Hi all.
Back to the original posters question about USB memory sticks. My suggestion is not to consider the medium, but the data. So, any device (USB stick, filing cabinet, server share, cloud storage, etc) does not in itself require protection (encryption, policy or otherwise). However, personal data (the definition is in the regulation, a bit too long winded for this answer unless you want me to find it) requires protection regardless of where it is stored. So if the USB device contains personal information, then yes it is absolutely covered by GDPR.
As for the question about the schools responsibility when using a 3rd party, the answer is yes. Generally speaking the School that collected the info is defined in GDPR as the 'Data Controller' and the 3rd party is the 'Data Processor'. Under GDPR both can be liable, which differs from the 1998 Data Protection Act.
In the post above, we see Microsoft's approach. This is becoming quite a standard approach with Software Providers (especially those with a SaaS service). In effect the vendor will be responsible for making sure that their software is compliant. But the customer (in this case the school) will be responsible for the policies, configurations, access, reporting etc. Thus resulting in 'shared responsibility'.
As per the earlier post, the ICO's 12 point plan is a great place to start. https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf
Regards,
Liam.