Does your Edtech comply with the GDPR?
The GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Organic Law 3/2018) regulate the processing of personal data in the edtech sector. The most critical aspects are:
Children's data (Art. 8 GDPR + LOPDGDD Art. 7): Art. 8 GDPR sets the conditions for children's consent in information society services. The LOPDGDD Art. 7 sets the minimum consent age at 14 in Spain. Children under 14 cannot give valid consent; parental consent is required. For children aged 14 to 18, the child's consent is valid but must be complemented with age-adapted information.
Biometric data (Art. 9 GDPR): Biometric data used for unique identification are special categories. Proctoring with facial recognition, iris scanning or voice requires a specific Art. 9 legal basis (explicit consent). The AEPD has published a report on facial recognition in exams, requiring free consent with a genuine alternative.
DPIA (Art. 35): The DPIA is mandatory for large-scale processing of special categories of data (biometrics) and systematic large-scale monitoring, especially of children.
Automated decisions (Art. 22): If AI is used to assess, admit or classify students, it may constitute an automated decision under Art. 22.
Security (Art. 32): Measures appropriate to the risk, especially for children's and biometric data.
- Children's data analysis — We verify parental consent (LOPDGDD Art. 7, under 14s)
- Biometrics analysis — We identify the Art. 9 legal basis for biometric proctoring
- Educational DPIA — We carry out the Art. 35 Impact Assessment for children's and biometric data
- Art. 22 analysis — We assess whether assessment AI constitutes an automated decision
- AEPD coordination — We act before the AEPD in inspections and complaints in the education sector
GDPR obligations for Edtech
GDPR obligations for an edtech include:
Children's consent:
- Verify the user's age
- For children under 14: obtain parental consent (LOPDGDD Art. 7)
- For children aged 14-18: child's consent with age-adapted information
- Document consent and age verification
Legal bases and transparency:
- Identify the Art. 6 legal basis (consent, contract, legitimate interest)
- For biometric data: Art. 9 legal basis (explicit consent)
- Information to the data subject and parents (Arts. 13-14), adapted to age
- Clear and accessible privacy policy, with language understandable to children
Data subject rights:
- Access, rectification, erasure, restriction, portability, objection (Arts. 15-21)
- Right not to be subject to automated decisions (Art. 22) if assessment AI is used
- Rights exercised by parents on behalf of children under 14
Security and breaches:
- Technical and organisational measures (Art. 32): encryption, access control
- Breach notification within 72 hours (Art. 33)
- Communication to affected persons (Art. 34) if there is a high risk (common with children's data)
DPIA and DPO:
- Mandatory DPIA for large-scale processing of children's and biometric data (Art. 35)
- Mandatory DPO if core activities consist of large-scale processing of special categories (Art. 37)
Fines: Up to €20 million or 4% of global turnover. The AEPD fined a school €10,000 (2025) for creating a child's electronic profile without parental consent.
Most relevant GDPR articles for Edtech
| Article | Topic | Application in edtech |
|---|---|---|
| Art. 8 | Children’s consent | LOPDGDD Art. 7: age 14 in Spain |
| Art. 9 | Special categories | Biometrics in proctoring: explicit consent |
| Art. 6 | Legal bases | Consent, contract, legitimate interest |
| Art. 13-14 | Information | Policy adapted to children and parents |
| Art. 22 | Automated decisions | Assessment, admission, classification AI |
| Art. 32 | Security | Encryption, access control |
| Art. 35 | DPIA | Large-scale children’s and biometric data |
| Art. 37 | DPO | Large-scale special categories processing |
| LOPDGDD Art. 7 | Children | Minimum consent age: 14 |
Real enforcement cases in edtech
- AEPD — School fine, €10,000 (2025) — Creation of a child’s electronic profile without parental consent (Arts. 6, 13 and 32 GDPR). Source: PSN Sercon blog
- AEPD — Report on facial recognition in online exams: AEPD
- AEPD — Resolution on biometric proctoring at a university: AEPD
- AEPD — Guide for educational institutions: AEPD
- AEPD — Principles for digital educational platforms: AEPD
- AEPD — FAQ on children and education: AEPD
GDPR compliance checklist for Edtech
- Identify all children’s data processing operations
- Implement age verification
- For under 14s: obtain parental consent (LOPDGDD Art. 7)
- For 14-18s: child’s consent with age-adapted information
- Identify the Art. 6 legal basis for each processing operation
- For biometrics: Art. 9 legal basis (explicit consent)
- Verify biometric consent is free and with a genuine alternative
- Draft child-adapted privacy policy (Arts. 13-14)
- Implement data subject rights mechanisms (Arts. 15-21)
- Assess whether assessment AI is an automated decision (Art. 22)
- Carry out DPIA for children’s and biometric data (Art. 35)
- Designate DPO where appropriate (Art. 37)
- Implement security measures (Art. 32): encryption, access
- Establish 72-hour breach notification procedure (Art. 33)
Related resources
- GDPR Hub — Resource centre on the GDPR
- GDPR Glossary — 45+ key terms with article references
- AI Act vs GDPR — Comparative table of both regulations
- GDPR Compliance Checker — Self-assess your compliance
- AI & Data Regulation Service — Integrated advisory
- AI Act for Edtech — Sectoral AI Act guide for edtech
- DPO as a Service — External Data Protection Officer
This page is general information, not legal advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.