A multi-year Danish investigation into a single municipality's Chromebooks eventually found 53 municipalities sharing student data with Google unlawfully — a pattern that's directly relevant to any EU school evaluating US-based EdTech.
How the Case Unfolded
On 14 July 2022, Denmark's data protection authority (Datatilsynet) issued a reprimand against Helsingør Municipality and imposed a general ban on using Google Chromebooks and Google Workspace in its primary schools, suspending related data transfers to the US until GDPR compliance could be demonstrated. A second decision on 18 August 2022 confirmed the ban, finding the municipality hadn't adequately documented and reduced the risks to pupils' rights. A third decision temporarily lifted the ban pending further clarification of the data processing agreement, and in a fifth decision dated 30 January 2024, the Danish DPA extended its investigation to 53 municipalities, finding they had unlawfully shared students' personal data with Google for some of Google's own development purposes — a violation of GDPR's purpose limitation principle under Article 6(1)(e).
The core legal issue throughout has centered on international data transfers: whether Google's contractual and technical safeguards for transferring EU student data to the US genuinely meet GDPR's requirements for third-country transfers, particularly following the Schrems II ruling that invalidated the previous EU-US Privacy Shield framework.
Why This Matters Beyond Denmark
GDPR is enforced by each member state's own data protection authority, and while a Danish ruling doesn't automatically bind schools in other EU countries, the underlying legal analysis applies EU-wide — any school or EdTech platform relying on a US-based cloud provider faces the same fundamental transfer-mechanism questions. This case is one of the clearest, most detailed public examples of a data protection authority actually working through what compliant EdTech data handling requires in practice, which makes it a useful reference regardless of jurisdiction.
What Schools and EdTech Providers Should Actually Check
- Confirm whether any student data is transferred outside the EU/EEA, and if so, what specific legal transfer mechanism (Standard Contractual Clauses, an adequacy decision, or another safeguard) applies — a general assurance of "GDPR compliance" from a vendor isn't sufficient documentation on its own.
- Conduct and retain a genuine data protection impact assessment (DPIA) — the Danish DPA specifically found the municipality's initial DPIA inadequate, not absent.
- Check whether the vendor's terms permit using student data for the vendor's own product development or improvement purposes — this was the specific violation found in the 2024 decision, separate from the transfer issue.
- Review the actual data processing agreement, not just marketing claims about privacy — the commercial and technical terms are what regulators examine.
- Document ongoing monitoring, not just a one-time assessment — the multi-year, multi-decision nature of this case shows regulators expect continued compliance, not a single point-in-time check.
Related Kibbo Tools
Sources
- GDPRhub — Datatilsynet (Denmark) - 2023-431-0001. gdprhub.eu
- European Data Protection Law Review — Danish DPA Banned the Use of Google Chromebooks and Google Workspace in Schools in Helsingør Municipality. edpl.lexxion.eu