Which tool is allowed to do what?
GDPR traffic-light.
Green means allowed, amber only with care, red is off-limits. When in doubt: no personal data of your pupils in non-GDPR-compliant services. Not legal advice — when unsure, clarify with your school’s data-protection officer.
EU-hosted AI (e.g. Mistral, Aleph Alpha)
Processing within the EU, GDPR-compliant where possible — still, never enter personal data of pupils.allowed
Processing within the EU, GDPR-compliant where possible — still, never enter personal data of pupils.allowed
Anonymised use (US tools without personal data)
Acceptable for general tasks as long as no real names, grades or health data are used.with care
Acceptable for general tasks as long as no real names, grades or health data are used.with care
US AI with pupils’ real names / grades
Not permitted: personal data of minors does not belong in non-GDPR-compliant services.off-limits
Not permitted: personal data of minors does not belong in non-GDPR-compliant services.off-limits
Uploading pupil data as training material
Off-limits. Inputs may be used for training — never use real personal data.off-limits
Off-limits. Inputs may be used for training — never use real personal data.off-limits
Uploading your own materials (no personal data)
Unproblematic as long as no third-party copyrights and no personal data are included.allowed
Unproblematic as long as no third-party copyrights and no personal data are included.allowed
Classification based on Professor Digital erklärt Künstliche Intelligenz für Lehrer · Prof. Dr. Alexander Holtermann, Ph.D., DBA · last checked on 2026-05-30.