[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9XnbYXCOMUKm1b_AbHs1EuYeak74bu9PI3n3prqvIg0":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"625e68d9-1cc1-4925-9cae-5f3f08fe76b7","Tietosuojavaltuutetun toimisto (Finland) - TSV\u002F40\u002F2018","tietosuojavaltuutetun-toimisto-finland-tsv-40-2018-80cdac","Created page with \"{{DPAdecisionBOX |Jurisdiction=Finland |DPA-BG-Color= |DPAlogo=LogoFI.png |DPA_Abbrevation=Tietosuojavaltuutetun toimisto |DPA_With_Country=Tietosuojavaltuutetun toimisto (Finland) |Case_Number_Name=TSV\u002F40\u002F2018 |ECLI= |Original_Source_Name_1=Finlex |Original_Source_Link_1=https:\u002F\u002Fwww.finlex.fi\u002Ffi\u002Fviranomaiset\u002Ftietosuojavaltuutettu\u002F2026\u002F27 |Original_Source_Language_1=Finnish |Original_Source_Language__Code_1=FI |Original_Source_Name_2= |Original_Source_Link_2= |Orig...\" New page {{DPAdecisionBOX |Jurisdiction=Finland |DPA-BG-Color= |DPAlogo=LogoFI.png |DPA_Abbrevation=Tietosuojavaltuutetun toimisto |DPA_With_Country=Tietosuojavaltuutetun toimisto (Finland) |Case_Number_Name=TSV\u002F40\u002F2018 |ECLI= |Original_Source_Name_1=Finlex |Original_Source_Link_1=https:\u002F\u002Fwww.finlex.fi\u002Ffi\u002Fviranomaiset\u002Ftietosuojavaltuutettu\u002F2026\u002F27 |Original_Source_Language_1=Finnish |Original_Source_Language__Code_1=FI |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Other |Outcome= |Date_Started= |Date_Decided=04.09.2026 |Date_Published=04.09.2026 |Year=2026 |Fine= |Currency= |GDPR_Article_1=Article 6(1)(c) GDPR |GDPR_Article_Link_1=Article 6 GDPR#1c |GDPR_Article_2= |GDPR_Article_Link_2= |GDPR_Article_3= |GDPR_Article_Link_3= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1= |National_Law_Link_1= |National_Law_Name_2= |National_Law_Link_2= |Party_Name_1=Espoon kaupunki |Party_Link_1=https:\u002F\u002Fwww.espoo.fi\u002Fen |Party_Name_2=Google |Party_Link_2= |Party_Name_3= |Party_Link_3= |Party_Name_4= |Party_Link_4= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status=Unknown |Appeal_To_Link= |Initial_Contributor=av | }} The DPA ordered a city to ensure that the personal data of pupils collected when using digital learning tools was only processed to fulfill the controller’s educational obligations. == English Summary == === Facts === In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from pupils’ (the data subjects’) parents. The controller clarified that it used a number of Google applications for educational purposes, including Google Classroom, Google Drive, and Google Docs. It invoked [[Article 6 GDPR|Article 6(1)(c) GDPR]] as the legal basis for the processing. According to the controller, the processing of personal data in connection with using these services was necessary to comply with the obligation to provide basic education laid down in the Finnish Basic Education Act. The DPA issued a decision in case 1509\u002F452\u002F18 in December 2021. This decision was appealed to the Supreme Administrative Court, which referred the case back to the DPA in its decision KHO:2025:29 in April 2025. The Supreme Administrative Court held that the DPA could not conclude [[Article 6 GDPR|Article 6(1)(c) GDPR]] was not applicable in any respect as a legal basis for the processing. In the present proceedings, the DPA was to decide the extent to which the controller could invoke the compliance with a legal obligation as a legal basis for the processing of personal data related to the use of Google’s digital learning tools. === Holding === The DPA ordered the controller to ensure that the personal data of pupils collected in connection with the use of Google's digital learning tools was solely processed for the purpose of fulfilling the controller's educational obligations. The processing could be based on Article 6(1)(c) only under these conditions. The DPA held that the controller could invoke Article 6(1)(c) as a legal basis for the use of learning tools essential to teaching. In addition, the processing must be carried out solely to fulfill educational obligations. The DPA pointed out that this legal basis applies to the use of tools that are central to teaching, such as text editors, calendars, email, presentation software, and programs intended for subject-specific instruction (such as language or math applications). When assessing the necessity requirement, the DPA took into account that digital learning tools can enable the extensive and long-term collection and other processing of school-aged children’s personal data by and for the benefit of external entities. Therefore, it held that the controller may not disclose or otherwise grant access to this data to the controller or other parties in a way that allows the controller to process the data for its own purposes, such as developing the learning tools or other services. == Comment == ''Share your comments here!'' == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the Finnish original. Please refer to the Finnish original for more details. Use of Google’s Educational Program in Schools Keywords Legal basis for processing personal data Year of the case 2026 Date of issuance September 4, 2026 Reference number TSV\u002F40\u002F2018 Legal Basis Decision pursuant to the EU General Data Protection Regulation Decision of the Data Protection Ombudsman Subject Use of Google’s educational software in schools Data Controller Data Controller: City of Espoo The Data Protection Ombudsman issued a decision in case 1509\u002F452\u002F18 on December 30, 2021. In its decision KHO:2025:29 issued on April 8, 2025, the Supreme Administrative Court remanded the matter to the Data Protection Ombudsman for further consideration. Contact from the complainant On April 30, 2018, the complainant contacted the Office of the Data Protection Ombudsman and reported that a school in Espoo uses Google’s educational software in its teaching but does not request parental consent for this. Statement received from the data controller The Office of the Data Protection Ombudsman requested a statement from the data controller via a request for information dated July 1, 2020, as well as via requests for additional information dated September 7, 2020, and November 22,2021. The data controller submitted a written explanation on August 14, 2020, and additional explanations on September 28, 2020, and November 26, 2021. After the Supreme Administrative Court referred the matter back to the Data Protection Ombudsman for consideration, the Office of the Data Protection Ombudsman requested on July 16,2025, the Office of the Data Protection Ombudsman requested a report from the data controller regarding the applications in use at the time of the investigation. The data controller provided a written report on this matter on August 27, 2025, and clarified its responses with a supplementary report at the request of the Office of the Data Protection Ombudsman on October 6, 2025. In its report, the data controller stated that it does not seek parental consent for the use of Google’s educational program; rather, the legal basis for processing is Article 6(1)(c) of the General Data Protection Regulation (compliance with a legal obligation). According to the data controller, the processing of personal data is necessary for the organization of basic education in accordance with the Basic Education Act. However, the Department of Education asks guardians to accept the terms of use for information and communication technology services, which describe the types of services used in teaching and the rules governing their use. According to the data controller, adherence to the terms of use is essential because the login credentials are also accessible outside of school hours. In the fall of 2025, the data controller submitted a report to the Office of the Data Protection Ombudsman detailing the applications it uses for educational purposes. According to the report, the data controller uses the following core Google services: Google Classroom, Google Drive, Google Docs\u002FSheets\u002FSlides\u002FForms, Google Sites, Gmail, Google Calendar, Google Keep, and Google Meet. In addition to these core services, the school also uses, for example, Google Maps, Google Translate, Google Search, and (Google-owned) YouTube. Google Workspace for Education Plus licenses, which offer expanded service management and security features, were implemented on January 31, 2024. The data controller states that it conducts risk and threat assessments for the services before approving and implementing them. Applicable Legislation The General Data Protection Regulation (EU) 2016\u002F679 of the European Parliament and of the Council (General Data Protection Regulation) and the National Data Protection Act (1050\u002F2018), which further specifies it, apply to this matter. Article 5(1)(a) of the General Data Protection Regulation sets forth the principle of lawfulness. According to this article, personal data must be processed lawfully. Article 5(1)(c) of the General Data Protection Regulation sets forth the principle of data minimization. According to this article, personal data must be appropriate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Data minimization is also required by Article 25 of the General Data Protection Regulation, paragraph 2 of which states that the controller must implement appropriate technical and organizational measures to ensure that, by default, only personal data necessary for each specific purpose of the processing is processed. This obligation applies to the amount of personal data collected, the scope of processing, the retention period, and accessibility. Article 6 of the General Data Protection Regulation sets forth the legal bases for the processing of personal data. According to paragraph 1(c) of that article, processing is lawful only if and to the extent that it is necessary for compliance with a legal obligation to which the controller is subject. According to paragraph 4 of that article, where the processing is carried out for a purpose other than that for which the data were collected, and the processing is not based on the data subject’s consent or on Union law or the law of a Member State, which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller shall take into account, among other things, the following to ensure that processing for another purpose is compatible with the purpose for which the data were originally collected: (a) the links between the purposes for which the personal data were collected and the purposes of the intended subsequent processing; (b) the context in which the personal data were collected, in particular with regard to the relationship between the data subjects and the controller; c) the nature of the personal data, in particular whether special categories of personal data are being processed in accordance with Article 9 or personal data relating to criminal convictions and offenses in accordance with Article 10; d) the potential consequences of the intended further processing for data subjects; e) the existence of appropriate safeguards, such as encryption or pseudonymization. Article 28 of the General Data Protection Regulation (GDPR) addresses the processor of personal data. According to paragraph 1(a) of that article, the controller may only use processors who implement adequate safeguards to ensure that appropriate technical and organizational measures are in place so that the processing complies with the requirements of the General Data Protection Regulation and ensures the protection of the data subject’s rights. Article 58(2) of the General Data Protection Regulation sets forth the supervisory authority’s corrective powers. Pursuant to subparagraph (d) of that article, the supervisory authority may order the controller or processor to bring processing operations into compliance with the provisions of the General Data Protection Regulation, if necessary, in a specific manner and within a specified time limit. Recitals of the General Data Protection Regulation Recital 38 states that special efforts should be made to protect the personal data of children, as they may not be fully aware of the risks, consequences, relevant safeguards, or their own rights regarding the processing of personal data. According to the recital, such special protection should apply, in particular, to the use of children’s personal data for marketing purposes or for theor user profiles, and to the collection of personal data relating to children when using services offered directly to children. Recital 75 notes the risks to the rights and freedoms of natural persons that may arise from the processing of personal data, which may cause harm, such as when processing the personal data of vulnerable natural persons, particularly children. Legal Issue In its decision issued on April 8, 2025, (Ref. No. 2181\u002F03.04.04.04.01\u002F2023), remanded the case to the Data Protection Ombudsman for further consideration. The Supreme Administrative Court has held that the Data Protection Ombudsman could not, on the grounds presented in its decision, conclude that Article 6(1)(c) of the General Data ProtectionRegulation (EU) 2016\u002F679 does not apply in any respect as a basis for the processing of personal data. The Data Protection Ombudsman assesses and decides on the matter, as mentioned above, on the basis of the General Data Protection Regulation (EU) 2016\u002F679 and the Data Protection Act (1050\u002F2018). This decision concerns the application of Article 6(1)(c) of the General Data Protection Regulation as a basis for processing when personal data is processed in an electronic educational program. This decision does not assess the applicability of other legal bases for processing under Article 6 of the General Data Protection Regulation to the processing of personal data in the context of the educational program. The Data Protection Ombudsman must determine: to what extent Article 6(1)(c) of the General Data Protection Regulation may serve as the legal basis for the processing of personal data related to the use of the educational program in the case of the data controller (compliance with a legal obligation). Decision of the Data Protection Ombudsman Decision As a general rule, Article 6(1)(c) of the General Data Protectioninsofar as it concerns the use of software essential to teaching—as described in more detail in the recitals of this decision—which is carried out solely to comply with the obligation to provide education.[1] The processing of personal data in educational software, pursuant to Article 6(1)(c) of the General Data Protection Regulation, requires, in practice, that the processing be limited exclusively to processing carried out for the purpose of organizing instruction and that the processing also otherwise comply with the requirement of necessity and other data protection provisions. The data controller may not disclose or grant access to a child’s personal data to third parties in order to comply with a legal obligation under Article 6(1)(c) of the General Data Protection Regulation. Order The data controller is ordered, pursuant to Article 58(2)(d) of the General Data Protection Regulation, to ensure that the personal data of students collected in connection with the use of the educational program is not processed, pursuant to Article 6(1)(c) of the General Data ProtectionRegulation for purposes other than solely fulfilling the controller’s educational obligations. Personal data collected to fulfill educational obligations may not, therefore, be processed, for example, for the service provider’s own purposes (such as service development). The issuance of this order concludes the Office of the Data Protection Ombudsman’s review of case TSV\u002F40\u002F2018. The order does not preclude the possibility that issues concerning the data controller related to the use of the electronic teaching program may be investigated by the Data Protection Ombudsman in connection with other potential supervisory measures. Reasons Case Initiated and Previous Proceedings In the case initiated at the Office of the Data Protection Ombudsman on April 30, 2018 (case no. 1509\u002F452\u002F18), the issue to be resolved was whether Article 6(1)(c) of the General Data Protection Regulation (compliance with a legal obligation) can serve as the legal basis for the processing of students’ personal data in connection with the use of Google’s educational program. The Data Protection Ombudsman resolved the matter on December 30, 2021. In his decision, the Data Protection Ombudsman states that Article 6(1)(c) of the General Data Protectionis not applicable as a basis for processing personal data in connection with the Google educational program used by the data controller. The decision does not address compliance with other provisions of the General Data Protection Regulation, such as which legal basis should apply instead, or whether the use of Google’s educational program otherwise complies with the requirements of the General Data Protection Regulation. The City of Espoo has appealed the Data Protection Ombudsman’s decision to the Helsinki Administrative Court. The Helsinki Administrative Court ruled on the matter on June 30, 2023.[2] In its ruling, the Helsinki Administrative Court upheld the Data Protection Ombudsman’s decision. The City of Espoo has appealed the decisions of the Data Protection Ombudsman and the Helsinki Administrative Court to the Supreme Administrative Court. In a decision issued on April 8, 2025, the Supreme Administrative Court remanded the case to the Data Protection Ombudsman for further consideration.[3] In its ruling, the Supreme Administrative Court states: The Data Protection Ombudsman could not, based on the grounds presented in its decision, conclude that Article 6(1)(c) of the General Data Protection Regulation is not applicable in any respect as a basis for the processing of personal data in this case. […] The Supreme Administrative Court does not, at this stage, address in detail the extent to which the processing of personal data at issue here may lack a basis under the General Data Protection Regulation. In this regard, the matter is remanded to the Data Protection Ombudsman for further consideration.[4] Processing of Personal Data in an Electronic Learning Program Pursuant to a Statutory Obligation Article 6 of the General Data Protection Regulation sets forth the conditions for the lawfulness of processing. According to this provision, compliance with a legal obligation on the part of the controller (Article 6(1)(c) of the General Data Protection Regulation) may constitute a basis for the processing of personal data. Compliance with a legal obligation (Article 6(1)(c) of the General Data Protection Regulation), that is, in this case, compliance with the obligation to provide basic education as set forth in the Basic Education Act (628\u002F1998), is the primary legal basis for a school’s processing of students’ personal data. Article 6(1)(c) of the General Data Protection Regulation may also serve as the legal basis for processing personal data in the context of electronic educational software.[5] In the context of electronic educational software, this legal basis for processing generally applies to the use of software that is central to teaching, specifically, for example, the use of tools such as word processors, calendars, email, presentation software, and programs intended for subject-specific instruction (such as language or math applications). Regarding the assessment of the legal basis for processing, it should also be noted that when evaluating the suitability of a legal basis, the legal bases set forth in Article 6 of the General Data Protection Regulation must be read in conjunction with the requirement of necessity for processing (Article 5(1)(c) of the General Data Protection Regulation, the principle of data minimization). The consideration of the necessity requirement when determining the legal basis for processing is explicitly stated in the legal basis itself, namely, in this case, in Article 6(1)(c) of the General Data Protection Regulation, which states that processing must be necessary for compliance with a legal obligation to which the controller is subject. The same has been established in the case law of the Court of Justice of the European Union regarding the interpretation of legal bases for processing: “the condition of necessity of the processing must be examined in conjunction with the principle of data minimization laid down in Article 5(1)(c) of the General Data Protection Regulation”[6], and “as is apparent from Article 6 in question, where the data subject has not given consent to the processing of his or her personal data for one or more specific purposes in accordance with Article 6(1)(a) of Regulation 2016\u002F679, the processing must meet the requirement of necessity, as is apparent from subparagraphs (b) through (f) of that paragraph.”[7] The concept of necessity is an autonomous concept of Union law that must be interpreted in such a way as to fully correspond to the objective of the General Data Protection Regulation, namely, to ensure a high level of protection of personal data.[8] With regard to whether the requirement of necessity for processing is met, it is essential to assess whether there are other alternatives to the intended method of processing that are less intrusive to the data subject’s privacy.[9] If there are effective alternatives to the processing that are less intrusive to the data subject’s privacy, the processing does not, in principle, meet the necessity requirement inherent in the legal basis for processing, and the legal basis for processing is not applicable. When assessing the intrusiveness of the processing and the various alternatives in the context of educational software, it is important to note that digital educational programs can, in practice, enable the extensive and long-term collection and other processing of school-aged children’s personal data by and for the benefit of entities external to the school and municipality. This potential for data collection targeting children is relatively new and requires the school or municipality, in its capacity as the data controller, to exercise particular care in decisions related to the processing of personal data. It is justified for schools to act responsibly so that children are not exposed, for example, to profiling carried out by third parties in the context of schoolwork. Digitalization is also part of the evolution in schools, and it is important that solutions related to the processing of personal data are implemented in a sustainable manner, respecting children’s privacy and the protection of personal data.[10] When assessing the necessity of processing, particular attention must be paid to whether whether the use of the educational program involves the processing of personal data carried out by the service provider for its own purposes or those of other third parties. Such processing of personal data is not necessary for the organization of instruction. When processing personal data solely for the purpose of fulfilling the obligation to organize instruction, the data controller, that is, in this case, the City of Espoo, may not disclose or otherwise grant access to this data to the educational program provider (in this case, Google) in a way that allows the educational program provider to process the data for its own purposes—such as developing the educational program service or other programs—or to act in a manner that results in the data being used by other parties. Such processing is not necessary for the organization of instruction. The data controller may not, under any circumstances, disclose or grant access to the data without first assessing whether the conditions set forth in Article 6(4) of the General Data Protection Regulation are met. The Data Protection Ombudsman notes in this context that, for example, diagnostic data collected when using a service is not necessarily exhaustively specified in the agreements governing the service. The data controller must ensure that it does not, for example, consent in agreements to the collection of non-identifiable diagnosticand telemetry data, nor does it consent to the processing of such data for the service provider’s or other parties’ own purposes (such as for the purpose of developing the service). To comply with this decision, the data controller must ensure that, when the legal obligation to provide education serves as the basis for processing (General Data ProtectionRegulation, Article 6(1)(c)), data on students collected in connection with the use of an electronic teaching program is not processed for any purposes other than solely to fulfill the obligation to provide basic education. Appeals Pursuant to Section 25 of the Data Protection Act (1050\u002F2018), an appeal against this decision may be filed in accordance with the right to administrativeCourt in accordance with the provisions of the Act on Proceedings in Administrative Matters (808\u002F2019). The appeal must be filed with the Helsinki Administrative Court. Service of the Decision The decision will be served by mail with a return receipt in accordance with Section 60 of the Administrative Procedure Act (434\u002F2003). Further Information on the Decision The decision was issued by Data Protection Ombudsman Anu Talus. The decision is not final. References [1] When a school processes students’ personal data to fulfill its educational obligations, Article 6(1)(c) of the General Data Protection Regulation (GDPR) is the primary legal basis for processing. [2] Ref. No. 630\u002F03.04.04.04.01\u002F2022. [3] Ref. No. 2181\u002F03.04.04.04.01\u002F2023. [4] Paragraphs 61 and 63 of the decision. [5] See, similarly, the Data Protection Ombudsman’s decision dated December 30, 2021, p. 5 (“The Data Protection Ombudsman emphasizes that compliance with a statutory obligation is the primary legal basis for processing when a school processes students’ personal data”) and p. 7 (“The processing of personal data related to the use of the [educational] program cannot automatically be considered necessary and proportionate, such that the data controller could justify the processing of students’ personal data directly and without case-by-case consideration based on its statutory obligation to provide basic education”). [6] See, e.g., Case C‑394\u002F23, paragraph 49 of the judgment. See, similarly, during the period when the Personal Data Act (523\u002F1999), based on the Data Protection Directive, was in force: “the requirement that processing be necessary must be examined in conjunction with the so-called principle of data minimization set forth in Article 6(1)(c) of Directive 95\u002F46; According to this principle, personal data must be adequate, relevant, and not excessive in relation to the purposes for which they are collected and\u002For further processed” (Case C-708\u002F18, paragraph 48 of the judgment). [7] Judgment of the Court of Justice of the European Union in Case C-77\u002F21, paragraph 57 of the judgment. [8] See, similarly, the judgment of the Court of Justice of the European Union in Case C-524\u002F06, paragraph 52. See also, for example, Case C-60\u002F22, paragraph 64, regarding the objective of the General Data Protection Regulation. [9] With reference to this requirement, the General Data Protection Regulation states that “Personal data should be processed only if the purpose of the processing cannot reasonably be achieved by other means” (Recital 39; see also, for example, Case C‑268\u002F21, paragraph 55, regarding the assessment of processing alternatives in relation to the data minimization requirement). The Court of Justice of the European Union has likewise held in its case law on the applicability of the legal basis for processing that “In that regard, it must be clarified that the requirement of necessity associated with the chosen legal basis is not met if the purpose of the data processing in question could reasonably be achieved just as effectively by other means that means that are less restrictive of the fundamental rights of data subjects, and in particular the rights to respect for private life and to the protection of personal data guaranteed by Articles 7 and 8 of the Charter, since exceptions and restrictions to the principle of personal data protection must be limited to what is strictly necessary” (Case C-394\u002F23, paragraph 28 of the judgment). In the same judgment, the Court of Justice of the European Union assessed whether there were other, less intrusive alternatives to the processing (paragraph 34 of the judgment). See also, for example, Case C-252\u002F21, para. 99. See also Case C‑268\u002F21, in which the Court of Justice of the European Union assessed whether the data controller has alternatives that do not interfere with the protection of personal data to such a great extent (paragraph 55 of the judgment). [10] Children’s personal data must be protected with particular care; see, for example, Recitals 38 and 75 of the General Data Protection Regulation. Children’s right to privacy is also enshrined, for example, in the UN Convention on the Rights of the Child (Article 16).","Finland's Data Protection Ombudsman (DPA) has ordered the city of Espoo to ensure that personal data of pupils collected through Google's digital learning tools is processed solely for educational obligations. The ruling stems from a complaint that the city was using Google applications without parental consent, invoking Article 6(1)(c) GDPR as the legal basis. The DPA clarified that while this legal basis can apply to essential teaching tools, data cannot be disclosed to third parties for their own purposes, such as service development.","Finland's DPA orders city to limit pupil data processing via Google tools.","Help Tietosuojavaltuutetun toimisto (Finland) - TSV\u002F40\u002F2018: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 11:56, 28 September 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators192 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 11:56, 28 September 2026 Tietosuojavaltuutetun toimisto - TSV\u002F40\u002F2018 Authority: Tietosuojavaltuutetun toimisto (Finland) Jurisdiction: Finland Relevant Law: Article 6(1)(c) GDPR Type: Other Outcome: n\u002Fa Started: Decided: 04.09.2026 Published: 04.09.2026 Fine: n\u002Fa Parties: Espoon kaupunki Google National Case Number\u002FName: TSV\u002F40\u002F2018 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Finnish Original Source: Finlex (in FI) Initial Contributor: av The DPA ordered a city to ensure that the personal data of pupils collected when using digital learning tools was only processed to fulfill the controller’s educational obligations. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from pupils’ (the data subjects’) parents. The controller clarified that it used a number of Google applications for educational purposes, including Google Classroom, Google Drive, and Google Docs. It invoked Article 6(1)(c) GDPR as the legal basis for the processing. According to the controller, the processing of personal data in connection with using these services was necessary to comply with the obligation to provide basic education laid down in the Finnish Basic Education Act. The DPA issued a decision in case 1509\u002F452\u002F18 in December 2021. This decision was appealed to the Supreme Administrative Court, which referred the case back to the DPA in its decision KHO:2025:29 in April 2025. The Supreme Administrative Court held that the DPA could not conclude Article 6(1)(c) GDPR was not applicable in any respect as a legal basis for the processing. In the present proceedings, the DPA was to decide the extent to which the controller could invoke the compliance with a legal obligation as a legal basis for the processing of personal data related to the use of Google’s digital learning tools. Holding The DPA ordered the controller to ensure that the personal data of pupils collected in connection with the use of Google's digital learning tools was solely processed for the purpose of fulfilling the controller's educational obligations. The processing could be based on Article 6(1)(c) only under these conditions. The DPA held that the controller could invoke Article 6(1)(c) as a legal basis for the use of learning tools essential to teaching. In addition, the processing must be carried out solely to fulfill educational obligations. The DPA pointed out that this legal basis applies to the use of tools that are central to teaching, such as text editors, calendars, email, presentation software, and programs intended for subject-specific instruction (such as language or math applications). When assessing the necessity requirement, the DPA took into account that digital learning tools can enable the extensive and long-term collection and other processing of school-aged children’s personal data by and for the benefit of external entities. Therefore, it held that the controller may not disclose or otherwise grant access to this data to the controller or other parties in a way that allows the controller to process the data for its own purposes, such as developing the learning tools or other services. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Finnish original. Please refer to the Finnish original for more details. Use of Google’s Educational Program in Schools Keywords Legal basis for processing personal data Year of the case 2026 Date of issuance September 4, 2026 Reference number TSV\u002F40\u002F2018 Legal Basis Decision pursuant to the EU General Data Protection Regulation Decision of the Data Protection Ombudsman Subject Use of Google’s educational software in schools Data Controller Data Controller: City of Espoo The Data Protection Ombudsman issued a decision in case 1509\u002F452\u002F18 on December 30, 2021. In its decision KHO:2025:29 issued on April 8, 2025, the Supreme Administrative Court remanded the matter to the Data Protection Ombudsman for further consideration. Contact from the complainant On April 30, 2018, the complainant contacted the Office of the Data Protection Ombudsman and reported that a school in Espoo uses Google’s educational software in its teaching but does not request parental consent for this. Statement received from the data controller The Office of the Data Protection Ombudsman requested a statement from the data controller via a request for information dated July 1, 2020, as well as via requests for additional information dated September 7, 2020, and November 22,2021. The data controller submitted a written explanation on August 14, 2020, and additional explanations on September 28, 2020, and November 26, 2021. After the Supreme Administrative Court referred the matter back to the Data Protection Ombudsman for consideration, the Office of the Data Protection Ombudsman requested on July 16,2025, the Office of the Data Protection Ombudsman requested a report from the data controller regarding the applications in use at the time of the investigation. The data controller provided a written report on this matter on August 27, 2025, and clarified its responses with a supplementary report at the request of the Office of the Data Protection Ombudsman on October 6, 2025. In its report, the data controller stated that it does not seek parental consent for the use of Google’s educational program; rather, the legal basis for processing is Article 6(1)(c) of the General Data Protection Regulation (compliance with a legal obligation). According to the data controller, the processing of personal data is necessary for the organization of basic education in accordance with the Basic Education Act. However, the Department of Education asks guardians to accept the terms of use for information and communication technology services, which describe the types of services used in teaching and the rules governing their use. According to the data controller, adherence to the terms of use is essential because the login credentials are also accessible outside of school hours. In the fall of 2025, the data controller submitted a report to the Office of the Data Protection Ombudsman detailing the applications it uses for educational purposes. According to the report, the data controller uses the following core Google services: Google Classroom, Google Drive, Google Docs\u002FSheets\u002FSlides\u002FForms, Google Sites, Gmail, Google Calendar, Google Keep, and Google Meet. In addition to these core services, the school also uses, for example, Google Maps, Google Translate, Google Search, and (Google-owned) YouTube. Google Workspace for Education Plus licenses, which offer expanded service management and security features, were implemented on January 31, 2024. The data controller states that it conducts risk and threat assessments for the services before approving and implementing them. Applicable Legislation The General Data Protection Regulation (EU) 2016\u002F679 of the European Parliament and of the Council (General Data Protection Regulation) and the National Data Protection Act (1050\u002F2018), which further specifies it, apply to this matter. Article 5(1)(a) of the General Data Protection Regulation sets forth the principle of lawfulness. According to this article, personal data must be processed lawfully. Article 5(1)(c) of the Gen","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV\u002F40\u002F2018&diff=53196&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F8\u002F87\u002FLogoFI.png","2026-09-28T11:56:53+00:00","2026-09-28T18:00:34.238271+00:00",7,[18,21,24,26],{"name":19,"type":20},"Google","vendor",{"name":22,"type":23},"Google Classroom","product",{"name":25,"type":23},"Google Drive",{"name":27,"type":23},"Google Docs","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":28,"icon":30,"name":31,"slug":32},null,"Policy","policy",[34,39,44,49],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":40},{"id":41,"icon":30,"name":42,"slug":43},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":45},{"id":46,"icon":30,"name":47,"slug":48},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":50},{"id":28,"icon":30,"name":31,"slug":32},[]]