MalwareBytes

Popular school apps may be sharing student data with advertisers


A two-year investigation into educational technology (EdTech) apps used by Utah schools found that many were collecting and sharing student data in ways that appeared inconsistent with their privacy commitments.

EdTech is a massive commercial industry and some argue that it functions much like traditional big tech by prioritizing profits, scalable software, and user data collection over proven learning outcomes.

The project, published by the Utah State Board of Education in partnership with Brigham Young University and Internet Safety Labs, examined network traffic from 100 EdTech apps between 2023 and 2025. Rather than relying only on privacy policies or vendor assurances, researchers looked at what the apps actually transmitted while in use.

What they found was concerning. Of the 85 tested apps with relevant data privacy agreements, 52% reportedly collected at least one student-data element that was not permitted under the agreement. Across all the apps tested, researchers found that 61% shared data with third parties, while 36% transmitted data to advertisers.

A school district may have a signed data privacy agreement with an EdTech provider specifying what information the company can collect, why it can use it, and who it may share it with. But contractual promises are not always reflected in how an app behaves. An app can include third-party analytics software, advertising-related services, or other embedded components that send information elsewhere without the school or district having a clear view of those transfers.

This shows how technical testing, including examination of live network traffic, can reveal behavior that paper-based assessments miss. The report concluded that such investigations could expose potential non-compliance not be found through traditional review processes.

The state’s response extended beyond publishing the findings. Vendors with potential issues were asked to explain or remedy them. Companies that addressed concerns could have their identities redacted in the public report, an approach designed to encourage corrective action while holding vendors that failed to respond to account.

Following the investigation, Utah passed H.B. 55, Privacy Compliance for Education Technology Vendors (2026), which took effect on July 1. It amends Utah Code § 53E-9-309. Among other changes, the law requires education entities to include specified student-data protections in vendor contracts, notify vendors of unauthorized use of student data, and terminate contracts when a vendor does not remedy a confirmed privacy violation after being notified.

Since we don’t all live in Utah, the more important question for every school system is: How are your apps behaving?

Protecting student data requires more than trusting a privacy policy. Schools need accurate inventories of the tools in use, clear contractual limits, and access to the technical expertise needed to test whether those limits are being observed.


By the way, did you know about the Malwarebytes Student Protection program?



Source link