An audit of 28 education technology providers found widespread uncertainty over how children’s information was being used, with some companies repurposing pupil data for product development, analytics and AI without fully recognising their legal responsibilities.
Education technology providers are being urged to strengthen their handling of children’s personal information after an ICO audit uncovered significant gaps in contracts, transparency, data retention and risk assessment.
The ICO carried out voluntary audits of 28 providers during 2024 and 2025, examining products widely used across primary and secondary schools. These included management information systems, safeguarding and behaviour platforms, learning management systems, classroom applications and services that transfer pupil information between different products.
The regulator made 596 recommendations across the audits, 98% of which providers accepted and put actions in place to address. It also issued 139 advisory notes and identified 118 examples of good practice.
Although the ICO said it found encouraging practices, particularly around information security, it warned that many providers did not have a complete understanding of how children’s data moved through their products or where responsibility for that information rested.
“Behind every school login screen, every homework app, and every register, a system is collecting children’s personal information,” Katie Searle, the ICO’s Director of Children’s Strategy, said in the report’s foreword.
“This ecosystem of edtech that supports teaching and admin in UK schools is vast and deeply embedded in everyday learning.”
The ICO said the classroom requires particular attention because children generally do not choose which technology their school uses and may have no practical way to opt out.
The products examined are used to process a broad range of information, from names, dates of birth and contact details to more sensitive details involving ethnicity, health, safeguarding incidents, pupil premium status and special educational needs and disabilities.
According to estimates supplied by the providers, the organisations audited collectively supplied learning management and behaviour systems used by over 70% of UK schools. Providers of safeguarding and data integration systems covered over 90% of schools, while the management information system providers examined were used by over 85%.
Unclear responsibility for children’s data
One of the most significant problems involved confusion over whether edtech companies were acting as processors or controllers of children’s information.
In simple terms, a processor handles information under the instructions of a school, while a controller makes decisions about why and how that information will be used. A company can occupy both roles when it uses the same information for different purposes.
Most providers considered themselves processors because they supplied services on behalf of schools. However, almost 70% were found to be controllers for at least some uses of children’s information without recognising that responsibility or meeting the additional legal requirements it created.
This commonly happened when companies used pupil information beyond their core contracted service, including to monitor product performance, develop and test new features, produce analytics or create supposedly anonymised datasets.
Some providers also used children’s information to train or test AI functions. In one case, a provider had previously created anonymised pupil profiles that were sold to third parties conducting education research.
The ICO found that providers often could not demonstrate that these additional uses were fair or lawful. Around 70% could not show that schools or children had instructed or authorised them to use the information in this way.
These activities were also frequently absent from contracts, privacy information and internal records, meaning schools, parents and pupils were unlikely to know that the processing was taking place.
The regulator said providers making their own decisions about these activities became controllers in practice, regardless of how they were described in contracts. This meant they were responsible for establishing a lawful basis, maintaining appropriate records, assessing privacy risks and explaining the processing to children and parents.
Contracts between schools and providers were also frequently too broad or vague to give clear instructions about how pupil information should be handled. This sometimes left providers to make their own decisions and made it difficult for schools to understand or control what happened to their pupils’ data.
Incomplete records and excessive collection
Almost 90% of providers were missing required information from their records of processing activities, or did not have complete records covering everything their products did with children’s information.
Common omissions included international data transfers, security measures, retention periods and additional uses such as product development, AI training and the creation of anonymised pupil profiles.
The ICO said incomplete records could leave both providers and schools without a full understanding of where information was going, which organisations could access it or what safeguards were in place.
Almost 50% of providers were also found not to have fully considered data minimisation. They either collected information that was not necessary for the product to function or could not explain why particular data was needed.
This was particularly common among classroom learning applications, some of which collected information including gender, ethnicity, health conditions, languages, special educational needs and eligibility for free school meals or pupil premium support.
While some providers allowed schools to decide whether these fields should be shared, others made them mandatory and collected the information automatically.
The ICO recommended that providers collect only the minimum information required for each feature. Its suggested approaches included using a child’s initials, a username or pseudonym instead of a full name, and using a school year or month and year of birth instead of a complete date of birth.
It also advised companies to make non-essential uses of personal and sensitive information optional and switched off by default.
Data retained without clear justification
Retention of children’s information was another major area of concern.
In around 70% of cases, providers either failed to specify clearly how long they would keep children’s information or retained it for periods they could not justify. A small number kept information indefinitely, either in case it became useful in the future or because planned deletion processes had not taken place.
Most providers applied fixed retention periods across all schools, leaving schools unable to choose how long their pupils’ information should remain within the product.
Recommended reading
- ICO Publishes Draft Guidance on Biometric Data Use in the UK
- UK Gov Asks for Insight Into Data Brokers Security
- UK Gov Introduces New Data Use and Access Bill
- Police Could Use Driving License Data for Facial Recognition in New Bill
There was also uncertainty about what happened when those periods ended. Some providers said information would be deleted but instead anonymised it and retained it for their own purposes.
In one isolated case, information described as anonymised could still be linked to an identifiable person and was being kept indefinitely.
The ICO warned that retaining children’s data longer than necessary increased the likelihood of a breach or misuse and could violate the storage limitation principle under UK data protection law.
Positive practices and next steps
Despite the compliance gaps, the audits also identified examples of providers building privacy safeguards into their products.
Some systems allowed schools to control which information was collected, how long it was retained and which functions were enabled. Several providers switched off non-essential processing by default and introduced strong access controls and authentication.
One provider prohibited the reuse of personal information internally and used synthetic data rather than real pupil records when testing and developing its products.
The ICO said providers should adopt this type of data protection by design approach throughout product development. It criticised examples where companies had launched new features switched on by default, created systems where information could not easily be retrieved or erased, or introduced AI functions without adequate safeguards.
The regulator stressed that its findings represented a snapshot at the time of each audit and that it had received no evidence of actual harm to children.
The work began before the Data (Use and Access) Act 2025, meaning the report does not address changes introduced by the legislation. GenAI assistants, school network infrastructure, video-conferencing platforms, device-monitoring software and physical surveillance technologies were also outside the scope of the audits.





