GDPR · Edtech

GDPR for Edtech: Children's Data, Biometrics and Consent

The LOPDGDD Art. 7 sets the minimum consent age at 14 in Spain. Learn the obligations for children's data, exam biometrics, parental consent and AEPD cases in edtech.

Does your Edtech comply with the GDPR?

The GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Organic Law 3/2018) regulate the processing of personal data in the edtech sector. The most critical aspects are:

Children's data (Art. 8 GDPR + LOPDGDD Art. 7): Art. 8 GDPR sets the conditions for children's consent in information society services. The LOPDGDD Art. 7 sets the minimum consent age at 14 in Spain. Children under 14 cannot give valid consent; parental consent is required. For children aged 14 to 18, the child's consent is valid but must be complemented with age-adapted information.

Biometric data (Art. 9 GDPR): Biometric data used for unique identification are special categories. Proctoring with facial recognition, iris scanning or voice requires a specific Art. 9 legal basis (explicit consent). The AEPD has published a report on facial recognition in exams, requiring free consent with a genuine alternative.

DPIA (Art. 35): The DPIA is mandatory for large-scale processing of special categories of data (biometrics) and systematic large-scale monitoring, especially of children.

Automated decisions (Art. 22): If AI is used to assess, admit or classify students, it may constitute an automated decision under Art. 22.

Security (Art. 32): Measures appropriate to the risk, especially for children's and biometric data.

  • Children's data analysis — We verify parental consent (LOPDGDD Art. 7, under 14s)
  • Biometrics analysis — We identify the Art. 9 legal basis for biometric proctoring
  • Educational DPIA — We carry out the Art. 35 Impact Assessment for children's and biometric data
  • Art. 22 analysis — We assess whether assessment AI constitutes an automated decision
  • AEPD coordination — We act before the AEPD in inspections and complaints in the education sector

GDPR obligations for Edtech

GDPR obligations for an edtech include:

Children's consent:

  • Verify the user's age
  • For children under 14: obtain parental consent (LOPDGDD Art. 7)
  • For children aged 14-18: child's consent with age-adapted information
  • Document consent and age verification

Legal bases and transparency:

  • Identify the Art. 6 legal basis (consent, contract, legitimate interest)
  • For biometric data: Art. 9 legal basis (explicit consent)
  • Information to the data subject and parents (Arts. 13-14), adapted to age
  • Clear and accessible privacy policy, with language understandable to children

Data subject rights:

  • Access, rectification, erasure, restriction, portability, objection (Arts. 15-21)
  • Right not to be subject to automated decisions (Art. 22) if assessment AI is used
  • Rights exercised by parents on behalf of children under 14

Security and breaches:

  • Technical and organisational measures (Art. 32): encryption, access control
  • Breach notification within 72 hours (Art. 33)
  • Communication to affected persons (Art. 34) if there is a high risk (common with children's data)

DPIA and DPO:

  • Mandatory DPIA for large-scale processing of children's and biometric data (Art. 35)
  • Mandatory DPO if core activities consist of large-scale processing of special categories (Art. 37)

Fines: Up to €20 million or 4% of global turnover. The AEPD fined a school €10,000 (2025) for creating a child's electronic profile without parental consent.

Most relevant GDPR articles for Edtech

ArticleTopicApplication in edtech
Art. 8Children’s consentLOPDGDD Art. 7: age 14 in Spain
Art. 9Special categoriesBiometrics in proctoring: explicit consent
Art. 6Legal basesConsent, contract, legitimate interest
Art. 13-14InformationPolicy adapted to children and parents
Art. 22Automated decisionsAssessment, admission, classification AI
Art. 32SecurityEncryption, access control
Art. 35DPIALarge-scale children’s and biometric data
Art. 37DPOLarge-scale special categories processing
LOPDGDD Art. 7ChildrenMinimum consent age: 14

Real enforcement cases in edtech

  • AEPD — School fine, €10,000 (2025) — Creation of a child’s electronic profile without parental consent (Arts. 6, 13 and 32 GDPR). Source: PSN Sercon blog
  • AEPD — Report on facial recognition in online exams: AEPD
  • AEPD — Resolution on biometric proctoring at a university: AEPD
  • AEPD — Guide for educational institutions: AEPD
  • AEPD — Principles for digital educational platforms: AEPD
  • AEPD — FAQ on children and education: AEPD

GDPR compliance checklist for Edtech

  • Identify all children’s data processing operations
  • Implement age verification
  • For under 14s: obtain parental consent (LOPDGDD Art. 7)
  • For 14-18s: child’s consent with age-adapted information
  • Identify the Art. 6 legal basis for each processing operation
  • For biometrics: Art. 9 legal basis (explicit consent)
  • Verify biometric consent is free and with a genuine alternative
  • Draft child-adapted privacy policy (Arts. 13-14)
  • Implement data subject rights mechanisms (Arts. 15-21)
  • Assess whether assessment AI is an automated decision (Art. 22)
  • Carry out DPIA for children’s and biometric data (Art. 35)
  • Designate DPO where appropriate (Art. 37)
  • Implement security measures (Art. 32): encryption, access
  • Establish 72-hour breach notification procedure (Art. 33)

This page is general information, not legal advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.

Featured Services

Frequently Asked Questions

From what age can a child give consent in Spain?

The LOPDGDD Art. 7 sets the minimum consent age at 14 in Spain. Children under 14 cannot give valid consent for the processing of their data in information society services; parental consent is required. For children aged 14 to 18, the child's consent is valid but must be complemented with age-adapted information. Art. 8 GDPR allows each Member State to set the minimum age between 13 and 16.

Is biometric proctoring legal in Spain?

Biometric proctoring (facial recognition, iris scanning) in exams processes biometric data, which are special categories under Art. 9 GDPR. It requires explicit consent (Art. 9(2)(a)). The AEPD has published a report on facial recognition in online exams, requiring that consent be free and with a genuine alternative. The AEPD has also ruled against the use of biometric proctoring at a Spanish university. In practice, biometric proctoring is very difficult to implement in a GDPR-compatible way.

When is the DPIA mandatory in edtech?

The DPIA (Art. 35 GDPR) is mandatory for high-risk processing, including large-scale processing of special categories of data (biometrics) and systematic large-scale monitoring, especially of children. In edtech, biometric proctoring, adaptive assessment with profiling and large-scale processing of children's data require a DPIA. It must document the risk analysis, mitigation measures and residual assessment.

What fines has the AEPD imposed in edtech?

The AEPD fined a school €10,000 (2025) for creating a child's electronic profile without parental consent (Arts. 6, 13 and 32 GDPR). It has also published a report on facial recognition for online exams, requiring that biometric consent be free and with a genuine alternative, and has ruled against the use of biometric proctoring at a Spanish university. These cases illustrate the AEPD's active supervision in the education sector.

Is assessment AI an automated decision under Art. 22?

It may be. If AI is used to assess, admit or classify students in a fully automated way, without significant human intervention, and produces legal effects or significantly affects the student, it constitutes an automated decision under Art. 22 GDPR. In that case, an exception is required (contract, legal authorisation, explicit consent) and additional safeguards (human intervention, information, right to express a point of view).

How is a child user's age verified?

The GDPR does not specify a particular method, but verification must be appropriate to the risk. Common methods: declaration with parental verification (for under 14s), documentary verification (ID) in high-risk cases, technical methods such as AI age estimation (with caution due to Art. 9). The AEPD has published principles for digital educational platforms that include recommendations on age verification.

What rights do parents have over their minor children's data?

Parents exercise GDPR rights (Arts. 15-21) on behalf of children under 14, in the child's interest. For children aged 14 to 18, the child exercises their own rights, but parents may supervise. The right of access allows parents to know what data is processed about their children. The right to erasure allows requesting data deletion, unless there is a legal retention obligation.

Which authorities supervise the GDPR in edtech in Spain?

The AEPD supervises the GDPR. In the education sector, regional education authorities may intervene in public schools. The AEPD has published specific guides for educational institutions, principles for digital educational platforms, and an FAQ on children and education. In educational AI cases, the AESIA (AI Act) may also intervene.

Contact

If you want to talk about intellectual property protection, AI and data regulation, startup formation or international expansion, write us a few lines and schedule a conversation with the team.

A2 Estudio Legal
María de Molina, 41
28006 Madrid · Spain

Tel: +34 913 451 406
Email: info@a2estudiolegal.com

Tell us briefly about your project, development stage and target countries. We will respond with the next steps to start working together.

Let's talk
Contact us