Wonde
 
  • Discover apps
  • My apps
  • About
    • Schools
    • Districts
    • Partners
    • Developers

    Our products

    • Edusync
    • MyLogin
    • Data Recovery
    • Wonde Portals

    Our company

    • About
    • Team
    • Reliability
    • Careers
    • Social Impact
    • Partnerships
    • Security

    Help & information

    • Support
    • Resources
    • API documentation
    • Legal & compliance
    • Contact us
  • Support
Teachers pre-register
  • Students
  • Schools
  • Districts
  • Developers
  • Discover apps
  • My apps
  • About
    • Schools
    • Districts
    • Partners
    • Developers

    Our products

    • Edusync
    • MyLogin
    • Data Recovery
    • Wonde Portals

    Our company

    • About
    • Team
    • Reliability
    • Careers
    • Social Impact
    • Partnerships
    • Security

    Helo & information

    • Support
    • Resources
    • API documentation
    • Legal & compliance
    • Contact us
  • Support

  • Log in as...

  • Students
  • Schools
  • Districts
  • Developers
  • Teachers pre-register
  • Resources
  • All Resources
  • Wonde Blog
  • Webinars
  • Walk-through videos
  • Case Studies
Wonde Blog

Spreadsheets shouldn’t be school infrastructure

Share article link

Spreadsheets shouldn’t be school infrastructure | the real cost of the CSV

There’s a file sitting on a USB stick somewhere in your school office right now. It contains the names, dates of birth, and contact details of hundreds of your pupils. It has no password. No encryption. And if someone accidentally opens it in Excel, half the UPNs or phone numbers will already have been mangled by autocorrect.

That file is a CSV. And it’s long overdue for retirement.

Why the CSV made sense, once

To be fair, the CSV earned its place. Your school’s MIS, and the Department for Education’s own data collections – from the census to exam board uploads – have long leaned on CSV exports, and for good reason:

  • Universal compatibility. Every spreadsheet tool – Excel, Google Sheets, LibreOffice – can read and write a CSV. No proprietary lock-in.
  • Tiny file sizes. If your school has limited bandwidth or older infrastructure, a plain text file uploads fast and cheap.
  • Offline-friendly. Your admin team can compile data without an internet connection and upload when they’re back online.
  • A bridge between systems. If you use one platform for registration and another for assessment or safeguarding, you can export a CSV and hand it across without the two systems ever needing to talk directly.

For a sector with a huge range of legacy systems and budgets, that logic is solid. A CSV is a lowest-common-denominator tool – and sometimes that’s exactly what you need.

But “lowest common denominator” has a cost.

Where CSVs are quietly breaking school data | The operation risks of manual MIS data exports

The CSV’s biggest problem isn’t what it does – it’s what it doesn’t do.

🚫 No validation, ever.

A CSV is just text. It has no idea what you’re supposed to be typing. Your admin team can enter a letter into a UPN field, hit save, and the file won’t flinch. The receiving system will, though – and it’ll reject the whole submission.

💥 One rogue comma, total failure.

Bulk uploads to MIS platforms and DfE collections are unforgiving. A single extra comma, a blank column header, or a misplaced space can get your entire file rejected. Not flagged. Not partially accepted. Rejected. That means tracking down the error line by line and starting again.

🔢 Excel actively corrupts your data.

This one stings. Open a CSV in Excel and it will helpfully:

  • Turn long reference numbers into scientific notation (4.5E+11 – useless)
  • Strip the leading zero from phone numbers (07911 123456 becomes 7911123456 – wrong)
  • Mangle dates depending on regional settings, silently swapping day and month

Excel does this on open, before you’ve changed a single thing. By the time you notice, the damage is done.

🔓 Zero security – and UK GDPR says that’s a problem.

CSV files have no encryption, no password protection, and no access control. A USB stick with pupil data left on a train, or an email sent to the wrong address, exposes everything. Under the UK GDPR and the Data Protection Act 2018, that’s not just careless – it’s a liability, and one the ICO takes seriously when it comes to children’s data. Manual exports also tend to leave your school’s data sitting on infrastructure no one’s tracking, which is precisely the gap a UK-based, GDPR-first sync was built to close rather than retrofit.

🗂️ Flat files can’t capture real life.

Your pupils have parents or carers. A history. A progression through year groups over time. A CSV is a two-dimensional grid – it can’t link a pupil’s record to their guardian’s contact details, or track how their attendance has changed across terms. Every connection has to be manually matched. Every term, again.

✏️ No audit trail.

Someone changed a grade. Someone updated a safeguarding note. Who? When? A CSV has no idea. There’s no log, no version history, no accountability. That’s a quiet risk to your data integrity, every single term.

Transitioning to secure, automated MIS integration | What good school data looks like

The issues above aren’t unfixable bugs – they’re fundamental limits of the format. And the fix isn’t a better spreadsheet template. It’s removing the CSV from the process entirely.

That’s what Wonde does.

Wonde automates the data sync between your MIS and the platforms that need that data – no manual exports, no reformatting, no upload failures. A pupil leaves? Covered. A year group changes? Sorted. A new academic year is starting and every record needs refreshing? Done – without your team spending a weekend on spreadsheets.

Because the sync is automated, it’s also more accurate (no human error), more secure (no unsecured files floating around), and faster – which matters most at the moments it’s hardest to find time: the start of a new term.

It’s worth being clear about what “automated” actually means, because not every rostering tool does the full job. Plenty of platforms can pull data out of your MIS to populate a roster – that solves half the problem. But if a teacher logs a safeguarding note or an attendance mark in a third-party app, that information needs to flow back into your central record too, or you’re just trading one disconnected file for another. Wonde’s sync works both ways, so your MIS stays the single source of truth instead of one of several conflicting ones.

That two-way reliability is also why Wonde supports the Department for Education’s own daily attendance data project – handling exactly the kind of sensitive, high-volume sync this article has been talking about, at a national level, every school day.

The CSV had a good run

It was the right tool for a specific moment – limited bandwidth, mixed software environments, and a need for something every school could use regardless of what systems they had.

But that moment has passed. Your school is carrying real administrative burden, real data risk, and real compliance pressure – and you’re carrying it with a file format that was never designed for any of it.

Your school’s data deserves better than a USB stick and “fingers crossed”. And your team’s Monday mornings deserve to start without a spreadsheet rebuild.

Discover how Wonde’s automated MIS data sync can streamline your school’s administration, secure pupil records, and aid compliance with GDPR compliance. 

👉 www.wonde.com/schools/connect/

Related articles

  • Wonde acquires cyber security specialists, Secure Schools

    A partnership at the forefront of the protection and safeguarding of school data. Wonde, a leading school data management specialist, has acquired Secure Schools, a principal provider of cyber security solutions in the UK Wonde is a premier data management specialist for over 30,000 schools worldwide, and through their innovative platform, they ensure schools can […]

    Blog Education
  • Does your school’s backup actually work? Find out in 10 minutes

    A ransomware attack hit a Southampton school. They were locked out for four days. The painful part? They had a backup. But they were unable to quickly restore systems. That's the gap nobody talks about. Not whether you have a backup, but whether it actually works when it matters.

    Blog Advice
  • Set it and forget it: The product you can trust with your summer data sync

    Why spending 20 minutes in your Wonde School Portal this June means total peace of mind over the summer break.

    Blog Advice

Any questions?

Ready to innovate and support schools.

Contact us
Our team will handle all the details.

30,000+

Schools trust Wonde

700+

Integrated apps

60+

Countries

35 million

Individuals data managed

Discover how Wonde can help your school, app, or company work smarter

  • Wonde Portals
  • Knowledge hub
Wonde

New to Wonde?

  • Schools
  • Districts
  • Partners
  • Developers

Our products

  • Edusync
  • MyLogin
  • Data Recovery
  • Wonde Portals

Our company

  • About
  • Team
  • Reliability
  • Careers
  • Social Impact
  • Partnerships
  • Security

Help & information

  • Support
  • Resources
  • API documentation
  • Legal & compliance
  • Contact us
  • Privacy notices
  • Licence agreements
  • Sub-processors
  • Cookie policy
  • Terms of use
  • Modern slavery statement
  • Carbon reduction plan
  • Data processing
© 2026 Wonde (US)
X/Twitter Instagram LinkedIn