I came across an article by Privacy First about the digital student, and it touches on something that continues to bother me about the way we discuss technology in European education. The discussion is often framed as a choice: we can embrace digital technology in schools, or we can protect the privacy of our children.That is the wrong choice.
You can find the article here: https://privacyfirst.nl/artikelen/de-digitale-leerling/ (text in Dutch). Privacy First rightly points out that schools process enormous amounts of information about pupils, ranging from names and contact details to school results, behaviour and sometimes information about a child’s development. Children are particularly vulnerable because they usually have little choice about the software their school tells them to use.
But the conclusion shouldn’t be that schools therefore need less technology. They need different technology: technology that respects privacy and complies with privacy laws.
Digital does not automatically mean Google
There is absolutely no law of nature saying that digital education requires Chromebooks, Google Workspace, Microsoft 365, Windows laptops or MacBooks. A school can give students Linux laptops. It can use Nextcloud or similar open source platforms for storing and sharing files, working together on documents, calendars, video calls and all the other things schools nowadays expect from a digital workplace.
And before somebody says that this sounds nice in theory but could never work for hundreds of thousands of users: it already does. The French region Île-de-France has deployed a sovereign collaboration environment based on Nextcloud for around 550,000 pupils, teachers and administrative staff. The system is part of the regional monlycée.net environment and was explicitly designed as an alternative to Microsoft solutions. It includes document collaboration through Collabora Online, file storage and integration with the region’s existing systems. The infrastructure is operated in France.
You read that right: half a million users. So perhaps we can finally stop pretending that European and open source alternatives are lovely little hobby projects that might work for three enthusiasts and a Raspberry Pi. See https://nextcloud.com/fr/blog/cloud-souverain-plateforme-collaborative-ile-de-france/ for more information.
We became lazy buyers of IT
There is another part of this discussion that I think we don’t talk about enough. A Belgian CIO recently said something to me that stuck: we have forgotten that we actually have to make conscious choices ourselves.
For many years it was incredibly easy not to choose. Microsoft was already there, so you bought some more Microsoft. Your organisation was using AWS, so the next workload went to AWS as well. Google offered a complete education package, so schools bought Chromebooks and Google services.
You could call that standardisation. I increasingly call it convenience. Or perhaps there is a better word for it: laziness. And that is dangerous, because over time, that convenience has turned into dependency.
That dependency matters much more today than it did ten or fifteen years ago. Europe has become deeply dependent on a relatively small number of American technology companies for cloud computing, productivity software, communication and increasingly AI. In their article, Privacy First has made essentially the same broader point about Europe’s dependence on foreign technology providers and the consequences for autonomy and control over data. With today’s geopolitical uncertainty, treating that dependency as merely a procurement detail is becoming increasingly difficult.
Of course you cannot migrate an entire organisation in a day. Nobody sensible is suggesting that. Île-de-France didn’t do that either. But that argument is rapidly becoming an excuse. If you are responsible for IT in a sizeable European organisation and you are still not investigating alternatives, testing them, identifying dependencies and developing a realistic migration path, I think you have a problem. Migration takes years. Which is precisely why you need to start before circumstances force you to.
And then there are the children
There is something particularly uncomfortable about teaching children about privacy, data protection and digital literacy while at the same time making them use platforms built by some of the world’s largest data-driven technology companies. Privacy First argues that privacy should not simply be another compliance box for schools to tick. It should be a basic design principle of the digital environment children grow up in.
I couldn’t agree more with that conclusion. We have GDPR. We have endless discussions about children’s online safety. We teach pupils to think carefully about what they share online. And then institutions themselves make the fundamental technology choices on their behalf.
Schools deserve support from governments and IT specialists to make better choices. But eventually somebody also has to take responsibility. The technology exists. The alternatives exist. Large-scale examples exist. Île-de-France is already showing that hundreds of thousands of pupils and teachers can work digitally without simply handing the entire environment to Microsoft or Google.
So this really isn’t a discussion about digital versus privacy. It is about whether school directors are willing to do the homework required to have both.