Remember when "school records" meant a manila folder in a filing cabinet? Yeah, those days are long gone. Now your kid's education generates a digital trail longer than their Spotify playlist: which apps they use, how long they spend on math problems, their reading level, behavior tracking, lunch account purchases, library checkouts, even their facial expressions during online learning.
And here's the thing—most of this happens without parents having any clue what's being collected, who can see it, or where it's going.
Student privacy is supposed to be protected by FERPA (the Family Educational Rights and Privacy Act), a law from 1974 that's trying its absolute best to regulate technology from 2025. It's like using a rotary phone to explain TikTok. Schools are collecting more data than ever, using dozens of EdTech apps and platforms, and the rules around what they can do with that information are... murky at best.
Let's be real: schools aren't trying to be sketchy. They're overwhelmed, underfunded, and just trying to keep up with the demands of modern education. But that doesn't mean your kid's data is automatically safe.
Here's what's actually happening:
The average school uses 1,400+ EdTech tools across their district. Yes, you read that right. Not all of them go through rigorous privacy reviews. Some teacher downloaded a "fun quiz app" that's now harvesting student emails.
Data brokers love education data. It's detailed, it's longitudinal (follows kids over years), and it's valuable for targeted advertising. Some EdTech companies have been caught selling or sharing student data with third parties.
AI is everywhere now. Schools are using AI for grading, behavior prediction, college admissions prep—and that means algorithms are making decisions about your kid based on data that might be incomplete or biased.
Once it's out there, it's really out there. Unlike a bad haircut, digital data doesn't just grow out. A behavior flag from third grade could theoretically follow your kid for years.
Don't just nod along at back-to-school night. Here are the specific questions that will make your school's data privacy coordinator sweat (in a good way):
About Data Collection
"What student data are you collecting, and which third-party apps or platforms have access to it?"
Push for a complete list. Not just the big platforms like Google Classroom or Canvas, but every single app teachers are using. Reading trackers, behavior management tools, educational games—all of it.
"How is my child's data being used to train AI models?"
This is the new frontier. Some EdTech companies use student work to improve their AI. Your kid's essays might be training the next ChatGPT competitor, and you should know about it.
"What happens to my child's data when they leave your school or graduate?"
Is it deleted? Archived? Transferred to the next school? Sold to a data broker? (Hopefully not that last one, but you'd be surprised.)
About Access and Security
"Who has access to my child's educational records, and what training do they receive about privacy?"
It's not just teachers. IT staff, administrators, counselors, sometimes even cafeteria workers (for lunch accounts) have access to various systems. Are they trained on FERPA? Do they understand what they can and can't share?
"What security measures protect student data from breaches?"
Schools get hacked. It happens. What's their incident response plan? How quickly will they notify you if there's a breach?
"Can I see what data you have on my child?"
Under FERPA, you have the right to review your child's educational records. But schools interpret "educational records" differently. Push for transparency about all the data they're collecting, including behavioral data and app usage.
About EdTech Vendors
"How do you vet EdTech vendors before allowing them in classrooms?"
Do they have a formal review process? Do they check privacy policies? Or does Karen from third grade just download whatever looks fun on the App Store?
"Are vendors complying with COPPA, FERPA, and state privacy laws?"
COPPA (Children's Online Privacy Protection Act)
requires parental consent for collecting data from kids under 13. Many EdTech companies skirt this by claiming "school consent" is enough. It's legally fuzzy and you should know where your school stands.
"Do any vendors use student data for advertising or sell it to third parties?"
The answer should be a hard no. If there's any hemming and hawing, that's a red flag.
About Your Rights
"How can I opt my child out of specific data collection or EdTech tools?"
Some data collection is unavoidable (grades, attendance), but a lot isn't. Can your kid skip the AI essay grader? Can they use a different reading app that doesn't track every page turn?
"What's your process for handling parent privacy concerns or complaints?"
There should be a clear process. If they look confused by this question, that's... not great.
FERPA is supposed to protect student privacy, but it has some massive loopholes:
- Schools can share data with "school officials with legitimate educational interest"—which is interpreted very broadly
- "Directory information" (name, photo, activities) can be shared unless you specifically opt out
- Data shared with vendors for "school purposes" doesn't require your consent
- Once data is "de-identified" (supposedly stripped of personal info), it can be used for research without consent—even though re-identification is often possible
Your rights under FERPA:
- Review your child's educational records
- Request corrections to inaccurate information
- Control disclosure of directory information
- File a complaint with the Department of Education if rights are violated
But here's the catch: FERPA only applies to schools that receive federal funding, and it doesn't cover everything. State laws often provide stronger protections—know what your state requires.
- Teachers asking students to sign up for apps using personal email addresses (not school accounts)
- Apps requiring extensive permissions (camera, microphone, location) for basic educational functions
- No clear privacy policy or terms of service
- Vague language about "improving services" or "personalized learning" (often code for data mining)
- Free tools that seem too good to be true (if you're not paying, your data probably is)
Look, schools are doing their best in an impossible situation. Education technology can be genuinely helpful—it can personalize learning, identify kids who need support, and make teachers' lives easier.
But "trust us, it's fine" isn't good enough when it comes to your kid's data.
You don't need to be adversarial, but you do need to be informed. These questions aren't about being that parent—they're about being a parent who gives a damn about privacy in an era when it's disappearing faster than your kid's ability to remember their login passwords.
Start with your school's website. Many districts now have privacy policies and EdTech vendor lists online. If they don't, that's your first red flag.
Request a meeting with your school's data privacy officer (or whoever handles this—could be the IT director, principal, or superintendent). Bring your questions. Be friendly but persistent.
Connect with other parents. You're not alone in caring about this. Parent groups have successfully pushed for stronger privacy policies in many districts.
Check your state's laws. Some states (California, New York, Illinois) have stronger student privacy protections than federal law. Know what applies to you.
Review and opt out of directory information if you're not comfortable with your kid's name and photo being shared.
And remember: schools work for you. Your kid's education shouldn't come at the cost of their privacy.
Want to understand more about COPPA and how it affects your kids online?
Or wondering what data your kid's favorite educational apps are collecting?![]()


