A two-year investigation has revealed that many educational software programs used in public classrooms routinely violate their own privacy commitments. Researchers found that over half of audited school apps collected unauthorized student data, frequently transmitting private digital footprints to third-party advertisers. The findings have already spurred major legal reforms in Utah and raised national concerns about student privacy.
What Happened
The investigation, conducted by the Utah State Board of Education in partnership with Brigham Young University and Internet Safety Labs, monitored actual network traffic from 100 popular education applications between 2023 and 2025. Unlike typical reviews that only check written policies, this study tracked what the software did in real-time.
The results exposed a massive gap between vendor promises and actual practice. According to the BYU News report, 52% of the tested apps that had signed data privacy agreements collected at least one data element they were not contractually allowed to touch. An ABC4 local news report detailed that 61% of all tested apps shared student information with third parties, while 36% sent data directly to commercial advertisers. In some cases, individual applications transmitted student information to dozens of different advertising entities. This tracking often relied on persistent unique identifiers, which allow companies to build permanent digital profiles of children without requiring them to log in.
The Bigger Picture
To address these leaks, state lawmakers passed Utah House Bill 55, which went into effect on July 1, 2026. The law requires school districts to write strict privacy terms into vendor contracts, notify companies of violations, and immediately terminate contracts within 30 days if a vendor fails to fix a confirmed breach.
Outside of Utah, families face a confusing patchwork of regulations. Under the federal Family Educational Rights and Privacy Act (FERPA), schools are allowed to share student data with vendors without parental consent under the "school official exception." However, FERPA does not directly regulate edtech vendors; it only regulates school districts. When school districts scrambled to manage major classroom data breaches, it became clear that relying solely on standard vendor promises leaves students unprotected. A school must establish strict vendor contracts to maintain legally mandated "direct control" over where student information goes.
What This Means for Families
When schools adopt massive amounts of classroom software, they often fall victim to what we have called school tech sprawl, and educators cannot monitor every tool's behavior. Many vendors use "free" tiers to attract teachers, but these free versions often lack basic protections. Trackers and advertising pixels remain highly active on general commercial versions of these sites, even if they are suppressed on official, paid school portals.
Once student data enters the advertising ecosystem, it is bought and sold by commercial data brokers. This exposure risks child profiling and targeted marketing before children are even old enough to vote.
What You Can Do
Families can start by asking their school boards for a complete, public list of all approved digital tools to ensure the district actively tracks which apps are in use. They can also urge districts to employ technical experts who can intercept and test actual network traffic from classroom apps, rather than just accepting written privacy policies. Finally, families can encourage educators to use only district-approved, paid premium software tiers bound by custom Data Protection Addenda, rather than unvetted free apps.