Learnya/ Blog

Educational Data: Sovereignty and Governance in the Age of AI

The EU AI Act, GDPR, Switzerland's revised FADP, FERPA: educational AI operates within a dense legal framework, handling some of the most sensitive data of all.

Server room in a data center
BalticServers.com (Fleshas), Wikimedia Commons  · CC BY-SA 3.0

Schools handle some of the most sensitive data there is: that of minors, about their difficulties, sometimes their health, their intimate progress. Entrusting this data to AI systems — often hosted outside the country, even outside the continent — is not a technical detail; it is a governance decision. The legal framework has grown considerably denser, and it now structures what is permitted.

Educational AI, a high-risk use in Europe

The European AI Act (Regulation 2024/1689) explicitly classifies several educational uses as 'high-risk': deciding access or admission, evaluating learning outcomes, steering a learner's path, or detecting prohibited behaviour during exams [1]. This classification, set out in Article 6 and Annex III, triggers heavy obligations: risk management, data quality, transparency, human oversight [2]. A system that grades or steers students is no gadget: it is a regulated device.

GDPR, FADP, FERPA: protecting people

Beyond the AI Act, personal-data protection applies fully. The EU's GDPR (2016/679) mandates a legal basis, minimisation, purpose limitation and data-subject rights [3]. In Switzerland, the revised Federal Act on Data Protection (FADP, in force since 1 September 2023) modernises this framework: breach notification, impact assessments for high-risk processing, a broadened definition of sensitive data, extraterritorial scope [4]. In the United States, FERPA specifically protects education records [5]. Three regimes, one shared requirement: the student's data does not belong to the vendor.

Sovereignty: where data lives, who governs it

Legal compliance does not settle everything. There remains the question of sovereignty: on what territory is data processed, under which jurisdiction, with what dependence on foreign providers? For many European and Swiss institutions, the answer leans toward controlled architectures — local or national processing, minimisation, sub-processor control, reversibility. The most responsible educational AI is often the one that keeps data close to the learner.

  • Map the data processed and its legal basis before any deployment.
  • Require providers to guarantee localisation, reversibility and no data reuse.
  • Run an impact assessment for high-risk uses (grading, steering).
  • Keep genuine human oversight over high-stakes decisions.

Privacy is not a brake on educational innovation: it is the condition of the trust that makes it possible.

Learnya synthesis

The OECD and UNESCO converge on this point: deploying AI in education must be subordinate to data protection, equity and a human-centred vision [6][7]. Technology moves fast; governance must move with it, not behind it.

From compliance to trust

Regulatory compliance is a floor, not a ceiling. Respecting the AI Act, GDPR or the FADP is indispensable, but not enough to establish the trust of families, students and teachers. That trust is earned through visible choices: minimising collected data, clearly explaining what it is for, offering real control, and avoiding opaque reuse for commercial purposes or training third-party models.

The localisation question illustrates the gap between legality and sovereignty well. Processing can be legal while depending on a provider subject to a foreign jurisdiction, with the uncertainties that entails about data access. For many European and Swiss educational actors, favouring national or regional hosting and controlled sub-processors is not excessive caution: it is a way of keeping control of data that concerns minors for years.

Finally, governance must be alive. An impact assessment done once and forgotten protects no one. High-risk uses — grading, steering, exam monitoring [1] — call for continuous follow-up: measuring bias, reassessing purposes, documenting human decisions. Technology moves fast; frozen governance quickly becomes governance in name only. It is the alliance of compliance, sovereignty and vigilance that makes educational AI trustworthy.

Sovereignty as an advantage, not a constraint

Data protection is often presented as a brake on innovation. Experience suggests the opposite: in a domain as sensitive as the education of minors, trust is the first driver of adoption. An institution, families and teachers will accept AI all the more readily when they know where the data goes and who controls it. Sovereignty then becomes a competitive and pedagogical advantage, not an imposed constraint.

As the AI Act rolls out and case law sharpens, actors who have built compliance and data control in from the start will be best placed. The point is not to choose between innovation and protection, but to make the latter the foundation of the former. This is especially true in the European and Swiss space, where the demand for privacy is both a value and a strong expectation.

Sources

  1. 1. Annex III: High-Risk AI Systems Referred to in Article 6(2) — point 3, Education and vocational training , Regulation (EU) 2024/1689 (EU AI Act) , European Union , 2024 https://artificialintelligenceact.eu/annex/3/
  2. 2. Article 6: Classification Rules for High-Risk AI Systems , Regulation (EU) 2024/1689 (EU AI Act) , European Union , 2024 https://artificialintelligenceact.eu/article/6/
  3. 3. General Data Protection Regulation (GDPR), Regulation (EU) 2016/679 , European Parliament and Council , EUR-Lex , 2016 https://eur-lex.europa.eu/eli/reg/2016/679/oj
  4. 4. Federal Act on Data Protection (FADP), SR 235.1 (revised, in force 1 Sept 2023) , Swiss Confederation , Fedlex , 2023 https://www.fedlex.admin.ch/eli/cc/2022/491/en
  5. 5. Family Educational Rights and Privacy Act (FERPA) , U.S. Department of Education, Student Privacy Policy Office , U.S. Department of Education , 2024 https://studentprivacy.ed.gov/ferpa
  6. 6. Opportunities, guidelines and guardrails for effective and equitable use of AI in education (Digital Education Outlook 2023) , OECD & Education International , OECD , 2023 https://www.oecd.org/en/publications/oecd-digital-education-outlook-2023_c74f03de-en/full-report/opportunities-guidelines-and-guardrails-for-effective-and-equitable-use-of-ai-in-education_2f0862dc.html
  7. 7. Guidance for generative AI in education and research , UNESCO , UNESCO , 2023 https://www.unesco.org/en/articles/guidance-generative-ai-education-and-research
← All articles