Poland Vetoes National School Database Over Student Privacy Fears

Poland's veto of a national student database highlights a global pushback against centralized EdTech platforms. Learn how to protect your child's data.

Sunday, August 30, 2026

Key Takeaways

  • ## The Pushback Against Student Data Tracking
  • Governments and privacy advocates are pushing back against the mass collection of student data.
  • On August 28, 2026, Polish President Karol Nawrocki vetoed a proposed national electronic student registry. Nawrocki cited a lack of encryption, costs exceeding 200 million zlotys, and a rushed 2027 deadline.
  • The veto comes amid growing evidence that educational technology handles personal information poorly. A 2025 BYU study revealed that 52% of popular educational apps collect student data. Despite having privacy agreements in place, 36% of these apps share that data with advertising networks.
  • In the United States, federal privacy laws fail to stop this sharing. Under the Family Educational Rights and Privacy Act (FERPA), the school official exception allows schools to share student personal data with third-party EdTech vendors without parental consent.
  • Centralizing this information also creates massive security targets. A March 2026 cybersecurity breach targeting Infinite Campus exposed 137,000 school staff accounts across 3,200 U.S. districts. The incident demonstrated the systemic vulnerability of centralized databases.

Polish President Karol Nawrocki has vetoed a controversial law to build a centralized, state-run electronic school register. This decision points to a growing global debate over how schools manage and protect sensitive student information. As we previously reported, school systems worldwide struggle to balance classroom technology with cybersecurity.

What Happened

On August 28, 2026, Polish President Karol Nawrocki officially refused to sign a bill that would have mandated a state-run electronic grade and attendance journal. According to Polish media reports, Nawrocki blocked the proposal because of risks to student cybersecurity and high implementation costs. He also warned that the transition would cause systemic organizational chaos. The veto stopped the creation of a centralized state e-register that would hold sensitive records for students nationwide.

The legislation aimed to transition all public schools to a single state-owned database. The president said the bill failed to outline mandatory security protocols like data encryption standards. It also lacked procedures for responding to system threats. According to Gazeta Prawna, critics also objected to the project's price tag, which was estimated to exceed 200 million Polish zlotys. Teachers' unions opposed the rapid rollout schedule, warning that forcing schools to integrate the system by September 2027 would trigger widespread organizational paralysis.

The Bigger Picture

The Polish veto shows a major cybersecurity vulnerability: centralization. Putting millions of students' records into a single database creates an attractive target for hackers. This threat is real. In March 2026, cybercriminals targeted a Salesforce platform used by Infinite Campus, a massive student information system used across the United States. The breach exposed 137,000 staff accounts across 3,200 school districts, compromising systems that hold data on roughly 11 million students.

Even when systems are not hacked, companies routinely exploit student privacy. A 2025 study by Brigham Young University researchers examined 100 of the most common educational apps. They discovered that 52% of EdTech vendors with data privacy agreements collected student data, and 36% shared that information with third-party advertising networks. These apps use unique identifiers to track children across the internet, building consumer profiles without parental consent.

Existing legal protections often fall short. Under the U.S. Family Educational Rights and Privacy Act (FERPA), schools regularly use the school official exception to share student files with external software companies without parental consent. While federal regulators like the Federal Trade Commission are increasing enforcement, state governments are passing strict digital sovereignty laws to close these loopholes.

What This Means for Families

For parents and educators, the Polish veto and global EdTech breaches show that school convenience cannot come at the expense of privacy. Centralized databases and unvetted classroom apps leave children vulnerable to identity theft and commercial tracking.

To protect student files, education leaders must move away from ad-hoc tech adoption. They need to implement strict data governance protocols. This includes "least-privilege access," which ensures only authorized staff can view specific records. It also requires "data minimization" to prevent schools from gathering unnecessary personal information.

What You Can Do

Parents can protect their children by asking school principals how they store student data and who has access to it. Make sure the district enforces least-privilege access policies. It is also wise to evaluate classroom apps and remain skeptical of platforms that require student profiles. As we previously detailed, many of these digital learning tools offer mixed results and may not be worth the privacy risk. Finally, families can opt out of directory sharing. Under FERPA, parents have the right to prevent schools from sharing directory information, such as names and addresses, with third parties.

Share: