The EdTech Service Provider’s Guide to Student Privacy
Schools rely on education technology (edtech) service providers to manage student data and provide
services and tools to help all students learn effectively. Edtech tools enhance students’ learning
experiences in a wide variety of ways, such as helping schools manage learning by streamlining
coursework and gradebooks and using data analytics to monitor progress and provide personalized
learning. These tools make learning more accessible by providing the option for virtual, independent
learning as well as building solutions tailored for individual learners.
Most of these systems require online service providers to access or store student data, raising concerns
about potential impacts on students’ privacy. To provide solutions that harness technology’s full potential
in schools while protecting student data, edtech service providers must comply with, and facilitate the
school’s ability to comply with, the array of federal and state student privacy laws in addition to local and
state contracting requirements. Because the speed of technological innovation sometimes outpaces
meaningful regulation, they should also align with industry best privacy practices where existing laws are
silent or unclear on certain practices. By working with schools to protect student data, service providers
can help to ensure an efficient, safe, and effective learning environment for students and educators.
This Guide is designed to help online edtech service providers protect student privacy while effectively
delivering educational products and services. There is no “one-size fits all” solution for ensuring data
privacy–each use case must take into account the specific technology, data utilization, and underlying
data governance framework. Recognizing that context matters, the Guide begins by defining the key
terms and explaining the application of relevant federal and state laws to support informed
conversations between service providers and education officials, and to help other stakeholders better
understand the evolving education privacy landscape. It also explores how providers can go beyond
legal compliance by implementing strong, transparent privacy practices that enhance both data
protection and service quality, offering practical guidance fo