Public
Examples
Website, brochures, external communications, freely available information.
Any tool
The choice of tool is yours, within the principles of the charter. Verification before circulation still applies.
Interactive tool
Four questions at most, and you know whether the data may go. The result carries a light, the conditions that apply and the passage of the common core behind it. Below the tool, the list of AITO-approved tools and the route for having a new one assessed.
Staff and faculty
What the tool does
What the tool does not do
Question 1 of 4
Name, address, grade, student file, CV, health information, photo, phone number, internal identifier.
This result guides you, it does not cover you. If doubt remains, write to aito@iscparis.com before sending anything.
Examples
Website, brochures, external communications, freely available information.
Any tool
The choice of tool is yours, within the principles of the charter. Verification before circulation still applies.
Examples
Course material, meeting notes, working documents, ongoing projects.
AITO-approved tools only
No further authorisation to request, but the tool must appear in the list below.
Examples
Budgets, examinations, strategy, contracts, sensitive correspondence.
Approved tools plus prior authorisation
Both conditions together, never one or the other.
Examples
HR data, student files, health, identity.
Prohibited
Prohibited in any tool ISC Paris has not approved. The Data Protection Officer is consulted whenever personal data is involved.
Common core V3, data classification.
If you are unsure which category applies, treat the data as confidential. Doubt is settled before you send, never after.
A student file with the name removed is still a student file. Effective pseudonymisation, within the meaning of Article 4(5) GDPR, does not remove personal data status: it does not authorise the use of an unapproved tool. Anonymisation within the meaning of Recital 26 is rarely achievable on rich text, and validating it falls to the Data Protection Officer.
| Tool | Data accepted | Hosting | Indicative footprint | Status |
|---|---|---|---|---|
| Conversational assistants and productivity | ||||
| ClaudeAnthropic, professional plan with training opt-out | Public, internal | United States, transfer covered (DPF, SCCs) | Standard to heavy | Approved |
| ChatGPTOpenAI, professional or Edu plan with training opt-out | Public, internal | United States, transfer covered (DPF, SCCs) | Standard to heavy | Approved |
| Microsoft Copilot 365ISC tenant | Public, internal | European Union, ISC tenant | Standard | Approved |
| GeminiGoogle, Workspace version with confidentiality guarantees | Public, internal | United States, transfer covered (DPF, SCCs) | Standard to heavy | Approved |
| PerplexityProfessional plan | Public, internal | United States, transfer covered (DPF, SCCs) | Standard | Approved |
| Audiovisual content creation | ||||
| HeyGenAvatars and generated videoWritten consent of the people concerned is mandatory, for their image. | Public, internal | United States, transfer covered (DPF, SCCs) | Heavy | Approved with conditions |
| ElevenLabsSpeech synthesis and voice cloningWritten consent of the people concerned is mandatory, for their voice. | Public, internal | United States, transfer covered (DPF, SCCs) | Standard to heavy | Approved with conditions |
| Code and development | ||||
| Claude CodeAnthropic command line interfaceNo confidential proprietary code without prior validation. | Public, internal | United States, transfer covered (DPF, SCCs) | Standard to heavy | Approved |
| OpenAI CodexCommand line or inside the editorNo confidential proprietary code without prior validation. | Public, internal | United States, transfer covered (DPF, SCCs) | Standard to heavy | Approved |
| Under assessment | ||||
| Claude CoworkAnthropic, collaborative workspaceReferred to IT and to the Data Protection Officer. Approval expected before any deployment. | To be determined | United States | To be assessed | Under assessment |
Professional plan
Team, Enterprise or Edu only. Never the free version, and never a personal account for ISC data other than public information.
Training opt-out
Enabled by default in the ISC configuration: no incoming data feeds model training.
Transfer outside the European Union
For tools hosted in the United States, the transfer is covered by the EU-US Data Privacy Framework and, in the alternative, by the European Commission standard contractual clauses.
Personal data
It remains subject to the opinion of the Data Protection Officer. No processing of sensitive data within the meaning of Article 9 GDPR without a prior impact assessment.
Image and voice
HeyGen and ElevenLabs require free, informed, written and revocable consent from the people concerned, with a consent register kept.
Source code
Claude Code and OpenAI Codex process neither proprietary code nor secrets, API keys and credentials included, without prior validation.
These tools may not process internal or confidential data. Personal use on public information remains possible within the charter.
Added
At any quarterly update.
Suspended
If the publisher changes policy: acquisition, amended terms of service, published security flaw.
Revoked
In the event of a serious incident or confirmed non-compliance.
Every change is emailed to all staff and published on the intranet, page AI Charter, approved tools.
Will the tool process anything other than public information? If so, it must be approved. If not, use remains possible within the charter, use statement included.
An email to aito@iscparis.com: the name of the tool and the link to its publisher, the intended use in one or two sentences, the type of data involved, the department or programme concerned.
The AI Transformation Office takes one of the three routes below, with the Data Protection Officer and IT. Legal joins in for high-risk uses.
Approved, approved with conditions, refused, or redirected to an equivalent approved tool.
If approved, the tool joins the list at the next quarterly update, and the detailed internal register.
Fast route
72 working hours
Tools already approved by the French Ministry of Higher Education, Renater, SecNumCloud or a European equivalent. Consistency check and acknowledgement of receipt.
Standard route
2 to 4 weeks
Tools with no high-risk use, public or internal data. Simplified GDPR and security audit, run by the Data Protection Officer and IT.
High-risk route
4 to 8 weeks
Extendable. Major deployments or high-risk uses within the meaning of Annex III of the AI Act. Fundamental rights impact assessment, data protection impact assessment where personal data is involved, IT audit, DPO signature, approval by the AITO and the executive committee.
Common to all three routes, examined in varying depth.
Annex A5, tool approval procedure and criteria. The three routes are set out in the AI Act compliance framework, Annex A1 § 7.2.
The tool applies written rules, nothing more. Where none covers your situation, the answer is not invented: it is asked for, before anything is sent.