Educational Data: Sovereignty and Governance in the Age of AI
The EU AI Act, GDPR, Switzerland's revised FADP, FERPA: educational AI operates within a dense legal framework, handling some of the most sensitive data of all.
The EU AI Act, GDPR, Switzerland's revised FADP, FERPA: educational AI operates within a dense legal framework, handling some of the most sensitive data of all.
Schools handle some of the most sensitive data there is: that of minors, about their difficulties, sometimes their health, their intimate progress. Entrusting this data to AI systems — often hosted outside the country, even outside the continent — is not a technical detail; it is a governance decision. The legal framework has grown considerably denser, and it now structures what is permitted.
The European AI Act (Regulation 2024/1689) explicitly classifies several educational uses as 'high-risk': deciding access or admission, evaluating learning outcomes, steering a learner's path, or detecting prohibited behaviour during exams [1]. This classification, set out in Article 6 and Annex III, triggers heavy obligations: risk management, data quality, transparency, human oversight [2]. A system that grades or steers students is no gadget: it is a regulated device.
Beyond the AI Act, personal-data protection applies fully. The EU's GDPR (2016/679) mandates a legal basis, minimisation, purpose limitation and data-subject rights [3]. In Switzerland, the revised Federal Act on Data Protection (FADP, in force since 1 September 2023) modernises this framework: breach notification, impact assessments for high-risk processing, a broadened definition of sensitive data, extraterritorial scope [4]. In the United States, FERPA specifically protects education records [5]. Three regimes, one shared requirement: the student's data does not belong to the vendor.
Legal compliance does not settle everything. There remains the question of sovereignty: on what territory is data processed, under which jurisdiction, with what dependence on foreign providers? For many European and Swiss institutions, the answer leans toward controlled architectures — local or national processing, minimisation, sub-processor control, reversibility. The most responsible educational AI is often the one that keeps data close to the learner.
Privacy is not a brake on educational innovation: it is the condition of the trust that makes it possible.
Learnya synthesis
The OECD and UNESCO converge on this point: deploying AI in education must be subordinate to data protection, equity and a human-centred vision [6][7]. Technology moves fast; governance must move with it, not behind it.
Regulatory compliance is a floor, not a ceiling. Respecting the AI Act, GDPR or the FADP is indispensable, but not enough to establish the trust of families, students and teachers. That trust is earned through visible choices: minimising collected data, clearly explaining what it is for, offering real control, and avoiding opaque reuse for commercial purposes or training third-party models.
The localisation question illustrates the gap between legality and sovereignty well. Processing can be legal while depending on a provider subject to a foreign jurisdiction, with the uncertainties that entails about data access. For many European and Swiss educational actors, favouring national or regional hosting and controlled sub-processors is not excessive caution: it is a way of keeping control of data that concerns minors for years.
Finally, governance must be alive. An impact assessment done once and forgotten protects no one. High-risk uses — grading, steering, exam monitoring [1] — call for continuous follow-up: measuring bias, reassessing purposes, documenting human decisions. Technology moves fast; frozen governance quickly becomes governance in name only. It is the alliance of compliance, sovereignty and vigilance that makes educational AI trustworthy.
Data protection is often presented as a brake on innovation. Experience suggests the opposite: in a domain as sensitive as the education of minors, trust is the first driver of adoption. An institution, families and teachers will accept AI all the more readily when they know where the data goes and who controls it. Sovereignty then becomes a competitive and pedagogical advantage, not an imposed constraint.
As the AI Act rolls out and case law sharpens, actors who have built compliance and data control in from the start will be best placed. The point is not to choose between innovation and protection, but to make the latter the foundation of the former. This is especially true in the European and Swiss space, where the demand for privacy is both a value and a strong expectation.