Learning analytics has moved from a curiosity to a strategic asset. Organizations now use LMS telemetry, assessment results, and skills evidence to route work, target development, and even inform redeployment decisions. But the same data that powers planning also touches deeply personal attributes: a learner's pace, struggles, career anxiety, and, increasingly, performance inferences drawn by algorithms that nobody has audited.
The legal landscape is tightening in parallel. GDPR's data minimization and purpose limitation principles apply to learning records, and the EU AI Act classifies systems used for employee evaluation as high-risk, triggering conformity assessment and human oversight. Add emerging algorithmic accountability regimes in the EU, Canada, and parts of Asia, and ungoverned people analytics is a liability, not a growth story.
The governance question is not simply 'is this legal,' it is 'what inferences may we draw at all.' Many enterprises discover their analytics stack draws conclusions from data that was collected for a different purpose, which is precisely the GDPR violation pattern regulators target. A purpose-based data architecture, where collection is tagged to its intended use, is the single most effective defense against this failure mode.
Ethics is harder than law. Capability scores attached to employees can become de facto performance ratings, and training gaps used for planning can silently become barriers to promotion. In our practice, we insist on a human-in-the-loop review for any analytic output that influences decisions about people, plus transparency rights for learners about what data is held and how it is used.
The pragmatic path is a learning data governance charter: declared purposes, a retention and deletion schedule, algorithmic audit logs, role-based access, and a clear separation between development data and administrative decision data. Enterprises with such a charter can move fast without fear; those without one should expect a regulator to write it for them.

