A new Utah law set to take effect in July 2026 will impose strict privacy penalties on classroom technology vendors. The legislation comes after researchers discovered that over half of the most popular education applications used in public schools violate their own data privacy agreements. This discovery shows the gap between school district policies and actual digital safety practices in classrooms.
What Happened
According to an investigation report prepared for the Utah State Board of Education, Brigham Young University professors Mark Keith and Justin Giboney identified major security leaks in student digital footprints. These leaks leave students vulnerable to targeted advertising and commercial tracking. The research team, which included student assistants, partnered with the non-profit Internet Safety Labs to test the network traffic of the 100 most popular classroom applications in Utah, simulating real student activity during 15- to 20-minute sessions.
The results were concerning. Despite having active data privacy agreements, 52% of the tested EdTech companies were actively collecting student data. Even worse, 36% of those companies were sharing this information with third-party advertisers. This tracking often relies on unique digital identifiers, which allow companies to build permanent advertising profiles of students as they browse the internet. This continues a broader trend we have previously tracked, where classroom tools collect personal details that put student digital footprints at risk.
The Bigger Picture
Under the federal Children's Online Privacy Protection Act (COPPA), online services are restricted from gathering personal data on children under 13. However, the BYU team discovered that several certified-safe vendors failed to meet these standards in practice. The researchers categorized vendors into three groups: those that were completely safe, those that broke rules unintentionally, and those that knowingly ignored data collection limits.
To address these persistent leaks, Utah lawmakers passed H.B. 55, Privacy Compliance for Education Technology Vendors. Starting July 1, 2026, the law requires school contracts to feature stricter privacy mandates. It also gives local educational authorities the power to perform independent technology audits. If a vendor fails to fix data violations, schools must terminate the contract within 30 days.
What This Means for Families
For families and educators, the BYU study is a reminder that a 'safe' label does not guarantee privacy. When schools adopt apps, they often trust the publisher's legal compliance without verifying what the software actually does. This leaves children vulnerable to targeted advertising and commercial profiling from a young age.
As seen in previous privacy battles, such as when New Mexico paused an AI reading tutor over data collection fears, state and school-level verification is becoming essential to protect children.
What You Can Do
Parents can take several steps to protect their children's data. First, ask your school board if they actively monitor app network traffic or if they rely solely on signed privacy pledges. Many school districts publish lists of pre-approved digital tools. You can check the privacy policies of major apps like Canvas, Duolingo, or Quizlet against your school’s approved database. Finally, teach students to use privacy-focused web browsers or ad-blockers on home devices to limit tracking when using school platforms outside of class hours.