EdTech Apps in Utah Schools Share Student Data with Advertisers, Violating Privacy Agreements
What Happened — A two‑year study of 100 educational‑technology apps used by Utah school districts found that 61 % of the apps transmitted student data to third parties and 36 % sent data directly to advertisers, despite contractual privacy agreements that prohibited such collection. Network‑traffic analysis revealed that more than half of the apps with a data‑privacy agreement collected at least one prohibited data element.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates a classic gap between contractual privacy commitments and actual technical behavior—exactly the kind of control failure SOC 2 / privacy‑framework audits require evidence to detect and remediate.
- Continuous monitoring of data flows (e.g., using CookiePLUS consent and DSAR tooling) provides the audit‑ready evidence needed to demonstrate compliance with state education‑privacy statutes and broader regulations such as GDPR/CCPA.
Who Is Affected — K‑12 school districts, EdTech vendors, and any education‑technology ecosystem that processes student‑level data.
Recommended Actions
- Inventory every EdTech app in use and map its data‑collection practices against signed privacy agreements.
- Deploy automated consent‑management and data‑flow monitoring (e.g., CookiePLUS) to capture real‑time evidence of third‑party transmissions for audit purposes.
- Update contracts to include explicit clauses on prohibited data sharing and enforce remediation timelines per Utah H.B. 55.
Technical Notes — Researchers captured live network traffic from 2023‑2025, identifying embedded analytics SDKs and advertising libraries that exfiltrated identifiers, location data, and usage metrics. No specific CVEs were involved; the issue stems from third‑party components and misaligned vendor contracts. Source: Malwarebytes Labs