Before You Upload a Passport: Student Data Questions for Any Education Agent CRM
When a CRM you chose leaks a student's passport scan, the regulator writes to you. Six questions to send any vendor first, and our own answers.
If you run a boutique agency with 1–15 counsellors, the honest starting point is this: when a CRM you chose leaks a student's passport scan, the regulator writes to you, not to the vendor. Under Article 33(1) of the GDPR the controller has to notify the supervisory authority “without undue delay and, where feasible, not later than 72 hours” after becoming aware of a breach. Your vendor's duty is different and softer — Article 33(2) only requires the processor to tell the controller “without undue delay.” So the six questions below are not vendor trivia. They are the questions that decide how fast you can meet a deadline that lands on your desk.
What does your agency actually hold on one student?
Count the files for a single UK application and the number is uncomfortable. A passport bio page. A birth certificate or national ID. Academic transcripts and an English test report. A bank statement or sponsor letter for the maintenance funds requirement. A personal statement that often names family circumstances. A CAS statement carrying the student's sponsor reference. That is seven document types before the visa application itself, and every one of them sits in whatever tool you picked in week one of the agency.
Most boutique agencies did not pick a tool. They accumulated one: WhatsApp for the scans, a shared Google Drive folder for the ones that mattered, a spreadsheet for the deadlines. We wrote about where that stops working in study abroad CRM vs spreadsheets. The data-protection version of the same problem is narrower and sharper: in a WhatsApp thread you cannot answer “who has seen this passport, and can I delete it everywhere in one action?”
Who is responsible if the CRM leaks it — you or the vendor?
Both, but not equally, and the split is the thing most agency owners get backwards. For your own recruitment activity you decide why and how the student's data is processed, which makes you the controller. The CRM processes it on your instructions, which makes it a processor.
Article 28(1) says the controller “shall use only processors providing sufficient guarantees.” Article 28(3) says the processing must be governed by a written contract that sets out the subject matter and duration, the nature and purpose of the processing, the type of personal data, the categories of data subjects, and your obligations and rights. The full official text of the Regulation is on EUR-Lex.
Read that as an operational rule rather than a legal one. “Sufficient guarantees” is a judgement you are making every time you upload a file, and a written contract you have never seen is not a guarantee. If a vendor cannot send you a data processing agreement within a day, you do not have one.
What should you ask a CRM vendor before you upload anything?
Six questions. Send them as an email, not as a call — you want the answers in writing. The third column is the part that usually gets skipped: each question maps to something that becomes your problem, on your timeline, in a bad week.
| Ask this | A straight answer looks like | Why it lands on you |
|---|---|---|
| Which country hosts the database and the uploaded files? | A named provider and a named region, not “the cloud” or “globally distributed.” | Transfers outside the UK or EEA need their own safeguards. You have to describe them in your own privacy notice. |
| Who are your sub-processors, and where does each one sit? | A published list with purposes and regions, plus a notice period before it changes. | Every sub-processor is a company your student never agreed to. You are the one who agreed for them. |
| How fast will you tell me about a breach? | A number of hours in the contract, not “promptly.” | Your 72-hour clock starts when you become aware. A vendor who takes a week has spent your whole budget. |
| Can I delete one student completely, and how long do backups keep them? | A stated retention window for backups and snapshots, with a date. | An erasure request has a deadline. “It is gone from the app” is not the same as gone. |
| Can a counsellor see students they were never assigned? | Role separation enforced on the server, not hidden in the interface. | Your largest realistic incident is an internal one, and a leaving counsellor is the classic case. |
| Send me your data processing agreement. | A link or an attachment, same day, no sales call attached. | Article 28(3) needs it in writing. No contract means the vendor is not lawfully your processor. |
Two answers should end the conversation. “We are fully GDPR compliant” with nothing after it is a slogan, not a fact, and no regulator issues that badge. And any answer that describes a certification the vendor does not hold — SOC 2 and ISO 27001 both have auditors and report numbers — is worth checking before anything else they said.
What do our own answers look like?
We publish ours so this article is not a set of questions we would fail. Enrollo's database and uploaded files sit in a Supabase-managed PostgreSQL instance in AWS EU (eu-west-1). Authentication identities are handled by Clerk. Data in transit uses TLS 1.2 or higher, and the platform providers encrypt data at rest with AES-256. Every database query is scoped by organisation in application middleware, and owner-versus-counsellor separation is enforced server-side. Applications moved to the trash are recoverable for 30 days before permanent deletion; point-in-time recovery covers the last 7 days and daily snapshots are retained for 30 days. The details, including full account deletion on request, are on our security page.
Our sub-processor list names eight companies with a purpose and a region for each, and we give at least 30 days' written notice before adding or replacing one. Three of those eight touch United States regions: Clerk runs in AWS US or EU, and Sentry and Resend are US. That is a real answer to question two, and it is not the flattering version.
Two more honest concessions. We hold no SOC 2 or ISO 27001 certification, so if your university partners require one on paper, we do not clear that bar today. And EU hosting is the default rather than a choice — a dedicated instance in another region is an enterprise arrangement, not something you can select yourself at $23 a month.
When is a spreadsheet actually safer?
Sometimes it is, and pretending otherwise would fail the first question in this article. A solo consultant with 12 active students, one laptop, full-disk encryption and a locked filing cabinet has a small and well-understood attack surface. Adding a CRM adds a vendor, a browser session, and a chain of sub-processors.
The line moves when a second person joins. At that point the spreadsheet is being emailed, the scans are in three inboxes, and nobody can say which copy is current. Access control is the thing a shared file cannot do and a CRM can: one student record, one set of permissions, one deletion. That is the same argument we make about deadlines in student deadline tracking and about tool selection in our education agent CRM features checklist — a second pair of hands is what breaks the manual version.
What to do this week
Copy the six questions into an email and send them to whichever CRM you are currently evaluating, including us. Set yourself one rule before you read the replies: any question answered with an adjective instead of a name, a number or a date counts as unanswered. If you want to see our answers inside the product rather than on a policy page, start the 14-day trial — no card, and every student record you create is deletable in one action.
Written by the person building enrollo. I run these same questions past our own stack, which is why the sub-processor list above includes the parts that are inconvenient to publish.
Written by
Enrollo
Team
Related Articles

EduAgent CRM Alternative for Boutique Education Agents
EduAgent CRM sells the front of the pipeline: enquiry capture, a branded student portal, invoices and appointments. enrollo sells the back of it: offer deadlines and the commission you chase after enrolment. Published prices, honest concessions, and a five-step test you can run in either trial.

SmartAgentic Alternative for Boutique Education Agents
SmartAgentic publishes ₹399 per user per month. enrollo bills flat for 1, 5 or 15 seats. The arithmetic for a boutique agency, with sources.

KONDESK Alternative for Boutique Education Agents
KONDESK sells per user and covers edu-immigration broadly. Enrollo sells a flat tier and covers study-abroad placement narrowly. Published pricing, honest concessions, and who each one fits.
Ready to streamline your agency?
Track students, automate commissions, and never miss a deadline. Everything your study abroad agency needs in one place.
No credit card required