The Estonian authority reminds schools of security principles for the use of applications and artificial intelligence

The Estonian Data Protection Inspectorate (AKI) has issued a circular reminding educational institutions of the principles for the secure use of applications and artificial intelligence.

Addressed to school staff, this circular emphasizes the need to assess each application before deployment, analyzing its purpose, the personal data processed, their storage location, and the role of the provider. Special attention is given to artificial intelligence tools, for which it is imperative to understand the use of entered data, notably for model training. The authority recommends using anonymized or pseudonymized data, prohibiting the entry of special categories of data, as well as systematic verification of AI-generated content, while maintaining human oversight for decisions affecting students. Institutions must maintain an inventory of authorized applications and clear usage policies, complemented by security measures such as multi-factor authentication, access rights management, regular updates, and data encryption.

In addition to this publication, AKI is organizing an online seminar on September 17 from 3:00 PM to 4:00 PM via Microsoft Teams to detail the recommendations of the circular. This seminar, which will not be recorded, is intended for school principals, teachers, education technologists, and other school employees, as well as local government agents. It will cover points of vigilance when adopting applications, specifics of tools based on artificial intelligence, and general aspects of managing their use.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire