Is Padlet GDPR compliant? What universities should check
Padlet is a simple board where students post text, images, links and files, often without creating an account. This page sets out what Padlet publicly documents about hosting, its data processing addendum, subprocessors, AI features and transfers, and what that means for a university deciding between personal and institutional accounts.
Short answer
Padlet is run by Wallwisher, Inc. in San Francisco, with EDPO appointed as its EU representative. It states that it is hosted on Google Cloud in the United States and relies on the EU-US Data Privacy Framework for transfers, with standard contractual clauses in its data processing addendum as a backstop. Its terms apply that DPA to Padlet for Schools and Padlet for Businesses subscribers, which is the main reason a university should use an institutional account rather than staff personal accounts. Padlet says it does not use personal data to train AI. Public profiles and public padlets exist on personal plans, so sharing settings matter.
What Padlet documents publicly
This summary reflects Padlet's legal site, privacy policy and help centre as read on 7 October 2026.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Wallwisher, Inc. DBA Padlet, headquartered in San Francisco with a regional office in Singapore. EU representative under Article 27 GDPR: European Data Protection Office (EDPO); UK representative: EDPO UK Ltd. | Privacy Policy [1], Security [4] |
| Where data is stored and processed | Documented Padlet is hosted on Google Cloud in the United States. Backups are kept with Amazon Web Services in the US, and content is delivered through CDNs including Cloudflare and Bunny CDN. An EU hosting option was not found in public documentation (checked 7 October 2026). | GDPR page [2], [4], Subprocessor list [5] |
| Data processing agreement | Plan-dependent A public DPA (last updated 8 March 2024) with Module 2 SCCs and the UK IDTA attached. The terms of service say the DPA applies to subscribers to Padlet for Schools or Padlet for Businesses (Padlet Teams). | DPA [3], Terms [6] |
| Subprocessors | Documented A public list naming Amazon Web Services, Cloudflare, Bunny CDN, Elastic, Google Cloud, Mailgun, Postmark, Snowflake, WebPurify, OpenAI and Hive, with purpose, data shared and location (mostly the United States). Customers can sign up for notification of new subprocessors. | [5], Subprocessors page [7] |
| International transfers (DPF, SCCs) | Documented Padlet states it is certified under the EU-US DPF, the UK Extension and the Swiss-US DPF, registered as Wallwisher, Inc. (status read from the vendor's privacy policy and GDPR page). The DPA incorporates SCCs in case the DPF is held invalid. | [1], [2], [3] |
| AI features and training on customer content | Documented AI providers power features such as AI image, AI Recipe and Padlet Arcade, and content moderation. Padlet says it shares only necessary information with AI providers and does not use personal data to train AI. The subprocessor list says prompts sent to OpenAI are not used to train models and that no personal data is shared with OpenAI. | [1], [5] |
| Retention and deletion | Documented IP addresses are not stored for longer than 30 days. Deletion requests are completed, including backups, within 30 days subject to legal requirements, and backups are kept for 30 days. Content a user posted on someone else's padlet is not deleted when the user deletes their account, but is anonymised. | [1], [2], [4] |
| Security certifications | Plan-dependent Padlet states it has been SOC 2 Type 1 certified since January 2023 (report on request), and that Padlet for Schools qualified for Australia's Safer Technologies 4 Schools badge in 2023. It relies on Google Cloud's ISO 27001 and SOC 2 certifications for hosting. A Padlet ISO 27001 certificate or SOC 2 Type 2 report was not found in public documentation (checked 7 October 2026). | [4] |
| Institution controls (SSO, admin, education licence) | Plan-dependent Padlet for Schools supports single sign-on with Google, Microsoft and ClassLink, a separate SAML SSO option, and automatic account creation for chosen email domains. School and business accounts are not public, and padlets can be limited to people in the same organisation. | Third-party login help [8], [1] |
Padlet also runs every piece of user content, whatever its privacy setting, through automated moderation checks, and authorised staff may review flagged content [1]. That is a reasonable safety measure for a service used in schools, and it is worth mentioning in the information given to students.
What this means for a university
Validemic's analysis
Student data. Students post names, photos, opinions, voice and video recordings, and sometimes coursework. Padlet makes it easy to contribute without an account, which lowers the barrier for students but means posts can be hard to attribute or remove. On personal plans, registered users have a public profile and public padlets can be indexed by search engines [1]. That is the main practical risk, and it is avoided by using Padlet for Schools with organisation-only sharing.
Minors. Padlet's terms say the service is not directed at children under 13 [6], which is rarely an issue at university, except for outreach with school pupils.
DPIA likelihood. Ordinary classroom use on an institutional account is unlikely by itself to meet the Article 35 GDPR threshold of likely high risk [9]. Reflective writing on sensitive topics, research participants or large-scale use with AI features would change that.
Transfers. Because hosting is in the United States, every use involves a transfer. The European Commission's adequacy decision of 10 July 2023 allows transfers to companies participating in the DPF [10], and Padlet states that it participates [2]. Check the official DPF list for Wallwisher, Inc. before relying on it, and keep the SCCs in the DPA in mind as the fallback.
Plan tier. The DPA is tied to Padlet for Schools and Business subscriptions [6]. Teachers using free or personal paid accounts for teaching sit outside that contract, so the university has no processor agreement for that data. An institutional licence plus guidance to move existing boards is the usual fix.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Padlet before approving it
- Will our Padlet for Schools agreement incorporate the DPA dated 8 March 2024, or a newer version?
- Is any EU hosting option planned or available on request for institutional customers?
- Which subprocessors receive student content, rather than only account data, and in which countries?
- Can administrators disable AI features, and which features send content to OpenAI or Hive?
- Can we enforce organisation-only sharing and stop staff creating public padlets under our domain?
- How are boards created by staff on personal accounts moved into our institutional account?
- Is a SOC 2 Type 2 report available, or only the Type 1 report from 2023?
- How do you handle access and deletion requests for posts made by anonymous contributors?
The EU AI Act angle
Padlet's AI features generate images and example boards and help moderate content. None of these matches the education uses listed as high-risk in Annex III, such as evaluating learning outcomes or monitoring students during tests [11]. The obligation that applies to universities now is Article 4 on AI literacy: deployers must take measures to support the AI literacy of staff using AI systems on their behalf [12]. The ban on emotion recognition in education in Article 5(1)(f) [13] is not engaged by anything we found in Padlet's documentation. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [14].
Sources
- Padlet Privacy Policy (last updated 5 October 2026), retrieved 7 October 2026
- Padlet: GDPR (last updated 23 March 2026), retrieved 7 October 2026
- Padlet Data Processing Addendum (last updated 8 March 2024), retrieved 7 October 2026
- Padlet: Security, retrieved 7 October 2026
- Padlet subprocessor list (Google Sheets), retrieved 7 October 2026
- Padlet Terms of Service, retrieved 7 October 2026
- Padlet: Subprocessors, retrieved 7 October 2026
- Enable third-party login for Padlet for Schools (at padlet.com), Padlet Help, retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Article 35, text read from the Publications Office copy, retrieved 7 October 2026
- EU-US data transfers, European Commission, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
About this page
We read Padlet's privacy policy, GDPR page, DPA, security page, terms, subprocessor pages and help centre, plus the relevant EU legal texts, on 7 October 2026. Statements about Padlet come from those pages; our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Padlet complies with the GDPR. If you spot an error or Padlet has updated a document, please contact us and we will correct it.
Frequently asked questions
Is Padlet GDPR compliant?
No tool is GDPR compliant on its own. Padlet publishes a GDPR page, a data processing addendum with standard contractual clauses and a subprocessor list, and is certified under the EU-US Data Privacy Framework as Wallwisher, Inc. Its terms apply the DPA to Padlet for Schools and Padlet for Businesses subscribers. A university's position depends on which plan staff use and how boards are shared.
Where does Padlet store data?
Padlet states that it is hosted on Google Cloud in the United States, with backups held with Amazon Web Services in the US. We did not find an EU hosting option in Padlet's public documentation on 7 October 2026.
Does Padlet use student posts to train AI?
Padlet's privacy policy says it shares only necessary information with AI service providers and does not use personal data to train AI. Its subprocessor list says prompts sent to OpenAI for image and example generation are not used to train models.
Are padlets public?
On personal plans, padlets can be public and indexable by search engines, and registered users have a public profile. Padlet says this does not apply to school or business accounts, where padlets can be restricted to people in the same organisation.
Does a university need a DPIA for Padlet?
Often not for ordinary teaching use on Padlet for Schools, but a documented screening is sensible. Sensitive topics, research data, external participants or large-scale use with AI features make a DPIA under Article 35 GDPR more likely.