University mandating third-party data-collecting app

Question
Can a university require me to use a third-party app or platform that collects my personal data?

Short answer

In principle, yes, a university can require you to use a third-party app or platform that processes your personal data, but only within the limits set by data protection law and by its own duties as a public authority or contracting body. The requirement is not automatically unlawful just because a private company is involved or because the app collects data. What matters is whether the processing is fair, necessary, proportionate, transparent, based on a valid lawful basis, and secured by an appropriate contract. Whether you can refuse depends heavily on what the app is used for and whether the university is genuinely relying on your consent.

The legal framework

The relevant law is the UK GDPR and the Data Protection Act 2018, regulated by the Information Commissioner’s Office (ICO). Any processing of your personal data by or on behalf of the university must satisfy the data protection principles in Article 5, including lawfulness, fairness and transparency, purpose limitation, data minimisation, storage limitation, and security.

When a university uses an external app or platform, the arrangement is usually that the university is the data controller (it decides why and how your data is processed) and the app provider is a data processor acting on the university’s instructions. Under Article 28 UK GDPR there must be a written contract obliging the provider to keep the data secure, to process it only on the university’s instructions, and not to use it for its own purposes. If the app provider is in fact using your data for its own commercial purposes, that is a materially different and more serious situation, because it may be acting as a controller in its own right and may need its own lawful basis and privacy information.

Lawful basis and whether you can refuse

The key practical question is what lawful basis the university relies on for making you use the app. This determines whether you have a genuine right to opt out.

Most universities do not rely on consent for core teaching, assessment and administration. They typically rely on performance of the contract between you and the university (your student agreement) under Article 6(1)(b), or on public task under Article 6(1)(e), because delivering higher education is a function carried out in the public interest. Where one of these bases applies, they do not need your consent, and you cannot simply refuse to use a required system for an essential academic function. For example, a compulsory virtual learning environment, an assessment or e-submission platform, an attendance system, or a library or exam system will usually fall here.

Consent under Article 6(1)(a) is different. The ICO’s position is that consent is only valid if it is freely given, specific, informed and unambiguous, and it is not appropriate where there is a clear imbalance of power or where you cannot realistically refuse without detriment. So if the university claims you are consenting but in reality you will fail a module or lose access to essential services if you decline, that is not valid consent, and it should be relying on a different lawful basis instead. Conversely, for genuinely optional or non-essential features, such as a wellbeing app, a social platform, or marketing communications, consent should be sought and you should be free to say no without penalty.

Special category data, such as health, disability or biometric data, needs an additional condition under Article 9. This is particularly relevant to things like remote exam proctoring software that uses facial recognition or room scanning, which has attracted specific ICO and sector concern about proportionality and intrusiveness.

What makes a requirement lawful or unlawful

A mandatory app is more likely to be lawful where the university can show all of the following: the processing is necessary for a legitimate educational or administrative purpose and there is no significantly less intrusive alternative (data minimisation); it has completed a Data Protection Impact Assessment for high-risk processing, which is legally required under Article 35 for things like large-scale monitoring, biometric or proctoring tools; it has a clear, accessible privacy notice telling you what data is collected, why, on what lawful basis, who it is shared with, how long it is kept, and whether data leaves the UK; and it has a compliant Article 28 processor contract in place.

A requirement is more likely to be unlawful or challengeable where the app collects far more data than needed, where the provider reuses your data for its own advertising or profiling, where sensitive data is processed without an Article 9 condition or a DPIA, where there is unnecessary international transfer without appropriate safeguards, or where you are given no privacy information at all.

Your rights regardless of the requirement

Even where the university can lawfully require the app, you keep your individual rights under the UK GDPR. These include the right to be informed, the right of access to your data, the right to rectification, and, depending on the lawful basis, rights to erasure, restriction and objection. Where the basis is public task or legitimate interests you have the right to object under Article 21, and the university must stop unless it shows compelling legitimate grounds. Where processing is based on consent, you can withdraw it at any time. You can also complain to the university’s Data Protection Officer and then to the ICO.

Reasonable adjustments and accessibility

If you have a disability, the university has duties under the Equality Act 2010 to make reasonable adjustments. If a required app is inaccessible to you, or if features such as camera monitoring would disadvantage you because of a disability or a protected characteristic, you can ask for an adjustment or an alternative method. This is a separate and often stronger line of challenge than data protection alone.

Missing facts that change the answer

To give a firm view, the important details are: what the app actually is and what it is used for (core assessment versus optional extra); exactly what data it collects, including whether it is special category data such as biometrics; whether the provider uses your data for its own purposes; what lawful basis the university states in its privacy notice; whether a DPIA was done for anything high-risk; and whether a refusal would genuinely block you from an essential academic function or is really optional. A compulsory exam-proctoring tool that scans your face and room raises very different issues from a timetable app.

Practical next steps

1. Read the privacy notice for the specific app and the university’s student privacy notice, and identify the stated lawful basis and the list of data collected.

2. Ask the university’s Data Protection Officer, in writing, to confirm the lawful basis, whether a DPIA was carried out, whether there is an Article 28 contract with the provider, whether the provider uses data for its own purposes, and whether any data is transferred outside the UK.

3. If you object to the amount or type of data, ask whether a less intrusive alternative is available, for example an alternative assessment method or an accessibility adjustment, and put the request in writing.

4. If you have a disability or other protected characteristic affected, make a formal request for reasonable adjustments under the Equality Act 2010.

5. Use the university complaints procedure if you are not satisfied, and keep a record of what you are told.

6. If you believe the processing is unlawful, disproportionate or unfair, you can raise a complaint with the ICO, though the ICO will usually expect you to have raised it with the university first. The ICO’s focus will be on whether the processing is necessary, proportionate, transparent and properly secured, not simply on the fact that an app is mandatory.

In summary, requiring a data-collecting third-party app is not inherently unlawful, and for core educational functions you generally cannot refuse. The real questions are the lawful basis, whether the data collection is proportionate and transparent, whether high-risk tools like proctoring have been properly assessed, and whether the provider is confined to acting on the university’s instructions rather than exploiting your data itself.

Current sources checked

This answer draws on broad legal knowledge and checks current law, guidance and procedure against relevant sources.

Consent | ICOico.org.ukLawful basis for sharing personal data - ICOico.org.ukStudent Privacy Noticehelp.open.ac.ukData sharing and using data processors | Information Complianceinformation-compliance.admin.cam.ac.uk
Verify important information before relying on it.
Was this helpful?
0 people found this helpful

Ready to stop guessing?

The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.