ComparisonSep 26, 2026
GDPR-Compliant AI Platforms for K-12: Who Really Keeps Data in Your Country?
Every K-12 AI platform claims GDPR compliance. Only one offers data residency outside the United States. Here's what international schools need to know.

Every K-12 AI platform claims GDPR compliance. The claim is easy to make and hard to verify — because "GDPR-compliant" can mean two very different things:
-
Legal compliance. The platform has Standard Contractual Clauses, a Data Processing Agreement, and a privacy policy that references GDPR. Student data is processed in the United States and transferred across the Atlantic under legal frameworks.
-
Data residency. Student data is stored and processed in the UK or EU. It does not cross international borders. AI inference, document processing, analytics — all of it runs on infrastructure in your jurisdiction.
Most K-12 AI platforms offer the first. This page is about which ones offer the second — because for a growing number of schools, trusts, and education authorities, legal transfer mechanisms are not enough.
Why data residency matters for schools
Three things have changed in the past year that make "where does the data really go?" a sharper question than it used to be:
Government procurement is getting stricter. The UK Department for Education's EdTech procurement guidance now asks vendors to specify where data is processed, not just whether they have SCCs. Multi-academy trusts running competitive tenders are increasingly including data residency as a scored criterion, not just a nice-to-have.
Parents are asking harder questions. "Is our children's data being sent to America?" is a question school leaders hear at governors' meetings and parent forums. The answer matters more when the data includes every message a child has sent to an AI tutor.
Legal transfer mechanisms are under pressure. The EU-U.S. Data Privacy Framework replaced Privacy Shield in 2023, but legal challenges continue. Schools that rely on transfer mechanisms are one court ruling away from a compliance gap. Data residency eliminates that risk entirely.
None of this means a platform without UK/EU data residency is breaking the law. SCCs and the Data Privacy Framework are valid legal mechanisms. But for schools that want to tell parents, governors, and regulators "student data never leaves the UK" — legal compliance alone doesn't get you there.
The platforms
Flint

Flint's security and privacy page (flintk12.com/security), captured September 2026.
Flint is the only K-12 AI platform in this comparison that offers data residency in the United Kingdom.
What this means in practice: When a school deploys Flint's UK instance (uk.flintk12.com), every layer of the platform runs on UK or EU infrastructure:
- Database. Student data is stored in Supabase on AWS
eu-west-2(London). It does not replicate to US regions. - AI inference. All Claude AI requests route through AWS Bedrock with EU geo inference profiles. Student prompts and AI responses stay within EU/UK geography.
- OpenAI services. Image generation, text-to-speech, and transcription use OpenAI's EU endpoint (
eu.api.openai.com), which guarantees both storage and inference within the EEA. Flint deliberately chose the EU endpoint over OpenAI's UK-specific endpoint because the UK endpoint processes data in the US — a detail most platforms don't check. - Document processing. OCR runs through Datalab with processing pinned to the EU (Netherlands). Document exports run through a Lambda function in London. There is no US fallback — if the EU provider is unavailable, the request fails rather than routing student content to a US server.
- Code execution. Student code runs on AWS AgentCore in London, not the US-based E2B sandboxes used by the global deployment.
- Analytics and error tracking. PostHog and Sentry receive anonymized data only — client IP is stripped, person profiles are disabled, and student content is excluded from log payloads before anything reaches US-based analytics infrastructure.
Cookie consent. The UK deployment requires explicit cookie consent (via CookieYes) before analytics or functional cookies are set. The global deployment does not — because US law doesn't require it.
DPO and representatives. Flint has appointed Engage Compliance Ltd as its Data Protection Officer under both UK GDPR Article 37 and EU GDPR Article 37. DataRep serves as the EU, UK, and Swiss data protection representative.
EU AI Act. Flint has assessed its offerings under the EU AI Act and determined they are not classified as "high risk." Regular audits cover AI-related components and synthetic content generation. DataRep serves as Flint's representative for EU AI Act and Digital Services Act compliance.
UK Pioneers Programme. Flint is a participant in the UK Department for Education's Pioneers Programme (June 2026 – March 2027), operating as a joint controller with the DfE under Article 26 of UK GDPR. This is the government's programme for researching and evaluating AI tutoring tools in schools — and Flint's data residency infrastructure is part of what made that partnership possible.
Data anonymization. When student data needs to be removed (e.g., a student leaves the school or a data subject makes an erasure request), Flint anonymizes rather than deletes — replacing PII with safe values in a single atomic transaction, preserving the audit trail while removing all identifying information. Consent events (type and timestamp) are retained as compliance proof; only device identifiers are redacted.
MagicSchool
MagicSchool states GDPR compliance in its privacy policy and has appointed data protection representatives in both the UK (DP Data Protection Services UK Ltd, London) and the EU (Global GmbH, Kiel, Germany).
Where data is processed: The United States. MagicSchool's privacy policy states: "We are a U.S.-based company and many of our service providers, advisors, partners or other recipients of data are also based in the U.S. This means that, if you use the Service, your personal information will necessarily be accessed and processed in the U.S."
Transfer mechanisms: EU-U.S. Data Privacy Framework, Standard Contractual Clauses.
Data residency outside the US: Not available. No EU or UK data hosting option exists.
Privacy certifications: SOC 2, FERPA, COPPA, 1EdTech certified, Common Sense Privacy verified (95% rating), EU-U.S. Data Privacy Framework certified.
International availability: Available internationally, but all data is processed in the US.
SchoolAI
SchoolAI's marketing materials reference GDPR, but detailed GDPR compliance documentation is limited on their public-facing pages. No EU or UK data protection representative is disclosed.
Where data is processed: The United States. No mention of international data residency options.
Transfer mechanisms: Not documented on public pages.
Data residency outside the US: Not available.
Privacy certifications: SOC 2 Type 2, FERPA, COPPA, 1EdTech TrustEd Apps, FIPPA (Canadian), ESSA Tier 3.
International availability: Primarily US-focused. No documented international operations or supported countries outside the US and Canada.
Khanmigo (Khan Academy)
Khan Academy's privacy documentation references FERPA and COPPA but does not mention GDPR in its publicly accessible materials.
Where data is processed: The United States.
Transfer mechanisms: Not documented on public pages.
Data residency outside the US: Not available.
International availability: Limited. Khanmigo for students and parents is US-only (requires a US billing address). Khanmigo for teachers is available in approximately 44 countries through a Microsoft partnership.
Privacy certifications: FERPA, COPPA, state privacy laws.
Brisk Teaching
Brisk Teaching has the most mature international compliance posture among the non-Flint platforms. They publish a dedicated European and UK Privacy Notice and have appointed DataRep as their EU, UK, and Swiss data protection representative.
Where data is processed: The United States. Despite strong GDPR documentation, data is processed in the US with transfer mechanisms.
Transfer mechanisms: EU adequacy determinations, Standard Contractual Clauses, EU-U.S. Data Privacy Framework, UK-U.S. Data Bridge.
Data residency outside the US: Not available.
Privacy certifications: SOC 2 Type II, FERPA, COPPA, GDPR (with dedicated EU/UK notice), 1EdTech (both certifications), Common Sense Privacy 95%, ISTE member. Signed National Data Privacy Agreements with 25 US states.
International availability: Yes — site available in 7 languages. Compliance with Canadian provincial and territorial privacy legislation.
Comparison table
| Capability | Flint | MagicSchool | SchoolAI | Khanmigo | Brisk |
|---|---|---|---|---|---|
| GDPR compliant | Yes | Yes | Mentioned, limited detail | Not documented | Yes (dedicated EU/UK notice) |
| Data residency in UK/EU | Yes (London / EU) | No (US only) | No (US only) | No (US only) | No (US only) |
| AI inference in UK/EU | Yes (Bedrock EU geo) | No | No | No | No |
| Document processing in UK/EU | Yes (EU, no US fallback) | No | No | No | No |
| Analytics PII stripped | Yes (IP, profiles, content) | Not documented | Not documented | Not documented | Not documented |
| Cookie consent required | Yes (UK deployment) | Not documented | Not documented | Not documented | Not documented |
| EU/UK data protection rep | Yes (DataRep) | Yes (UK + EU reps) | No | Not documented | Yes (DataRep) |
| Data Protection Officer | Yes (Engage Compliance) | Not documented | Not documented | Not documented | Not documented |
| Standard Contractual Clauses | Yes | Yes | Not documented | Not documented | Yes |
| EU-US Data Privacy Framework | Yes | Yes | Not documented | Not documented | Yes |
| UK-US Data Bridge | Yes (UK IDTA) | Not stated | Not documented | Not documented | Yes |
| EU AI Act assessed | Yes (not high-risk) | Not documented | Not documented | Not documented | Not documented |
| No AI training on student data | Confirmed | Confirmed | Confirmed | Confirmed (per privacy policy) | Confirmed |
| International availability | Yes (UK, US, custom) | Yes (US data) | Primarily US | Teachers: ~44 countries; Students: US-only | Yes (7 languages) |
| Custom DPAs | Yes, any jurisdiction | Not documented | Not documented | Not documented | Yes (25 US states) |
| FERPA | Yes | Yes | Yes | Yes | Yes |
| SOC 2 | In progress | Yes | Yes (Type 2) | Not documented | Yes (Type II) |
What to ask any platform about international privacy
If your school, trust, or education authority is evaluating AI platforms for international use, these questions separate genuine data residency from GDPR-compliance paperwork:
-
"Where is student data physically stored — which country, which cloud region?" The answer should be a specific AWS/GCP/Azure region, not "we comply with GDPR." If the answer is "the United States," everything else is a transfer mechanism.
-
"Where does AI inference happen? When a student sends a message to the AI, which server processes it?" This is the question most platforms can't answer. Even if the database is in the EU, the AI model call might route to the US — and that means student content crosses the Atlantic on every interaction.
-
"If the EU or UK processing service is unavailable, does the system fail or fall back to a US server?" Failover to a US region means data residency isn't guaranteed under load. A platform that fails closed rather than routing to the US is making a real commitment.
-
"Does your analytics or error-tracking infrastructure receive student content or PII?" Many platforms send full request bodies and user data to US-based analytics services (PostHog, Sentry, Mixpanel). If PII isn't stripped before it reaches those services, data residency has a leak.
-
"Can you show me the sub-processor list with processing locations for each?" A published sub-processor list with specific countries and cloud regions for each service is the best evidence. Flint publishes this at flintk12.com/legal/subprocessors.
-
"Do you have a DPO and an Article 27 representative in the UK and EU?" GDPR requires a representative in the jurisdiction where data subjects are located. Not all platforms have appointed one.
The bottom line
Every platform in this comparison can produce a Data Processing Agreement and point to Standard Contractual Clauses. That's table stakes — it's the legal paperwork that allows US companies to process European data.
Data residency is a different thing. It means student data stays in the UK or EU — every message, every AI interaction, every document upload, every analytics event. No transatlantic transfers, no reliance on legal frameworks that could be invalidated by a court ruling, no explaining to parents that their child's data is "protected" while sitting on a server in Virginia.
Today, Flint is the only K-12 AI platform that offers this. If your school needs data residency — because your procurement rules require it, because your governors expect it, or because you want to give parents an unambiguous answer — that's the gap this page exists to name.
Get started with Flint or book a demo to see the UK deployment in action.
Last updated: September 2026
