Is iThenticate GDPR compliant? What universities should check
iThenticate is Turnitin's similarity checker for manuscripts, theses, grant proposals and other high-stakes research writing. Universities use it in research offices, graduate schools and university presses. This page sets out what Turnitin publicly documents about iThenticate and what a university should check, given that unpublished research is often confidential as well as personal.
Short answer
iThenticate is run by Turnitin, LLC, a US company that acts as a processor for institutions under its data processing agreement with the EU standard contractual clauses attached. Turnitin says iThenticate stores data on AWS with data centres in the US, Europe and Asia-Pacific, and that it complies with the EU-US Data Privacy Framework. Whether checked manuscripts stay in a searchable database depends on whether the account has a private repository, and permanent deletion requires purging files from the Trash folder. AI writing detection is a paid add-on. For universities the main questions are which region holds the account, what manuscripts are indexed, and how confidential or participant data inside manuscripts is handled.
What Turnitin documents publicly about iThenticate
This summary covers iThenticate 2.0 and, where noted, Classic iThenticate (version 1), as described in Turnitin's documentation on 7 October 2026.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented iThenticate is a Turnitin product. The processor in Turnitin's DPA is Turnitin, LLC of Oakland, California, with group companies in the UK, India, the Netherlands, Ukraine and the US acceding to the SCCs. Turnitin names a Data Protection Officer based in the UK. | iThenticate product page [1], DPA [7] |
| Where data is stored and processed | Plan-dependent Turnitin says iThenticate "stores data on a highly secure AWS platform with data centers in the U.S., Europe, and Asia-Pacific". The DPA says the AWS platform stores submitted content in Frankfurt for EU storage, with randomised, encrypted sections processed in the US for comparison. Support staff may work in the UK, the EU, Ukraine, the Philippines, Australia or India. | [1], [7], Services Privacy Policy [8] |
| Data processing agreement | Documented Turnitin's public DPA covers its academic integrity services, describes processing of names, email addresses, academic IDs and submission content, and incorporates the 2021 SCCs. | [7] |
| Subprocessors | Documented A public Turnitin list (last updated February 2026) including Amazon Web Services, Google, Microsoft (Bing), Cockroach Labs, Concentrix, SDL (machine translation for multilingual comparison, where offered), Skyflow and Zendesk. The DPA promises 30 days' notice of new subprocessors. | Subprocessor list [10], [7] |
| International transfers (DPF, SCCs) | Documented Turnitin states that it complies with the EU-US DPF, the UK Extension and the Swiss-US DPF (status read from the vendor's privacy policy). The DPA adds SCCs and a section on US surveillance law and government access requests. | [8], [7], GDPR FAQ [9] |
| Repository and comparison database | Plan-dependent Administrators control whether users can index documents in a private repository accessible only to the user or institution. Comparison sources include Crossref member content, CORE open-access metadata and ProQuest theses. In Classic iThenticate, accounts without a private repository do not save uploads in a searchable database. | [1], Private repositories (Classic) [5] |
| Retention and deletion | Documented Users can delete submissions, but a file in Trash stays in the repository index until purged. Administrators can delete papers via Paper Lookup. The Classic guide says files are completely erased 90 days after permanent deletion. The DPA describes indefinite storage of submissions unless the institution instructs otherwise. | Permanent deletion [4], [5], [7] |
| AI features and training on customer content | Plan-dependent AI writing detection is a paid add-on available only with iThenticate 2.0, shown as a percentage in the Similarity Report. Turnitin's services privacy policy lists developing AI models related to writing, citations, grammar or plagiarism detection among its purposes, which may use anonymised, aggregated or de-identified data where permitted by law and customer agreements. | [1], Upgrading to iThenticate 2.0 [2], [8] |
| Security certifications | Plan-dependent Turnitin says it undergoes annual SOC 2 Type II audits by an external, independent auditor. An iThenticate-specific ISO 27001 certificate was not found in public documentation (checked 7 October 2026). | [8] |
Turnitin has moved customers from Classic iThenticate to iThenticate 2.0. Its migration guidance says accounts, users, submissions, reports and folders are moved, while some inactive accounts, deleted submissions, and unindexed submissions without a Similarity Report are not migrated [2][3].
What this means for a university
Validemic's analysis
Manuscripts are more than text. A manuscript or grant proposal carries the names of authors and co-authors and, in some fields, descriptions of research participants, case details or quotations from interviews. The DPA itself acknowledges that sensitive data could be processed when people submit work about themselves [7]. Research offices should tell researchers to remove participant data and confidential material before checking, or confirm that the processing is covered by the research project's own legal basis and information to participants.
Confidentiality and repositories. Unpublished work indexed into a repository can later produce matches for other users of the same repository. Decide whether your account needs a private repository at all, who can add to it, and how researchers are told. Remember that deleting a file is a two-step process [4].
Region. Turnitin describes regional AWS data centres for iThenticate [1], but also US comparison processing on the AWS platform [7]. Record which region your account uses and what leaves it.
DPIA likelihood. For routine checks of a researcher's own manuscript, a full DPIA may not always be needed, but large-scale screening of theses or applications, or use of AI writing detection in misconduct procedures, points towards one under Article 35 GDPR [11]. Article 22 GDPR protects people against decisions based solely on automated processing with significant effects [11].
University presses. If your press uses iThenticate through Crossref Similarity Check, Crossref says participating members allow Turnitin to index their published content in exchange for reduced-rate access [6]. That is a publisher decision, separate from the research office's account.
Transfers. The DPF adequacy decision of 10 July 2023 covers certified US companies [12]. Turnitin's DPA also relies on SCCs for its group companies outside the EEA [7].
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Turnitin before approving iThenticate
- Which data centre region holds our iThenticate account, and which data is processed outside it?
- Does our account have a private repository, who can index into it, and can we disable indexing by default?
- After a file is purged from Trash, how long until it is erased from backups and all systems?
- Are documents we check, including AI writing results, used in any form to train or improve Turnitin models? Can we exclude this contractually?
- How do you classify AI writing detection in iThenticate under Article 6 and Annex III of the AI Act?
- What logs of checks and AI results are available to us, and for how long?
- Which subprocessors process manuscript content, and in which countries?
- How do you handle a manuscript that contains special category data about research participants?
- Can we receive your SOC 2 Type II report?
The EU AI Act angle
When iThenticate meets Annex III. Annex III, point 3, of the AI Act lists as high-risk AI systems intended to evaluate learning outcomes (point 3(b)) and AI systems intended for monitoring and detecting prohibited behaviour of students during tests (point 3(d)), in educational institutions at all levels [13]. Point 3(a) adds systems intended to determine access or admission. Similarity checking of a journal manuscript is outside education in this sense, but Turnitin's own product page lists admissions officers and students among iThenticate users [1], and doctoral theses are both research and assessed work. AI writing detection used in those settings deserves a classification check. Article 6(3) allows an Annex III system not to be treated as high-risk where it does not pose a significant risk, for example where it performs only a narrow procedural or preparatory task [14]. We found no public AI Act classification for iThenticate (checked 7 October 2026).
Deployer duties. If a use is high-risk, Article 26 requires the university to follow the instructions for use, assign competent human oversight, monitor operation, keep logs for at least six months, inform the people affected and use the provider's information in its DPIA [15]. Article 27 requires a fundamental rights impact assessment before first use by bodies governed by public law, which includes many public universities [16].
Already in force. Emotion recognition in education is prohibited by Article 5(1)(f), except for medical or safety reasons, and has been since 2 February 2025 [17][18]; iThenticate does not describe such a feature. The AI literacy duty in Article 4, as amended, applies now [20].
Timeline. Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026 [19]. Under the amended Article 113, high-risk rules for Annex III systems apply from 2 December 2027 [18].
Sources
- iThenticate product page and FAQ, Turnitin, retrieved 7 October 2026
- Upgrading to iThenticate 2.0, Turnitin Guides (dated 11 April 2025), retrieved 7 October 2026
- User data migration to iThenticate 2.0, Turnitin Guides (dated 13 January 2025), retrieved 7 October 2026
- How to permanently delete a document from the repository in iThenticate 2.0, Turnitin Help Center, retrieved 7 October 2026
- Private repositories/nodes (Classic iThenticate), iThenticate Guides (updated 8 July 2025), retrieved 7 October 2026
- Similarity Check, Crossref, retrieved 7 October 2026
- Turnitin Data Processing Agreement, retrieved 7 October 2026
- Turnitin Services Privacy Policy (last updated 4 February 2026), retrieved 7 October 2026
- Turnitin and GDPR (FAQ), retrieved 7 October 2026
- Turnitin Subprocessors (last updated February 2026), retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Articles 22 and 35, text read from the Publications Office copy, retrieved 7 October 2026
- EU-US data transfers, European Commission, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
- AI Act Article 6: Classification rules for high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 26: Obligations of deployers of high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 27: Fundamental rights impact assessment, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
- AI Act, Shaping Europe's digital future (European Commission), with link to the AI Omnibus final text (OJ L 2026/1744), retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
About this page
We read Turnitin's iThenticate product page and FAQ, its iThenticate help articles on migration, private repositories and deletion, Turnitin's DPA, services privacy policy, GDPR FAQ and subprocessor list, Crossref's Similarity Check page, the GDPR and the consolidated AI Act text on 7 October 2026. The official Data Privacy Framework list did not return results for automated queries that day, so DPF status is taken from Turnitin's own privacy policy. Statements about iThenticate come from Turnitin's and Crossref's own pages; our interpretation is labelled as Validemic's analysis. This is not legal advice and does not say whether any particular use of iThenticate complies with the GDPR or the AI Act. If you see an error or an outdated detail, please contact us and we will correct it.
Frequently asked questions
Is iThenticate GDPR compliant?
No tool is GDPR compliant on its own. iThenticate is a Turnitin product covered by Turnitin's services privacy policy and data processing agreement, which includes the 2021 standard contractual clauses. Turnitin says it complies with the EU-US Data Privacy Framework and that iThenticate data is stored on AWS with data centres in the US, Europe and Asia-Pacific. Whether a university's use is lawful depends on its contract, region, repository settings and what manuscripts contain.
Does iThenticate keep the documents I check?
It depends on the account. Turnitin says administrators control whether users can index documents in a private repository that only the user or institution can access. Its Classic iThenticate guide says that without a private repository, uploaded documents are not saved in a searchable database used for future comparisons.
How do I permanently delete a manuscript from iThenticate?
In iThenticate 2.0, Turnitin describes two stages: move the file to Trash, then purge it from Trash. Moving to Trash alone does not remove it from the repository index. Administrators can also delete papers with the Paper Lookup tool. Turnitin's Classic guide says files are completely erased 90 days after permanent deletion.
What is the difference between iThenticate and Crossref Similarity Check?
Crossref describes Similarity Check as a service for its members, powered by iThenticate, offering reduced-rate access in return for allowing Turnitin to index the member's published content. University presses that are Crossref members may use iThenticate through this route.
Does iThenticate detect AI writing?
Turnitin offers AI writing detection for iThenticate as a paid add-on, available only with iThenticate 2.0. Its product page says detection of paraphrased or bypassed content is available in English only. Results should be treated as an indicator for human review, not as proof.