The Pays de la Loire Region has ordered Chromebooks for its "My Computer at High School" program before completing a required data protection impact assessment (AIPD), a step mandated by the European Union's General Data Protection Regulation (GDPR). The program, launched in the 2021 school year, provides laptops to about 48,000 students each year, typically starting in their second year or first year of a CAP (Certificate of Professional Aptitude) program. The region plans to renew the equipment for the 2026–2027 school year, with the budget rising from 20 million euros in 2025 to 23 million euros in 2026. Orders have already been placed, and the devices are expected to arrive by late October or early November 2026.
As of September 17, 2026, the AIPD process is still ongoing and cannot be disclosed publicly, according to the region. André Martin, the region’s vice president in charge of high schools, emphasized that data storage will be “guaranteed in terms of security and carried out in Europe, not in the United States.” However, this assurance does not eliminate the risk that American authorities could access the data under the Cloud Act, a U.S. law allowing the government to request data from companies, even if the data is stored outside the country.
France’s data protection authority, CNIL, has previously warned that collaborative tools governed by U.S. law, like those used by Google, may pose challenges under the GDPR if data transfer safeguards are inadequate. The Ministry of National Education has also expressed concerns about deploying Google or Microsoft solutions in schools, stating it would not expand such use if it conflicts with GDPR rules.
In Denmark, a similar situation saw the data protection authority penalize the commune of Helsingør and investigate 53 other communes using the same devices. However, no national ban was imposed, and local authorities, like the Pays de la Loire Region, are legally allowed to procure such equipment. The choice of Chromebooks does not fully resolve data processing concerns, as features like guest sessions in ChromeOS—which allow use without a Google account—must be documented and evaluated in the AIPD.
The AIPD is a critical document required by the GDPR to be completed before implementing data processing systems, though its publication is not mandatory. Sharing its key findings, identified risks, and safeguards could help explain the decision and inform public debate. However, the region’s response to a request for administrative transparency did not clarify when the AIPD would be completed or how it would align with the program’s implementation, limiting the ability to assess the decision fully.
The debate goes beyond the specific choice of Chromebooks. Each technology decision carries future dependencies—technical, financial, legal, and strategic. Supporters of Chromebooks highlight their ease of management, low maintenance, and efficiency, but concerns about data control, reliance on a single ecosystem, and the ability to reverse the decision must also be addressed. Pedagogical needs, such as specialized software for subjects like physics or engineering, may also be affected, as ChromeOS’s Linux environment can be restricted by administrators.
Ultimately, the issue is not just about Google or the Chromebook. It’s about the transparency of the digital dependencies created by public institutions and the need to document and discuss the associated risks, assumptions, and exit strategies. The publication of the AIPD or at least its main conclusions should accompany the debate, not come after it.
Pays de la Loire Region Proceeds with Chromebook Deployment Ahead of Data Protection Assessment
AI-rewritten from original reportingHow it works
gdprchromebookdata-protectionpublic-educationcloud-actdigital-dependencies



