Skip to content

Ed tech companies used pupil data without telling schools – ICO

Audits found nearly three quarters of providers could not prove their additional use of data was fair
4 min read
|

Listen to this story

Members can listen to an AI-generated audio version of this article.

1.0x

Audio narration uses an AI-generated voice.

0:00 0:00

Ministers plan to introduce new guidance on how education technology companies can use children’s data, as audits found many providers could not prove their approach was lawful or authorised by schools.

The Information Commissioner’s Office carried out 28 audits of unnamed ed tech providers including information management systems, safeguarding tools, learning systems and classroom apps between 2024 and 2025.

It made more than 500 recommendations to the firms.

The Department for Education estimates there are up to 1,200 active ed tech businesses in England, which generate an estimated £6.5 billion in annual turnover.

Ninety per cent of primary and 92 per cent of secondary schools currently use an ed tech platform, according to technology company Glass.AI.

The audits found nearly three quarters of providers could not prove their additional use of children’s data was fair, and many did not inform schools this information was being used in written contracts.

Jen Persson, chief executive of the digital safety campaign group Defend Digital Me, said children “are paying the price for a lack of technology standards and enforcement across education, with risks that last a lifetime”.

But the British Educational Suppliers Association said the ed tech sector had a “strong willingness to operate transparently, engage constructively with the regulator and take action where improvements are required”.

The ICO is working with the Department for Digital, Culture, Media and Sport to provide a new code on the use of children’s personal information in digital systems in educational settings.

This will be introduced through secondary legislation.

Additional use of data

The ICO found many firms were using children’s information for multiple purposes, such as developing products, analysing performance or producing anonymised information for other purposes.

Some also used data to train AI functionality or share anonymised information with third parties – with one selling anonymised profiles for education research.

In total, 70 per cent of ed tech firms audited could not show that the school or child had given consent that their information could be used in these ways.

Instead the ICO found “there was usually only general information provided about ed tech products, and how they used children’s information”.

The report warned that providers needed to assess whether reusing information in this way complied with the law.

It also said that written contracts should state whether all personal information is deleted or is instead returned to the “controller”, based on UK GDPR laws.

A further 70 per cent of providers failed to document personal data breaches or were found to be following incorrect processes when handling them.

Children ‘paying the price’

Following the audits, the ICO made 596 recommendations to firms, of which only 98 per cent were accepted.

Companies agreed to provide more detailed information and resources to schools explaining how they used children’s information. They also agreed to review their privacy information.

Persson welcomed the audit’s findings but that warned more work needed to be carried out.

She added: “Children have a right to quality education but are paying the price for a lack of technology standards and enforcement across education, with risks that last a lifetime.

“Many schools lack the capacity to do the necessary due diligence to see or understand what the ICO audits have found. Since it doesn’t name the products, schools will be none the wiser which were breaking the law before the interventions and why, or how to tell them apart from others for future.”

A 2025 report by the Nuffield foundation similarly warned that there was a lack of support for schools when it came to purchasing ed tech platforms, and that there is a lack of “evaluation and oversight” of the firms.

But a BESA spokesperson said the ICO’s report “found substantial evidence of good practice among the relatively small number of providers” it audited, with most implementing strong practice.

The spokesperson said while the report “makes clear that some suppliers need to strengthen how they document and explain their use of data”, the sector has a “strong willingness to operate transparently, engage constructively with the regulator and take action where improvements are required”.

Data protection a ‘key consideration’

Michael Murray, the ICO’s head of regulatory strategy, told Schools Week that schools “should make data protection a key consideration from the outset”, and have a clear internal process for assessing and approving products.

Schools should “also be transparent with staff, pupils, parents and carers about how the ed tech tools will use their personal information,” Murray said.

The DfE was approached for comment.

Share

Explore more on these topics

No Comments

Featured jobs from FE Week jobs / Schools Week jobs

Browse more news