Sovereign video and the GDPR: a guide for education and training
Video conferencing has become an everyday tool in education and vocational training. But behind the simplicity of one click to join a class or a webinar sits a question many institutions and training providers have yet to settle: is their video tool GDPR-compliant, and is their pupils’, students’ and learners’ data genuinely protected?
This guide reviews the legal framework, the concrete risks, the criteria for choosing and the options available in 2026.
What does “sovereign video conferencing” mean?
Sovereign video conferencing is a tool whose data (audio, video, chat, connection metadata) stays under the control of the organisation using it, hosted on national or European territory, and not subject to extraterritorial laws such as the American CLOUD Act.
Three conditions have to be met at once.
- Hosting on the territory, on infrastructure not subject to the law of a third country.
- No technical dependency on extraterritorial suppliers, including the invisible parts (STUN servers, TLS certificates, CDNs, analytics).
- Transparency of the code, so that what the software actually does with the data can be verified.
A tool hosted in France but published by an American company is not enough: the CLOUD Act lets the United States government demand access to data held by an American company, whatever the country of hosting.
What are the concrete risks for an institution using Zoom or Teams?
The risk is not theoretical. It shows up in several ways.
Extraterritorial access to data. When a class is delivered over Zoom or Teams, the audio and video streams pass through servers controlled by an American company. Even if those servers are physically in Europe, the CLOUD Act allows the American authorities to require access to that data without going through European mutual legal assistance mechanisms. For an institution processing minors’ data or confidential research, that is a documented legal risk.
Metadata collection. Beyond the content of meetings, American tools collect metadata: who took part, when, for how long, on which device, from where. That metadata makes it possible to reconstruct habits, relationships and behaviour without ever touching the content.
Functional dependency. An institution that builds its teaching processes around a proprietary tool (scheduling, recordings, LMS integration, room management) becomes captive to it. A price rise, a change in terms of use or a political decision (such as the public sector ban of January 2026) can force an emergency migration.
Reputational risk. For a public institution, using a tool the French data protection authority advises against and the public sector has banned sends a contradictory signal. For a Qualiopi-certified training provider, it is a potential weak point in an audit.
Why are education and training particularly exposed?
The data at stake is sensitive
In education, video conferencing processes minors’ data (image, voice, name, connection data), teaching content that is sometimes confidential, ongoing research in higher education, and exchanges that can touch on health or disability. The French data protection authority explicitly underlined those risks in its 2021 opinion, issued at the request of the French conferences of grandes écoles and university presidents (IT-Connect).
In vocational training the data is just as sensitive: learners’ identity and career history, qualification level, assessments, connection data on e-learning platforms, and sometimes health data (medical training) or disability-related data. The training provider is the data controller under the GDPR (DPO Partage).
The regulatory framework tightened in 2025 and 2026
The French data protection authority has advised against Zoom and Teams in higher education since 2021. Its opinion recalls that these tools are published by American companies subject to the CLOUD Act, and that the data processed (students, researchers, minors) needs guarantees those tools cannot reliably offer (Phonandroid).
Decree 2025-1165 of 5 December 2025 wrote a digital reference framework into the French education code, requiring public secondary schools to use tools compliant with the interoperability, security and responsible-digital standards set by the ministry (Légifrance). It is the first time a binding technical framework has entered the education code (Café pédagogique).
On 26 January 2026, the French minister for the civil service announced a ban on Zoom, Teams, Webex and Google Meet across the whole public sector. Civil servants must move to Visio, the sovereign platform run by DINUM (CX Foundation). That ban does not yet apply to schools or to private training providers, but it sets a clear political direction.
The French directorate for digital education is explicit: it has insisted that the collaborative suites used in schools be controlled and sovereign, because pupils’ data is politically sensitive (Café pédagogique).
What are the GDPR obligations for video conferencing?
The GDPR applies as soon as a video conferencing tool processes personal data, which is the case in every session (image, voice, participant name, connection metadata, chat content).
For schools and universities
The institution is the data controller. It has to make sure the video tool respects the GDPR principles: data minimisation (collect only what is necessary), storage limitation, data security and information for the people concerned. When participants are minors, vigilance must be greater still.
Recording a virtual class is processing of personal data in its own right. It requires a lawful basis (legitimate interest or consent), prior information for participants, a defined retention period and an entry in the record of processing activities (la-visioconference.com).
For vocational training providers
The training provider is the data controller for teaching and administrative management. Relations with French funding bodies, the personal training account run by the Caisse des Dépôts and the national employment agency involve data transfers governed by specific regulations (DPO Partage).
The Qualiopi certification, mandatory for courses funded from public or pooled funds, includes requirements on follow-up, traceability and continuous improvement that involve collecting personal data. The video tool has to make those functions possible while respecting the GDPR.
In practice, a training provider using video conferencing has to be able to document learner attendance (digital attendance sheets), keep session recordings for traceability, and export participation data to send to funders. Each of those operations is processing of personal data and has to appear in the record.
Recording deserves particular attention. Recording a training session captures participants’ image, voice and name. Their consent has to be collected, or legitimate interest has to be documented. The retention period must be defined (usually aligned with Qualiopi obligations, which means three to five years depending on the funder). And the recording has to be stored securely, ideally encrypted at rest.
A video conferencing tool that stores recordings in an American cloud (which Zoom and Teams do by default) creates a structural problem: your learners’ training data is then subject to the CLOUD Act, with no technical remedy available to you.
In 2026 the GDPR obligations tighten further: professionals handling sensitive data have to show annual training in data protection and cybersecurity (Adnov). Article 39 of the GDPR requires the data protection officer to raise awareness and train the staff involved in processing operations (Leto).
How to assess a video tool’s GDPR compliance
Here are the criteria to check, from the most fundamental to the most technical.
1. Is the vendor subject to the CLOUD Act?
If the vendor is an American company (Zoom, Microsoft, Google, 8x8/Jitsi), the CLOUD Act applies whatever the hosting location. That is the first filter.
2. Where is the data hosted?
The data (media streams, chat, recordings, metadata) has to stay in the European Union, ideally in France. Watch the invisible parts: a tool can be “hosted in France” while using a Google STUN server, an American CDN or TLS certificates from an American authority.
3. Which data is collected?
A well-designed sovereign tool minimises data: no mandatory user account, no tracking cookie, no behavioural data collection. Every piece of data collected has to have a precise, documented purpose.
4. Is the data encrypted?
Encryption in transit (DTLS-SRTP) is standard in WebRTC and protects data on the network. Encryption of data at rest (configuration, chat history, recordings) is essential additional protection if the server is compromised.
5. What happens at the end of the session?
Session data has to be deleted automatically when the room closes. Recordings must have a defined retention period and be deletable on request.
6. Can the code be audited?
Open source software lets the institution (or a trusted third party) verify what the tool really does with the data. Closed code means taking the vendor at their word.
7. Does the tool work with your LMS?
In education, compatibility with Moodle (through the BigBlueButton API or LTI) is often a blocking criterion. A video tool that does not fit into the existing LMS breaks the teaching path and forces teachers to juggle several interfaces.
8. Is the tool genuinely independent?
Beyond the software licence, check the dependency chain: does the tool use a STUN or TURN server run by an American third party (Google, Amazon)? Is the TLS certificate issued by a European authority? Do updates travel over sovereign infrastructure? Those details separate real sovereignty from sovereignty as a façade.
Comparing the options for education and training
| Criterion | Zoom / Teams | BigBlueButton | Jitsi Meet | Vuisio |
|---|---|---|---|---|
| Vendor | United States | Canada | United States (8x8) | France (Geezot) |
| CLOUD Act | Yes | No (self-hosted) | Yes (8x8) | No |
| Licence | Proprietary | LGPL 3.0 | Apache 2.0 | AGPL 3.0 |
| Moodle compatibility | Third-party plugin | Native | LTI plugin | BBB-compatible API (docs.vuis.io) |
| User account required | Yes | Yes (Greenlight) | Yes (meet.jit.si) | No (docs.vuis.io) |
| Cookies | Yes | Yes | Yes | None imposed by the core (docs.vuis.io) |
| Encryption at rest | Not documented | Not documented | Not documented | AES-256-GCM (docs.vuis.io) |
| Automatic cleanup | No | 14 days by default | Not documented | Data erased when the room closes (docs.vuis.io) |
| STUN server | Their own (USA) | Not documented | European Nextcloud (docs.vuis.io) | |
| TLS certificate | Their own (USA) | Let’s Encrypt (USA) | Let’s Encrypt (USA) | Actalis, European, by default (docs.vuis.io) |
| Minimum infrastructure | Vendor cloud | 16 GB RAM, 8 cores, Ubuntu | 8 GB RAM recommended | 1 GB of RAM, 2 cores for ten participants |
| Sovereign cloud in France | No | No | No | Yes (free or Pro) |
| Recording | Vendor cloud | On the server (BBB format) | Jibri (Chrome plus ffmpeg, 8 GB RAM per session) | Native MP4 (Pro module) |
| Voice anonymisation | No | No | No | Yes (docs.vuis.io) |
| Price | Licence per user | Free (heavy infrastructure) | Free (infrastructure) / JaaS 0.35 USD per MAU | Free / Pro €29 per host per month |
How Vuisio meets the needs of education and training
Vuisio was designed for organisations that cannot entrust their audiences’ data to a foreign supplier.
Sovereign down to the details. Hosting in France, a French vendor, auditable source code (AGPL 3.0), no user account (an ephemeral numeric identifier), no cookie, no behavioural tracking (docs.vuis.io). The default STUN server is European (Nextcloud), the default TLS certificate is European (Actalis). Room data is encrypted with AES-256-GCM and deleted automatically when the room closes (docs.vuis.io).
Compatible with Moodle and existing LMSes. The compat-api module implements the BigBlueButton protocol (docs.vuis.io), which lets institutions already running Moodle migrate without touching the existing integration. The teacher starts the meeting from their course, the student joins with one click.
Light, even for small institutions. The Rust SFU architecture with no transcoding lets Vuisio run on modest hardware (docs.vuis.io). A server with 1 GB of RAM and 2 cores carries about ten participants. A standard server with 6 vCPU carries 450 to 500 participants. That is a decisive advantage for schools, rural secondary schools and training providers with no IT department.
Suited to vocational training. Native MP4 recording (Pro module) lets sessions be kept for Qualiopi traceability. Chat and session metadata are encrypted and exportable for teaching follow-up (docs.vuis.io). Billing per host rather than per participant suits providers training groups of varying size.
A feature unique in education: voice anonymisation. Vuisio offers a real-time voice anonymisation module (docs.vuis.io), useful where participants’ identity has to be protected (testimony, consultations, sensitive assessments).
How to migrate to a sovereign solution
From Moodle plus BigBlueButton
This is the most common scenario in education. Install Vuisio’s compat-api module (vuisio module add compat-api), change the server URL and the shared secret in the Moodle configuration (Administration > Plugins > BigBlueButton), and test. Rooms, roles and join links keep working.
From Zoom or Teams (with no LMS)
Share a Vuisio link (through the lobby module or the API) with your participants. Nothing to install, everything runs in the browser. The free sovereign cloud plan limits neither the length of the session nor the number of participants.
For institutions with no infrastructure
Vuisio’s free sovereign cloud needs no server, no certificate and no maintenance. If the institution wants full control, the interactive installer deploys an instance in a few minutes on a Debian or Ubuntu server (docs.vuis.io), with atomic updates and automatic rollback. Our complete guide to hosting your own video conferencing compares the self-hosting options step by step.
What to write in your GDPR record
If you deploy a new video conferencing tool, your record of processing activities has to document the following.
The purpose of the processing (virtual classes, training, webinars). The lawful basis (a public interest task for public institutions, legitimate interest or consent for private organisations). The categories of data processed (image, voice, name, connection metadata, chat content, recordings). The recipients (who has access: teachers, administrators, the host). The security measures (encryption in transit, encryption at rest, access control, automatic cleanup). The retention period (ephemeral for live sessions, defined for recordings). And transfers outside the EU: with a sovereign tool hosted in France, the answer is none.
With Vuisio, most of those points are covered by design: no account, no cookie, encrypted data, automatic cleanup, hosting in France, no transfer outside the EU.
Good practice in daily use
Choosing a sovereign tool is necessary but not sufficient. Everyday habits matter as much as the infrastructure.
Inform participants before each session. The GDPR requires that the people concerned be informed that their data is collected. In practice, a note in the invitation or a reminder at the start of the session is enough: state the purpose (class, training), the tool used, where the data is hosted and how long anything is kept.
Get consent for recording. If you record the session, consent has to be collected before the recording starts. Legitimate interest can also serve as a lawful basis, but it has to be documented and proportionate. In every case, participants must be told the session is being recorded, by whom, and for how long the file will be kept.
Limit the data you collect. A well-designed tool minimises collection by default. Do not ask participants to create an account if a link is enough. Do not collect location or behavioural data if it is not needed. The minimisation principle (article 5 of the GDPR) applies fully to video conferencing.
Set retention periods. Recordings of classes or training sessions should not be kept indefinitely. Align retention with your legal obligations (Qualiopi, the training agreement, funders’ requirements) and delete the files when the time is up.
Document it in the record of processing. Video conferencing is processing of personal data. It has to appear in your GDPR record with its purpose, lawful basis, categories of data, recipients, security measures and retention period.
Train your teams. The French data protection authority recalls that failing to raise staff awareness is a breach of the accountability obligation (Leto). Make sure teachers and trainers know the basics: do not share meeting links publicly, enable the waiting room or a password, do not record without telling people.
In summary
The French regulatory framework of 2025 and 2026 sets a clear direction for education and training: digital tools must be sovereign, secure and interoperable. The data protection authority advises against Zoom and Teams in teaching. The decree of 5 December 2025 imposes binding standards on secondary schools. And the public sector has banned American tools since January 2026.
Vuisio lets schools, universities and training providers become compliant without giving up usability: Moodle-compatible, light, encrypted, with no account, no cookie, hosted in France, and free to start.
Try Vuisio free and hold your video tools up to the GDPR.
Frequently asked questions
Does a training provider have to comply with the GDPR for video conferencing?
Yes. The training provider is the data controller for its learners' teaching and administrative data. Video conferencing processes personal data (image, voice, name, connection data). It has to appear in the record of processing activities and respect the principles of minimisation and security.
Does the French data protection authority ban Zoom and Teams in education?
It does not formally ban them but has strongly advised against them in higher education since 2021, because the data passes through servers belonging to American companies subject to the CLOUD Act. The decree of 5 December 2025 also requires public secondary schools to use tools compliant with the ministry's security and interoperability standards.
Does the CLOUD Act apply to my pupils' or learners' data?
If you use a tool published by an American company (Zoom, Teams, Google Meet), the CLOUD Act lets the United States government demand access to the data, even when hosted in Europe. That covers the image, voice, chat and connection metadata of your pupils or learners.
Is recording a virtual class processing of personal data?
Yes. A recording captures participants' image, voice and name. It is processing of personal data under the GDPR, which requires a lawful basis (legitimate interest or consent), prior information for participants, a defined retention period and an entry in the record of processing activities.
Does Qualiopi impose requirements on video conferencing?
Not directly on the video tool, but the French Qualiopi certification requires course follow-up, traceable attendance and continuous improvement, all of which involve collecting personal data. The video tool has to make those functions possible while respecting the GDPR.
Is Vuisio GDPR-compliant for education and training?
Yes. Vuisio is hosted in France, creates no user account, uses no cookie, encrypts data at rest with AES-256-GCM, and deletes room data automatically when the room closes. No data passes through a server subject to the CLOUD Act.
How do you choose between BigBlueButton and Vuisio for a school?
Both are open source and work with Moodle. BBB requires heavy infrastructure (16 GB of RAM, 8 cores, dedicated Ubuntu) and has no encryption at rest. Vuisio carries about ten participants on 1 GB of RAM, encrypts data with AES-256-GCM, and offers a free sovereign cloud with no infrastructure to run.
Is there a free sovereign cloud for video conferencing in schools?
Yes. Vuisio offers a free sovereign cloud hosted in France, with no limit on length or participants, including chat, screen sharing, webcam, files, reactions, the basic whiteboard and polls. Recording and participation analytics belong to the Pro plan. No card and no infrastructure required.
Complete guide : Hosting your own video conferencing in 2026: the complete guide