Madrid catholic school fined €12,000 for turning google classroom into a data sieve

A Madrid primary school has 30 days to pay €12,000 after Spain’s data watchdog caught it feeding pupils’ personal data into Google Workspace without parental consent, firewalls, or any real idea of where that data might end up.

The holy mary loophole: unlimited chrome, zero safeguards

Holy Mary Catholic School deployed Google Workspace for Education as a daily diary, attendance sheet and homework portal for children as young as six. The platform came with unrestricted internet access, meaning first-graders could bounce from arithmetic drills to YouTube wormholes during class time. According to the AEPD ruling, the school never signed a data-processing agreement with Google, never carried out a privacy impact assessment, and never told parents it was creating Gmail accounts for their kids.

Investigators found the domain hmschool.edu had been whitelisted inside Chrome’s admin console, effectively disabling SafeSearch, age filters and download blocks. One third-grader’s browsing log shows 47 visits to Fortnite fan sites in a single morning. The school’s defence — “we trusted Google’s default settings” — was dismissed as negligence.

A mother’s screenshot that started the domino effect

A mother’s screenshot that started the domino effect

The breach surfaced in March 2024 when a mother noticed her eight-year-old had received a spam mail advertising mobile games on his school-issued Gmail. She asked why he even had a Gmail address; the headteacher replied it was “standard practice”. She filed a complaint the same afternoon. The AEPD opened proceedings within weeks, interviewing teachers and seizing server logs that revealed pupils’ full names, photos and behavioural notes were stored on U.S. cloud shards governed by Standard Contractual Clauses — clauses the school had never reviewed.

Under the GDPR, processing a child’s data requires “explicit, verifiable consent”. The school produced a generic clause buried on page nine of the enrolment form, but regulators ruled it invalid because it mentioned neither Google nor cloud storage outside the EU.

The €12,000 penalty is relatively light — the AEPD could have levied up to €20 million — yet it lands amid a broader crackdown on ed-tech sloppiness. Spain has 14 similar cases open, including one involving a regional government that licensed Microsoft 365 for 600,000 students without auditing privacy settings.

Google for Education insists its tools are “built for the classroom”, but the Holy Mary file shows the tech giant’s admin dashboards still leave fatal gaps if schools click “accept” without customising policies. The AEPD’s message is blunt: handing children’s data to Silicon Valley is not a turnkey operation.

Meanwhile, Holy Mary has two weeks to appeal. Parents have already set up a Telegram channel to pool funds for a collective lawsuit should the school try to pass the fine on via tuition hikes. The lesson Spain’s privacy regulator just taught is older than any algorithm: if you don’t configure the system, the system will configure you.