Introduction: a file that opens before the first lesson
Your child started Year 1 three weeks ago. They still can't read fluently. And yet they already have a national student ID number, an account on a digital learning environment, a line in a cafeteria billing system, a photo in a class directory, and probably three accounts on educational apps whose terms of use you have never read.
None of this processing is illegitimate in itself. The education system has to manage enrolments, grades, absences, meals and school trips. Teachers need tools. Local authorities need to know who eats what and who goes home at what time. But the accumulation produces something nobody actually decided on: a longitudinal profile, built without the consent of the person concerned, which will follow a child through fifteen years of schooling and, for some of its components, well beyond.

For several years now, the CNIL has devoted a significant share of its audits to the education sector, and its recommendations on minors' data are explicit: a child is not an ordinary user, their ability to understand consent is limited, and the principle of data minimisation must be applied with heightened strictness. The European Data Protection Board (EDPB) takes the same line.
This guide is not an argument for pulling anyone out of school. It explains what is collected at each tier of the school system, what you can refuse with no educational consequences, and how to ask the right questions of the right person.
Part 1 — Mapping the collection: four tiers, four controllers
The most common misconception among parents is to think of "the school" as a single point of contact. In reality, four distinct data controllers are stacked on top of one another, with different legal bases and different retention periods.
Tier 1 — The State: the administrative school record
The Ministry of Education runs national databases: ONDE (the digital tool for primary school management) at primary level, SIECLE at secondary level, Affelnet for school placement, Parcoursup on the way out. Every pupil receives a national student identifier (INE), an 11-character number that follows them from nursery school through to higher education.
What it contains: civil status, address, legal guardians, academic path, repeated years, elective subjects, exam results. Legal basis: public interest task. You cannot object to it, and that is coherent — compulsory education implies monitoring.
What you can do, however: check accuracy (right to rectification), and keep an eye on optional fields. Many enrolment forms include sections that are explicitly non-mandatory: parents' occupations, number of siblings, language spoken at home. An empty field has never blocked an enrolment.
Tier 2 — The local authority: cafeteria, after-school care, transport
The town hall (primary schools), the département (middle schools) or the region (high schools) manage catering, school transport, and morning and evening care. This is the most intrusive tier, and the one parents watch least.
It holds: means-tested family income bracket, benefits claimant number, dietary requirements (data that can reveal religious beliefs or a health condition), arrival and departure times, unpaid bills, bank details.
Tier 3 — The school: student life and digital tools
Grades, absences, lateness, sanctions, teachers' comments, internal messaging, the homework log. In practice: Pronote, the regional learning platform, sometimes boarding or student-life management software.
Tier 4 — Third parties: apps, platforms, providers
This is the wild tier. In a single year, an enthusiastic teacher can have their pupils create accounts on a quiz platform, an educational video service, an online drawing tool and a homework submission space. Each with its own servers, its own cookies, its terms of use written in English and its business model — sometimes ad-funded.
A useful rule: the further down the tiers you go, the less mandatory the processing, and the greater your room to refuse.
Part 2 — The biometric cafeteria: the topic that gets too little attention
What the CNIL has actually ruled
For a few years now, some schools — high schools above all — have been installing devices at the canteen entrance that recognise hand geometry, vein patterns or faces, to replace the card left at home.
The CNIL's position is consistent and restrictive. Biometrics fall under sensitive data within the meaning of Article 9 of the GDPR: their processing is prohibited in principle, subject to exceptions. For access control to a school canteen, the authority considers that there is no necessity justifying such a system, since a badge, a code or visual recognition by a staff member serves the same function. In 2019, the Marseille administrative court annulled a regional authority's decision to trial facial recognition at the entrance of two high schools, relying in particular on the absence of freely given consent from the pupils.
In practical terms for a parent: if you are handed an enrolment form for a biometric catering system, you can refuse without giving a reason and ask for the alternative. A refusal cannot deprive your child of meals.
The card, the badge and the electronic purse
That leaves the common case: a contactless card, a prepaid account, a record of entries. Here the issue is no longer biometrics but granularity. A canteen system does not need to know that a pupil took two desserts on 14 March; it needs to know how many meals to bill.
Questions to put in writing to the service manager:
- Are the specific dishes chosen recorded, and for what purpose?
- How long is the entry history kept after the end of the school year?
- Are dietary requirements stored in plain text, and who can see them?
- Are unpaid bills passed on to a third party?
A simple RFID card protector for a canteen or transport card also prevents opportunistic reads inside a backpack; it's a two-euro accessory that settles an entire category of problems.
Part 3 — Learning platforms, Pronote and apps: the daily build-up
What the digital learning environment knows about your child
A learning platform is not just a homework log. It's a connection journal. Time of access, IP address, documents opened, messages sent, homework handed in late at 11:47 pm. None of this metadata appears on a report card, but it exists and is technically exploitable.
Two simple habits:
- Read the privacy policy of your regional or education authority's platform. It's public, often short, and states log retention periods (typically 6 to 12 months).
- Keep the parent account separate from the child's account. Many families share a single login, which mixes the trails and gives the child a view of exchanges that don't concern them — and vice versa.

Third-party apps: the three-line question to ask
When an app is imposed for homework, you have the right to know who processes the data. A template message, addressed to the teacher and then, if there's no reply, to the head teacher:
Hello, my child has been asked to use the app X. Could you tell me who the data controller is, the legal basis relied upon, where the data is hosted and how long it is retained? Failing that, what non-digital alternative is available for completing this work?
The message isn't aggressive: it asks for information the school should be able to supply. In practice, it often has an unexpected effect — the teacher discovers they don't know, and the question moves up to the education authority's data protection officer, who does exist and whose contact details are published.
Equipment: what household hardware can absorb
A lot of the trail comes not from school but from the device used at home. Two practical angles:
- A family laptop dedicated to homework, with a separate user account per child, compartmentalises far better than a shared smartphone.
- A privacy screen filter limits sideways glances when a teenager works in a shared space or a library — and incidentally reduces accidental capture during video calls.
For offline work, a paper rough book remains the most watertight tool ever invented: nothing leaves the room.
Part 4 — Photos, videos and class directories: image rights in practice
What parental authorisation actually covers
Every September, a form goes round: "image rights authorisation". It is often drafted so broadly that it amounts to a blank cheque: "distribution on all media, for an unlimited period".
The CNIL and the ministry both stress that an authorisation must be specific: one use, one medium, one duration. You are perfectly entitled to return the form annotated:
| Requested use | Possible answer |
|---|---|
| Display within school premises | Accepted |
| Printed school newsletter given to families | Accepted |
| The school's public website | Refused |
| Social media accounts of the school or town hall | Refused |
| Local press | Case by case, on request |
| Duration | Current school year only |
A partial refusal is valid. The school must apply it, and it cannot be used to justify excluding a child from a trip or an activity.
Photos taken by other parents
The end-of-year show, the school fair, the field trip: thirty phones are filming, and the video ends up in a messaging group and then, sometimes, on social media. Legally, a photograph taken in a family setting falls under the GDPR's household exemption — but as soon as it is published, the other children's image rights apply.
The only approach that works is a collective one: ask the school council or a parents' meeting to adopt a simple, posted rule — photograph your own child, don't publish other people's. Many schools have adopted it and the effect is clear.
Part 5 — Your rights, and how to exercise them without conflict
The five useful rights
- Access: obtain a copy of the data held about your child (school record, canteen history, logs if you explicitly ask for them).
- Rectification: correct an address error, an outdated entry, an inaccurate observation.
- Erasure: limited for mandatory records, real for optional processing (photos, apps, newsletters).
- Objection: applicable to non-mandatory processing.
- Restriction: freeze a disputed processing operation while it is checked.
Requests go to the data controller: the head teacher for student life, the town hall for the canteen, the education authority for national databases. Every education authority and every local authority has a data protection officer (DPO) whose contact details must be published. The response deadline is one month. If you hear nothing, filing a complaint online with the CNIL is free and requires no lawyer.

Keeping a record of your steps
A trivial but decisive piece of advice: keep a dated copy of every annotated form, every email, every reply. A ring binder with pockets or a card folder for the school file is plenty, and beats a pile of photocopies at the bottom of a drawer. When a request drags on for eight months, a written timeline makes all the difference.
When contact needs to stay discreet
There are situations where a parent wants to report something — a security problem, a questionable practice, a doubt about some processing — without their name circulating in the staff room. A message sent from a channel that doesn't reveal your personal line lets you open the conversation without exposing yourself, especially in small towns where everyone knows everyone. This isn't distrust: it's the condition for some reports existing at all.
Part 6 — The vigilant parent's calendar
At the start of term (September)
- Fill in only the mandatory fields on the form.
- Annotate the image authorisation use by use.
- Ask for the list of digital apps planned for the year.
- Refuse any biometric catering system.
During the year
- Check the data visible in the learning platform once a term.
- Deregister from abandoned apps (an inactive account is still an account).
- Report any unauthorised photo publication immediately.
At the end of a school stage
- Request deletion of accounts tied to third-party tools when changing schools.
- Check that the previous year's online class photo directory has been taken down.
- Get a copy of the school record before it is transferred.
In the event of an incident
Schools and local authorities suffer data breaches too — several after-school care management databases have been exposed in France in recent years. If you are notified:
- Ask in writing for the precise nature of the data involved.
- Check whether a phone number or bank account details were part of the leak.
- Be wary of the approaches "from the school" that follow: a leaked school file fuels highly credible phishing attempts, because the scammer knows the child's first name and the name of the school.
- A book on personal data protection, kept within reach, helps separate a genuine risk from background noise — and helps explain the situation to a teenager without alarming them.
Conclusion: passing on a reflex rather than a fear
A child in school in France today will, by the time they come of age, have accumulated more data about themselves than any generation before them, without ever having had the chance to consent to it. This is not a technical inevitability: it's the result of thousands of small decisions taken by default, in forms nobody reads.
A parent's job is not to block school technology — it has become inseparable from learning. It is to restore proportion: tick fewer boxes, ask questions in writing, refuse what isn't necessary, and show your child that you can say no to a data processing operation without standing outside the school system.
That is probably the most durable skill anyone can pass on to a pupil in 2026: understanding that personal data can't be taken back, and that a field left blank is sometimes the best answer to a question nobody had the right to ask you.



