Is Kahoot! GDPR compliant? What universities should check
Kahoot! is a game-based quiz platform from Kahoot! AS in Oslo, used in lectures, seminars and student events. This page sets out what Kahoot! publicly documents about its data processing agreement, hosting, sub-processors, AI features and security, and what that means for a university.
Short answer
Kahoot! AS is a Norwegian company, and Norway is part of the EEA, where the GDPR applies. Kahoot! publishes its data processing agreement online, names itself as processor for organisations in the UK and EEA, stores customer personal data long-term in the EU and Canada, and lists ISO/IEC 27001:2022 and a SOC 2 Type 2 report. Its AI features run mainly on Microsoft Azure in Europe, and it says platform data is not used to train models. The points to check are the Canada hosting, the age of the sub-processor list compared with the AI page, and whether staff use an institutional plan with SSO rather than free personal accounts.
What Kahoot! documents publicly
This summary reflects Kahoot!'s trust centre pages, read on 7 October 2026: the privacy notice (effective 1 September 2026), the DPA (effective 22 January 2025), the sub-processor list (effective 3 March 2025), the AI features page (effective 13 November 2025) and the higher education page. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Kahoot! AS, organisation number 997 770 234, Kronprinsesse Märthas plass 1, 0160 Oslo, Norway, with affiliates in the EU and elsewhere listed as controllers for the privacy notice. Norway's supervisory authority sits on the EDPB for GDPR matters. | [1] [9] |
| Where data is stored | Documented Cloud and hosting providers have data centres in the EU, Canada, Australia and the USA. Long-term storage of customer personal data is in the EU and Canada. For European users using the service from the EU, data is processed only in the EU and Canada, except where personal data is added in videos or support tickets. | [2] |
| Data processing agreement | Documented A public DPA applies to all customers where Kahoot! is a processor, unless another agreement is in place. The customer is controller, Kahoot! is processor, with sub-processor objection rights (15 days), audit rights and deletion or return of data within 90 days of termination. The DPA says neither party intends Kahoot! to process sensitive data. | [3] |
| Processor or controller | Plan-dependent For school services, or services provided through an organisation in the UK and EEA, Kahoot! processes personal data as a processor and the school or organisation is controller. For other purposes in the privacy notice, such as personal accounts, Kahoot! is controller. | [1] |
| Sub-processors | Documented The list names AWS (EU, Canada and regional processing in the US, Australia and Japan for users there), Aiven (EU and Canada), Google Cloud (EU and Canada, plus global infrastructure for technical functionality), OVH Canada, Hetzner Germany, Cloudflare (Story videos), Zendesk (support, hosted in the EU), SendGrid via Twilio Ireland (email) and Kahoot! group companies. | [2] |
| International transfers | Documented Transfers rely on adequacy decisions, including the EU-U.S. DPF and its UK and Swiss extensions, or on standard contractual clauses. Which recipients rely on the DPF is not stated. The official DPF list API was not responding on the check date. | [1] [3] |
| AI features and training | Documented AI-assisted creator, PDF to kahoot, Story text enhancer, search and brainstorm clustering, among others. The main LLM provider is Microsoft Azure based in Europe; some features also use Perplexity (paid plans), Google or on-device Apple models. Brainstorm clustering uses a model hosted by Kahoot! itself. No platform data is used to train or refine models, and users are told not to put personal data into prompts or uploads. | [4] [1] |
| Retention and deletion | Documented After a subscription ends, deletion of all organisation data starts automatically within 90 days, with the organisation owner notified first. The privacy notice uses purpose-based retention criteria. | [5] [1] |
| Security certifications | Documented The higher education page lists ISO/IEC 27001:2022 and an AICPA SOC 2 Type 2 report, encryption in transit (TLS 1.2 or higher) and at rest, and a bug bounty programme. | [5] |
| Institution controls | Plan-dependent Roles, feature toggles including AI where the plan allows, SSO, SCIM and domain claim to stop unauthorised use under the organisation's domain. | [5] |
Kahoot! deserves credit for publishing its full DPA on the web rather than only on request, for a sub-processor list with entities and addresses, and for an AI page that names models and providers per feature and explains which features run on Kahoot!'s own infrastructure or on the user's device.
What this means for a university
Validemic's analysis
The plan decides the role. Through an institutional plan, Kahoot! is a processor and the university is controller [1] [3]. A lecturer using a free personal account is in a different position: Kahoot! is then controller for that account [1], and the university has little visibility. For regular teaching use, an institutional licence with SSO and domain claim [5] brings staff accounts under the DPA.
Canada is part of the hosting picture. Long-term storage is in the EU and Canada [2]. The European Commission's list of adequacy decisions includes Canada for commercial organisations [12], and Kahoot!'s privacy notice relies on adequacy decisions in general terms [1]. Universities that require EU-only storage should raise this before contracting, since the sub-processor page describes Canada as part of the default set-up for European users [2].
Compare the sub-processor list with the AI page. The AI page names Microsoft Azure as main LLM provider and also Perplexity and Google for some features [4]. These names were not on the sub-processor list dated 3 March 2025 [2]. Kahoot! says it does not knowingly send personal data to Microsoft in prompts [4], which may explain the difference, but a university should ask how AI providers are treated under the DPA.
Keep sensitive content out. The DPA says Kahoot! is not intended to process sensitive data [3]. That fits normal quiz use. Quizzes or brainstorms that ask students about health, beliefs or similar topics would conflict with that assumption.
DPIA likelihood. Quizzes with nicknames are unlikely to meet the Article 35 threshold of likely high risk [6]. Graded use with identified students, or use with school pupils in outreach, would justify at least a documented screening. Our DPIA screening tool gives a first view.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Kahoot! before approving it
- Can we sign the published DPA or an institutional version, and which version applies to our contract?
- Can our organisation's data be stored only in the EU, or is Canada always part of long-term storage?
- How are Microsoft Azure, Perplexity and Google treated under the DPA when our users use AI features, and will the sub-processor list be updated to reflect them?
- Can administrators switch off AI features for all users on our plan, including Perplexity enrichment?
- How do we bring existing personal accounts of our staff under the institutional plan through domain claim, and what happens to their content?
- Can we receive the ISO/IEC 27001:2022 certificate, its scope and the SOC 2 Type 2 report?
- Which of Kahoot!'s transfers rely on the EU-U.S. DPF, and which on standard contractual clauses?
- What player data is kept from live games, and for how long, under an institutional plan?
The EU AI Act angle
Kahoot!'s AI features generate questions, enhance text and cluster brainstorm answers. These are content creation aids rather than the education uses listed as high-risk in Annex III, such as evaluating learning outcomes or monitoring students during tests [7]. If AI-generated quizzes were used for graded assessment, that line would deserve a closer look. The obligation that applies now is Article 4: deployers must take measures to support the AI literacy of staff using AI systems on their behalf [8]. Emotion recognition in education is prohibited by Article 5(1)(f) [10]; we found no such feature in Kahoot!'s documentation. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [11].
Sources
- Kahoot! Privacy Notice (effective 1 September 2026), retrieved 7 October 2026
- Sub-processors for Kahoot! (effective 3 March 2025), retrieved 7 October 2026
- Kahoot! Data Processing Agreement (effective 22 January 2025), retrieved 7 October 2026
- AI-powered features in Kahoot! (effective 13 November 2025), retrieved 7 October 2026
- Higher education and enterprise customers, Kahoot! Trust Center, retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Article 35, text read from the Publications Office copy, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
- EDPB members, European Data Protection Board, retrieved 7 October 2026
- AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
- Adequacy decisions, European Commission, retrieved 7 October 2026
About this page
We read Kahoot!'s privacy notice, data processing agreement, sub-processor list, AI features page and higher education trust page, the EDPB members page and the relevant EU legal texts on 7 October 2026. The official Data Privacy Framework list API returned errors on that date. Statements about Kahoot! come from those pages; our own interpretation is labelled as Validemic's analysis. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it.
This page is not legal advice and does not say whether any particular use of Kahoot! complies with the GDPR. If you work for Kahoot! and see an error, or a document has been updated, please contact us and we will correct it.
Frequently asked questions
Is Kahoot! GDPR compliant?
No tool is GDPR compliant on its own. Kahoot! AS is a Norwegian company, and Norway applies the GDPR as an EEA country. Kahoot! publishes a data processing agreement in which it acts as processor, a sub-processor list and an AI features page, and lists ISO/IEC 27001:2022 and a SOC 2 Type 2 report. How a university configures and uses it still matters.
Where does Kahoot! store data?
Kahoot!'s sub-processor page says long-term storage of personal data for customers is hosted in the EU and Canada, and that for European users using the service from the EU, data is processed only in the EU and Canada, except where personal data is added in videos or support tickets.
Does Kahoot! sign a data processing agreement?
Kahoot! publishes a DPA (effective 22 January 2025) that applies to all customers where Kahoot! acts as a processor, unless a separate agreement is in place. The customer is the controller. Its privacy notice says Kahoot! is a processor when services are provided through a school or organisation in the UK and EEA.
Does Kahoot! use student data to train AI?
Kahoot!'s privacy notice says it does not use personal data collected through the platform to train or refine large language models and does not allow its AI vendors to do so. Its AI features page names Microsoft Azure based in Europe as its main AI provider and advises users not to put personal data into AI prompts or uploads.
Can a university control which Kahoot! features students use?
Kahoot!'s higher education trust page says organisations can assign user roles, toggle features including AI where the plan allows, and use SSO, SCIM and domain claim. Organisation data deletion starts automatically within 90 days of a subscription ending.