Edesio
Security
December 15, 2025
7 min read

GDPR and Student Data: Our Commitment

Edesio Team

Author

Personal data protection in education is not optional—it is a legal and ethical obligation. As a platform processing student data, often from minors, Edesio is committed to full compliance with the GDPR and CNIL recommendations. Here is how we protect your students' data.

The legal framework: GDPR and education-specific rules

The General Data Protection Regulation (GDPR) applies fully to the education sector. In France, the CNIL (National Commission for Information Technology and Civil Liberties) issues specific recommendations for schools, taking into account the particular sensitivity of minors' data.

15 years: the age of digital majority in France

Source: CNIL

Data controllers in the French national education system:

  • DASEN (Academic Director) for primary education
  • School principal for secondary education (middle and high school)
  • Obligation to appoint a Data Protection Officer (DPO)
  • Mandatory maintenance of a record of processing activities

The risks of American solutions

"The U.S. CLOUD Act allows American authorities to access data stored by American companies, regardless of where the servers are located."

CNIL

The CNIL has repeatedly warned about the risks associated with using American tools such as Microsoft Teams or Google Workspace in an educational context. These solutions, even with servers in Europe, remain subject to American law, which can constitute a GDPR violation.

Edesio's commitments

Edesio uses exclusively French and European technologies to ensure that your data remains under European jurisdiction.

Our data protection guarantees:

  • Mistral AI: French technology, data processed in Europe
  • Supabase hosting: servers in the European Union
  • Encryption of data in transit and at rest
  • No transfer of data outside the EU
  • Right of access, rectification, and deletion respected
  • No resale or sharing of data with third parties

Enhanced protection for minors

For students under 15, the GDPR imposes additional protections. Parental consent is required for non-essential services. At Edesio, we apply the principle of data minimization: we only collect data strictly necessary for the service to function.

Data collected by Edesio:

  • First and last name (for identification)
  • Email address (for login)
  • Answers to questions (for pedagogical tracking)
  • Progress statistics (for rankings)
  • No sensitive data (health, religion, etc.) is collected

Transparency and user rights

In accordance with the GDPR, we guarantee all users the exercise of their rights:

Guaranteed rights:

  • Right of access: view all data concerning you
  • Right of rectification: correct inaccurate information
  • Right to erasure: request deletion of your data
  • Right to portability: retrieve your data in a standard format
  • Right to object: refuse certain non-essential processing

Data breach notification

In the event of a data breach, we commit to notifying the CNIL within 72 hours and informing affected users as soon as possible. Our technical team continuously monitors the security of our infrastructure to prevent any incident.

By choosing Edesio, you opt for a solution designed from the outset to comply with the GDPR and protect your students' data.

Sources and references

Ready to transform your lessons with AI?

Discover how Edesio can help you create engaging learning experiences for your students.

Suggested articles

Education

Artificial Intelligence in French Education: 2026 State of Play

How AI is transforming traditional teaching methods and enabling personalized learning for every student. 2026 data analysis.

Technology

Mistral AI: The French AI That Protects Your Data

Discover why we chose Mistral AI, the French artificial intelligence solution, to guarantee the sovereignty of your educational data.