The records you hold are about children. Parents consented, teachers use them, a dozen third-party platforms process them, and they stay on file for years after the student leaves. Nobody in that chain consented to each step directly, which is why the paperwork matters. It is the consent chain, written down.
Your setup is probably familiar. A Microsoft 365 tenant, a student information system, a learning management system, and a filter and backup somewhere. School-owned laptops next to family-owned ones. A few dozen specialist platforms picked up over the years. The platforms are rarely the problem. Nobody has ever looked at the whole thing at once and made it fit together.
We run that audit during onboarding and sequence the clean-up around your calendar. Some things cannot move during reports, and some cannot move during exams. You get a register of who holds what, who can reach it, and how you would prove it in a Child Safe audit.