GDPR check

Is Slido GDPR compliant? What universities should check

Slido is a live polling, quiz and Q&A tool used in lectures, seminars and staff meetings, often inside Webex, Zoom, Teams or PowerPoint. This page sets out what Slido and its owner Cisco publicly document about hosting, the data processing addendum, subprocessors, transfers and AI features, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Slido is run by sli.do s. r. o., a Slovak company that Cisco acquired in 2021. Its data processing addendum is part of the Terms of Service for all customers, its core service runs on Amazon Web Services in Ireland and Germany, and Cisco states that it is certified under the EU-US Data Privacy Framework. The point a university most needs to read is the plan difference: Slido's own documentation treats participant content in non-Enterprise plans as data it may also use to improve its service, and Slido AI handles paid and free plans differently. The answer for your institution depends on the plan you buy and how you configure it.

What Slido documents publicly

The table summarises what Slido and Cisco state in their own documentation, read on 7 October 2026. It covers Slido as used by an institution for polls, quizzes and audience Q&A.

TopicWhat the vendor statesSource
Company and establishmentDocumented The contracting party is sli.do s. r. o. in Bratislava, Slovakia. Slido was acquired by Cisco Systems, Inc. on 2 May 2021, and the Cisco Online Privacy Statement applies to Slido customers. Cisco names the Dutch Autoriteit Persoonsgegevens as its EU lead authority.Slido legal page [1]
Where data is stored and processedDocumented Amazon Web Services hosts the service, with personal data located in Ireland and Germany. The Offer Disclosure lists Ireland as the data centre with back-up in Germany. Cisco affiliates may also act as subprocessors under SCCs.[1], Offer Disclosure (PDF) [3]
Data processing agreementDocumented Slido's DPA (version 1.10) forms part of the Terms for all clients, with the customer as controller and Slido as processor. It provides for deletion or return of customer personal data at the end of the service, at the customer's choice.Slido DPA v1.10 (PDF) [2]
Plan differences in data rolesPlan-dependent The DPA covers participant profile data and "event content data in Enterprise plans". The Offer Disclosure lists participant content in non-Enterprise plans as processed by the customer and by Slido, including for improvement of the service and development of new ones.[2], [3]
SubprocessorsDocumented The subprocessor table (last updated 15 September 2026, effective 15 October 2026) lists Amazon Web Services. A separate table of service providers, used where Slido is controller, includes Atlassian, Gainsight, Google and Microsoft, some with US locations. New vendors are announced on the website, and customers can subscribe to email notices.[1], [2]
International transfers (DPF, SCCs)Documented Cisco states that it is certified under the EU-US DPF, its UK Extension and the Swiss-US DPF (DPF status read from the vendor's privacy statement; the official list API returned no results for any query on the check date). Cisco also relies on SCCs and Binding Corporate Rules for controllers.[1]
AI features and trainingPlan-dependent Slido AI uses Cisco AI technologies and GPT models via the Microsoft Azure OpenAI Service. Data from paid plans is "not stored or used at all", while Basic plan data is anonymised and may be used to improve services. Only owners and admins of paid annual plans can switch AI off.Slido AI settings [4]
Retention and deletionPlan-dependent Participant profile and content data linked to a meeting is retained until account termination. Zoom-integration data is deleted 90 days after the user's last interaction. Technical data is deleted 180 days after collection.[3]
Security certificationsDocumented ISO/IEC 27001, 27017, 27018 and 27701, ISO 22301, a SOC 2 Type II report and French HDS certification for the service provisioned in the EEA. The DPA says the latest audit report is available on request under NDA.[2], [3]
Institution controlsDocumented Organisers can enable anonymous participation at event and organisation level, require single sign-on, and delete submitted content. Special categories of data must not be submitted under the Terms.[2], [3]

Slido deserves credit for the level of detail it publishes. Few classroom tools set out, in one document, which party controls each data category, why it is processed and how long it is kept. That detail is also what makes the plan question visible, which is useful for a privacy office.

What this means for a university

Validemic's analysis

Student data. Slido is mostly text: names, poll answers, quiz results and questions students type during a lecture. That seems low-risk until you consider what students write. Questions in a medical ethics seminar, a mental health workshop or a staff survey can reveal health, beliefs or opinions about colleagues. Anonymous participation, which Slido supports, is the strongest single setting a teacher can switch on where names are not needed.

Recordings. Slido itself does not record lectures, but it is often shown on screen during sessions that are recorded in Webex, Zoom, Teams or a lecture capture system. Questions displayed with names, and students' images and voices captured by the recording, then sit in another system with its own retention rules. Teachers should know that a named question on the projector may end up in a recording that is kept for years.

Plan tier. This is the central issue. Under the Offer Disclosure, content in non-Enterprise plans is also processed by Slido for its own purposes. For a university, that means a teacher on a personal or departmental non-Enterprise plan creates a different data relationship from an institution on an Enterprise contract. Confirm in writing which plan your licence is and how Slido classifies it, especially for education plans.

AI features. The AI settings article states that paid-plan data is not stored or used, which is a clear commitment. Two points need follow-up. First, only paid annual plans can switch AI off. Second, the subprocessor table we read lists Amazon Web Services but does not show a separate entry for the Microsoft Azure OpenAI Service, so ask Slido how that processing is covered contractually and where it takes place.

Transfers. The European Commission adopted its adequacy decision for the EU-US Data Privacy Framework on 10 July 2023 [5]. Cisco states it participates. Core hosting stays in the EU, but Cisco affiliates and some service providers sit in the US, so keep the SCCs and Cisco's DPF statement on file.

DPIA likelihood. Article 35 GDPR requires a DPIA where processing is likely to result in a high risk [6]. Routine polls on an Enterprise plan with anonymous participation are unlikely to reach that threshold alone. Large-scale use, sensitive topics or AI features on plans that cannot switch them off push towards at least a documented screening.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Slido before approving it

  1. Is our licence an Enterprise plan for the purposes of the Offer Disclosure, and if not, which participant content does Slido process as a controller?
  2. Does the DPA cover all participant content on our plan, including questions and poll answers?
  3. Which Slido AI features are on by default for our plan, and can we switch them off centrally?
  4. How is processing by the Microsoft Azure OpenAI Service covered in the subprocessor list and DPA, and in which region does it run?
  5. Can we set default anonymous participation for the whole organisation?
  6. How long is event data kept after an event ends, and can administrators enforce earlier deletion?
  7. Can we obtain the current SOC 2 Type II report and ISO certificates under NDA?
  8. Which notification address should receive new subprocessor notices?

The EU AI Act angle

Slido AI drafts polls and quizzes, refines questions and groups submitted ideas. These are productivity functions, not the education uses listed as high-risk in Annex III of the AI Act. For most universities, the relevant duty today is AI literacy: Article 4, as amended, requires deployers to take measures to support the AI literacy of staff using AI systems on their behalf [7]. Teachers should check AI-drafted quiz questions before using them for anything that counts towards a grade.

Article 5(1)(f) prohibits AI systems that infer emotions of people in education institutions, except for medical or safety reasons [8]. We found nothing in Slido's public documentation describing emotion inference. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [9]. If quiz results were ever used with AI to evaluate learning outcomes, that use would need a fresh assessment.

Sources

  1. Slido legal page: Terms of Service, Slido Privacy (last updated 4 May 2026), Subprocessors and Service Providers (last updated 15 September 2026) and Privacy Commitment, retrieved 7 October 2026
  2. Slido Data Processing Addendum, version 1.10 (PDF), retrieved 7 October 2026
  3. Slido Offer Disclosure, version 1.0, September 2025 (PDF), retrieved 7 October 2026
  4. Slido AI settings: all you need to know, Slido Community (12 February 2025), retrieved 7 October 2026
  5. EU-US data transfers, European Commission, retrieved 7 October 2026
  6. Regulation (EU) 2016/679 (GDPR), Article 35, retrieved 7 October 2026
  7. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  8. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  9. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Slido's legal page (terms, privacy, subprocessors and privacy commitment), its DPA, its Offer Disclosure, its AI settings article and the relevant EU texts on 7 October 2026. The official Data Privacy Framework list API returned no results on that date, so DPF status comes from Cisco's own statement. Every statement about Slido above comes from those sources, and our own view is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Slido complies with the GDPR. If you spot an error or Slido has updated a document, please contact us and we will correct it.

Frequently asked questions

Is Slido GDPR compliant?

No tool is GDPR compliant on its own. Slido offers a data processing addendum that forms part of its Terms of Service, hosts its service on Amazon Web Services in Ireland and Germany, and its parent Cisco states that it is certified under the EU-US Data Privacy Framework. Whether a university's use complies depends on its plan, settings, lawful basis and the information it gives students.

Where does Slido store data?

Slido's subprocessor table lists Amazon Web Services with personal data hosted in Ireland and Germany, and its Offer Disclosure names Ireland as the data centre location with back-up in Germany. Some service providers Slido uses as a controller, such as CRM and helpdesk tools, list locations in the United States.

Does Slido use student answers to improve its service?

It depends on the plan. Slido's Offer Disclosure lists participant content in non-Enterprise plans as processed by both the customer and Slido, including for improving the service and developing new ones. For Enterprise plans, participant content is processed by the customer for provision of the service only.

Can students answer Slido polls anonymously?

Yes, if the organiser allows it. Slido says organisers can turn on anonymous participation at event and organisation level, after which participants can choose to interact anonymously. Quizzes still require names, and where an organiser requires single sign-on, participant names are displayed by default.

Does Slido AI send data to OpenAI?

Slido's community article on AI settings says Slido AI uses Cisco AI technologies and models from the Microsoft Azure OpenAI Service. It states that data from paid plans is not stored or used, while data from Basic plans is anonymised and may be used to improve services. Only owners and admins of paid annual plans can disable AI features.