H
Policy Domain

Data Protection & Safeguarding

This domain establishes the Regional Education Data Protection Standard (REDPS), prohibits the sale or commercial exploitation of student data, sets safeguarding requirements for digital learning environments and defines breach and incident response duties.

Why it matters

Caribbean context

Most platforms used in Caribbean schools were built under US or European frameworks that do not reflect Caribbean law. Without REDPS, default vendor settings govern Caribbean student data.

Policy commitments

4 provisions in this domain

Each provision is a binding commitment in the policy. Open a card for the full statement, a plain-language summary and the principles and initiatives it connects to.
  • Full policy statement

    All digital and AI tools used in CMSAT schools must comply with the Regional Education Data Protection Standard, which covers data minimisation, purpose restriction, parental consent, encryption, access controls, breach notification and data residency requirements. REDPS compliance is a condition of endorsement.

    Guiding principles
    Data Sovereignty
    Related roadmap initiatives
What it looks like in practice

A Caribbean scenario

Two-year removal for a clear violation

A vendor is found to have transferred student data for commercial profiling. Endorsement is withdrawn, the vendor is barred from re-application for two years, and Ministries are notified to terminate the deployment.

Who does what

Responsibility matrix

  • Maintain REDPS and coordinate incident response
  • Publish endorsement, suspension and removal decisions
Before you begin

Preconditions for implementation

First 24 months

Where to start

  1. 01Publish REDPS and make compliance a condition of endorsement
  2. 02Stand up regional incident response coordination
  3. 03Issue safeguarding guidance for digital learning environments
Evidence of success

What progress looks like

  • 100% of endorsed tools demonstrate REDPS compliance
  • Breach notifications are received and acted upon within defined timelines
  • No endorsed tool sells, transfers or commercially exploits student data
Common barriers

Likely risks and practical responses

Relying on consent buried in terms of service

MitigationTreat REDPS as the floor regardless of vendor terms; consent language cannot override the prohibition on commercial exploitation.

Related roadmap initiatives

What this domain looks like in the roadmap