Solutions
Product
Pricing
Resources
Start free trial

ClassDojo RGPD: What EU Schools Must Verify Before Signing

Is ClassDojo RGPD compliant? ClassDojo’s own answer, published in its help center, is a one-word “Yes.” That answer is not wrong, but it is not the whole picture either: ClassDojo names an EU representative, signs a data processing addendum, and runs annual audits — while its default transfer mechanism still routes student data to US servers, and at least one independent review has questioned whether the consent behind that transfer is legally sound. A French or EU school’s DPO cannot sign off on the marketing claim. They need to verify five specific things in the contract itself.

Before you approve ClassDojo for your school, check:

  • Which entity signed your DPA — and whether it’s dated after January 2025 (the current revision)
  • Whether your contract uses the EU-U.S. Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs) as the transfer basis
  • Whether any behavioral or health-related notes entered into ClassDojo count as “special category” data — because the SCCs exclude it
  • The breach-notification clause’s actual SLA (not the marketing page’s tone)
  • Who has power to authorize storing data outside the continental US, and whether anyone at your school has done so
  • What happens to the data if you cancel — and how long “as long as required” actually runs in your contract’s Exhibit A

The rest of this article walks through what’s actually in the documents — and where an EU-hosted alternative like Beneylu changes the calculus entirely, by keeping data in France by default instead of transferring it to the US under the EU-U.S. DPF.

Is ClassDojo RGPD Compliant? What the Company Claims

ClassDojo’s help center states plainly: “Is ClassDojo General Data Protection Regulation (GDPR) Compliant? Yes.” (ClassDojo Help Center) The company frames its role carefully: for school-context data, “ClassDojo acts as a Processor… and we will process personal information, including Student Data, only at the direction and control of the school” — meaning the school, not ClassDojo, holds the compliance obligations that flow from being the Controller. For data parents enter directly (Family Chat, Premium Features), ClassDojo positions itself as Controller instead.

To back the claim, ClassDojo has appointed an Article 27 EU representative — “the European Data Protection Office (EDPO)… Avenue Huart Hamoir 71, 1030 Brussels, Belgium” — and a separate UK representative, EDPO UK Ltd, in London. Naming a representative is a genuine compliance step, not a formality schools should dismiss. But it answers “can a regulator reach ClassDojo,” not “is the transfer of my students’ data itself lawful.” That’s a separate question, and it’s where the “Yes” needs unpacking.

The Transfer Mechanism Behind the Claim

ClassDojo’s own transfer FAQ is direct about where data lives by default: “As a US-based company, we store user data in the United States.” (ClassDojo Help Center — Transfer FAQ) The legal basis for that transfer is the EU-U.S. Data Privacy Framework: “ClassDojo relies on the DPF Programs when transferring data either as a processor or controller… [and] complies with the EU-U.S. DPF, the UK Extension, and the Swiss-U.S. DPF as set forth by the U.S. Department of Commerce.”

The DPF is a real adequacy mechanism, not a workaround — but it rests on an EU Commission adequacy decision about US law, not on data staying in the EU. ClassDojo remains “subject to the jurisdiction and regulatory enforcement powers of the U.S. Federal Trade Commission” and may have to “disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.” SCCs are built into the DPA as a fallback, but the contract’s own order-of-precedence clause makes clear they only become legally binding if the DPF itself is invalidated in the UK, EU, or Switzerland — a school cannot simply request them as an alternative transfer basis. A school that wants EU-only storage instead needs the separate written authorization the DPA requires under §13.

What the Signed DPA Actually Commits To

The binding document is ClassDojo’s International Data Processing Addendum, signed for ClassDojo, Inc. (Delaware) — the entity named in this DPA’s signature block, from a document whose defined “ClassDojo” party covers either that entity or ClassDojo Technology Inc. (British Columbia) — by Jeff Buening, its District Partnerships GM, in a revision dated January 2025. It is more specific than the help-center FAQs, and worth reading clause by clause rather than taking on faith.

On storage location, the DPA is unambiguous: “Personal Data shall be stored, backed up and served only on servers and data centers based in the continental United States unless Customer has given prior written authorization to ClassDojo to store such Customer Data in additional countries.” (DPA §13) The same section confirms ClassDojo can transfer data “to and in the United States” and to third countries beyond the EEA “without an adequacy statement from the UK government or European Commission” — language your DPO should read literally, not skim past.

On breach response, the SLA is concrete: ClassDojo “shall, without undue delay, but in no event later than seventy-two (72) hours after such confirmation, notify LEA via email of the Personal Data Breach.” (DPA §10.1) On sub-processors, a school has “thirty (30) days after receipt of ClassDojo’s notice” to object to a new one; if ClassDojo can’t resolve the objection “within a reasonable period of time, which shall not exceed sixty (60) days,” it must drop the sub-processor, replace it, or let the school walk away without penalty. On retention, data is kept “for as long as required by LEA to perform the Services,” with account data held “until termination of ClassDojo’s relationship with an End User” — durations that depend on your contract’s definition of “required,” not a fixed number. ClassDojo also runs at least one audit annually, folding SOC 2 Type II Security Criteria into it starting in 2025.

The clause that most changes the compliance picture, though, is this one, stated identically for both transfer scenarios in the DPA’s Exhibit A: “Data exporter shall not submit special categories of Personal Data to the Services.” Health notes, disability accommodations, biometric identifiers — none of it is covered by the transfer safeguards ClassDojo has built. If your school’s use of ClassDojo (or any behavior-tracking tool) touches that category, the DPA doesn’t protect the transfer; it excludes it.

GDPR Compliance Checklist Before You Sign

A workable gdpr compliance review of ClassDojo — or any vendor — confirms in writing, per contract: (1) the DPA revision date and signing entities match what’s live today; (2) that DPF remains the operative transfer basis — the DPA’s own order-of-precedence clause ties SCCs to DPF being invalidated, not to a school’s request; (3) that no special-category data enters the tool, since the SCCs exclude it; (4) the actual retention period in your Exhibit A, not the marketing language; and (5) who at your institution has authority to approve out-of-continental-US storage, since that requires “prior written authorization.”

One scope note: ClassDojo’s website privacy policy — covering classdojo.com visitors, not logged-in classroom use — states “The Sites are not directed toward individuals under the age of thirteen (13)” (ClassDojo Privacy Policy). That describes the marketing site only; the in-product Service is used daily by children well under 13. Conflating the two is an easy, consequential misreading.

The one independent, non-vendor review of ClassDojo’s GDPR posture that this research found comes from Data Protection Education (DPE), a UK education data-protection advisory — and it’s from December 2020, so treat it as a still-relevant but aging data point rather than a current audit. DPE’s core concern was consent: it argued that transfer consent collected at login is questionable, since consent may not be freely given when schools mandate ClassDojo use as a job requirement — a concern that maps onto GDPR Article 7’s imbalance-of-power principle. (Data Protection Education) DPE separately noted, in 2020, that ClassDojo’s SCCs excluded special categories of data — a finding this research’s read of the current 2025 DPA corroborates independently, five years later. DPE’s practical recommendation was to avoid ClassDojo for anything touching protected categories and use “more secure methods” instead.

Two caveats apply here and nowhere else in this article: the live ClassDojo help-center pages 403 automated retrieval tools, so this analysis relied on Wayback Machine snapshots — check the live version yourself before citing it in a compliance file. And the EU’s own reference point for children’s data is still being built: the European Data Protection Board says “extra vigilance is essential” for children’s data and is “currently developing Guidelines on children’s data processing” as of early 2026 — not yet finalized, so no single binding EU standard exists yet to score any vendor against. (EDPB, Data Protection Day 2026)

That regulatory attention is intensifying in France specifically. The Ministry of Education and the CNIL renewed their data-protection partnership on 16 December 2025, signed by minister Édouard Geffray and CNIL president Marie-Laure Denis; since 2025, the CNIL has published two practical guides on data breaches in national education. (CNIL) A US-hosted classroom tool is entering that environment with more scrutiny ahead, not less.

ClassDojo Alternatives for EU Schools: What Changes If You Switch

For a DPO weighing classdojo alternatives, the honest comparison isn’t “compliant vs. non-compliant” — ClassDojo’s paperwork is real. It’s “which transfer question do you want to be answering in three years.”

ClassDojo Competitors That Skip the US Transfer Question

Beneylu, a French EdTech platform built for the ENT (espace numérique de travail) model, removes the US-transfer question by design rather than by contract. Its documentation names its hosting directly: Microsoft Azure France for “serveurs, sauvegardes et bases de données” in the “France Central” region with backup in “France Sud,” plus OVH datacenters in Roubaix and Gravelines. (Beneylu et le RGPD) Because the data never leaves the EU, there’s no DPF reliance, no SCC exhibit, and no “special category data excluded” carve-out to track — the question simply doesn’t arise the way it does for ClassDojo.

Best ClassDojo Alternatives for 2025–2026, Compared

CriterionClassDojoBeneylu
Default data locationContinental US serversFrance (Azure France Central/Sud, OVH Roubaix/Gravelines)
EU transfer basisEU-U.S. DPF (default); SCCs apply only if DPF is invalidatedNot applicable — data stays in the EU
Legal/commercial basisSigned commercial DPA per districtOften operated under a public-service mandate (“mission d’intérêt public”) rather than a standard commercial contract

Neither row fully substitutes for the other’s use case — ClassDojo’s engagement and family-communication features are more extensive than a typical ENT tool, and Beneylu’s public-mandate model isn’t available to every school type. The verdict is narrower than “pick the compliant one”: if your school avoids special-category data in ClassDojo, confirms DPF is still its operative transfer basis, and files the written non-US-storage authorization, the contractual gaps close considerably. If that paperwork discipline isn’t realistic for your team, an EU-native platform removes the question instead of managing it. For a broader survey of EU-hosted classroom-communication tools, see BeeNet’s alternatives comparisons.

The Verdict: What Your DPO Sign-Off Should Require

ClassDojo’s GDPR answer is “Yes” in the sense that matters to a regulator checking for an Article 27 representative, a signed DPA, and a breach-notification clause — all present. It is a qualified “yes, if” in the sense that matters to a DPO: yes, if you’ve confirmed DPF remains valid as your transfer basis (SCCs only take over if DPF itself is invalidated); yes, if no special-category data ever enters the tool; yes, if someone has actually signed the written authorization the DPA requires before any non-US storage. None of those conditions is automatic — each needs a specific, documented action from your school, not a checkbox on a vendor FAQ.

That’s a due-diligence workflow, not a one-time decision — and it’s exactly what gets lost between a signed contract and what teachers type into a behavior-tracking app six months later. A platform that bakes that workflow in — data-handling settings, retention controls, and audit trails living next to the messaging and safety features administrators already use daily, rather than in a separate PDF nobody rereads — closes that gap by design. Concretely, that can mean a retention setting that auto-purges behavior-log entries a fixed number of days after the school year ends instead of running on ClassDojo’s open-ended “as long as required” language, plus an audit-log entry showing which staff member approved storing a note outside the EU, timestamped and retrievable — not a verbal or email-thread approval nobody can produce six months later. BeeNet is one implementation path built around that pairing, alongside document handling and safety workflows that keep the compliance surface and the daily communication tool in the same system. If you’re mid-evaluation, the schools use case and pricing pages outline what that looks like, or book a walkthrough to compare it against your current setup.

References

  1. ClassDojo, Inc. “How ClassDojo complies with GDPR.” ClassDojo Help Center. Retrieved via Wayback Machine snapshot, February 2026. https://help.classdojo.com/hc/en-us/articles/360039729772-How-ClassDojo-complies-with-GDPR
  2. ClassDojo, Inc. “International Data Processing Addendum” (Revision January 2025). https://static.classdojo.com/docs/DPA/classdojo-int-dpa.pdf
  3. ClassDojo, Inc. “Transfer of Personal Data to the U.S.” ClassDojo Help Center. Retrieved via Wayback Machine snapshot, October 2025. https://help.classdojo.com/hc/en-us/articles/360053338371-Transfer-of-Personal-Data-to-the-U-S
  4. ClassDojo, Inc. “Website Privacy Policy” (Last Updated June 30, 2025). https://new-external.classdojo.com/legal/privacy-terms
  5. England, James / Data Protection Education. “Class Dojo International Data Sharing.” December 2020. https://dataprotection.education/news/83-best-practice-updates/183-class-dojo-data-sharing
  6. CNIL. “Le ministère de l’Éducation nationale et la CNIL renouvellent leur partenariat.” 16 December 2025. https://www.cnil.fr/fr/renouvellement-partanariat-ministere-education-nationale-cnil
  7. Beneylu. “Beneylu et le RGPD.” 2026. https://beneylu.com/fr/beneylu-et-le-rgpd/
  8. European Data Protection Board. “Data Protection Day 2026: keeping children’s personal data safe online.” 28 January 2026. https://www.edpb.europa.eu/news/news/2026/data-protection-day-2026-keeping-childrens-personal-data-safe-online_en

Ready to Transform Your School Communication?

Start saving time and increasing parent engagement with BeeNet.

Request Demo