How does the GDPR apply to EdTech behavioral data?
Setting legal basis, minimization and DPIA for behavioral data EdTech platforms collect on minor students.
Student data governance is the discipline that regulates how a school or an EdTech company collects, processes and retains the behavioral data generated by adaptive learning platforms: quiz attempts, time spent on each item, navigation path, and in some systems even attention or frustration signals inferred from interaction. The starting point is Art. 8 of EU Regulation 2016/679 (GDPR): when a service is offered directly to a minor, consent is valid from age 16, but each Member State may lower that threshold down to a minimum of 13; Italy set it at 14 under Art. 2-quinquies of Legislative Decree 196/2003. Below that age, consent must come from whoever holds parental responsibility, verified with reasonable measures given available technology. In a school setting, though, the most common legal basis is not consent but a public interest task or a legal obligation of the school, which shifts the focus from "who signed" to "how much data is actually collected and for how long".
What makes the processing sensitive
Three factors compound. First, the subject is almost always a minor, a category for which the GDPR demands reinforced protection precisely because they are less aware of the risks of processing. Second, the data is not just biographical but behavioral and continuous: an adaptive learning platform builds a granular profile over time of how a student thinks and reacts, not just what they know. Third, when that profile feeds a system that decides or influences a student's access, evaluation or learning path, the system may fall under Annex III of the AI Act as a high-risk system: this entry owns the upstream data governance that feeds those systems (legal basis, minimization, DPIA, controller and processor roles), not the classification of the system itself.
An enterprise example
A secondary school adopts an EdTech vendor's adaptive math platform, which logs logins, time per exercise, number of attempts and error path to personalize the content sequence. Before adoption, the school must clarify its own role as data controller and the vendor's as processor under Art. 28, with an agreement binding the vendor not to reuse the data for its own purposes such as training commercial models. Since this is systematic profiling of minors, a data protection impact assessment (DPIA) is almost always required before activation: the DPIA must verify that the data collected is minimized against the educational purpose, that the more intrusive behavioral signals such as emotion analysis are disabled absent demonstrated need, and that data is retained only for the duration of the school program, with anonymization before any statistical or research use.
Why it matters for decision makers
Whoever supplies or purchases an EdTech platform that profiles minor students needs to answer four questions before signing: which legal basis covers the collection, which party between school and vendor is controller and which is processor, whether a DPIA was conducted and with what outcome, and how long behavioral data is retained after the course ends. An EdTech company that cannot answer these questions exposes both itself and every school client to regulatory scrutiny, with the obligation to delete data collected without sufficient legal basis. It is the same exercise required for any processing of personal data of a vulnerable category, with schools as a highly visible context and algorithmic profiling of minors as a point of maximum regulatory attention in the coming years.
This entry is informational and does not constitute legal advice: for decisions on the processing of minors' data, involve your DPO or legal counsel.
Related terms
- Algorithmic admissions · Algorithmic scoring for access to schools and courses: high risk under the AI Act, almost always without exceptions.
- Data governance · The rules, roles and processes that make company data reliable, secure and usable: who can do what, on which data, at what quality.
- Athlete data governance · Governing biometric and performance data collected by athlete wearables as GDPR health data, not as sports metrics.
- Data Controller vs Data Processor · The controller decides the purpose and means of processing and is accountable; the processor handles data on the controller's documented instructions via a DPA.
- Anonymization vs pseudonymization · Pseudonymization stays personal data and is reversible with a key; anonymization must be irreversible.
A term that hits close to home? Let's talk.
CONTACT ME