All news
Regulation August 24, 2026 6 min

In schools, advertising trackers are prohibited — and consent has nothing to do with it

The CNIL publishes the rules for collaborative tools in primary and secondary education: the commercial neutrality of the public education service rules them out in principle, and a DPIA is almost always mandatory

In short

Advertising trackers prohibited in principle, on grounds of the commercial neutrality of the public service. Legal basis: public interest task, not consent. A DPIA is mandatory where two EDPB criteria are met, and with minors the first one is met immediately. For public collèges and lycées, décret no. 2025-1165 of 5 December 2025 applies on top.

Commercial neutrality is not a recommendation

Here the CNIL does not hedge. The controller must make sure the tool does not use advertising trackers, which are «in principle prohibited» because of the neutrality of the public education service, which includes commercial neutrality. If the tool does use tracking devices for advertising exploitation or profiling, the controller must disable those features.

This rule does not come from the GDPR and cannot be solved with a consent box: it comes from public service law. A supplier who answers «the user can refuse» has not answered the question.

Why consent does not hold

Where using collaborative tools for teaching involves processing personal data, the controller must first determine the legal basis for each operation. If the processing serves the school's public service tasks — whether the school is public or private, and in particular the public digital education service under article L.131-2 of the education code — the basis is the performance of a task carried out in the public interest.

Consent, the CNIL writes, can hardly be relied on: to be valid it must be freely given, that is neither coerced nor influenced by the controller's position of authority. A pupil, their legal guardian or a teacher must be able to refuse without suffering negative consequences, and in a school setting that condition is not met.

A DPIA, nearly always

Three of the EDPB criteria are relevant here: processing concerning vulnerable persons, large-scale processing, and processing of sensitive data. Minors fall into the first category — and so does administrative and teaching staff when in a relationship of subordination.

Where at least two criteria are met, the DPIA must be carried out before the processing starts. The CNIL adds that in most cases it is likely to be necessary, and that where there is doubt it is better to do it. The controller can ask its DPO for assistance, and can call on the tool's supplier, who as a processor must help under article 28(3)(f).

The privacy notice has to be written for whoever must read it

The notice must be concise, transparent, intelligible and easily accessible (articles 12, 13 and 14). For minors the CNIL asks that it be adapted to their age: plain language following ISO 24495-1:2023 and ISO 24495-2:2025, or the «easy to read and understand» method for people with reading difficulties or disabilities.

  • Before the processing begins, for example at first login to the tool.
  • Also by email to everyone concerned.
  • And again at the start of each school year: in primary schools, at the parents' meeting.

The decree that narrows the choice

For public collèges and lycées the GDPR is not the whole story. Décret no. 2025-1165 of 5 December 2025, on the reference framework for digital technology in education, requires the use of digital tools and services meeting technical requirements on security, interoperability and responsible digital practice set by the minister.

What to ask the supplier before signing

If the tool uses advertising trackers, how they are disabled and who verifies it. The article 28 guarantees: data protection policy, terms of use, information security policy, any ISO 27000 certification or code of conduct. Assistance with the DPIA. End-of-contract clauses on reversibility and deletion. On transfers, the CNIL cites ANSSI's SecNumCloud qualification as an example guaranteeing that the provider is subject to European law alone.

Official source:CNIL — Enseignement du premier et du second degrés : les règles et bonnes pratiques pour utiliser les outils collaboratifs en ligne (24 août 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2documents on the same subject, with one rule apart

Same tool, same day, different rule: why trackers are not banned at university

On 24 August the CNIL published two texts on the same subject, one for schools and one for universities. Anyone who reads only the first and applies it to the second gets one specific thing wrong: in schools advertising trackers are «in principle prohibited», while in higher education the CNIL «recommends preferring» tools that do not use them. Everything else — legal basis, DPIA, processor guarantees, transfers — is the same.

Aug 24, 2026New 5 min