Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Edtech Privacy topic
No spam. Unsubscribe anytime.
State audit and network testing finds many EdTech apps share student data beyond contracts; USBE begins remediation
Summary
A technical review of 100 widely used educational apps found about half sent data elements not listed in vendor agreements and sometimes routed data to third‑party advertising and analytics firms; USBE and academic partners notified vendors and began remediation and training.
Get email alerts on the Edtech Privacy topic
No spam. Unsubscribe anytime.
A technical audit of commonly used educational software presented on Sept. 1 found that many third‑party education apps send student data beyond what vendors declared in their contracts with LEAs. Researchers and USBE staff said the work — combining public registries and network‑traffic testing — found approximately 52% of tested apps transmitted data elements not explicitly disclosed in vendor exhibits and, in multiple cases, forwarded information to third‑party analytics or ad‑tech vendors; USBE has begun vendor follow‑up and remediation.
The study was led by Mark Keith, a professor at Brigham Young University’s Marriott School of Management, and carried out with USBE staff. Researchers compiled a list of edtech apps used in Utah schools from LEA websites, USBE registries and other sources, cleaned the list to about 3,000 unique apps, and sampled roughly 100 widely used apps across disciplines for network packet analysis. Testers installed each app on a device, inspected outgoing and incoming packets, and compared observed traffic to each vendor’s data‑privacy agreement (exhibit B) and to the Utah Student Data Protection Act and federal privacy rules.
Key findings and follow‑up. The researchers reported that in the tested sample, about half of the apps sent data elements that were not in their stated agreements; some data was routed to third parties categorized as aggregators, analytics providers or adtech companies. The study team then shared findings with each vendor and asked for explanations or remediation. USBE’s data‑privacy staff reviewed vendor responses; vendors fell into categories including those that corrected practices, those that provided acceptable explanations, and a minority requiring further scrutiny. The USBE team recommended additional vendor training, stronger contracting and routine audits; it also noted that mergers and acquisitions sometimes change data‑handling practices after contracts are signed.
What Utah law and USBE can do. Presenters said Utah’s student‑data protections are among the strongest in the country (they referenced the Utah Student Data Protection Act of 2016) and that USBE has a dedicated data‑privacy office and a data privacy council. The presenters urged more accountability: run‑time audits, clearer contract exhibits listing allowed data elements, and training for LEA contract holders so they can audit vendors on‑site or request network traffic reports. Researchers noted this work is relatively unique among states, and USBE officials said the report will feed a broader remediation and outreach program.
Committee reaction and next steps. Committee members welcomed the technical approach and asked whether USBE will notify parents; presenters said public notification and further stakeholder outreach are next‑step items for USBE’s data‑privacy office and the data‑privacy advisory committee. USBE staff said many vendors cooperated and corrected practices when shown the network evidence; the agency plans to scale the audit process and provide training to LEAs so they can vet apps before classroom use.
Ending: USBE and academic partners recommended formalizing regular auditing of third‑party educational apps, expanding training for LEA contract holders, and adding vendor accountability clauses to contracts; committee members asked USBE to consider parent notifications and use the report to update guidance for districts and charter schools.
