GDPR check

Is TimeEdit GDPR compliant? What universities should check

TimeEdit runs timetabling, room booking and exam scheduling at many European universities, and it is expanding into curriculum, workload and student engagement with AI features. Because it is a Swedish company hosting in the EU, the transfer questions are simpler than for US suites, but the data it holds about students and staff is broad. This page sets out what TimeEdit documents and what to check.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

TimeEdit AB is a Swedish company based in Gothenburg. Its public DPA makes TimeEdit the processor, names Google Cloud and Amazon Web Services in Belgium as hosting subprocessors, gives 30 days to object to new subprocessors and requires deletion within ten business days after the services end. Its Trust Center lists ISO/IEC 27001:2022. That is a strong baseline for a scheduling system. The questions for a university concern the breadth of data (timetables, exam arrangements, attendance), support access from TimeEdit's offices outside the EU, a subprocessor list that differs between the DPA and the Trust Center, and new AI features such as at-risk detection.

What TimeEdit documents publicly

Everything in this table comes from TimeEdit's own pages, read on 7 October 2026. Numbers in brackets refer to the sources at the end.

TopicWhat the vendor statesSource
Company and establishment Documented TimeEdit AB (556565-9009), Kungsportsplatsen 1, Gothenburg, Sweden, founded in 1992. TimeEdit also lists offices in Warwick (UK), Utrecht (Netherlands), Singapore and Melbourne (Australia), and says it serves more than 225 institutions in 18 countries. [1], [5]
Data processing agreement Documented A public DPA names TimeEdit AB as processor and the customer as controller. No version date was shown on the page we read. [2]
Where data is hosted Documented Google Cloud (hosting, Belgium) and Amazon Web Services (disaster recovery, Belgium). [2]
Subprocessors Two lists The DPA table lists Google Cloud and AWS. The Trust Center lists AWS, Google Cloud and Zendesk for support. The controller is informed before data goes to a new subprocessor and has 30 days to object. [2], [3]
International transfers Documented The DPA refers to the Standard Contractual Clauses for transfers outside the EEA. Which offices outside the EEA can access customer data for support was not found in public documentation (checked 7 October 2026). [2]
Breach notification Documented TimeEdit notifies the controller "without undue delay" after becoming aware of a personal data breach. No fixed number of hours is stated. [2]
Retention and deletion Documented Personal data is deleted within ten business days of the end of the services involving processing. [2]
Security certifications Documented The Trust Center lists ISO/IEC 27001:2022, Cyber Essentials and G-Cloud, with a recovery time and recovery point objective of 24 hours, encryption at rest, role-based access and penetration testing. The Trust Center also offers documents such as security white papers and penetration test reports. [3]
AI features Partly documented TimeEdit lists change management automation, curriculum translation, at-risk detection, a study catalogue chatbot, conversational data collection and natural language queries, plus an MCP server for assistants such as ChatGPT, Claude or Copilot. It says data "is never used to train external models". The underlying model providers for TimeEdit's own AI features were not found in public documentation (checked 7 October 2026). [4]

TimeEdit deserves credit for a public DPA with concrete deadlines, EU hosting named down to the country, a short deletion period and a Trust Center with an ISO 27001 certificate, which is more than many niche education vendors publish.

What this means for a university

Validemic's analysis

A European processor simplifies the basics. With its head office in Sweden and hosting in Belgium [1], [2], TimeEdit is directly subject to the GDPR as a processor, and for cross-border processing the Swedish authority, IMY, would be expected to act as lead authority under Article 56 [6]. That removes much of the transfer analysis needed for US or Australian vendors.

Scheduling data is broader than it looks. A timetable links named students and staff to places and times. Exam scheduling often includes extra time or separate rooms for students with disabilities, which can reveal health data covered by Article 9 GDPR [6]. Attendance and engagement modules add behavioural data. The DPA and the records of processing should list these categories explicitly, not just "schedule data".

Publishing schedules is a controller decision. TimeEdit's Viewer module distributes schedules via web, mobile, LMS, calendar feeds and digital signage, with role-based filtered views [10]. Some universities also publish timetables openly, which can show lecturers' names and, depending on configuration, student group or exam information to anyone. Digital signage in corridors is a form of publication too. That is the university's choice as controller, not TimeEdit's, and it should rest on a documented legal basis and data minimisation under Article 5 GDPR [6]. Check what the public view shows for exams and for small groups where a single student may be identifiable.

Retention during the contract is yours to set. The DPA's ten-day deletion applies when the services end [2]. While the contract runs, years of historical timetables, bookings and attendance may stay in the system unless the university defines retention periods and asks TimeEdit how to purge old terms. Align this with the institution's retention schedule.

EU hosting does not settle access. Hosting is in Belgium [2], but TimeEdit has offices in the UK, Singapore and Australia [5]. Under the GDPR, remote access from outside the EEA is a transfer. The European Commission lists the UK as adequate but not Singapore or Australia [9], so support access from those two offices would need the SCCs referred to in the DPA [2]. Ask which teams can access your production data.

Reconcile the subprocessor lists. Zendesk appears in the Trust Center but not in the DPA table [2], [3]. That may simply mean support tickets are handled outside the DPA's list, but support tickets often contain personal data. Ask for the authoritative list for your contract and where Zendesk stores your data.

At-risk detection is a different kind of processing. Flagging students as disengaged from attendance or activity is profiling under Article 4(4) GDPR [6]. If a flag leads to decisions with legal or similarly significant effects, Article 22 applies. Most institutions use such flags to offer support, which is lower risk, but a DPIA under Article 35 is likely to be appropriate before switching it on [6].

Assistants connected through MCP. Connecting ChatGPT, Claude or Copilot to TimeEdit through its MCP server sends query results to that assistant's provider [4]. TimeEdit's statement about training covers TimeEdit; what happens in the assistant depends on your agreement with that provider. See our pages on Microsoft Copilot and ChatGPT.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask TimeEdit before approving or renewing

  1. Which DPA version applies to our contract, and is the subprocessor list in it complete, including Zendesk and any AI model providers?
  2. From which countries can TimeEdit staff access our production data, and which transfer mechanism covers each?
  3. Which personal data categories do the exam and attendance modules process, and can special category data be kept out of free-text fields?
  4. Which model providers power the AI features, where do they run, and can each feature be switched off per module?
  5. How does at-risk detection work, which data does it use, and can staff see why a student was flagged?
  6. Can we obtain the ISO 27001 certificate and scope statement and the latest penetration test summary?
  7. Which schedule fields are visible in public views, calendar feeds and signage by default, and can we restrict them per role?
  8. How can we purge timetables, bookings and attendance data from past terms in line with our retention schedule?
  9. Within what time does TimeEdit notify us of a breach in practice, given the 72-hour deadline we face under Article 33?

The EU AI Act angle

Classic timetable optimisation is not generative AI, but TimeEdit's newer features are AI systems, and a university that uses them is a deployer under Regulation (EU) 2024/1689 [7]. Article 4 on AI literacy has applied since 2 February 2025; the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, reworded it as a duty to take measures to support staff AI literacy [8]. Annex III point 3 lists education uses such as determining admission, evaluating learning outcomes, assessing the appropriate level of education and monitoring students during tests [7]. Scheduling and translation are not on that list. At-risk detection should be checked against it carefully, depending on whether its output steers decisions about students; the Annex III obligations apply from 2 December 2027 under the Omnibus [8]. Our AI Act education checker helps with a first view.

Sources

  1. TimeEdit Privacy Policy (last updated 3 December 2025), retrieved 7 October 2026.
  2. TimeEdit Data Processing Agreement, retrieved 7 October 2026.
  3. TimeEdit Trust Center, retrieved 7 October 2026.
  4. TimeEdit, AI in the Academic Operations Platform, retrieved 7 October 2026.
  5. TimeEdit, About, retrieved 7 October 2026.
  6. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 4, 5, 9, 22, 33, 35 and 56, retrieved 7 October 2026.
  7. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 4 and Annex III, retrieved 7 October 2026.
  8. Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026.
  9. European Commission, Adequacy decisions, retrieved 7 October 2026.
  10. TimeEdit, Viewer, retrieved 7 October 2026.

About this page

We read TimeEdit's privacy policy, DPA, Trust Center, AI, Viewer and company pages on 7 October 2026. We did not test a TimeEdit environment or review a customer-specific agreement, and we did not review the downloadable Trust Center documents. "Not found" means we could not find information in public documentation; it does not mean it does not exist.

This page is not legal advice and is not a statement that TimeEdit is or is not GDPR compliant, which depends on your contract, configuration and use. If you work at TimeEdit or spot an error, please contact us and we will correct it.

Frequently asked questions

Where does TimeEdit host university data?

TimeEdit's public DPA lists Google Cloud in Belgium for hosting and Amazon Web Services in Belgium for disaster recovery. Its Trust Center also lists Zendesk among the providers it uses, which is not in the DPA's subprocessor table, so ask TimeEdit to confirm the current list for your contract.

Does TimeEdit sign a data processing agreement?

Yes. TimeEdit publishes a DPA in which TimeEdit AB is processor and the customer is controller. It includes 30 days to object to new subprocessors, breach notification without undue delay and deletion within ten business days after the services end.

Is TimeEdit ISO 27001 certified?

TimeEdit's Trust Center lists ISO/IEC 27001:2022, along with Cyber Essentials and G-Cloud. Ask for the certificate and its scope statement to confirm which services and locations are covered.

Does TimeEdit use our data to train AI models?

TimeEdit's AI page says data stays inside the TimeEdit environment and is never used to train external models. We did not find a public statement on whether customer data is used to train or tune TimeEdit's own models (checked 7 October 2026).