Solutions
Product
Pricing Compare
Resources
Request Free Trial

Is Your School Vendor Contract Missing This GDPR Clause?

Is Your School Vendor Contract Missing This GDPR Clause?

If your school still treats a vendor’s “GDPR compliant” badge as proof enough, CNIL’s 2025 enforcement data says otherwise. The bilan named insufficient data security among the top reasons French regulators sanctioned organizations last year, and a separate enforcement track shows processors, the vendors schools sign contracts with, sanctioned specifically for skipping Article 28 obligations.

Four checks are worth running before you read any further:

  • Does the contract name specific security measures, not just “industry-standard security”?
  • Does it say what happens to your data when the contract ends?
  • Do you know who the vendor’s own subcontractors are?
  • Can you audit the vendor, or only take its word for it?

The full eight-clause checklist, with CNIL’s own model language, is below.

What CNIL’s 2025 Bilan Actually Found

CNIL issued 259 decisions in 2025, including 83 sanctions: 78 fines, 3 penalty-payment (astreinte) decisions, and 2 warnings, with 27 of those fines carrying additional corrective orders. Together they total €486,839,500 in cumulative fines. Fourteen of those organizations were sanctioned specifically for “manquement relatif à la sécurité des données personnelles” (a breach relating to the security of personal data), “notably for lacking robust password measures,” per CNIL’s own summary.

That data-security category sits alongside a distinct enforcement thread that matters more directly to a school reviewing its supplier list: CNIL’s restricted committee “sanctioned subcontractors/processors for failing to implement appropriate security measures, processing data outside the controller’s instructions, and retaining data beyond the contractual relationship.” Weak passwords, shared accounts, and inadequate protective measures were named as the concrete failures behind the security sanctions.

No school or education vendor appears by name in CNIL’s 2025 bilan. The closest education-sector mention is a compliance notice to child-welfare services (“aide sociale à l’enfance”) over retention policy, not a fine. Nothing here says a specific French school’s vendor stack is non-compliant today. What the bilan does establish is the pattern regulators are actively enforcing: weak security controls and processor contracts that don’t hold up. That pattern is exactly what CNIL’s Article 28 guidance exists to help a school avoid.

Why a “GDPR Compliant” Badge Isn’t a Contract

When a vendor selling to schools says it’s GDPR compliant, that claim is marketing copy, not a legal instrument. CNIL is explicit that any company processing data on a school’s behalf (a communication platform, a canteen payment provider, an attendance system) is a processor (“sous-traitant”), and that “treatments of data by a processor must comply with the GDPR and be governed by a contract with the controller.” The school is the controller. The obligation to verify the contract, not just accept the badge, sits with the school.

CNIL also draws a specific line most schools don’t check: a processor may only reuse the data it handles “if reuse is compatible with the initial treatment and the controller has given written authorization.” A vendor that repurposes attendance or messaging data for its own product analytics without that written authorization would be out of contract, regardless of what its marketing page says about compliance.

The Article 28 Checklist: What Every School’s Vendor Contract Must Contain

CNIL publishes its own model Article 28 clauses: the exact contract language a processor agreement is supposed to contain. Pull your current vendor contracts and check each one against this list:

ClauseWhat CNIL’s model text requiresRed flag if missing
Purpose limitationProcessing exclusively for the defined purpose(s) of the serviceContract is silent on what the vendor may and may not do with the data
Documented instructionsVendor processes only per the controller’s written instructionsNo instruction record; vendor sets its own processing terms
ConfidentialityVendor staff bound to confidentialityNo mention of staff obligations
Security measures (Section 11)Pseudonymization, encryption, system resilience, regular security testingGeneric “industry-standard security” language with no specifics
Sub-subcontractingEither general authorization with prior notice, or named-entity-only authorizationNo visibility into which third parties the vendor itself uses
Data subject rightsVendor must assist the school in handling access and rectification requestsNo defined process for parent or staff data requests
Audit rightsSchool retains supervisory audit rights over the processorContract gives the school no way to verify compliance itself
Data fate on terminationDestruction, return, or transfer, with written justification if destroyedNo clause on what happens to student data when the contract ends

A French vendor contract missing more than one or two of these matches the category of failure CNIL’s restricted committee sanctioned processors for in 2025: no security measures, no instruction boundary, no clarity on what happens to the data afterward.

What This Looks Like in Practice

Turning this into action takes an afternoon with the contracts you already have, not a new procurement process.

  • The contract audit. Pull every vendor contract involving student or family data (messaging platform, canteen payments, attendance tracking) into one folder, and check each against the eight-row table above. This is a document-review task, not a legal engagement; most gaps are visible on a first read.
  • The renewal-time question. Before signing a vendor’s renewal invoice, send one written request: confirmation of its sub-subcontractor list and what happens to your data if the contract ends. A vendor that can’t answer in writing within a few days is telling you something.
  • The one-page breach note. CNIL’s own education breach guide recommends concrete habits: use BCC rather than CC on multi-parent emails, password-protect sensitive attachments and send the password separately, and use only tools referenced by the Éducation nationale or your académie. Written up as a single page and pinned in the staff room, that’s a meaningful first line of defense against one of the incident types CNIL’s guide catalogs: misdirected email.

What CNIL’s Own Breach Data Says About Schools

CNIL reports being notified of only around 30 data breaches a year, on average, across primary and secondary schools combined, over the last five years. That sounds low, and CNIL says so itself: “this figure does not reflect the reality schools live day to day,” based on what CNIL observes when it engages directly with schools. Read that as an underreporting signal, not a low-risk one: the gap between 30 formal notifications and CNIL’s own field observations is CNIL’s regulator, not a third party, telling you the official count understates the real picture.

The five incident types CNIL’s guide catalogs are mostly mundane, not exotic: lost or stolen equipment, misdirected email, user error exposing data publicly, credential theft, and outside attacks. Most of them don’t require a sophisticated attacker: they’re associated with an unencrypted laptop, a CC field used where BCC belonged, or a password shared past the person it was meant for; the guide’s own examples show the attacks category can still involve deliberate intrusion attempts. A vendor contract with a real security clause doesn’t stop these on its own, but it’s the mechanism that turns the vendor’s side of the failure (not implementing agreed security measures) into something you can point to and act on, rather than discover after the fact.

Separately, compliance commentary on CNIL’s 2025 activity notes that its simplified sanction procedure, introduced in 2022, now handles a majority of cases and has cut typical resolution time from 18–24 months to roughly 4–6 months. The direction is the same either way: enforcement moves faster than it used to. A contract gap sitting unaddressed is a shorter wait than it was two years ago.

The Verdict: What to Do Before Your Next Vendor Renewal

The practical conclusion is narrow and specific: stop accepting “GDPR compliant” as a checkbox, and start checking whether each vendor contract actually contains CNIL’s Article 28 clauses: purpose limitation, documented instructions, named security measures, sub-subcontracting visibility, audit rights, and a clear data-fate clause on termination. That’s a contract review your school can run this week with the documents already on file, using CNIL’s own model text as the yardstick.

Where a platform choice enters this picture is in how much of that checklist it removes from your plate before you ever sign. A vendor that publishes its own data-processing terms against CNIL’s model clauses, keeps parent and student data on infrastructure it controls directly rather than through an unnamed chain of sub-subcontractors, and gives you audit visibility by design is one implementation path through this checklist, not a replacement for reading your contract. BeeNet’s data security features are worth checking against that same list, and you can see it firsthand via a demo.

Related reading: school rollout details, document handling, and current pricing.

CNIL’s enforcement track for processor contracts is already active. The question for your next vendor renewal is whether you do it before you sign, or after CNIL asks why you didn’t.

References

  1. CNIL. “Sanctions et mesures correctrices : la CNIL présente le bilan 2025.” 2026. https://www.cnil.fr/fr/bilan-sanctions-2025
  2. CNIL. “Sanctions and corrective measures: CNIL’s actions in 2025.” 2026. https://www.cnil.fr/en/sanctions-and-corrective-measures-cnils-actions-2025
  3. CNIL. “Travailler avec un sous-traitant.” 2025. https://www.cnil.fr/fr/sous-traitant
  4. CNIL. “Sous-traitance : Exemple de clauses.” 2025. https://www.cnil.fr/fr/sous-traitance-exemple-de-clauses
  5. CNIL. “Établissements scolaires et périscolaires.” 2025. https://www.cnil.fr/fr/etablissements-scolaires-et-periscolaires
  6. CNIL, in collaboration with academic DPOs and the Ministry of National Education. “Guide pratique - Les violations de données dans l’éducation.” May 2025. https://www.cnil.fr/sites/cnil/files/2025-05/guide_violations_education_etablissements.pdf
  7. Legiscope. “Bilan CNIL 2025 et priorités 2026 : 83 sanctions, 486M€.” 2026. https://www.legiscope.com/blog/bilan-cnil-sanctions-2025-priorites-2026.html (procedural note on simplified-procedure timelines only; sanction-count and euro breakdown figures not used — they conflict with the official CNIL bilan)

Continue reading

Ready to Transform Your School Communication?

Start saving time and increasing parent engagement with BeeNet.

Request Demo