The CNIL reminds the rules for the use of online collaborative tools in primary and secondary education
The National Commission on Informatics and Liberty (CNIL) has published recommendations on the use of online collaborative tools in primary and secondary education to ensure their compliance with the GDPR.
Schools, as data controllers, must base the processing of personal data on the performance of a task carried out in the public interest, as consent is hardly applicable due to the imbalance in the relationship with students and staff. Clear, concise, and appropriate information, especially for minors, must be provided to the data subjects in accordance with Article 12, Article 13 and Article 14 of the GDPR. Conducting a data protection impact assessment (DPIA) is generally necessary, as the processing often involves vulnerable individuals and is carried out on a large scale, in accordance with Article 35 of the GDPR.
The data controller must select processors providing sufficient guarantees, as required by Article 28 of the GDPR, and formalize the relationship by a contract. They must also ensure that the provider does not use advertising trackers, in accordance with the principle of commercial neutrality of the public service. Particular attention must be paid to data transfers outside the European Union, governed by Chapter V of the GDPR. The CNIL recommends protecting data against risks of access by authorities of third countries, suggesting for example the use of SecNumCloud qualified providers by the National Cybersecurity Agency of France (ANSSI). Finally, decree n° 2025-1165 of 5 December 2025 imposes specific technical requirements on public middle and high schools.
Schools, as data controllers, must base the processing of personal data on the performance of a task carried out in the public interest, as consent is hardly applicable due to the imbalance in the relationship with students and staff. Clear, concise, and appropriate information, especially for minors, must be provided to the data subjects in accordance with Article 12, Article 13 and Article 14 of the GDPR. Conducting a data protection impact assessment (DPIA) is generally necessary, as the processing often involves vulnerable individuals and is carried out on a large scale, in accordance with Article 35 of the GDPR.
The data controller must select processors providing sufficient guarantees, as required by Article 28 of the GDPR, and formalize the relationship by a contract. They must also ensure that the provider does not use advertising trackers, in accordance with the principle of commercial neutrality of the public service. Particular attention must be paid to data transfers outside the European Union, governed by Chapter V of the GDPR. The CNIL recommends protecting data against risks of access by authorities of third countries, suggesting for example the use of SecNumCloud qualified providers by the National Cybersecurity Agency of France (ANSSI). Finally, decree n° 2025-1165 of 5 December 2025 imposes specific technical requirements on public middle and high schools.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire