Student Data Privacy: Questions to Ask an EdTech Vendor

Ask a vendor seven questions, in writing, before any pupil logs in. They cover what is collected, who sees it, where it is kept, what is public, other uses, leaving, and who to call.

In short

  • Seven questions cover what is collected, who sees it, storage, public pages, other uses, leaving and incidents.
  • A good answer is specific and written down, and a worrying answer is vague or leaves the detail until after you sign.
  • Official texts share three ideas: collect only what is needed, give children's data extra care, and the school stays responsible.
  • This is general information and not legal advice, so check the rules of your own country with your own adviser.

A reading platform can hold a lot about a child: a name, a class, what they read, which words they got wrong and when they logged in. Before you sign, you need to know what happens to that record. This article gives seven questions, what good and worrying answers sound like, and the official texts behind them. It is general information for school staff, not legal advice. Laws differ between countries, so check the rules of your own country with your school's own adviser.

What should you ask an edtech vendor about student data?

Ask seven questions, in writing, before any pupil gets an account. They cover what is collected, who can see it, storage, public pages, other uses, leaving and incidents.

  1. What data do you collect on each pupil, and why do you need each item?
  2. Who can see a pupil's data, inside the school and inside your company?
  3. Where is the data stored, and for how long?
  4. What is public, and what is never public?
  5. Do you use the data for anything beyond running the service?
  6. What happens to the data when we leave?
  7. Who do we call if something goes wrong, and how fast will you tell us?

Send the list at the same stage as the buyer's checklist, and before you run a pilot. A pilot class is real pupils with real data.

Three ideas behind the questions

The questions rest on three ideas. Each appears in an official text. The texts are cited here for what they say, not as a statement of what applies to your school.

  • Collect only what is needed. The European Union's General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) calls this data minimisation. Article 5 says personal data must be adequate, relevant and limited to what is necessary for the purpose.
  • Children's data deserves extra care. Recital 38 of the GDPR says children merit specific protection, because they may be less aware of the risks, the safeguards and their rights.
  • The school stays responsible for the choice of vendor. The Council of Europe (2021) guidelines cover data processed off site by third parties. They say education providers must remain aware of their ongoing responsibilities.

The Council of Europe guidelines were adopted by the Committee of Convention 108 in November 2020. They are guidance, not a law. They say that due diligence must be carried out to establish a third party's ability to protect personal data. The seven questions are a plain version of that due diligence.

Pupils cannot do this checking for themselves. Livingstone, Stoilova and Nandagiri (2019) reviewed the research on children's data and privacy online. They report that, on the available evidence, commercial privacy is the area children are least able to understand and manage on their own. They also note that the evidence on child development and privacy is insufficient. So the adults who choose the product have to ask.

Questions 1 and 2: what is collected, and who can see it

Ask for the list of data fields, item by item, with the reason for each. A reading platform needs a name or username, a class and a record of reading and quiz answers. If the list includes a home address, a photograph or a date of birth, ask what each one is for.

The United Kingdom's Information Commissioner's Office (ICO) states the idea in its code of practice on age appropriate design. The code tells providers to collect and retain only the minimum amount of personal data they need. That means the data needed for the parts of the service a child is actively and knowingly using.

The code is written for providers of online services likely to be accessed by children in the UK. Whether it applies to your product is a question for your adviser.

Then ask who can open an individual pupil's record. Inside the school, the answer should follow roles. A teacher sees their own classes, and a coordinator sees the grade. See what teachers should see in a reading dashboard.

Inside the company, ask which staff can open a pupil's record, and for what reason. Ask too for the list of other companies that handle the data for the vendor. The Council of Europe guidelines say that schools should publish a list of their partners, such as vendors and subcontractors.

Questions 3 and 4: where it is kept, for how long, and what is public

Ask for the country where the data is stored and the period it is kept. Article 5 of the GDPR sets out storage limitation. Data should be kept in a form that identifies people for no longer than is necessary for the purpose. The Council of Europe guidelines add that pupils and their legal guardians should be informed before personal data crosses a border.

'As long as necessary' is not an answer. Ask for a number: how many months after a pupil leaves, and how many months after the contract ends.

Then ask what an outsider can see. If the product has leaderboards, public school pages or certificates that can be shared, ask three things:

  • Can a pupil's name, photograph or score appear on any page open to the public or to other schools?
  • What is the default setting on the first day, before anyone changes anything?
  • Who can change that setting: the pupil, the teacher or the school's administrator?

The ICO code says settings must be 'high privacy' by default, unless the provider can show a compelling reason for a different default. If you plan a reading competition between schools, ask exactly what the other schools will see.

Question 5: is the data used for anything else?

Running the service means showing the pupil their stories and showing the teacher the results. Other uses include advertising, building profiles of pupils, sharing or selling data, and developing other products.

Article 5 of the GDPR sets out purpose limitation. Data collected for specified purposes should not be further processed in a way that is incompatible with those purposes. Recital 38 says the protection of children should apply in particular to marketing and to creating personality or user profiles.

The Council of Europe guidelines are more direct. Children's data collected by educational software should not be processed to serve or target behavioural advertisements. It should not be used to send marketing messages about upgrades or other products to children or families.

The OECD (2021) Recommendation on Children in the Digital Environment is published with guidelines for digital service providers. They ask providers to limit the collection of personal data to what is needed to provide the service in the child's best interests. The same limit covers later use and disclosure to third parties. OECD Recommendations are not legally binding.

Questions 6 and 7: leaving, and when something goes wrong

Ask what happens to the data on the day the contract ends. Article 28 of the GDPR covers a company that processes data on behalf of another body, which the law calls the controller. The contract must say that the company deletes or returns all personal data when the service ends. The controller chooses which. The exception is data that the law requires to be stored.

Whether your school is the controller for a given product depends on the facts and on your law. The Council of Europe guidelines note that a provider may be a controller in its own right. Ask your adviser.

Ask what happens if the vendor is sold. The Council of Europe guidelines say the terms agreed at procurement should continue to apply after a purchase, merger or acquisition.

Last, ask for a named contact and a time limit for telling you about a breach. Article 33 of the GDPR says a processor shall notify the controller without undue delay after becoming aware of a personal data breach. The controller then notifies the supervisory authority, where feasible within 72 hours, unless the breach is unlikely to put people's rights at risk.

Your country's rule may differ. Whatever it is, the vendor's promise should be written into the contract.

What good and worrying answers sound like

Use the table when the answers arrive. A good answer is specific and can be checked. A worrying answer is vague, or leaves the detail until after you sign.

Seven questions, with a good answer and a worrying answer for each (illustrative wording)
QuestionA good answer sounds likeA worrying answer sounds like
1. What do you collect, and why?'Here is the list of fields, with the reason for each. These three are optional.''We collect what we need to improve the experience.'
2. Who can see it?'Teachers see their own classes. Named support staff open a record only when the school asks.''Our team has access, as you would expect.'
3. Where is it kept, and for how long?'In this country. We delete pupil records this many months after the contract ends.''In the cloud, for as long as necessary.'
4. What is public?'Nothing about a named pupil. Public pages show school totals, and only if the school opts in.''Pupils love seeing their names on the leaderboard.'
5. Is it used for anything else?'No advertising, no profiling, no sale or sharing of pupil data. It is in the contract.''We may share data with trusted partners.'
6. What happens when we leave?'We give you an export, delete our copies and confirm the deletion in writing.''Accounts become inactive.'
7. Who do we call?'This named person. We tell you without delay if pupil data is affected.''Use the contact form on our website.'

One worrying answer is a reason for a follow-up question, not an accusation. Several worrying answers, with no clear reply to your follow-up, are a reason to stop.

How to use the questions in your school

Send the questions by email, so that the answers are in writing. File the reply with the contract, and share it with whoever advises your school on data protection.

Example (invented school)

The English coordinator at an invented school emails the seven questions to a vendor before a six-week pilot with class 6A. The reply answers five questions clearly. On storage it says 'as long as necessary'. On other uses it mentions 'partners'. She sends two follow-up questions: how many months, and which partners, for what purpose? The answers go to the head and to the school's data protection adviser. The pilot starts only after both have read them.

Tell parents what you chose and why. A short note on what the platform records and who sees it belongs with your reports to parents. The OECD guidelines ask providers for information that is concise, intelligible and written in clear, plain and age-appropriate language. Ask the vendor for a notice of that kind.

Remember the limits of this article. The GDPR is a European Union law. The ICO code is United Kingdom guidance. The Council of Europe and OECD texts are guidance, not law. Your country may have its own law on pupils' data. Check with your school's adviser or your national data protection authority.

How iRead handles this

In iRead, individual student data is visible only to the school's own staff. A school's public page shows aggregate numbers only, never individual students. Appearing in the schools directory and in the inter-school competition is opt-in. Put the seven questions to iRead as you would to any vendor, and ask for the answers in writing.

The core principle: Ask before any pupil logs in, ask in writing, and treat a vague answer as no answer.

See it in iRead: Individual student data is visible only to the school's own staff. A school's public page shows aggregate numbers only, never individual students.

See iRead for school leaders

Key takeaway

Seven written questions give you a clear first picture of how a vendor handles pupil data. Check the legal detail for your own country with your own adviser.

Frequently asked questions

What questions should a school ask an edtech vendor about student data?

Ask seven. What data do you collect, and why? Who can see it? Where is it stored, and for how long? What is public? Is it used for anything beyond the service? What happens when we leave? Who do we call if something goes wrong?

Is student data safe with edtech products?

It depends on the product and the contract, so no general answer is possible. Put the seven questions to the vendor in writing. Have your school's data protection adviser read the replies before any pupil gets an account.

What is data minimisation?

It means collecting only what is needed. Article 5 of the European Union's General Data Protection Regulation says personal data must be adequate, relevant and limited to what is necessary for the purpose. In practice, ask the vendor to give a reason for each data field.

Who is responsible for student data, the school or the vendor?

It depends on your country's law and on who decides how the data is used. The Council of Europe (2021) guidelines say education providers must remain aware of their ongoing responsibilities when third parties process data off site. Ask your own adviser.

Sources

  1. European Parliament and Council of the European Union (2016). Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). Official Journal of the European Union, L 119, 4.5.2016, 1-88. eur-lex.europa.eu/eli/reg/2016/679/oj
  2. Council of Europe, Consultative Committee of Convention 108 (2021). Children's data protection in an education setting: Guidelines. Council of Europe, Strasbourg (guidelines adopted November 2020). rm.coe.int/prems-001721-gbr-2051-convention-108-txt-a5-web-web-9-/1680a9c562
  3. Information Commissioner's Office (2020). Age appropriate design: A code of practice for online services. Information Commissioner's Office, United Kingdom. ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/
  4. OECD (2021). Recommendation of the Council on Children in the Digital Environment. OECD Legal Instruments, OECD/LEGAL/0389. legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0389
  5. Livingstone, S., Stoilova, M., & Nandagiri, R. (2019). Children's data and privacy online: Growing up in a digital age. An evidence review. London School of Economics and Political Science. eprints.lse.ac.uk/101283/
Ready to see it in practice?

We'll show your team how iRead puts this into practice.