In 1998, the World Wide Web was still a novelty, and multiple government agencies and advocates had already raised alarms about website owners collecting children's personal information without regulation.

At the time, a Federal Trade Commission (FTC) investigation showed that about 14% of children used the internet at home or school, while 89% of websites marketed to children were directly collecting personal information from young users. The FTC noted in its report that the most concerning issue was that predators could easily communicate with children in chat rooms or online forums.

These "deep concerns" drove the creation of laws to protect children's online personal data, aiming to prevent accidental exposure of children's life details and ensure their safety.

However, more than two decades later, educators, parents, researchers, and lawmakers are still raising alarms about the vulnerability of children's online personal data—now nearly every child can access the internet through home, school, or a smartphone in their pocket.

Federal laws and regulations have brought oversight and the promotion of best practices, as well as fostering collaboration between edtech companies and school systems. But critics point out that some of these laws are now outdated or misinterpreted.

For example, the Children's Online Privacy Protection Act (COPPA) was enacted in 2000 and last updated in 2013, just as social media was truly taking off.


"Protecting student privacy is crucial, but lawmakers often don't communicate with those on the front lines to understand best practices."

c26dbb7f8ae5524841267a35b6468bcbecf9efd7dcf6efba56bf278ef43ecb45.png

Amelia Vance

Vice President of Youth and Education Privacy at the Future of Privacy Forum


Since then, most state education departments and legislatures have enacted stricter policies to further protect children's online privacy. According to the Data Quality Campaign, between 2014 and 2020, 45 states and Washington, D.C. enacted new student data privacy laws.

However, while school systems are required to protect children's online data, they are also encouraged or mandated to collect and retain vast amounts of information about each student.

These data points include students' academic performance, images and videos, creative content, disciplinary records, social-emotional and physical health conditions, special education records, socioeconomic status, and more.

Moreover, school systems often place their trust in third-party edtech providers to protect this student information.

Kara Arundel/K-12 Dive, data source: Government Accountability Office
 

Although online threat monitoring and data breach detection for students have become more sophisticated over the years, some privacy advocates still worry about unfair tracking of students' online activities and the security of such vast amounts of data.

A survey of district IT leaders by the Consortium for School Networking ranked student data privacy and security as the second-highest technology priority after cybersecurity.

In fact, managing and protecting student online data was already a system under pressure with conflicting goals, and the 2020 pandemic forced all students to learn virtually from home, complicating matters further.

Safeguarding Student Data

Nancy Byrnes has served as IT director for Fairfield Public Schools in Connecticut since 2000. Over the years, she has witnessed technology evolve from computer labs that students visited a few times a week to a situation where every student in grades 3 through 12 and many staff members now have school-issued devices.

The district, with 9,300 students, manages about 12,000 devices and 67 paid applications, along with many free ones.

Before the pandemic, Fairfield had established a streamlined process to review new digital tools, requiring consideration of each application's instructional value and federal and state student privacy compliance requirements.

"We try to avoid 'babysitter' apps," Byrnes said. "We really don't want to give kids things that aren't directly related to education."

To verify that an app won't compromise student personal data, Byrnes next reviews its terms of service and confirms the site owner doesn't have a reputation as a "bad actor." Then, developers must agree to the district's student privacy compliance pledge, which includes state and federal protocols.


"The real question is that data sharing should be driven by 'need to know,' and what benefit does sharing each data element have for teachers and students?"

c26dbb7f8ae5524841267a35b6468bcbecf9efd7dcf6efba56bf278ef43ecb45.png

Doug Casey

Board Chair of the State Educational Technology Directors Association, Executive Director of the Connecticut Commission for Educational Technology


Byrnes says a district-level online system operated by edtech company LearnPlatform allows teachers and administrators to request new apps, improving process efficiency and helping reinforce the need to protect student data among educators. The district publicly lists the companies operating district apps and each app's student privacy compliance status.

A review by the U.S. Department of Education's Student Privacy Policy Office of 1,504 district websites from September 2018 to April 2020 showed that only 4% of districts posted data inventories on their websites listing the student information collected. 12% of district websites had navigation menus containing sections indicating where data practices and student privacy information were located.

In Fairfield, the app approval process can take months because district staff must verify that student information is collected only for the district's educational purposes and that personally identifiable information is not collected for marketing or other non-educational purposes.

When the pandemic hit in March 2020, the Connecticut State Department of Education implemented a temporary compliance pledge program, allowing districts to use state-reviewed apps without executing their own protocols.

Byrnes says district-level oversight is still necessary, but it helped streamline the process during those busy months when learning shifted online.

Even when following all best practices, protecting student data is not foolproof. For example, when a district stops using an app, the tool owner should delete all student data according to the compliance pledge. But Byrnes says it's difficult to prove this actually happened.

According to Byrnes, in rare cases, edtech companies go out of business, making it nearly impossible to ensure student private data is permanently deleted.

"No one knows where that data is," she said.

Navigating Federal and State Rules

Several federal laws require schools to protect student privacy and aim to prevent inappropriate online behavior. Each law is administered by a different federal agency:

  • Family Educational Rights and Privacy Act (FERPA, 1974): This law gives parents certain privacy rights regarding their children's education records. When students turn 18, these rights transfer to the students themselves. It was last amended in 2012. The U.S. Department of Education oversees this act.
  • The Department of Education also oversees regulations for the Protection of Pupil Rights Amendment (PPRA, 1984), which grants parents and students rights regarding survey participation, such as notification and opt-out options.
  • Children's Online Privacy Protection Act (COPPA, 2000): The Federal Trade Commission has jurisdiction over this act, which restricts website and online service operators from collecting personal data from children under 13 without parental consent.
  • Children's Internet Protection Act (CIPA, 2000): This law requires K-12 schools and libraries using E-rate discounts to limit children's exposure to obscene content. It also requires schools to monitor minors' online activities and educate students about appropriate online behavior. The Federal Communications Commission oversees this law, with implementation rules updated in 2011.

Some student data privacy experts say some laws are outdated or misunderstood. A bipartisan bill in Congress would update COPPA to prohibit internet companies from collecting personal information from individuals aged 13 to 15 without parental consent. The legislation, which has not yet been acted on, would also create an "eraser button" requiring companies to enable parents and children to delete children's or teens' personal information when "technically feasible."

In September, several organizations, including the American Civil Liberties Union, the Center for Democracy & Technology, and the State Educational Technology Directors Association, urged Congress to update CIPA to clarify that the law does not require schools to conduct "broad, invasive, and continuous monitoring of students' online lives."

Elizabeth Laird, Director of Equity in Civic Technology at the Center for Democracy & Technology, says the increase in students' online activity means districts' responsibility to monitor bullying, potential violence, and inappropriate content has grown, but schools need to carefully consider the negative consequences of collecting all this data.

These organizations are calling for clarification of CIPA because school systems should not monitor students' online activities merely for legal compliance, Laird says. "They should be able to explain why they're doing it, connecting it to larger goals, rather than this unintentional expansion and constant surveillance of students," she says.

Others argue that federal laws themselves are not the problem—rather, it's the mismatch of state laws and regulations that creates financial and operational burdens on local school systems and edtech providers.

According to Amelia Vance, Vice President of Youth and Education Privacy at the Future of Privacy Forum, more than 1,000 state student privacy bills have been introduced nationwide since 2014, with about 130 enacted.

Data privacy experts say some state student privacy laws, while well-intentioned, do not align with how schools actually operate.

"Protecting student privacy is crucial," Vance says, "but lawmakers often don't communicate with those on the front lines to understand best practices."

For example, in Louisiana, some families struggled to access free meals early in the pandemic because state rules prevented schools from sharing data about students eligible for free or reduced-price meals with agencies helping distribute food during school closures. Months later, the state legislature passed a bill giving schools temporary authority to share limited student information for this purpose.

Collaborative Efforts in Data Protection

Doug Casey, Board Chair of the State Educational Technology Directors Association, says one of the most promising proposals in COPPA legislation is the "eraser button," which would allow users to delete children's personal information from apps.

He says such a request to tech companies is currently easier said than done because if data elements are mixed with other data points, or if data structures are redeveloped without built-in deletion features, it's difficult to simply delete data elements.

"From an engineering perspective, it's not that easy to just say 'press the magic button and everything disappears,'" Casey says, who is also the Executive Director of the Connecticut Commission for Educational Technology.

Who's Responsible and Intent in Student Data Breaches

Between July 1, 2016, and May 5, 2020, school staff caused most accidental disclosures.

Fairfield Public Schools is working with Infinite Campus, its student information system management company, to find solutions for clearing student data no longer needed. "I don't want to expose information that no longer needs to be retained, because that just gives bad actors an opportunity to access information we shouldn't be keeping in the 'file cabinet' because you no longer need it," Byrnes says.

Vance says in some cases, outdated records retention laws exacerbate the difficulty districts face in managing sensitive data.

In New Jersey, districts must retain certain student records for 100 years. These records include former students' birth dates, parents' names, gender, health history and immunization records, standardized assessment results, grades, attendance, courses taken, and more.

Casey says a positive trend over the past five years is the closer collaboration between educators and edtech companies and developers. He says this relationship is important for both sides: edtech developers and engineers need to better understand districts' needs and responsibilities, while school systems need to understand edtech companies' constraints.

"I think we tend to think about federal legislation, state legislation, and school districts, but we don't think as much about the edtech providers we rely on, so they need to be brought into the conversation too," Casey says.

Sara Kloek, Senior Director of Education Policy at the Software & Information Industry Association (SIIA), a trade association representing the edtech industry, says because association members view school systems as customers, their business models depend on being responsive to school needs, including student data protection.

Collaboration among educators, privacy advocates, and edtech companies has led to the development of national best practices that help edtech companies use common terminology and practices, even as they must comply with different state regulations and respond to individual districts' priorities, Kloek says.

According to Vance, highlighting model approaches has been an effective way for school systems to learn best practices. She points to Utah and Maryland as taking thoughtful approaches to understanding their student data privacy challenges and finding solutions. Utah has also created multiple state-level positions dedicated to student privacy issues, including training for district-level staff.

Casey and others say thoughtful data governance in school systems is an effective way to protect student information, and ongoing training for teachers on protecting student data is equally important. In the past, school systems' IT departments were the gatekeepers of all these student data elements. But now, teachers can access student information systems and extract data fields to share with edtech providers.

"The real question is that data sharing should be driven by 'need to know,' and what benefit does sharing each data element have for teachers and students?" Casey says. "Because if there's no direct benefit, it shouldn't be shared."

Editor's note: This story has been updated to include Doug Casey's additional role as Executive Director of the Connecticut Commission for Educational Technology.