{"id":12768,"date":"2026-09-07T08:18:22","date_gmt":"2026-09-07T07:18:22","guid":{"rendered":"https:\/\/lawwwing.com\/?p=12768"},"modified":"2026-09-07T09:05:01","modified_gmt":"2026-09-07T08:05:01","slug":"back-to-school-personal-data-protection-in-classroom","status":"publish","type":"post","link":"https:\/\/lawwwing.com\/en\/back-to-school-personal-data-protection-in-classroom\/","title":{"rendered":"Back to School: How Is Personal Data Protected in the Classroom?"},"content":{"rendered":"\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Are you a teacher or do you manage an e-learning platform? September is here, which means it is time to go back to school\u2014and a good opportunity to remember how data protection is managed in the academic environment.<\/p>\n\n\n\n<p>If you are a teacher, part of a school\u2019s management team, or the owner or developer of an e-learning platform or educational SaaS solution, you cannot overlook data protection regulations. It is important to remember that you have specific legal obligations whenever you process students\u2019 personal data\u2014for example, when you record a virtual class, create a user account in an educational application, or hire a digital service to use in the classroom.<\/p>\n\n\n\n<p>We are experiencing an ongoing digital transformation of the education sector, reflected in the growing use of e-learning platforms, educational SaaS solutions, and virtual classrooms. This technological development brings with it a number of data protection challenges, particularly when dealing with underage students.<\/p>\n\n\n\n<p>For this reason, education authorities, educational institutions, and educational platform providers must comply with the following legal framework: the General Data Protection Regulation (GDPR), the Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and the<a href=\"https:\/\/www.aepd.es\/documento\/apd-plataformas-educativas-administraciones-centros.pdf\"> guidelines<\/a> issued by the Spanish Data Protection Agency (AEPD).<\/p>\n\n\n\n<p>In this article, we will explain the main legal requirements for ensuring data protection in each of these educational contexts.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">1. Data Protection on E-Learning Platforms<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>E-learning platforms process large volumes of personal data. Therefore, when minors are involved, it must be taken into account that the GDPR emphasizes that children\u2019s personal data require special protection due to their vulnerability.<\/p>\n\n\n\n<p>The AEPD distinguishes between two types of data on e-learning platforms:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Data provided by users:<\/strong> names, email addresses, grades, submitted assignments, communications, etc. In these cases, the educational institutions would generally be the data controllers.<\/li>\n\n\n\n<li><strong>Data generated automatically:<\/strong> IP addresses, device identifiers, location data, activity logs, cookies, usage metadata, etc. In this context, the provider may also act as a data controller with respect to this data if it uses it for its own purposes, such as behavioral analysis, product improvement, or profiling.<\/li>\n<\/ul>\n\n\n\n<p>It should also be taken into account that e-learning platforms sometimes include services unrelated to their educational function, such as search engines, advertising-supported video platforms, or artificial intelligence tools for commercial purposes. Therefore, according to the AEPD\u2019s guidelines, these services <strong>should be disabled by default.<\/strong><\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-2-color has-text-color has-link-color wp-elements-4cdaba6a2937414220fdd4e313fdd451\">Recording Classes<\/h3>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>In virtual classes, there may often be a need or intention to record a session. In such cases, the following requirements and principles must be applied in order to comply with data protection regulations:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Information and transparency. <\/strong>Teachers and students must be informed about the processing of their data before the course begins. One possibility for e-learning platforms is to include this notice in their privacy terms and require users to read and accept them in order to obtain valid consent. It is also recommended that students be informed before the class begins that the session will be recorded.<\/li>\n\n\n\n<li><strong>Purpose limitation.<\/strong> Recordings of classes may only be used for the educational purpose that was previously communicated.<\/li>\n\n\n\n<li><strong>Consent management. <\/strong>Explicit and specific consent must be obtained from students in order to record the sessions.<\/li>\n\n\n\n<li><strong>Right to object. <\/strong>Students have the right to object to the continued processing of their personal data.<\/li>\n\n\n\n<li><strong>Right to withdraw consent. <\/strong>Students have the right to withdraw their consent at any time. This will not affect the lawfulness of recordings made previously when valid consent had been provided.<\/li>\n<\/ol>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-2-color has-text-color has-link-color wp-elements-bafcb84e5c23d5379ec50045e9c6024a\">International Transfers on E-Learning Platforms<\/h3>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Many e-learning platforms store data on servers located in the United States or operated by multinational companies. In this regard, the judgment of the Court of Justice of the European Union (CJEU) of July 2020 (Case<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/ALL\/?uri=CELEX:62018CJ0311\"> C-311\/18<\/a>) was particularly significant.<\/p>\n\n\n\n<p>In this judgment, the CJEU established that an adequacy decision adopted by the European Commission certifies that a country ensures a level of protection equivalent to that of the EU and therefore allows data transfers to that country. The judgment invalidated the EU-US Privacy Shield, which meant that organizations had to rely on Standard Contractual Clauses (SCCs).<\/p>\n\n\n\n<p>Under this mechanism, it must be assessed on a case-by-case basis whether the legislation of the recipient country allows an equivalent level of protection to that provided within the EU. If sufficient supplementary measures cannot be implemented to guarantee security, the data exporter is required to suspend the transfer of the data.<\/p>\n\n\n\n<p>For this reason, several European countries discourage or restrict the use of platforms hosted outside the EU for educational activities, and the use of platforms whose data is hosted entirely within the EU is recommended.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">2. Educational SaaS Platforms<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>It is essential for SaaS platforms to ensure data protection <strong>by design and by default<\/strong>. This means that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The platform should be configured to process only the <strong>data that is necessary<\/strong>.<\/li>\n\n\n\n<li><strong>Additional services should remain disabled:<\/strong> advertising tools, commercial analytics, or AI features should be switched off by default.<\/li>\n\n\n\n<li><strong>Granular controls:<\/strong> data controllers should be able to activate or deactivate the various functionalities.<\/li>\n\n\n\n<li><strong>Secure configuration:<\/strong> strong passwords, multi-factor authentication, and data encryption should be implemented.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-contrast-2-color has-text-color has-link-color wp-elements-b947dd589c1d1b1d668b366a7217155f\">Educational Platforms in the Classroom<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>In the school environment, the<a href=\"https:\/\/www.aepd.es\/sites\/default\/files\/2019-09\/guia-orientaciones-apps-datos-alumnos.pdf\"> AEPD<\/a> recommends that educational applications be included in schools\u2019 <strong>security policies<\/strong>. Furthermore, before these applications can be used in the classroom, teachers should request authorization from the school, which will conduct a security assessment.<\/p>\n\n\n\n<p>The educational institution should only authorize the use of SaaS platforms that provide <strong>clear and accessible information<\/strong> in their security policy regarding:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The identity and address of the data controller.<\/li>\n\n\n\n<li>The specific purposes for which the data is used. One of these purposes should not be the creation of profiles of minors.<\/li>\n\n\n\n<li>Any potential disclosures of data to third parties, their identity, and the purpose for which the data is shared.<\/li>\n\n\n\n<li>The rights of data subjects.<\/li>\n\n\n\n<li>The location of the servers where the data is stored and the applicable retention periods.<\/li>\n\n\n\n<li>The application\u2019s security measures.<\/li>\n\n\n\n<li>The access the application has to the device (such as the microphone, camera, or location) or to data stored on the device.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-2-color has-text-color has-link-color wp-elements-963ec7c3862409fbd6fa9944721e752c\">Technical Security Measures Required for SaaS Platforms<\/h3>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The service provider must provide the appropriate technical tools to enable the educational institution to comply with security requirements, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Backups:<\/strong> the application should provide mechanisms that allow data to be backed up or downloaded so that the institution can comply with its related obligations. For this reason, it is important for the institution to include the backup of data processed through these applications in its security policy.<\/li>\n\n\n\n<li><strong>Unambiguous and personalized user authentication:<\/strong> in the case of minors, the AEPD recommends identifying them through usernames and passwords. Likewise, the identification of minors through biometric systems, such as facial recognition or fingerprints, should be avoided.<\/li>\n\n\n\n<li><strong>Data minimization:<\/strong> it is important to ensure that tools limit data collection to what is strictly necessary and avoid requesting excessive information.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The digital transformation of education offers significant opportunities, but it also creates new challenges in terms of privacy and data protection, particularly when it comes to protecting minors\u2019 personal data. E-learning platforms and educational SaaS solutions must ensure that data protection is incorporated <strong>by design and by default<\/strong>, applying principles of data minimization, transparency, security, and control over the use of information.<\/p>\n\n\n\n<p>For educational institutions, it is not simply a matter of choosing technological tools for the classroom. They must also ensure that these tools comply with the requirements established by the GDPR, the LOPDGDD, and the AEPD\u2019s recommendations. It is therefore necessary to conduct a security assessment of applications, understand where data is stored, and control what information is collected and for what purposes. All these steps are essential to building secure digital educational environments that respect students\u2019 privacy, particularly that of minors.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Do You Want to Comply with All These Requirements?<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Having up-to-date legal documents and properly managing consent are key to complying with regulations and providing a secure digital environment.<\/p>\n\n\n\n<p>With Lawwwing, you can automate the creation and updating of your legal documents and privacy policy, tailored to your business activity and the applicable regulations. You can also implement a cookie banner that properly manages user consent.<\/p>\n\n\n\n<p>Automate your legal documents and easily configure your cookie banner with Lawwwing.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-1 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-background wp-element-button\" href=\"https:\/\/lawwwing.com\/en\/blog\/\" style=\"background:linear-gradient(135deg,rgb(132,206,249) 0%,rgb(219,180,255) 100%)\">DIGITAL LAW AND DATA PROTECTION BLOG<\/a><\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Are you a teacher or do you manage an e-learning platform? September is here, which means it is time to go back to school\u2014and a good opportunity to remember how data protection is managed in the academic environment. If you are a teacher, part of a school\u2019s management team, or the owner or developer of [&hellip;]<\/p>\n","protected":false},"author":22,"featured_media":12769,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[335,216,210,207,672,202,246],"tags":[677],"class_list":["post-12768","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aepd-en","category-consent","category-data-protection","category-lopdgdd-en","category-privacidad-y-proteccion-de-datos-ue-en","category-rgpd-en","category-seguridad-en","tag-proteccion-de-datos-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12768","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/comments?post=12768"}],"version-history":[{"count":1,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12768\/revisions"}],"predecessor-version":[{"id":12772,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12768\/revisions\/12772"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media\/12769"}],"wp:attachment":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media?parent=12768"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/categories?post=12768"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/tags?post=12768"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}