A study shows that most classroom software applications quietly leak student data to commercial advertising networks. Researchers from Brigham Young University and the Utah State Board of Education tracked network traffic from popular educational tools to see where student information goes. The findings led state lawmakers to pass strict new privacy laws.
What Happened
According to the BYU News report, researchers used active test accounts to audit 100 K-12 educational apps. They found that 61% of all analyzed classroom apps shared student data with third parties, and 36% sent student data directly to advertisers. Even when school districts had contracts prohibiting data collection, 52% of the EdTech platforms gathered student information anyway.
Much of this tracking relies on "unique digital identifiers" that follow children across the internet. Commercial networks use these identifiers to build permanent advertising profiles. In some cases, individual classroom apps transmitted student data to over 30 separate advertising entities.
This is not an isolated glitch. A class-action lawsuit against i-Ready, an online testing and learning platform, alleges that the program logged detailed student behaviors. These behaviors included learning disability flags, mouse movements, and specific click histories. The platform then shared them with Google without parental consent.
The Bigger Picture
This data leakage has led to rapid legal action. In Utah, the study's findings prompted state lawmakers to pass H.B. 55. Under this law, Utah school districts must terminate their contract with any EdTech vendor within 30 days if the vendor does not correct a confirmed student data leak.
On a national level, the Federal Trade Commission updated its rules under the Children's Online Privacy Protection Act (COPPA). EdTech companies can no longer bypass parental authorization by using school-level consent for commercial tracking. This matches data governance standards under the Family Educational Rights and Privacy Act (FERPA), which require schools to maintain direct control over student data.
As we previously reported regarding state financial literacy mandates, digitizing school curriculums quickly often leaves student privacy unprotected by current legal frameworks.
What This Means for Families
For parents and educators, the main concern is that these data leaks happen automatically. Often, school administrators and app developers do not even realize it is happening. Commercial networks use unique identifiers to target children with ads, establishing a digital profile before students can understand the consequences.
The BYU researchers also found that many vendors only protect student privacy on paid premium tiers. This leaves students who use free versions exposed to commercial profiling.
What You Can Do
- Ask school administrators for the Data Privacy Agreement (DPA) of any required app. Make sure the agreement covers free versions, not just paid ones.
- Push for district-level technical audits. School systems must monitor the actual network traffic of classroom apps instead of trusting written vendor promises.
- Turn off ad personalization on your child's home devices. You can also use browsers that block third-party trackers.