In short
Advertising trackers prohibited in principle, on grounds of the commercial neutrality of the public service. Legal basis: public interest task, not consent. A DPIA is mandatory where two EDPB criteria are met, and with minors the first one is met immediately. For public collèges and lycées, décret no. 2025-1165 of 5 December 2025 applies on top.
Commercial neutrality is not a recommendation
Here the CNIL does not hedge. The controller must make sure the tool does not use advertising trackers, which are «in principle prohibited» because of the neutrality of the public education service, which includes commercial neutrality. If the tool does use tracking devices for advertising exploitation or profiling, the controller must disable those features.
This rule does not come from the GDPR and cannot be solved with a consent box: it comes from public service law. A supplier who answers «the user can refuse» has not answered the question.
Why consent does not hold
Where using collaborative tools for teaching involves processing personal data, the controller must first determine the legal basis for each operation. If the processing serves the school's public service tasks — whether the school is public or private, and in particular the public digital education service under article L.131-2 of the education code — the basis is the performance of a task carried out in the public interest.
Consent, the CNIL writes, can hardly be relied on: to be valid it must be freely given, that is neither coerced nor influenced by the controller's position of authority. A pupil, their legal guardian or a teacher must be able to refuse without suffering negative consequences, and in a school setting that condition is not met.
A DPIA, nearly always
Three of the EDPB criteria are relevant here: processing concerning vulnerable persons, large-scale processing, and processing of sensitive data. Minors fall into the first category — and so does administrative and teaching staff when in a relationship of subordination.
Where at least two criteria are met, the DPIA must be carried out before the processing starts. The CNIL adds that in most cases it is likely to be necessary, and that where there is doubt it is better to do it. The controller can ask its DPO for assistance, and can call on the tool's supplier, who as a processor must help under article 28(3)(f).
The privacy notice has to be written for whoever must read it
The notice must be concise, transparent, intelligible and easily accessible (articles 12, 13 and 14). For minors the CNIL asks that it be adapted to their age: plain language following ISO 24495-1:2023 and ISO 24495-2:2025, or the «easy to read and understand» method for people with reading difficulties or disabilities.
- Before the processing begins, for example at first login to the tool.
- Also by email to everyone concerned.
- And again at the start of each school year: in primary schools, at the parents' meeting.
The decree that narrows the choice
For public collèges and lycées the GDPR is not the whole story. Décret no. 2025-1165 of 5 December 2025, on the reference framework for digital technology in education, requires the use of digital tools and services meeting technical requirements on security, interoperability and responsible digital practice set by the minister.
What to ask the supplier before signing
If the tool uses advertising trackers, how they are disabled and who verifies it. The article 28 guarantees: data protection policy, terms of use, information security policy, any ISO 27000 certification or code of conduct. Assistance with the DPIA. End-of-contract clauses on reversibility and deletion. On transfers, the CNIL cites ANSSI's SecNumCloud qualification as an example guaranteeing that the provider is subject to European law alone.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free