Utah Audit Reveals Popular Classroom Apps Routinely Leak Student Data

A Utah technical audit reveals that 52% of school apps collect unauthorized student data. Learn how families and educators can protect student privacy.

Friday, September 4, 2026

Key Takeaways

  • A 2025 Utah State Board of Education investigation found that 52% of classroom apps collected student data in violation of signed privacy agreements. Technical testing showed that 36% of these analyzed apps shared unique student identifiers, including advertising and device IDs, with commercial advertisers.
  • In response, Utah passed House Bill 55. Effective July 1, 2026, the law lets school districts independently audit EdTech vendors. It also mandates that schools terminate contracts within 30 days if a vendor fails to fix privacy leaks.

Educational technology software in classrooms often operates far differently than what school districts are promised on paper. A multiyear investigation commissioned by the Utah State Board of Education has revealed that more than half of tested classroom applications collected data in direct violation of their signed privacy agreements. The technical audit shows a systemic lack of compliance, leaving students vulnerable to commercial tracking despite written contracts.

What Happened

In an effort to verify whether technology vendors respect student boundaries, researchers at Brigham Young University and the non-profit Internet Safety Labs analyzed the network traffic of 100 popular classroom applications. According to the official investigation report published in August 2025, 52 percent of the apps that had signed standard data privacy agreements collected at least one type of unauthorized student data.

The audit also revealed that 36 percent of these applications shared student information with advertising-related entities. Instead of collecting basic operational telemetry, these tools transmitted persistent unique identifiers, including advertising IDs, analytics IDs, and device signatures, to commercial ad networks. Under federal regulations like the Children's Online Privacy Protection Act (COPPA), these persistent identifiers are legally classified as personal data because they allow companies to recognize and profile children across different websites over time.

The Bigger Picture

The findings in Utah are part of a school tracking pattern documented across the country. In 2022, an Internet Safety Labs national benchmark study of more than 1,700 school-recommended applications found that 96 percent sent data to third parties, and 78 percent shared it with advertising or marketing platforms.

While written agreements like the Student Data Privacy Consortium contracts are standard in school procurement, Utah's director of privacy, Katy Challis, noted in a GovTech interview that actual software behavior frequently fails to match legal disclosures. This mismatch means districts are often flying blind when they approve digital classroom tools.

This data sharing is not restricted to early education. Even higher education platforms have faced legal action, such as a recent class-action lawsuit against Southern New Hampshire University for allegedly transmitting student GPAs and financial aid data to Google and TikTok via web trackers.

What This Means for Families

For parents and educators, the Utah investigation shows that signed contracts alone cannot guarantee student digital safety. When school apps leak persistent identifiers to commercial ad networks, these networks can build detailed behavioral profiles of children. These profiles can persist into adulthood, affecting the advertisements and content they see online.

As we previously reported on school surveillance and tracking practices, school-mandated technology often bypasses traditional parental consent. However, policymakers are beginning to push back. In response to these privacy failures, Utah enacted House Bill 55, which took effect on July 1, 2026. The law grants schools the authority to conduct independent audits and legally requires them to terminate a vendor's contract within 30 days if a confirmed data leak is not resolved.

What You Can Do

  • Use free, independent databases like the App Microscope to inspect the safety ratings and data-sharing behaviors of apps used in your children's classrooms.
  • If you live in Utah or states with similar laws, ask your school board how they plan to audit vendors and enforce the 30-day contract termination rules for non-compliant apps.
  • Ask your school principal for opt-out forms regarding non-essential educational tools. Under updated FTC COPPA interpretations, schools cannot easily bypass parental consent for third-party commercial tracking.
Share: