Utah Audit Shows Classroom Apps Share Student Data With Advertisers

A two-year Utah audit found that 52% of classroom apps violate privacy agreements, sending student data to advertisers. Learn what this means for your school.

Wednesday, August 26, 2026

Key Takeaways

  • A joint investigation of 100 educational apps used in Utah public schools found that 52% of apps with signed privacy agreements collected unauthorized student data, including persistent unique identifiers. Live network traffic tracking showed that 61% of classroom apps shared student data with third parties, while 36% sent data directly to commercial advertisers.
  • In response, Utah passed House Bill 55. Under this law, school districts must enforce strict privacy terms and notify vendors of any violations. If a vendor does not resolve a breach within 30 days, the district must terminate the contract. Because federal regulations under FERPA do not directly govern EdTech vendors, school districts must use these customized contracts to legally protect student privacy.

A two-year investigation has revealed that many educational software programs used in public classrooms routinely violate their own privacy commitments. Researchers found that over half of audited school apps collected unauthorized student data, frequently transmitting private digital footprints to third-party advertisers. The findings have already spurred major legal reforms in Utah and raised national concerns about student privacy.

What Happened

The investigation, conducted by the Utah State Board of Education in partnership with Brigham Young University and Internet Safety Labs, monitored actual network traffic from 100 popular education applications between 2023 and 2025. Unlike typical reviews that only check written policies, this study tracked what the software did in real-time.

The results exposed a massive gap between vendor promises and actual practice. According to the BYU News report, 52% of the tested apps that had signed data privacy agreements collected at least one data element they were not contractually allowed to touch. An ABC4 local news report detailed that 61% of all tested apps shared student information with third parties, while 36% sent data directly to commercial advertisers. In some cases, individual applications transmitted student information to dozens of different advertising entities. This tracking often relied on persistent unique identifiers, which allow companies to build permanent digital profiles of children without requiring them to log in.

The Bigger Picture

To address these leaks, state lawmakers passed Utah House Bill 55, which went into effect on July 1, 2026. The law requires school districts to write strict privacy terms into vendor contracts, notify companies of violations, and immediately terminate contracts within 30 days if a vendor fails to fix a confirmed breach.

Outside of Utah, families face a confusing patchwork of regulations. Under the federal Family Educational Rights and Privacy Act (FERPA), schools are allowed to share student data with vendors without parental consent under the "school official exception." However, FERPA does not directly regulate edtech vendors; it only regulates school districts. When school districts scrambled to manage major classroom data breaches, it became clear that relying solely on standard vendor promises leaves students unprotected. A school must establish strict vendor contracts to maintain legally mandated "direct control" over where student information goes.

What This Means for Families

When schools adopt massive amounts of classroom software, they often fall victim to what we have called school tech sprawl, and educators cannot monitor every tool's behavior. Many vendors use "free" tiers to attract teachers, but these free versions often lack basic protections. Trackers and advertising pixels remain highly active on general commercial versions of these sites, even if they are suppressed on official, paid school portals.

Once student data enters the advertising ecosystem, it is bought and sold by commercial data brokers. This exposure risks child profiling and targeted marketing before children are even old enough to vote.

What You Can Do

Families can start by asking their school boards for a complete, public list of all approved digital tools to ensure the district actively tracks which apps are in use. They can also urge districts to employ technical experts who can intercept and test actual network traffic from classroom apps, rather than just accepting written privacy policies. Finally, families can encourage educators to use only district-approved, paid premium software tiers bound by custom Data Protection Addenda, rather than unvetted free apps.

Share: