In short
Two documents, same day, same subject. The difference is the trackers: prohibited in principle at school, discouraged at university. The student is an adult but in a situation of subordination, so they remain a vulnerable person for DPIA purposes and consent still does not work as a legal basis.
The one real difference
In the school text the CNIL writes that the controller must make sure the tool does not use advertising trackers, «in principle prohibited» because of the neutrality of the public education service, which includes commercial neutrality. If they are there, they must be switched off.
In the higher education text the same authority, on the same day, «recommends preferring tools that do not involve, on the supplier's part, the use of trackers or tracking devices for advertising exploitation, profiling or commercial reuse of the data, or for which such features can be disabled by the establishment». Recommends: it does not prohibit. And the neutrality principle of the public education service is not invoked.
This is not an oversight. The school prohibition rests on a principle concerning the public service of school education; higher education has its own framework. For a DPO the practical consequence is concrete: the tracker conclusion written in a secondary school's DPIA cannot be copied into a university's, because the legal premise is not the same.
The student is an adult, and still vulnerable
On vulnerability the CNIL does not retreat. In the university text it justifies the recommendation to protect data against the risk of disclosure to third-country authorities precisely by «the vulnerability of the data subjects, in particular students, who are in a situation of subordination».
Subordination has two effects. In the legal basis analysis it rules out consent, which must be freely given and not influenced by the controller's position of authority: the student must be able to refuse without negative consequences, and cannot. In the DPIA analysis it triggers the vulnerable persons criterion, exactly as minors do.
What does not change
- Legal basis: performance of a task in the public interest, for public and private establishments alike.
- A notice that is concise, transparent, intelligible and easily accessible (articles 12, 13 and 14), available before the processing starts and repeated at the start of each year.
- DPIA mandatory where two EDPB criteria are met, and likely in most cases.
- Processor guarantees under article 28 and a contract with the mandatory terms, including end-of-contract clauses on reversibility and deletion.
- Transfers under chapter V, with SecNumCloud cited as an example of exclusive submission to European law.
What is missing at university
Two things present in the school text do not appear in the university one: the reference to article L.131-2 of the education code, which concerns the public digital education service at school level, and décret no. 2025-1165 of 5 December 2025, which constrains the technical choices of public collèges and lycées. Universities are free on that front, and more exposed on the other: the choice has to be reasoned in the DPIA, not delegated to the supplier.
The mistake to avoid
Treating the two documents as one. They are twins for eighty per cent of their length and diverge exactly where the purchasing decision is usually made: whether a tool with advertising trackers is acceptable. At school the answer is no. At university it is «better not, and if they are there they must be capable of being switched off».
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free