Priority sector
Schools, universities, training providers and research organisations handle data of students, often minors, and valuable research assets.
Key obligations
Children's data merits specific protection, and in Spain the LOPDGDD requires schools and universities to designate a DPO.
AI systems used for admission, the evaluation of learning outcomes or the monitoring of tests are high-risk under the AI Act.
Research organisations are listed among the other critical sectors in Annex II of NIS2.
As public bodies, public universities must designate a DPO and establish internal whistleblowing channels.
Education and research institutions combine data of minors, academic records, research data and open, decentralised IT environments. They are frequent targets of cyberattacks and increasingly use AI tools for teaching, assessment and administration. Public institutions add the duties of public bodies, including transparency and procurement rules.
Data Protection Officer: for schools, school groups, universities and training providers;
AI governance: rules for the use of AI by teachers, students and administrative staff;
information security: NIS2 measures for research organisations and incident response;
integrity programmes: whistleblowing channels and research integrity procedures.
A free Compliance Assessment identifies the priorities for your institution.
Related domains: Data Protection · Artificial Intelligence · Cybersecurity (NIS2) · Whistleblower Protection · Anti-Corruption
Regulated functions: Data Protection Officer · Information Security Officer · Whistleblowing Officer · All sectors
General information as at October 2026; it does not constitute legal advice.
Request a free assessment designed for schools, universities and research organisations.