Guide

    GDPR for madrasahs: a plain-English guide

    What UK GDPR actually requires from a madrasah — without the legal jargon.

    If your madrasah holds any personal data on children — names, ages, contact details, attendance, progress — UK GDPR applies. The good news: compliance for a small maktab is mostly common sense.

    1. Register with the ICO

    If you collect personal data and aren't purely volunteer-run with no fees, you almost certainly need to register with the Information Commissioner's Office (ICO). It costs around $51/year and takes 10 minutes online.

    2. Pick a lawful basis

    For most madrasahs the lawful basis is contract (you're providing a paid service to the parent) or legitimate interests. Religious belief is special-category data and needs explicit consent — which signing up for an Islamic school usually implies.

    3. Write a privacy notice

    Tell parents what data you collect, why, who you share it with, and how long you keep it. Put it on your website and link it from your enrolment form.

    4. Pick GDPR-safe software

    • Data should be stored in the UK or EU — not the US.
    • The provider should have a Data Processing Agreement (DPA) you can sign.
    • The provider should be ICO-registered themselves.
    • If the platform has AI features, check what's actually sent to which AI provider, that it isn't used to train anyone's models, and that children can't access it directly.

    5. Have a breach plan

    If something goes wrong (a list of student emails leaked, for example), you have 72 hours to report high-risk breaches to the ICO. Keep a one-page breach process so you're not improvising.

    Labbaik is UK GDPR compliant, ICO-registered (ZC136003), with EU-region data — see the security page for the full breakdown, or our AI features disclosure for exactly what's sent to Anthropic and OpenAI.