GDPR for dance schools: a plain-English checklist
Most dance schools hold more personal data than they realise: names and ages of children, medical notes, emergency contacts, photos and payment history. GDPR is not about paperwork for its own sake — it is about knowing what you hold, why you hold it, and being able to show it.
Know what data you hold
Start with a simple list. For each item, write down where it lives, who can see it and how long you keep it. If the answer is "in a WhatsApp group" or "on my personal phone", that is the first thing to fix.
- Dancer names, dates of birth and class allocations
- Parent and emergency contact details
- Medical conditions, allergies and access needs
- Photo and video permissions
- Payments, invoices and outstanding balances
Get consent right — and separately
Consent for photos is not the same as consent for marketing, and neither is required to run a class. Keep them as separate opt-ins so a parent can say yes to one and no to another, and record the date each choice was made.
Consent must be as easy to withdraw as it was to give. A parent portal where a family can flip a switch themselves is far safer than an email thread you have to remember to action.
Treat medical data as special category data
Health information carries extra obligations. Restrict it to the staff who genuinely need it — usually the teacher on the register and your safeguarding lead — rather than every helper with a login.
Set retention periods and stick to them
You do not need to keep a leaver's medical notes for a decade. Financial records typically need six years for HMRC; most operational data can go much sooner. Write the periods down and diarise a yearly clear-out.
Be ready for a parent request
A parent can ask for a copy of everything you hold about their child, and you have one month to respond. If your data is spread across spreadsheets, inboxes and chat groups, that request becomes a weekend of work. If it is in one system, it is an export.
Where My Dance School helps
- Consents captured per family with timestamps and self-service withdrawal
- Medical and access notes visible only to permitted staff roles
- Data held on European servers with role-based access controls
- One place to export a family's record if you receive a request

