[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fj0Ey5r9uoeVDt1bPMp7DvkykBxRuWaI0HLbD30I_DXg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"b96ac5cc-496d-44ef-9c35-80ce5c0a448d","finnish-dpa-orders-espoo-to-restrict-google-tools-data-processing-for-students","3d140027-937b-4d7f-b4cf-1d297102566a","Finnish DPA Orders Espoo to Restrict Google Tools Data Processing for Students","The city of Espoo failed to adequately define and limit the legal basis for processing children's personal data when deploying third-party educational tools like Google Classroom and Drive. While GDPR Article 6(1)(c) may justify essential teaching functions, the city did not ensure that Google was prohibited from using pupil data for its own commercial purposes, creating a compliance gap. This matters because children represent a particularly vulnerable data subject category, and schools acting as data controllers bear responsibility for how processors handle that data. Failing to conduct proper Data Protection Impact Assessments (DPIAs) and vendor due diligence before deployment exposes institutions to regulatory sanctions and erodes public trust.","**Immediate actions:**\n- Audit all active third-party educational tools to confirm data processing agreements explicitly prohibit vendor use of student data for non-educational purposes.\n- Suspend or restrict any tool where a lawful GDPR processing basis (Article 6) cannot be clearly documented.\n\n**Long-term improvements:**\n- Mandate Data Protection Impact Assessments (DPIAs) before deploying any third-party platform that processes personal data of minors.\n- Establish a formal vendor review process that includes contractual data processing agreements (DPAs) aligned with GDPR Article 28.\n- Develop a Children's Data Policy that specifies consent requirements, data minimisation standards, and permissible processing purposes.\n\n**Governance & monitoring:**\n- Appoint or engage a Data Protection Officer (DPO) to continuously review EdTech tool compliance against GDPR obligations.\n- Implement periodic reviews of third-party data processor agreements to ensure ongoing alignment with regulatory requirements.",[12,13,14,15,16,17,18,19,20],"GDPR Article 6(1)(c) – Lawfulness of processing","GDPR Article 28 – Processor obligations and contracts","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","GDPR Recital 38 – Special protection for children's personal data","NIST Privacy Framework PR.P-P4 – Data processing policies","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management","ITIL Service Design – Supplier Management","published","2026-09-28T19:21:36.529505+00:00","2026-09-28T19:21:36.231+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV\u002F40\u002F2018&diff=53198&oldid=53196","tietosuojavaltuutetun-toimisto-finland-tsv-40-2018-24fa8e","Tietosuojavaltuutetun toimisto (Finland) - TSV\u002F40\u002F2018",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]