The Information Commissioner’s Office (ICO) has told education technology companies to improve how they collect, reuse and explain their use of pupils’ personal information after regulatory audits uncovered widespread shortcomings.
In its Edtech Examined report, The ICO examined 28 providers whose products are used in primary and secondary schools. These included management information systems, safeguarding and behaviour platforms, learning-management systems, classroom applications and data-integration services.
According to the ICO’s report, many providers described themselves as data processors acting on schools’ instructions but also used children’s information for their own purposes.
These additional purposes included assessing product performance, developing and testing services and producing anonymised datasets. Some providers used pupil information to train artificial-intelligence features or shared anonymised data with third parties. One company had previously created anonymised pupil profiles for sale to organisations conducting educational research.
The regulator found that providers could not always demonstrate that these additional uses were fair or supported by an appropriate lawful basis. Companies had also not consistently recognised that using information for their own purposes could make them data controllers with additional legal responsibilities.
The ICO said that contracts between schools and technology suppliers frequently lacked sufficient detail about how children’s information would be processed. Broad contractual terms and unclear instructions sometimes allowed suppliers to make their own decisions about the use of pupil data. In several cases, providers could not show that schools had authorised these additional activities.
Privacy information was another area of concern. Although most suppliers published privacy policies, the ICO found that some contained only general explanations or were incomplete, outdated or insufficiently specific. This could prevent schools from properly explaining to pupils, parents and carers how education platforms use personal information.
The ICO also found examples of subcontractors whose contractual terms allowed them to retain children’s information for AI training. Some providers only became aware of these conditions during the audits.
The regulator made 596 recommendations across the 28 participating companies. Providers accepted 98 per cent of them and agreed to take remedial action.
The audits were voluntary, and the ICO has not identified the companies or products involved. Its published case studies have also been anonymised.
The ICO said its work represented a snapshot of practices at the time of each audit. It did not receive evidence that the identified shortcomings had caused actual harm to children.
The findings will inform a proposed statutory code governing the use of children’s personal information in digital education systems. The government intends to introduce the requirement through secondary legislation.
Schools were advised to make data protection a central consideration when selecting technology, establish clear approval procedures and explain transparently to families how each product will use pupils’ information.