Insights7 min read

Why Your School's Data Isn't Safe in Spreadsheets

Your school's records in Excel are one crashed laptop or lost USB from disaster. The real risks of spreadsheets, and what safe cloud storage looks like.

By Niraj Kumar Jha ·

Why Your School's Data Isn't Safe in Spreadsheets

Key takeaways

  • A spreadsheet on one laptop is not a backup - one crash, surge, or lost USB can erase a year of records with no recovery.
  • Spreadsheets have no roles and no audit trail, so anyone can silently break data and no one can prove who changed what or when.
  • When the file and the knowledge of it live with one staff member, their departure puts your records in question.
  • Safe storage means encrypted, auto-backed-up cloud records with role-based access and a full edit history - not being more careful with Excel.

Somewhere in your school, right now, there is a laptop. On it sits a folder, and in that folder is the file - the one with every student's name, guardian phone number, fee balance, and exam mark for the year. Maybe there is a copy on a USB stick in a drawer. Maybe last month's version is attached to an email. That single spreadsheet, and the two or three people who know their way around it, is your entire school's memory. And it is one crashed laptop, one wrong formula, one lost USB, or one departing staff member away from being gone. Not corrupted, not delayed - gone, with no way to get it back.

Schools trust spreadsheets because they feel solid. You can see the file. You saved it. It opens when you double-click it. But the safety is an illusion, because a spreadsheet was never built to be a school's system of record. It was built for one person to do sums on one computer. Everything you have layered on top of that - hundreds of students, years of history, multiple people editing, real money attached - is weight it was never designed to carry. This post is about the specific ways that weight breaks it, and what safe storage actually looks like.


One File, One Machine, No Backup

Start with the most basic risk, because it is the one that ends schools' worst days.

A spreadsheet on a laptop is not backed up by existing. If that laptop is stolen from the office, dropped on the stairs, fried by a power surge during load-shedding, or simply dies of old age, the file dies with it. The USB copy in the drawer is from whenever someone last remembered to make it - which is to say, out of date, and just as losable as the laptop.

People assume "it's on the computer" means "it's safe." It means the opposite. A single copy in a single place is the textbook definition of no backup. And the failure is total: you do not lose this month's data, you lose the year. Rebuilding a fee ledger or an attendance history from paper receipts and memory, if it is even possible, costs weeks and is never fully accurate.

This fragility is one of the biggest hidden liabilities of manual administration, which we cover more broadly in the hidden costs of running a school on paper and Excel.


Everyone Who Can Open It Can Break It

The second risk is that a spreadsheet has no idea who you are.

Whoever can open the file can change anything in it. There are no roles, no permissions, no "the receptionist can update contact numbers but cannot touch fee balances." One shared file passed between the office computer, the accountant's laptop, and a teacher's home machine means every one of those people has full power over every cell.

And spreadsheets break in ways that hide themselves:

  • A sort applied to the visible columns but not the rest, silently scrambling which mark belongs to which student.
  • A row deleted to "clean up" that a formula three sheets away depended on.
  • A formula overwritten with a typed-in number, so the totals stop updating and no one notices for a month.
  • A find-and-replace that reached further than intended.

None of these throws an error. The file still opens, still looks fine, still gives you numbers. They are just the wrong numbers, and by the time you notice, you cannot tell when it happened or which version was correct.


No Audit Trail Means No Truth

This is the risk that turns a small problem into an unwinnable argument.

The question a spreadsheet can never answer is "who changed this, and when?" When a parent insists they paid, or a mark is disputed, or a balance looks wrong, the honest answer from a shared spreadsheet is "we cannot know." There is no history of edits, no record of who touched what. Whoever saved the file last quietly overwrote everyone before them - and took the evidence with them.

A school's records exist precisely to settle disputes: this student paid, this mark was awarded, this parent was informed. A system with no audit trail cannot do that job. It can only offer the current state of the file, which is whatever the last person to save it decided it should be. That is not a record. It is a rumour that opens in Excel.


The Staff Member Who Leaves With the Keys

Because access and knowledge both concentrate in whoever "runs" the spreadsheet, that person walking out is a data risk, not just a staffing one.

They know where the files live, which version is current, what the colour-coding means, and how the formulas hang together. When they leave - especially if they leave unhappily - that knowledge goes with them, and sometimes so do the files, sitting in a personal email account or a home laptop or a USB nobody else has. The school is left holding a spreadsheet it half understands and cannot fully trust, wondering whether the copy it has is even the latest one.

You should never be in a position where one resignation puts your student records in question. But a spreadsheet system almost guarantees it, because the file and the person who understands it are inseparable.


What Safe Storage Actually Looks Like

The good news is that none of this is hard to solve - it just cannot be solved by being more careful with spreadsheets. It is solved by storing records in a system built for the job. In practice, safe school data has four properties:

  • Backed up automatically, off your premises. The data lives in the cloud and is copied continuously, so a dead laptop, a power surge, or a lost USB is an inconvenience, not a catastrophe. There is no "did someone make a backup?" because the system always did.
  • Access controlled by role. People see and change only what their job requires. The receptionist updates contacts, the accountant handles fees, a teacher enters marks for their own classes - and nobody can quietly break a part of the system they should not touch.
  • A full audit trail. Every change is recorded with who made it and when. Disputes become a lookup instead of an argument, and mistakes can be traced and undone.
  • Encrypted, so a breach is not a disaster. Student and guardian data is sensitive. Stored properly, it is encrypted at rest, so even a compromised device does not hand over readable records.

For a country like Nepal, where power and connectivity are not always steady, "cloud" raises a fair question about what happens when the internet is down. That trade-off is real and worth understanding properly, which we cover in cloud vs offline school software for Nepal. The short version: a well-built cloud system syncs when connectivity returns, and even an imperfect connection is far safer than a single file on a single machine. There is also a duty-of-care dimension to holding children's data, which we go into in student data privacy and security for Nepal schools.


The Move Is Smaller Than the Risk

Schools stay on spreadsheets partly out of habit and partly out of fear that moving off them will be painful. It is worth being honest that the fear is usually bigger than the task. Importing an existing student list, fee structure, and history into a proper system is a well-worn path, and it is a one-time effort - we walk through it in how to migrate from Excel to school software.

Weigh that one-time effort against what you are risking every single day the records stay in a spreadsheet: total loss from one dead laptop, silent corruption no one can trace, disputes you cannot settle, and a single resignation that puts your data in doubt. The spreadsheet feels safe because it is familiar. Familiar and safe are not the same thing.


Gurukul stores your school's records in an encrypted, automatically backed-up cloud system with role-based access and a full audit trail - so a lost laptop, a wrong formula, or a departing staff member is never a disaster. See the platform or book a free demo.

Frequently asked questions

A spreadsheet was built for one person to do sums on one machine, not to be a school's system of record. A single file on a single laptop has no automatic backup, no access control, and no audit trail, so it can be lost, silently corrupted, or edited by anyone who opens it.

If records live only in a spreadsheet on that machine, they are gone - not delayed, gone. A USB copy is only as recent as the last time someone remembered to make it and is just as easy to lose. There is no way to fully rebuild a year of fee and attendance history from memory.

Records stored in a system built for the job: backed up automatically off-site in the cloud, access controlled by role so people only touch what their job needs, a full audit trail of who changed what and when, and encryption so a lost device does not expose readable data.

Gurukul

Run your school without the spreadsheets.

Attendance, fees, exams, reports - one platform built for Nepal. Book a free 30-minute demo and see it on your school's data.

Written by

Niraj Kumar Jha

Niraj Kumar Jha

Founder, Gurukul

Building Gurukul - the school management platform built for the real world. Spent years watching Nepal's schools run on Excel and WhatsApp, then decided to do something about it. Full-stack engineer working across database architecture, AI integration, and frontend delivery, and he writes these guides from what schools actually deal with day to day.

Last updated August 4, 2026