Existing clients

Log in to your client extranet for free matter information, know-how and documents.

Client extranet portal

Staff

Mills & Reeve system for employees.

Staff Login
22 Jul 2026
4 minutes read

Edtech: data protection in focus

Last month the Information Commissioner’s Office published “Edtech examined”, a report outlining a range of data protection compliance findings concerning suppliers of edtech systems to primary and secondary schools. The report also has some potential for read across to HE and FE.

The report considers data protection compliance in the context of the “vast and deeply embedded” ecosystem of edtech systems that support teaching and administration in UK schools.  

The report is based on voluntary audits undertaken by the ICO with a representative sample of 28 providers widely used in schools. The systems audited focused on those used in school administration, learning and behaviour management. These systems collectively process a wide range of children’s data including information about academic performance, families, health, disability, behaviour and discipline. The audits included technical demonstrations, reviewing information such as privacy notices, contracts, data protection impact assessments, policies and training and also face-to face discussions or written communications. When considering compliance, the ICO is mindful that UK data protection law underlines the need for specific protections for children and their data in various respects, further considered in its guidance and the Age Appropriate Design Code of Practice. 

Key findings

At 73 pages the report is detailed, including case studies and links to relevant ICO advice. It identifies areas for improvement including:

1.    Not always identifying the controller for each processing activity

Typically, providers had been classified as processors, with consequences for how they had complied (or not complied) with other areas of data protection law.

The report includes “many providers also used children’s information for their own additional purposes – such as developing products or producing anonymised information – without recognising that they were controllers of this additional processing. When providers didn’t identify themselves as controllers of specific processing activities, they usually hadn’t met the responsibilities of controllers in UK data protection law. This resulted in gaps in safeguards to protect children’s privacy.”

2.    Using personal information for other purposes

Linked to the use of children’s data for other purposes such as those mentioned above, the ICO found providers were often unable to demonstrate the fairness of processing, and hadn’t always identified a lawful basis for such further processing.

3.    Contracts lacking detail

The ICO observed that many contracts didn’t describe clearly how children’s information would be used by providers. Further, “broad or vague terms or unclear instructions led providers to make their own decisions and determine the purposes and means of processing for themselves”.

4.    Mapping and recording processing activities

The ICO found that providers need to better map the various data flows and improve the detail of their records of processing activities.

5.    Explaining the use of children’s personal information transparently

The report found that more detailed privacy information was needed, in turn so that it could be made available to schools, families and children so that informed decisions could be made about the privacy risks.

6.    Retaining information for only as long as necessary 

The ICO found that many providers hadn’t specified retention periods, or explained how information would be deleted.

7.    Data protection impact assessments

DPIAs had not always been completed, or were lacking adequate detail.

8.    Overseeing sub-processors

The ICO asks edtech providers to exercise greater control and oversight of any sub-processors, including ensuring that appropriate due diligence and school authorisation are in place before granting access to children’s data.

9.    Handling personal data breaches

Data breach processes were often too broad, and needed to include better detail on how breaches would be identified and investigated, as well as how they would be reported to the ICO, schools and others affected.

10.    A data protection by design approach 

The report emphasises a need for a “by design” approach, such as turning off non-core functionality and processing by default.

What next?

The audits generated 596 recommendations to improve compliance or processes, 139 “advisory notes” and 118 “good practice notes”. The report notes that 98% of the recommendations were accepted by the edtech providers. The ICO says it continues to work with providers and is liaising with the UK government on secondary legislation to establish an edtech code of practice.

The ICO’s report is a good reminder of the importance of paying attention to data protection in the education sector. We have been helping technology providers meet the ICO’s expectations and can also help those procuring new edtech solutions with their data protection due diligence.  If you need advice in relation to the above, please contact your usual Mills & Reeve contact or the authors as appropriate.

Our content explained

Every piece of content we create is correct on the date it’s published but please don’t rely on it as legal advice. If you’d like to speak to us about your own legal requirements, please contact one of our expert lawyers.