GDPR check

Is Turnitin GDPR compliant? What universities should check

Turnitin checks student work against a large database of papers and web sources, and now flags text it predicts was written by AI. This page sets out what Turnitin publicly documents about data location, its data processing agreement, repositories and AI, and why the EU AI Act matters more here than for most teaching tools.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Turnitin, LLC is a US company that acts as a processor for institutions. It publishes a data processing agreement with the EU standard contractual clauses attached, says it is certified under the EU-US Data Privacy Framework, and states that its AWS platform stores submitted content in Frankfurt, with encrypted fragments compared in the US. Administrators control whether papers go into Turnitin's standard repository, and whether AI writing detection is switched on. Turnitin itself says the AI writing score should not be the sole basis for action against a student. Under the EU AI Act, AI used to evaluate learning outcomes or to detect prohibited behaviour during tests is listed as high-risk, with deployer obligations applying from 2 December 2027.

What Turnitin documents publicly

This summary covers Turnitin's integrity services, including Feedback Studio, Similarity and AI writing detection, as described in Turnitin's own documentation on 7 October 2026.

TopicWhat the vendor statesSource
Company and establishmentDocumented The processor named in the DPA is Turnitin, LLC of Oakland, California (with ExamSoft Worldwide LLC for ExamSoft services). Turnitin says it employs a Data Protection Officer. An EU establishment or Article 27 representative was not found in public documentation (checked 7 October 2026).DPA [1], GDPR FAQ [3]
Where data is stored and processedPlan-dependent The DPA says the AWS platform stores 100% of submitted content in an EU data centre (currently Frankfurt), with randomised, encrypted sections processed in the US for comparison; non-AWS services run from US data centres in California. The GDPR FAQ says the database of submissions used for comparison is located in the US. The services privacy policy says data is transferred to the US and that support staff work in the UK, the EU, Ukraine, the Philippines, Australia and India.[1], [3], Services Privacy Policy [2]
Data processing agreementDocumented A public DPA between Turnitin and the institution, describing processing of submissions, names, emails and student IDs for text comparison and grading, with the 2021 SCCs at Annex A and deletion on request certified in writing.[1]
SubprocessorsDocumented A public list (last updated February 2026) with entities such as Amazon Web Services, Google, Microsoft (Bing), Cockroach Labs, Concentrix, Zendesk and Skyflow; locations are given as "Global". The DPA promises at least 30 days' notice of new subprocessors by updating the list.Subprocessor list [4], [1]
International transfers (DPF, SCCs)Documented Turnitin and ExamSoft state they comply with the EU-US DPF, the UK Extension and the Swiss-US DPF (status read from Turnitin's privacy policies). The DPA also incorporates SCCs.[2], [3]
AI features and training on customer contentPlan-dependent Purposes in the services privacy policy include generating prompts to large language models where applicable, and developing machine learning or AI models related to writing, citations, grammar or plagiarism detection, which may use anonymised, aggregated or de-identified student data where permitted by law and customer agreements. The AI writing detection model was trained on AI-generated and authentic academic writing.[2], AI writing FAQs [5]
Retention and deletionPlan-dependent Administrators choose between the standard paper repository, an institutional repository or no repository for instructors' assignments. Customers can request full deletion of submissions, but not deletion of only the AI writing component. Retention otherwise follows "the period necessary" for the stated purposes.Account settings [6], [5], [2]
Security certificationsPlan-dependent Turnitin says it undergoes annual SOC 2 Type II audits by an independent auditor. An ISO 27001 certificate was not found in public documentation (checked 7 October 2026).[2], [3]
Institution controls (SSO, admin, education licence)Documented Institutional admin accounts with sub-accounts, repository options and an AI writing detection setting (enabled by default, part of the Originality add-on) controlled from the top-level account. Single sign-on options were not found in the pages we read.[6]

On AI writing detection specifically, Turnitin states that the model aims to keep the false positive rate under 1% for documents with over 20% AI writing, shows no score in the 1% to 19% range to limit false positives, needs at least 300 words of long-form prose, and supports English, Spanish, Japanese and Arabic [5]. It also says Turnitin "does not make a determination of misconduct" and that the percentage should not be the sole basis for action [5].

What this means for a university

Validemic's analysis

Student data. Every submission is personal data: the author's name and ID, and often personal content inside the essay itself. Students rarely have a real choice about submitting, so transparency (what is stored, for how long, who compares against it) matters more than for optional tools. The repository setting is the most important privacy decision an administrator makes in Turnitin, because it decides whether papers stay in a shared database after the course ends.

Minors. Rarely relevant at university level, except for pupils in bridging or early-entry programmes.

DPIA likelihood. We would expect most universities to need a DPIA. Article 35 GDPR points to high-risk processing using new technologies and to systematic evaluation of personal aspects based on automated processing [7]. Large-scale processing of student work, a cross-institution comparison database and AI predictions that can feed misconduct procedures fit that description. Article 22 GDPR also gives students the right not to be subject to decisions based solely on automated processing with significant effects [7].

Transfers. Turnitin's own documents describe EU storage for AWS-based services but also US processing for comparison and a US-located submission database [1][3]. That is not necessarily a problem, given the DPF adequacy decision adopted on 10 July 2023 [8] and the SCCs in the DPA, but the university's records should say which description applies to its products.

Plan tier. AI writing detection is part of the Originality add-on and is enabled by default where licensed [6]. Decide deliberately whether to keep it on, and for which sub-accounts.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Turnitin before approving it

  1. For each product we license, is it delivered from the AWS platform with EU storage, or from US data centres? Which data leaves the EU, and in what form?
  2. How does the DPA statement on Frankfurt storage fit with the GDPR FAQ statement that the comparison database is in the US?
  3. Do you use our students' submissions or writing process data, in any form, to develop or improve AI models? Can we exclude this in our agreement?
  4. How do you classify AI writing detection, and any AI-assisted grading we use, under Article 6 and Annex III of the EU AI Act? Will you provide instructions for use and Article 13 information?
  5. What evidence supports the stated false positive rate for non-native English writers and for disciplines and languages common at our institution?
  6. What logs of AI writing detection results are available to us, and for how long?
  7. If we choose "no repository", what is still retained, and for how long?
  8. Which subprocessors process submission content, and in which countries?
  9. Can we receive your SOC 2 Type II report and your most recent penetration test summary?
  10. How do you support access and deletion requests from students who have left the institution?

The EU AI Act angle

Why Turnitin is in scope for analysis. Annex III, point 3, of the AI Act lists as high-risk, among others, AI systems intended to evaluate learning outcomes (point 3(b)) and AI systems intended for monitoring and detecting prohibited behaviour of students during tests (point 3(d)) in educational institutions at all levels [9]. AI writing detection is used to support decisions about academic misconduct, and AI-assisted grading features evaluate student work. Whether a given Turnitin feature is high-risk depends on its intended purpose as set by the provider, and on Article 6(3), which says an Annex III system is not high-risk where it does not pose a significant risk, for example because it only performs a narrow procedural task or a preparatory task to an assessment [10]. Turnitin's public documentation does not state its classification under the AI Act (checked 7 October 2026), so ask for it in writing.

What a university would have to do as deployer. If a feature is high-risk, Article 26 requires the deployer to use it in line with the instructions for use, assign human oversight to people with the necessary competence, training and authority, monitor its operation, keep the logs under its control for at least six months, inform the people subject to decisions it supports, and use the provider's information when carrying out a DPIA [11]. Article 27 adds a fundamental rights impact assessment for deployers that are bodies governed by public law, which covers many public universities [12]. In practice, Turnitin's own advice that the score is not a basis for action on its own lines up with the human oversight duty: written procedures, trained reviewers and a right for the student to respond.

When it applies. High-risk obligations were originally due on 2 August 2026. The Commission proposed postponing them in its Digital Omnibus on AI on 19 November 2025; a political agreement followed on 7 May 2026 and the amending regulation entered into force on 27 July 2026 [13]. Under Article 113 as amended, Chapter III, Sections 1 to 3 apply to Annex III high-risk systems from 2 December 2027 [14]. The amending act is Regulation (EU) 2026/1744 [13]. The time is useful: procurement contracts signed now will still be running in December 2027.

Already in force. The AI literacy duty in Article 4 (as amended) and the prohibitions in Article 5 apply now [15][16]. Emotion recognition in education, banned by Article 5(1)(f), is not something Turnitin's text tools describe doing.

Sources

  1. Turnitin Data Processing Agreement, retrieved 7 October 2026
  2. Turnitin Services Privacy Policy (last updated 4 February 2026), Turnitin Guides, retrieved 7 October 2026
  3. Turnitin and GDPR (FAQ), retrieved 7 October 2026
  4. Turnitin Subprocessors (last updated February 2026), retrieved 7 October 2026
  5. Turnitin's AI writing detection capabilities FAQs (updated 6 October 2026), retrieved 7 October 2026
  6. Account settings for Turnitin Feedback Studio and Originality Check, retrieved 7 October 2026
  7. Regulation (EU) 2016/679 (GDPR), Articles 22 and 35, text read from the Publications Office copy, retrieved 7 October 2026
  8. EU-US data transfers, European Commission, retrieved 7 October 2026
  9. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
  10. AI Act Article 6: Classification rules for high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  11. AI Act Article 26: Obligations of deployers of high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  12. AI Act Article 27: Fundamental rights impact assessment, AI Act Service Desk, retrieved 7 October 2026
  13. AI Act, Shaping Europe's digital future (European Commission), with link to the AI Omnibus final text (OJ L 2026/1744), retrieved 7 October 2026
  14. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
  15. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  16. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Turnitin's DPA, services privacy policy, GDPR FAQ, subprocessor list and help-centre articles on account settings and AI writing detection, plus the GDPR and the consolidated AI Act text, on 7 October 2026. EUR-Lex was not fully reachable for automated retrieval that day, so we read the AI Act through the Commission's AI Act Service Desk, which reproduces the EUR-Lex consolidated version. Statements about Turnitin come from Turnitin's own pages; our interpretation is labelled as Validemic's analysis. This is not legal advice, and it does not say whether any particular use of Turnitin complies with the GDPR or the AI Act. If you see an error or an outdated detail, please contact us and we will correct it.

Frequently asked questions

Is Turnitin GDPR compliant?

No tool is GDPR compliant on its own. Turnitin publishes a data processing agreement with standard contractual clauses, says it is certified under the EU-US Data Privacy Framework and offers EU storage of submissions on its AWS platform. Whether a university's use is lawful depends on its contract, repository settings, transparency to students and how results are used in misconduct procedures.

Where does Turnitin store student papers?

Turnitin's DPA says its AWS platform stores all submitted content in an EU data centre, currently Frankfurt, while randomised and encrypted sections are processed in the US for comparison. Its GDPR FAQ says the database of submissions used for comparison is in the US, and non-AWS services run from US data centres. Ask Turnitin which applies to your products.

Can a university stop Turnitin keeping student papers?

Administrators can let instructors choose between the standard paper repository and no repository, offer an institutional repository, or send all papers to the standard repository. The choice affects what Turnitin retains and what future submissions are compared against.

Is Turnitin's AI writing detection high-risk under the EU AI Act?

Possibly, depending on intended purpose and use. Annex III lists AI systems intended to evaluate learning outcomes, and to monitor and detect prohibited behaviour of students during tests, as high-risk. Turnitin's public documentation does not state a classification. Those obligations apply from 2 December 2027 after the Digital Omnibus on AI.

Can a Turnitin AI score be used to fail a student?

Turnitin itself says the AI writing percentage should not be used as the sole basis for action or as a definitive grading measure. Under Article 22 GDPR, students also have the right not to be subject to decisions based solely on automated processing that significantly affect them. Human review against the institution's own policy is needed.

Does Turnitin use student papers to train AI?

Turnitin's services privacy policy lists, among its purposes, developing and improving machine learning or AI models related to writing, citations, grammar or plagiarism detection, which may include anonymised, aggregated or de-identified student data where permitted by law and customer agreements. Universities should address this in the contract.