Collaborative tools in education and GDPR compliance: the CNIL’s recommendations
Key takeaways
On August 24, 2026, the CNIL published two recommendations on digital collaborative tools: one focusing on primary and secondary education and the other focusing on higher education.
Virtual learning environments, messaging services, online office suites, storage spaces and collaborative platforms: schools and higher education institutions make extensive use of collaborative tools, often hosted in the cloud, which in most cases involve the processing of personal data.
On August 24, 2026, just a few days before the start of the new school year, the CNIL published two recommendations regarding the use of these tools: one focusing on primary and secondary education and the other focusing on higher education. (1)
The two recommendations are very similar. However, they include a number of points specific to primary and secondary education. It is also useful to recall the criteria that make the appointment of a Data Protection Officer (DPO) mandatory for educational institutions.
1. Recommendations common to primary and secondary education and higher education
The two recommendations are based on a largely common set of requirements, including determining the legal basis for processing, informing users, carrying out a data protection impact assessment, the conditions for engaging a processor, and monitoring transfers of data outside the European Union.
1.1 Determine the legal basis for processing
The use of a collaborative tool may involve several separate personal data processing operations. The controller must therefore determine the legal basis for each of them before the tool is deployed.
For primary and secondary education, the CNIL links this analysis to the public service mission for digital education and distance learning established by the Law of July 8, 2013. (2)
The public digital education service is responsible, in particular, for providing schools and educational institutions with digital services that enhance teaching, provide teachers with resources and tools for monitoring students’ progress, and facilitate communication with families.
Where the processing is carried out as part of the public service missions of schools, whether public or private, the CNIL states that the controller may rely on the legal basis under which “processing is necessary for the performance of a task carried out in the public interest”. (3)
1.2 Inform users
Under the transparency obligation, pupils, students, legal guardians and staff must be provided with clear and accessible information about the processing operations carried out through the collaborative tool. (4) This information must be provided in a “concise, transparent, intelligible and easily accessible form.”
As a reminder, this information, which should in principle be accessible when users first log in to the tool, must identify the controller and state, in particular, the purposes and legal bases of the processing, data subjects’ rights, the recipients of the data, the applicable retention periods and, where relevant, the DPO’s contact details.
1.3 Assess whether a data protection impact assessment is required
Under Article 35 of the GDPR, a Data Protection Impact Assessment (DPIA) must be carried out where processing is “likely to result in a high risk to the rights and freedoms of natural persons.”
According to the CNIL, the use of digital collaborative tools in education requires a DPIA where at least two of the criteria identified by the European Data Protection Board (EDPB) are met. (5) Relevant criteria include, in particular:
· data concerning vulnerable data subjects, including children;
· data processed on a large scale;
· sensitive data or data of a highly personal nature.
The CNIL therefore considers that, in the majority of cases, it is likely that a DPIA will be required for the use of such tools in education.
1.4 Conditions for engaging processors
Article 28 of the GDPR requires a controller engaging processors to use “only processors providing sufficient guarantees to implement appropriate technical and organisational measures” and to govern the relationship through a contract that meets the requirements of the Regulation.
It is therefore necessary to review the terms of use of the tool, its privacy and security policies, any certifications held by the provider, and any use of sub-processors.
1.5 Monitor transfers of data outside the European Union
The controller must verify the conditions under which the data is hosted and whether it is transferred to a third country outside the EU. (6) Where such transfers take place, the risks of access by the public authorities of that country must be taken into account.
Given the vulnerability of certain data subjects and the nature of the data that may be processed, the CNIL mentions the use of a provider offering an ANSSI-qualified SecNumCloud service as one possible solution to strengthen data protection against the risk of access by third-country authorities.
2. Recommendations specific to primary and secondary education
Certain recommendations apply more specifically to primary and secondary education because the processing will generally involve children.
2.1 Specific protection for children
In primary and secondary education, a significant proportion of data subjects are children. The information provided to them must therefore be expressed in particularly clear and understandable terms and be adapted to their age group.
2.2 A strict position on advertising trackers
The controller must ensure that the tool does not use advertising trackers, as these are prohibited under the principle of neutrality governing the public education service, including commercial neutrality. Where the tool includes tracking technologies for advertising or profiling purposes, these features must be disabled.
This prohibition does not apply to higher education. However, the CNIL recommends giving preference to tools that do not allow the provider to use tracking technologies for advertising, profiling or commercial reuse purposes, or that allow such technologies to be disabled.
2.3 Specific technical rules for public lower and upper secondary schools
The Decree of December 5, 2025 provides that: “Information systems, services and digital tools implemented in public lower and upper secondary schools in the performance of their educational missions shall comply with reference frameworks for interoperability, security and responsible digital practices (...).” (7)
An exception applies to tools designed for use in the professional world where they are necessary solely for technical and vocational education.
3. Are educational institutions required to appoint a DPO?
The CNIL recommendations state that controllers may rely on the advice of their Data Protection Officer (DPO). However, not all institutions are required to appoint their own individual DPO.
3.1 Public schools
For public schools, the appointment of a DPO is mandatory under Article 37(1)(a) of the GDPR, which applies where “the processing is carried out by a public authority or body.” The DPO function may be shared.
Within the French national education system, the DPO function is organized at the level of each regional education authority (académie): a DPO is appointed for the schools and educational institutions within that authority. Depending on the processing concerned, the controller may be the head of the institution for local public educational institutions (établissements publics locaux d’enseignement, or EPLE), the Academic Director of National Education Services (directeur académique des services de l’Éducation nationale or DASEN) for primary schools acting under authority delegated by the rector, or the rector for processing carried out at the level of the education authority.
3.2 Private schools
For private schools, the performance of a public service mission is not, in itself, sufficient to make the appointment of a DPO mandatory for each institution.
However, where an institution meets one of the other criteria set out in Article 37 of the GDPR, a DPO must be appointed. This is the case, in particular, where the institution’s core activities involve “regular and systematic monitoring of data subjects on a large scale” or “processing on a large scale of special categories of data.” The DPO function may be shared, for example at group level or through an organization representing several institutions.
3.3 Higher education
In higher education, public institutions generally have their own DPO pursuant to Article 37(1) (a) of the GDPR.
For private higher education institutions, as with private primary and secondary schools, the requirement to appoint a DPO depends on the other criteria set out in Article 37.
* * * * * * * * * * *
(1) “Primary and secondary education: rules and best practices for using online collaborative tools” and “Higher education: rules and best practices for using online collaborative tools”, CNIL, August 24, 2026 (in French)
(2) Article 16 of Law No. 2013-595 of July 8, 2013 on policy and programming for the reform of the French school system, codified in Article L.131-2 of the French Education Code.
(3) See GDPR, Article 6(1) (e).
(4) See GDPR, Articles 12, 13 and 14.
(5) “Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is ‘likely to result in a high risk’ for the purposes of Regulation 2016/679”, Article 29 Working Party, April 4, 2017 (revised and last adopted on October 4, 2017).
(6) See GDPR, Chapter V.
(7) Decree No. 2025-1165 of December 5, 2025 on the reference framework for digital technology in education and Article R.421-78-3 of the French Education Code.
Bénédicte DELEPORTE
Attorney at Law
Deleporte Wentz Avocat
September 2026