Skip to content
Topic Contested in court

Education

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing in educational institutions

530 linked items 1 Case Law12 Guidance446 Enforcement51 News20 Literature

Overview

10 sources · Jul 15, 2026

Legal Framework

Educational institutions process substantial volumes of personal data spanning student records, staff information, and incident documentation. The primary legal basis requirements flow from Article 6 GDPR, with Article 6(1)(f) governing legitimate interests processing — particularly relevant where institutions balance student access rights against staff privacy and safety. Article 5 GDPR imposes the principles of lawfulness, fairness, minimization, and purpose limitation on all such processing. Articles 12 and 15 GDPR establish the data subject's right of access, which creates direct tension when disclosed documents contain third-party personal data. Article 32 GDPR mandates appropriate technical and organizational security measures, while Articles 33 and 34 GDPR require breach notification to supervisory authorities and affected individuals. The EDPB Guidelines 9/2022 clarify breach notification obligations, and EDPB Guidelines 01/2022 address the scope and limitations of access rights.

Key Developments

A 2024 ruling by the Dutch Administrative Jurisdiction Division (Afdeling bestuursrechtspraak) involving Zadkine establishes a practical threshold for redacting staff personal data in educational administrative proceedings. The institution expelled a student whose conduct posed a serious threat to order and safety, then redacted staff names, email addresses, and incident-related observations from documents disclosed to the student. The court upheld restricted access to unredacted versions, weighing staff privacy and safety interests — and the need to preserve confidential incident reporting channels — against the student's access interest. This confirms that where real risks to staff safety exist, Article 15 access rights yield to third-party protection under Article 6(1)(f) balancing.

Enforcement actions reinforce two distinct compliance failure points. The Polish DPO (UODO) fined the Minister of Justice €23,540 for insufficient technical and organizational measures, underscoring that educational and public-sector bodies must implement concrete Article 32 safeguards. The Belgian DPA fined Société Wallonne des Eaux €86,000 for lacking a valid legal basis, confirming that Article 6 deficiencies carry significant financial exposure regardless of sector.

Practical Guidance

  • Establish and document a valid Article 6 legal basis for each processing purpose — educational institutions cannot rely on implicit authority; each category of processing (student administration, incident tracking, staff monitoring) requires an identified and recorded lawful ground.

  • Implement a structured redaction protocol for Article 15 access requests — when disclosing documents to students or parents, assess whether third-party staff data can be disclosed or must be redacted, applying a documented balancing test that weighs safety risks, confidentiality of incident reporting, and the data subject's legitimate access interest.

  • Maintain a confidential incident reporting framework — the Zadkine ruling demonstrates that courts will protect the integrity of staff incident reports where unrestricted disclosure would chill future reporting; document this rationale when redacting.

  • Deploy Article 32 technical and organizational measures proportionate to risk — the UODO enforcement action confirms that generic security policies are insufficient; institutions need access controls, encryption, logging, and staff training specifically calibrated to the sensitivity of educational data.

  • Prepare a breach response procedure aligned with EDPB Guidelines 9/2022 — educational institutions handling minors' data face elevated breach notification obligations; establish internal detection, assessment, and notification workflows covering both the 72-hour authority notification and individual notification thresholds.

Everything on this topic, by type links go to the exact provision / paragraph / section
Case Law 1
¶1 Bij besluit van 29 november 2024 heeft het college [appellant] uitgeschreven van de opleiding en hem de toegang tot de gebouwen van onderwijsinstellin… Weggelakte persoonsgegevens is gerechtvaardigd in dit geval gelet op persoonlijke levenssfeer medewerkers en veiligheid van hen en de onderwijsinstelling ¶2 Het college heeft de Afdeling wegens het bestaan van gewichtige redenen verzocht te bepalen dat alleen de Afdeling kennis zal nemen van de ongeschoond… Weggelakte persoonsgegevens is gerechtvaardigd in dit geval gelet op persoonlijke levenssfeer medewerkers en veiligheid van hen en de onderwijsinstelling ¶3 Het college heeft het verzoek gedaan omdat de onder 1) genoemde stukken persoonsgegevens van medewerkers bevatten en het belang van de bescherming van… Weggelakte persoonsgegevens is gerechtvaardigd in dit geval gelet op persoonlijke levenssfeer medewerkers en veiligheid van hen en de onderwijsinstelling ¶7 De Afdeling heeft ook de onder 2) genoemde stukken ingezien. De ongeschoonde versies van deze stukken bevatten persoonsgegevens zoals namen en e-maila… Weggelakte persoonsgegevens is gerechtvaardigd in dit geval gelet op persoonlijke levenssfeer medewerkers en veiligheid van hen en de onderwijsinstelling 210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein CJEU Jun 2018
Guidance 12
§21 Van een wanverhouding is ook sprake in het kader van de arbeidsverhouding 18 . Gezien de afhankelijkheid die voortvloeit uit de relatie tussen werkgev… Richtsnoeren 05/2020 inzake toestemming overeenkomstig Verordening 2016/679 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines on the application of article 651a gdpr Guidelines 03/2021 on the application of Article 65(1)(a) GDPR EDPB May 2023 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 guidelines on virtual voice assistants Guidelines 02/2021 on virtual voice assistants EDPB Jul 2021
Enforcement 446
Belgian Data Protection Authority (APD) Société Wallonne des Eaux: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) May 2026 Polish National Personal Data Protection Office (UODO) Minister of Justice: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) Jun 2026 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) University of Szeged: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Feb 2026 Hellenic Data Protection Authority (HDPA) KEAT - Centre for Education & Rehabilitation of the Blind: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) Feb 2026 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Obuda University: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Feb 2026 Spanish Data Protection Authority (aepd) HOLY MARY CATHOLIC SCHOOL, S.L.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) Mar 2026 Italian Data Protection Authority (Garante) Conservatory: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Feb 2026 Italian Data Protection Authority (Garante) Piacenza Bar Association: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Mar 2026 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Domeniul Public și Privat SA: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Mar 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Hilversum: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Zoetermeer: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Gooise Meren: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Eindhoven: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Ede: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Veenendaal: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Huizen: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Haarlemmermeer: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Hungarian University of Agriculture and Life Sciences: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Jan 2026 Italian Data Protection Authority (Garante) Ministero delle Imprese e del Made in Italy: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Feb 2026 Italian Data Protection Authority (Garante) Het hoger onderwijsinstelling 'Statista Aldo Moro' in Fara Sabina: Onvoldoende wettelijke basis voor de verwerking van gegevens. Italian Data Protection Authority (Garante) Oct 2025 NL Show 426 more →
News 51
noyb - European Center for Digital Rights noyb win: Microsoft 365 Education may not track school children noyb - European Center for Digital Rights Oct 2025 Electronic Frontier Foundation More License Plate Reader Mission Creep: School Residency Verification, Background Checks, and Noise Complaints Electronic Frontier Foundation May 2026 GDPRhub VS Rijeka - Us I-199/2025-9 GDPRhub Jan 2026 GDPRhub VS Rijeka - Us I-199/2025-9 (This appears to be a reference number or code, and is best left as is.) GDPRhub Jan 2026 European Digital Rights Information Integrity & Wikipedia: How community-governed platforms can inform future policy-making. European Digital Rights Feb 2026 Autoriteit Persoonsgegevens HAN fined 175,000 euros for insufficient security of personal data Autoriteit Persoonsgegevens Dec 2025 Autoriteit Persoonsgegevens HAN has been fined €175,000 for inadequate protection of personal data. Autoriteit Persoonsgegevens Dec 2025 GDPRhub ΔΔΚ - 1181/18 GDPRhub Jan 2026 Electronic Frontier Foundation Op-ed: Weakening Section 230 Would Chill Online Speech Electronic Frontier Foundation Feb 2026 Electronic Frontier Foundation Congress Wants To Hand Your Parenting to Big Tech Electronic Frontier Foundation Jan 2026 Electronic Frontier Foundation Speaking Freely: Yazan Badran Electronic Frontier Foundation Feb 2026 Electronic Frontier Foundation RIP Dave Farber, EFF Board Member and Friend Electronic Frontier Foundation Feb 2026 Electronic Frontier Foundation Smart AI Policy Means Examining Its Real Harms and Benefits Electronic Frontier Foundation Feb 2026 University of Twente University of Twente: On the effectiveness of online proctoring using the Proctorio platform. University of Twente Nov 2025 University of Twente University of Twente: Regarding the effectiveness of online proctoring using the Proctorio platform. University of Twente Nov 2025 University of Twente University of Twente: On the Efficacy of Online Proctoring using Proctorio University of Twente Nov 2025 SSRN Legacy Switches: A Proposal to Protect Privacy, Security, Competition, and the Environment from the Internet of Things SSRN Nov 2025 Government Here is the annual report. Government Apr 2025 Government Monitor tailored education MBO. 2024 Measurement Government Apr 2025 Government Monitoring of appropriate education in vocational secondary education. Measurement in 2024. Government Apr 2025 Show 31 more →
Literature 20
European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Cyprus: A Look into the Law for the Effective Application of the GDPR European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Finland: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ France: The French Approach to the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 Innovative STEM Education GDPR - General Data Protection Regulation on Sites Requiring Accessibility Innovative STEM Education Jun 2021 European Data Protection Law Review GDPR Implementation Series ∙ Latvia: The Implementation of the GDPR in a New Legislative Framework European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR European Data Protection Law Review Jan 2017 Journal of Data Protection Privacy General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain Journal of Data Protection Privacy Sep 2021