France’s data protection authority is warning primary and secondary schools that the growing use of cloud-based collaboration platforms creates far more than an IT procurement issue.
In new guidance published Aug. 24, 2026, the Commission Nationale de l’Informatique et des Libertés, or CNIL, laid out a detailed compliance framework for schools using online collaborative tools, including digital workspaces, cloud platforms and alternatives to traditional educational portals.
The message is significant well beyond France’s education sector.
France’s CNIL Warns Schools on Cloud Collaboration Tools: GDPR, Advertising Trackers, DPIAs and Foreign Data Access All Come Into Play
The CNIL makes clear that when a school deploys an online platform capable of processing student communications, schoolwork, grades, teacher evaluations or personal documents, the organization must understand exactly what data is being processed, establish the correct legal basis, scrutinize the technology provider, disable advertising and profiling trackers, provide age-appropriate privacy information, evaluate whether a Data Protection Impact Assessment is required and address risks created by international data transfers.
For privacy teams, school systems and education technology providers, the guidance offers a useful preview of how European regulators increasingly expect organizations handling children’s data to approach cloud services under the GDPR.
Online Education Tools Process Far More Personal Data Than Many Organizations Realize
The CNIL begins with an increasingly familiar reality: digital transformation has pushed schools toward online collaborative environments that depend heavily on cloud computing.
These platforms can facilitate communication among administrators, teachers, students and parents, but they also routinely process substantial amounts of personal information.
The CNIL specifically points to:
- communications between school administrators, teachers, students and parents;
- student assignments and schoolwork;
- personal student documents stored in digital vaults;
- grades; and
- teacher comments and evaluations.
Schools therefore cannot evaluate these products solely on functionality, pricing or ease of use.
They are processing environments subject to the GDPR, and the organization acting as controller remains responsible for determining whether that processing complies with European data protection law.
That distinction is particularly important as schools adopt more third-party software.
A platform may be operated entirely by an outside technology vendor, yet the school cannot simply transfer its GDPR responsibilities to the software provider.
Schools Need a Legal Basis for Each Processing Activity
One of the first obligations identified by the CNIL is determining the appropriate legal basis for the personal-data processing performed through the platform.
Where processing is necessary to fulfill the public-service mission of the educational institution, including the public digital education mission recognized under French education law, the controller may be able to rely on performance of a task carried out in the public interest.
Importantly, the CNIL says this principle can apply to both public and private schools when the processing relates to the institution’s public-service educational mission.
That is a more appropriate legal analysis than simply assuming everything can be justified through consent.
In fact, the CNIL specifically warns that consent may often be difficult to use as a valid legal basis in an educational environment.
For consent to be valid under the GDPR, it must be freely given.
Students, parents, teachers and school employees must have a genuine choice and must not face negative consequences if they refuse.
The authority points to the inherent power relationships inside educational institutions as one reason consent may not always satisfy that requirement.
This is an important reminder for any organization processing children’s information.
A checkbox alone does not make consent valid.
The surrounding relationship matters.
The CNIL Takes a Hard Position on Advertising Trackers in School Software
One of the strongest sections of the guidance concerns advertising technology.
The CNIL says schools must pay close attention to processing performed by the technology provider for its own purposes.
In particular, the controller should ensure that the collaborative platform does not use advertising trackers.
According to the authority, such advertising technologies are generally incompatible with the principle of neutrality applicable to France’s public education service, including commercial neutrality.
If a collaborative education product nevertheless contains tracking mechanisms used for advertising exploitation or profiling, the CNIL says the controller must disable those functions.
This is potentially one of the most consequential parts of the guidance for education technology companies.
A platform cannot simply be evaluated as a single application.
Schools need to examine the third-party technologies operating inside it.
That can include:
- advertising pixels;
- analytics SDKs;
- tracking cookies;
- behavioral profiling technologies;
- embedded marketing tools;
- third-party scripts;
- device identifiers; and
- other technologies transmitting information outside the educational environment.
The issue is not merely whether the vendor calls itself an educational technology provider.
The question is what the software actually does.
Privacy Notices Need to Be Understandable to Children
Transparency is another major focus.
Students, parents and school staff must be informed about all relevant processing taking place through the collaborative tool.
The CNIL reiterates the GDPR requirement that privacy information be concise, transparent, understandable and easily accessible.
The notice should address matters including:
- the identity and contact information of the controller;
- DPO contact information where applicable;
- the purposes of processing;
- the legal basis;
- recipients or categories of recipients;
- transfers outside the European Union;
- retention periods; and
- data-subject rights.
But the CNIL goes further when children are involved.
Privacy information provided to minors should be written in a simple, educational and age-appropriate format.
The authority specifically encourages clear-language methods and points organizations toward accessibility frameworks designed to make information easier to understand.
That has implications far outside the school sector.
A privacy policy technically satisfying every disclosure requirement can still fail its practical purpose if the intended audience cannot understand it.
Regulators increasingly expect children’s privacy notices to reflect the age and comprehension level of the user rather than simply reuse adult-facing legal language.
Privacy Information Should Come Before the Processing
Timing also matters.
The CNIL says privacy information should be readily available before the relevant data processing begins.
For school platforms, that could mean presenting it during the first login by a student or member of staff.
Schools could also distribute privacy information directly by email and repeat relevant disclosures at the beginning of the academic year.
This echoes a broader theme increasingly visible across privacy regulation:
Disclosure after collection is often too late.
The relevant information should be available when the individual is deciding whether and how to use the service.
CNIL Says a DPIA Will Probably Be Necessary in Many Cases
The guidance places substantial emphasis on Data Protection Impact Assessments.
Under Article 35 of the GDPR, a DPIA is required where processing is likely to result in a high risk to individuals’ rights and freedoms.
The CNIL identifies several risk criteria that are especially relevant to educational platforms:
- processing involving vulnerable individuals, including minors;
- large-scale processing;
- long-term or continuous processing;
- broad geographic scope; and
- processing of sensitive information, including health data.
Where at least two of the relevant European Data Protection Board risk criteria are present, the CNIL says a DPIA should be performed before the processing begins.
And the authority goes even further:
For these types of school collaboration systems, it says a DPIA will probably be required in the majority of cases.
That is a significant compliance message.
DPIAs should not be treated as documentation prepared after a platform has already been deployed.
The assessment is supposed to happen before the high-risk processing begins.
The Controller Cannot Outsource the DPIA Obligation
The responsibility for the assessment remains with the controller.
The controller may ask its DPO for advice and may obtain assistance from the technology vendor acting as processor, but the school or other controlling organization remains responsible for conducting the DPIA.
This distinction matters because cloud vendors frequently provide security documents, risk assessments and compliance certifications.
Those resources can be helpful.
They are not substitutes for the controller evaluating its own use of the platform.
The risk created by an educational technology service depends not merely on the software itself, but on how the school configures it, which students use it, what information is uploaded, which features are enabled and what third parties receive data.
Vendor Due Diligence Must Be More Than a Contract
The CNIL also reminds controllers that Article 28 of the GDPR requires them to use processors offering sufficient guarantees regarding appropriate technical and organizational measures.
More importantly, the controller must be able to demonstrate that it actually evaluated those guarantees.
The authority identifies potentially useful evidence including:
- privacy policies;
- terms of use;
- information-security policies;
- GDPR codes of conduct;
- GDPR certifications; and
- security certifications such as those within the ISO 27000 family.
This is a critical distinction in vendor management.
Signing a Data Processing Agreement is not the same thing as conducting processor due diligence.
The organization should know what safeguards actually exist.
Processor Agreements Need to Address What Happens When the Relationship Ends
The CNIL also highlights what should happen when the vendor relationship ends.
Article 28 processor agreements must address the subject matter, duration and purpose of processing, the obligations of the parties and security requirements.
The CNIL specifically calls attention to end-of-contract obligations, including reversibility and deletion of personal data when the relationship concludes.
This may seem administrative, but it addresses a major real-world privacy risk.
Organizations regularly terminate software vendors without fully determining:
- whether the vendor still possesses historical student data;
- whether backups remain;
- whether former subprocessors retain copies;
- whether accounts and tokens remain active;
- whether data can actually be exported;
- and whether deletion has been verified.
A vendor can become a former vendor contractually while remaining a current privacy risk technically.
Schools Need Visibility Into the Entire Subprocessor Chain
The guidance also references the European Data Protection Board’s October 2024 opinion concerning controller obligations when processors use additional subprocessors.
The broader point is straightforward:
The first vendor in the contract is not always the last organization touching the data.
A cloud collaboration platform may itself depend on:
- hosting providers;
- analytics services;
- support platforms;
- infrastructure vendors;
- security services;
- communications providers; and
- other subprocessors.
Controllers need sufficient visibility into that chain to evaluate whether the processing remains compliant.
That becomes particularly important where children, educational records or sensitive information are involved.
International Cloud Transfers Remain a Major Concern
The CNIL dedicates an entire portion of the guidance to transfers outside the European Union and the risks of foreign-government access.
Under Chapter V of the GDPR, personal information generally cannot be transferred to countries outside the EU without an appropriate legal mechanism and sufficient protection.
The controller must evaluate both the legal framework governing the transfer and the cybersecurity protections surrounding it.
The CNIL treats this as particularly important in the education context because students are vulnerable data subjects and educational platforms may process large quantities of information, including sensitive data such as health information.
The authority therefore recommends protecting data against the risk that public authorities in third countries could obtain access.
That is an important signal for organizations relying on multinational cloud providers.
A valid contract alone may not end the analysis.
Organizations may also need to evaluate technical controls, encryption, architecture, jurisdiction and the circumstances in which foreign authorities might compel access.
CNIL Points to SecNumCloud as an Example of Stronger Sovereignty Protection
The CNIL specifically identifies France’s SecNumCloud qualification as one possible approach.
SecNumCloud is administered by France’s national cybersecurity agency, ANSSI.
The CNIL notes that using a provider benefiting from the qualification can help ensure that the provider is subject exclusively to European law.
The inclusion of SecNumCloud is notable because it reinforces the connection between privacy compliance, cybersecurity and digital sovereignty.
For especially sensitive processing, European regulators increasingly care not merely where the server is physically located, but which legal regimes can ultimately compel access to the data.
France Is Also Raising Security Requirements for Public Schools
The guidance references France’s Dec. 5, 2025 decree governing the digital education framework.
According to the CNIL, the decree requires public middle and secondary schools to use digital tools and services meeting specified requirements concerning security, interoperability and responsible digital practices established by the education ministry.
That means privacy compliance is becoming embedded directly into broader education technology procurement.
Schools are increasingly expected to evaluate products based on more than features.
Security architecture, data portability, interoperability, data minimization and responsible design can all become procurement requirements.
The Larger Lesson for EdTech Companies
Although the guidance is directed primarily toward French primary and secondary education, education technology providers should read it carefully.
The CNIL is effectively describing the standards against which their customers may evaluate them.
A vendor selling into European schools should be prepared to answer questions such as:
What personal information does the platform collect?
Which processing occurs on behalf of the school?
Which processing does the vendor perform for its own purposes?
Are advertising or profiling technologies embedded?
Which cookies, SDKs and trackers operate?
Which subprocessors receive information?
Where is the information stored?
Can foreign governments compel access?
What certifications exist?
How is information encrypted?
How long is it retained?
Can the school obtain its data when the contract ends?
Can the vendor prove deletion?
Does the platform process sensitive information?
Can the vendor assist with a DPIA?
Are privacy notices understandable to children?
Are the most privacy-protective settings enabled by default?
Those questions are quickly becoming part of the commercial sales process for privacy-sensitive technology.
The Bigger Privacy Trend: Protect Children by Changing the Architecture
The CNIL guidance fits into a much broader regulatory movement.
Around the world, privacy authorities are moving away from the idea that children’s privacy can be protected primarily through lengthy notices and parental consent forms.
Regulators increasingly want privacy protections embedded directly into the product.
That means:
- collecting less information;
- disabling advertising;
- limiting profiling;
- using privacy-protective defaults;
- performing risk assessments before launch;
- restricting third-party access;
- limiting retention;
- reducing unnecessary international transfers; and
- proving that safeguards actually function.
France’s latest guidance follows exactly that model.
The emphasis is not simply on telling students what the technology does.
It is on controlling what the technology is allowed to do.
What Schools Should Review Now
Schools using collaborative platforms should use the CNIL guidance as a practical audit framework.
That review should include the legal basis for each processing activity, the categories of student and staff information involved, advertising and tracking technologies, child-facing privacy notices, DPIA requirements, processor contracts, subprocessor chains, retention schedules, deletion processes and international-transfer safeguards.
Schools should also involve their DPO early rather than after deployment.
The CNIL explicitly encourages organizations to rely on DPO expertise when implementing these systems.
Most importantly, organizations should evaluate what the platform actually does technically.
A vendor’s promise that its platform is “GDPR compliant” does not answer whether advertising trackers are active, whether data leaves the EU, whether subprocessors can independently use information, or whether children’s information is being minimized appropriately.
Those facts require verification.
Why This Guidance Matters Beyond France
This is formally guidance from the French regulator.
But the underlying obligations largely derive from the GDPR itself: transparency, legal basis, processor accountability, DPIAs, children’s privacy, international transfers and security.
That makes the CNIL document relevant to organizations across the European Economic Area and to technology companies selling products into European schools.
It also provides a useful warning for companies outside education.
The regulatory direction is increasingly clear.
Organizations handling children’s information are expected to know their vendors.
They are expected to know their data flows.
They are expected to understand their trackers.
They are expected to minimize collection.
They are expected to evaluate high-risk processing before deployment.
And they are increasingly expected to provide evidence that those safeguards actually work.
For schools and EdTech companies, GDPR compliance is no longer simply about having the correct privacy notice.
It is becoming an architectural requirement.