Share

ICO calls for stronger edtech data protection to safeguard children in schools

The Information Commissioner’s Office (ICO) has published a new report examining data protection practices across the education technology (edtech) sector. It identified both the examples of good practice and areas requiring further improvement.

The report, ‘Edtech examined’, is based on a programme of consensual audits carried out during 2024 and 2025 with 28 edtech providers whose products are widely used in primary and secondary schools across the UK.

The audits covered a range of technologies commonly used in education, including management information systems, safeguarding tools, behaviour management platforms, learning management systems, classroom applications and data integration services.

Balancing innovation with data protection

According to the ICO, schools, parents and pupils must be able to trust that the digital tools used in education handle children’s personal information responsibly and in line with data protection legislation.

An ICO spokesperson said:

“The ICO is committed to ensuring that children’s personal information is processed responsibly and fairly, complying with data protection law. This includes processing that occurs through educational technology (edtech) products used in schools.

“Because children may not be able to choose or opt out of many digital tools their schools adopt, it is essential that parents, caregivers and pupils can trust that this technology meets the highest standards of data protection.”

The regulator found a number of positive practices across the sector, particularly in relation to information security. However, the audits also identified compliance gaps that required attention.

Common challenges identified

Among the most frequent issues identified were providers not correctly determining whether they were acting as data processors or data controllers, particularly where children’s data was being used for analytics or product development purposes.

The ICO also highlighted concerns around:

  • insufficiently detailed contracts between providers and schools
  • incomplete data flow mapping
  • weak implementation of data minimisation and storage limitation principles
  • outdated or inaccessible privacy information
  • Gaps in Data Protection Impact Assessments (DPIAs)

The regulator said these findings demonstrate the importance of robust governance arrangements as schools continue to increase their use of digital technologies.

Providers respond to recommendations

Despite identifying areas for improvement, the ICO said the audit programme has already driven significant progress across the sector.

The report found that providers accepted and implemented 98 per cent of the 596 recommendations made during the audit process.

The ICO spokesperson said:

“Through the audits, the ICO has successfully driven improvements across the sector, with providers accepting and putting in place 98 per cent of the 596 recommendations that were made.”

Looking ahead

The ICO is now working with the Department for Education and devolved authorities to support improvements in how children’s personal information is handled within educational settings.

As part of this work, discussions are underway regarding the potential development of a new edtech code, which could help establish clearer expectations for providers and strengthen data protection standards across technologies used widely in schools.

The ICO spokesperson added:

“As part of this, we are discussing how a new edtech code could contribute to ensuring children’s data is better protected across the tools and platforms schools use widely, as one of a range of measures to drive lasting change.”

The report offers school leaders, trusts and edtech providers an insight into the data protection challenges facing the sector, while highlighting the steps being taken to build greater confidence in the digital tools increasingly used to support teaching, learning and school management.

You may also like...