GDPR and Schools

I am a school teacher in the UK. I have made a MySQL database and set of PHP pages to help students in my school. The school are asking me to complete a Data Protection Impact Assessment. I can answer the questions relating to my website but the data could also be accessed by someone hacking InfinityFree and I don’t know how to answer the questions about InfinityFree’s security or GDPR compliance.
Can anyone help with this?

InfinityFree is based in the UK EU and complies with GDPR to the best of Admin’s ability.


InfinityFree is actually a company in the Netherlands, which means that the GDPR (not the UK equivalent) applies. The hosting servers themselves are maintained by iFastNet, which is a UK company, which means they need to follow the same laws you do.