional.

Most tuition centre owners didn’t open a centre to think about data protection law. But the Personal Data Protection Act applies to every organisation in Singapore that collects, uses or discloses personal data — and a tuition centre does all three, every single day, mostly about children. The good news: for a business your size, compliance is less about lawyers and more about a handful of habits. This guide covers the essentials.

What personal data does a tuition centre actually hold?

More than you’d list off the top of your head. A typical centre holds:

  • Student data: names, dates of birth, school names, levels, photos, attendance history, assessment results, and sometimes health or special-needs notes.
  • Parent data: names, phone numbers, email and home addresses, and the parent-child relationship itself.
  • Payment data: bank transfer references, payment histories, outstanding balances, and whatever payment details your collection method involves.
  • Staff data: tutors’ NRIC details, bank accounts, and employment records.

Under the PDPA, personal data is anything that can identify an individual, on its own or combined with other information you have. A class register qualifies. So does a WhatsApp group member list. And note the point that surprises many owners: much of your data is about minors, which is a good reason to hold yourself to a higher standard of care even where the Act doesn’t spell one out.

Consent, in plain terms

The PDPA’s starting position is simple: collect, use and disclose personal data only with consent, and only for purposes a reasonable person would consider appropriate — purposes you’ve actually told people about.

For a tuition centre, that translates to three habits:

Say what you collect and why, at enrolment. A short paragraph in your enrolment form covering what data you collect and what you use it for (scheduling, attendance, billing, progress updates, emergency contact) goes a long way. Consent for young students generally comes from a parent or guardian.

Treat new uses as new questions. Consent for administering classes is not consent for everything. Marketing messages and promotional photos are separate purposes — ask separately, and make the photo question an explicit yes/no rather than a buried clause. Remember too that Singapore’s Do Not Call provisions restrict marketing messages and calls to numbers registered on the DNC Registry.

Make withdrawal easy. Parents can withdraw consent, ask what data you hold about them, and ask for corrections. You need a way to actually do those things — which is hard if the data lives in six places.

Where tuition centres commonly slip up

These patterns come up again and again in small education businesses. None of them involve bad intent.

The class WhatsApp group. Add twenty parents to one group and you’ve disclosed every parent’s phone number (and often full name and photo) to nineteen strangers — without asking anyone. It’s the single most common data exposure in the industry, and it’s usually done as a favour.

Photos shared without consent. A cute class moment posted to the centre’s social media feels harmless. But photos of identifiable children are personal data, and posting them publicly is disclosure. If you didn’t get an explicit yes from the parents, don’t post.

Spreadsheets on personal laptops. The master student list on a tutor’s own laptop, emailed back and forth, copied to a USB stick before the holidays. Every copy is a copy you can’t protect, can’t update and can’t delete. When that laptop is lost or a tutor leaves, so does your control over the data.

Keeping everything forever. The PDPA expects you to stop retaining personal data once it’s no longer needed for the purpose it was collected. Records of students who left in 2019 shouldn’t still be sitting in an open shared drive.

A simple PDPA checklist for your centre

Work through this in an afternoon. It won’t make you a lawyer, but it will put you ahead of most centres.

  1. Appoint a Data Protection Officer. Every organisation must designate someone responsible for data protection — in a small centre, that’s usually the owner. Publish a contact for data questions.
  2. List your data. Write down what personal data you hold, where it lives (forms, spreadsheets, phones, apps), and who can access each store.
  3. Fix your enrolment form. Add a clear collection-and-use statement, plus a separate, explicit opt-in for photos and one for marketing.
  4. Close the WhatsApp exposure. Move class-wide communication to a channel that doesn’t reveal every parent’s number to every other parent.
  5. Get data off personal devices. One system of record, access per role, no master spreadsheet copies.
  6. Set a retention rule. Decide how long you keep ex-student records, and actually delete on schedule.
  7. Prepare for the bad day. Know that Singapore has data breach notification requirements, and decide now who assesses and reports an incident. The PDPC website has guidance on when notification is required.
  8. Brief your tutors. Most exposures are staff habits. A 20-minute walkthrough of the rules above covers most of the risk.

How software takes most of this off your plate

Notice that checklist items 2, 4, 5 and 6 are really one problem: student data scattered across spreadsheets, phones and inboxes. Centralising it is the fix, and it’s what a school management platform is for.

With Skooly, student, parent, attendance and billing records live in one system instead of on personal laptops — one place to secure, one place to correct, one place to answer “what do you hold about my child?” from. Announcements and updates reach parents through the Skooly One parent app, so class-wide communication doesn’t mean exposing every parent’s phone number to the whole group. And data is encrypted at rest and in transit, which is a stronger baseline than any spreadsheet-and-USB workflow can offer.

Skooly runs on this model for more than 4,950 schools and 19,950 teachers across 10+ countries. If you’re weighing a move off spreadsheets, our guide to tuition centre management software in Singapore covers what to look for, and plans are on the pricing page.

Frequently asked questions

Yes. The PDPA applies to organisations regardless of size, including sole proprietors. A two-classroom centre has the same core obligations as a chain — the difference is only in how much data you handle.

For photos of identifiable children used beyond your stated purposes — especially publicly, like social media — you should have explicit consent from a parent or guardian. Make it a clear opt-in on your enrolment form rather than assuming.

It can be. Adding parents to a shared group discloses their phone numbers to every other member, usually without consent. Safer options are broadcast-style channels or a parent app where members can't see each other's contact details.

Every organisation must designate one, and in a small centre it's typically the owner or centre manager. The DPO's job is practical: know what data you hold, field data questions from parents, and lead the response if something goes wrong.

The PDPA expects you to stop retaining personal data once it no longer serves the purpose it was collected for or a legal/business need. Set a written retention period for ex-student records and delete on schedule — the PDPC website has guidance to help you decide what's reasonable.

Want your student data in one secure place instead of six?

Start your free 14-day pilot — we set Skooly up for you, with your real students and classes, so you can see checklist items 2 through 6 solved before you pay anything.