EduGenAI is a national platform built by the Dutch higher-education ICT cooperative SURF together with the Npuls programme (which pools funding from Dutch mbo, hbo and wo institutions) to give students and staff safe, equitable access to generative AI. Rather than each institution separately procuring commercial AI tools, EduGenAI routes access through SURF's own datacentre in Watergraafsmeer (Amsterdam) to open-source models, and pseudonymises requests to commercial models - including OpenAI's GPT models hosted on Azure, Meta's Llama, Mistral and Anthropic's Claude - so that providers cannot link prompts to individual users.
Before the platform moved from prototype to pilot, SURF and Npuls commissioned an independent Data Protection Impact Assessment from Privacy Company, published on 8 August 2025. The DPIA identified 12 residual risks, all assessed as low after the mitigations already built into the architecture (pseudonymisation, EU-hosted infrastructure for open-source models, and contractual restrictions on high-risk uses). The platform explicitly excludes high-risk applications such as automated assessment or fraud detection from its current scope.
The pilot runs through the 2025-2026 academic year with participating institutions including the University of Twente; based on its results, SURF and Npuls plan to develop EduGenAI into a standing national service for Dutch mbo, hbo and wo institutions from late 2026. Because the DPIA and its 12-risk finding are published prior to full rollout, the case is a rare example in this catalogue of privacy governance built in ahead of deployment rather than imposed after a violation - though, as a pilot, its learning and equity outcomes are not yet independently measured.
Read the full analysis: https://www.surf.nl/files/2025-09/250808-dpia-on-edugenai-for-surf.pdf
Where this practice's information was retrieved from, and when.