Skip to content
Topic Contested in court

Education

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing in educational institutions

352 linked items 1 Case Law12 Guidance277 Enforcement42 News20 Literature

Overview

13 sources · Sep 8, 2026

Legal Framework

Processing personal data in educational institutions requires a lawful basis under the GDPR. While consent under Article 7 is theoretically available, the EDPB has flagged that dependency relationships inherent to institutional settings undermine voluntariness. The EDPB's reasoning on employer-employee dynamics applies by analogy to publicly funded schools and other educational settings where students occupy a subordinate position:

"Gezien de afhankelijkheid die voortvloeit uit de relatie tussen werkgever en werknemer, is het onwaarschijnlijk dat de betrokkene zijn werkgever toestemming voor gegevensverwerking zou kunnen weigeren"
— EDPB Guidelines 05/2020, §21

Educational institutions must therefore look to Article 6(1)(c) (legal obligation), Article 6(1)(e) (public task), or Article 6(1)(f) (legitimate interests) for most routine processing. Where special category data is involved — health records, psychological assessments — Article 9 restrictions apply, requiring additional conditions under Article 9(2).

Key Developments

The Raad van State's Zadkine ruling demonstrates how courts handle the tension between student access rights and staff privacy in educational settings. The institution expelled a student whose conduct constituted a serious threat to order and safety. When the student sought access to unredacted internal documents — including teacher notes from the Eduarte information system and incident reports — the institution requested that only the court review the unredacted versions.

The institution's rationale was that disclosing staff personal data would create a real risk:

"Er bestaat volgens het college een reëel risico dat het verstrekken van deze gegevens leidt tot onwenselijke situaties."
— Raad van State, Zadkine

The Afdeling endorsed this approach, confirming that protecting staff privacy and confidential incident reporting serves the institution's proper functioning:

"De Afdeling acht het verzoek tot beperkte kennisneming van deze stukken gerechtvaardigd."
— Raad van State, Zadkine

This ruling reinforces that educational institutions can restrict access to unredacted personal data of staff where safety and confidentiality interests outweigh the individual's access interest.

Status of the Debate

This topic is actively litigated. The Zadkine ruling aligns with the earlier Afdeling decision in ECLI:NL:RVS:2023:2816, building a consistent — but still developing — body of administrative case law on how educational institutions balance staff privacy against student transparency rights. No court split is on record, but the precise threshold for when safety concerns justify withholding unredacted documents remains fact-specific and contested. Enforcement actions by DPAs — including the UODO's fine against the Polish Minister of Justice for insufficient technical and organisational measures — underscore that institutions face regulatory scrutiny alongside private litigation.

Practical Guidance

  • Do not rely on consent as the primary legal basis for processing student or staff data in publicly funded educational institutions; the power imbalance makes consent vulnerable to challenge under EDPB guidance.
  • Apply a documented balancing test before disclosing staff personal data in proceedings involving students, weighing the institution's safety and functioning interests against the individual's access rights.
  • Redact staff personal data in documents shared with students where safety concerns are present, and request restricted judicial review of unredacted versions where necessary.
  • Maintain confidential incident reporting channels; the Zadkine ruling supports restricting access where unrestricted disclosure would chill future reporting by staff or third parties.
  • Implement technical and organisational measures proportionate to the sensitivity of educational data, as enforcement actions show that DPA fines target institutions that fail on this front.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 1/2018 certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation Guidelines ·EDPB Guidance EDPB Jun 2019 example of EU-wide certification
why this is here
An international School offering schooling to data subjects in the Union is based in Member State “A”.

The document uses an education example to illustrate how a European Data Protection Seal should accommodate national regulations.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 05/2020 consent under Regulation 2016/679 Guidelines on consent Guidelines ·EDPB Guidance EDPB May 2020 consent in public school example
why this is here
A public school asks students for consent to use their photographs in a printed student magazine.

Provides an example involving a school but does not address educational data processing generally.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

University of Twente: On the Efficacy of Online Proctoring using Proctorio The results of a controlled experiment using Proctorio, an online proctoring system, show that it is ineffective at detecting cheating. News University of Twente Nov 2025 university online exam integrity
why this is here
The results of a controlled experiment using Proctorio, an online proctoring system, show that it is ineffective at detecting cheating.

Directly addresses processing of student data and exam integrity in a university context, a core educational processing activity.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

HAN fined 175,000 euros for insufficient security of personal data ⇄ De Autoriteit Persoonsgegevens (AP) legt HAN University of Applied Sciences (HAN) een boete op van 175.000 euro voor het overtreden van de Algemene verordening gegevensbescherming… News Autoriteit Persoonsgegevens Dec 2025 University as data controller
why this is here
HAN University of Applied Sciences (HAN)

The document involves a university, but the core issue is security, not educational data processing specifics; it supports the education topic only as the context of the data controller.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 277 Enforcement · all 42 News