School Tech Audits Reveal Major Gaps in Student Data Protection

A landmark UK audit of school EdTech providers reveals widespread data tracking. Learn how educational platforms handle, store, and share your child's data.

Tuesday, July 21, 2026

Key Takeaways

  • An investigation by the UK Information Commissioner's Office found that nearly 70% of audited EdTech providers failed to recognize when they were acting as data controllers. This failure led to the unauthorized reuse of student data.
  • A 13-year study of 21,000 educational websites documented a rise in third-party tracking, which exposed pupils to passive corporate monitoring.
  • Audited EdTech developers have accepted and started to implement 98% of the 596 compliance recommendations issued by data protection regulators.

School classrooms rely heavily on digital software, but a recent regulatory investigation reveals that the educational technology (EdTech) tools students use daily fail to protect their personal information. An audit of school-focused software developers has exposed systemic flaws in how student data is tracked, stored, and repurposed.

What Happened

According to the Information Commissioner's Office (ICO) "Edtech examined" report, consensual audits of 28 widely used EdTech providers in the UK revealed significant compliance failures. The official ICO statement noted that while information security was generally strong, major vulnerabilities emerged around consent and the secondary use of children's data. Most notably, nearly 70% of audited providers failed to recognize when they were acting as "data controllers" rather than mere "processors," according to a Digit.fyi report on the findings. As a result, these companies routinely used sensitive pupil data for product development, internal analytics, and artificial intelligence training without the legal authority to do so. In response to these findings, the ICO issued 596 compliance recommendations, of which 98% have already been accepted and actioned by the audited firms.

The Bigger Picture

These findings show a systemic challenge in education privacy. School platforms have integrated complex tracking systems, exposing children to passive monitoring by corporate entities. A 13-year longitudinal study published in the Proceedings of the 18th ACM Web Science Conference 2026 tracked over 21,000 educational websites and documented a substantial rise in third-party tracking. The research showed that to improve functionality, educational sites have increasingly integrated third-party tools, which quickly exposes learners to dominant corporate trackers. Many educational platforms load tracking cookies, social media trackers, and analytics tools before obtaining user consent. This practice violates basic data protection principles. According to a guide by Cookie-Script on education platform cookie management, this premature loading means sensitive student profiles, including academic performance and behavioral data, are often shared with third-party vendors without anyone realizing it. Even standard cookie preferences can be deceptively structured. Many sites require persistent cookie consent settings that are difficult for children or busy parents to use.

What This Means for Families

Unlike normal web browsing, where users can choose to leave a site if they dislike its privacy practices, students have no choice but to use the digital tools their schools require. If a school uses a learning management system or video provider that tracks student habits, pupils are forced to participate in that passive surveillance. The legal distinction between a "processor" (which simply stores school records) and a "controller" (which can reuse data to build new AI products) is vital. When EdTech companies blur this line, they turn classroom activities into proprietary corporate training data. Parents and educators must realize that educational tools are not inherently safe or private by default. Legal experts at Freeths LLP emphasize that this audit is a warning shot to the entire sector, and formal rules for EdTech data processing are likely coming.

What You Can Do

Parents can take several steps to protect their children's data. First, request data protection impact assessments (DPIAs) from your school administration. Schools are legally required to evaluate high-risk classroom apps, so ask for copies of these assessments for any software your child uses daily. Next, configure strict browser protections on your student's home and school devices. Enabling browser-level tracking protection blocks third-party analytics cookies from loading automatically. Finally, advocate for safer cookie policies by pushing your local school board to select EdTech partners that explicitly commit to keeping data processing strictly limited to educational delivery rather than product development.

Share: