Skip to main content

Four suggestions for getting privacy right when developing edtech

Read Time 4 Mins
Principles
Data & Security

As digital interactions increase, so does the flow of learner data—and the risk of its misuse. But edtech can respect and protect learner privacy. Here’s how.

Edtech is, and perhaps always will be, in the privacy spotlight. 

In order to bring the benefits of technology to learning and assessment, we need to capture information about the learning process and people’s skills. The more data we capture, the better the analysis we can do and the better the learning or assessment will be. 

But with great amounts of data comes great responsibility. And so regulators, politicians, learners and their stakeholders are keen to ensure that privacy is respected.

Three of the most pressing concerns are that:

  1. Learners, parents and those with their interests at heart need to ensure personal learner data is used only for learning or assessment and not for marketing or commercial purposes.
  2. With the shocking commonality of data breaches, everyone wants to make sure that private data about learners is not hacked or disclosed.
  3. Governments and other stakeholders are often keen to ensure that information on their young people isn’t disclosed to foreign governments. 

Most edtech companies are highly reputable. However, AI has raised the stakes. Learning tools now generate content, score responses, and adapt to individual learners—which means more data flowing through more systems, and a new question on every buyer’s lips: is our learners’ data training someone else’s model? Regulators are asking the same thing, and legislation is moving fast on both sides of the Atlantic.

The regulatory picture

Start with the United States, where children’s privacy rules have grown real teeth. In 2025, the FTC finalized the first major update to the COPPA Rule in over a decade, tightening limits on how companies can monetize children’s data and requiring opt-in consent before sharing that data with third parties—including for training AI models. Edtech providers serving under-13s should treat the amended rule as their new baseline.

The states haven’t waited for Washington. A steadily growing list of US states has passed comprehensive privacy laws, and several target learners directly. California—often a leader in privacy among US states—passed the Student Test Taker Privacy Protection Act (SB 1172) in 2022, which limits proctoring providers to collecting only the personal information strictly necessary to deliver the exam, and gives test takers a private right of action if they don’t. California’s Age-Appropriate Design Code took a bumpier road—courts have tied much of the law up in litigation—but the design-for-privacy principles behind that law keep resurfacing in other states’ bills. The direction of travel is clear even where individual laws stall.

Meanwhile in Europe, regulators are stepping up enforcement of the GDPR privacy law, with thousands of enforcement actions recorded and cumulative fines running into the billions of euros—and the pace accelerating rather than plateauing. Some of these are in the education space—including for inappropriate remote proctoring and various data breaches. Cross-border data transfers remain the highest-value enforcement trigger. The EU–US Data Privacy Framework, adopted in 2023, gave transfers to certified US companies a firmer legal footing—but transfers that fall outside the framework, or rely on outdated contractual clauses without supplementary measures, continue to attract severe penalties.

A second layer of European regulation adds to this: the EU AI Act, whose obligations for high-risk systems phase in from 2026. AI used in education and assessment sits squarely in the high-risk category, bringing requirements for transparency, human oversight, and data governance on top of existing GDPR duties.

Many other countries are also making new legislation to protect personal data. This is going to increase, not decrease.

What can you do about it?

Privacy is not something you do once and don’t have to worry about again; it needs to be a permanent part of your modus operandi. Here are four suggestions for edtech companies to consider. 

1. Build privacy into your design and design process

It’s a cliché but it really is true that it’s much more expensive to retrofit privacy later than add it in to start. As part of this, consider pseudonymization. This is when you separate out the name and other identifying information for learners from the data about them and is described more below.

2. Adopt an approach of full transparency with learners and their stakeholders

Document what data you gather, the purposes you collect it for, what you do with it and how long you keep it. Often this is required by law, but if you go beyond the minimum required, do it proactively and communicate it well, it will help build trust with your learners and stakeholders.

3. Your privacy is only as good as that of your suppliers and partners

Many privacy and security failures are down to third parties so make sure that you review the privacy practices of your vendors and put in place good data protection contracts. At Learnosity, we strive to be leaders in assessment privacy and work only with trusted suppliers.

4. Get someone on your team who knows or learns about privacy

Privacy is principle-based, and understanding these principles will stand you in good stead in the myriad of product and communication decisions made day to day. The IAPP (International Association of Privacy Professionals) is a good place to learn and get certified. Two of my Learnosity colleagues and I have IAPP certifications and it helps us greatly.

Pseudonymity: Reducing risk by reducing identifiability

At the 2022 ATP Innovations in Testing conference, I led a session with Marc Weinstein of Caveon on “Pseudonymity, an Answer to Assessment Privacy Concerns?”.

Pseudonymity is a way of storing electronic data where names or other information that identify a person are stored separately from the data about them. When using pseudonymity, learner data is associated with a numeric ID representing the learner rather than with the person’s name. There is a separate index that allows matching the numeric ID to the name, stored separately.

For example, Learnosity customers know who their learners are, but they pass to Learnosity APIs a pseudonymized ID only. In the diagram below, the learner is called Jane Doe, but an ID is generated “1234567”. Learnosity knows only this and not the learner’s name, address, or date of birth. Learnosity’s APIs deliver the assessment and pass the result back to the client, but are never privy to who the learner is.

Pseudonymous data is still personal data, but pseudonymity reduces the number of people or systems with access to real identities and so greatly reduces compliance and security risks.

However the regulatory landscape shifts, that logic holds—the less identifiable the data you hold, the smaller your exposure under every law described above, old and new.

John Kleeman

EVP at Learnosity

More articles from John