ICO spotlight on Edtech: key data protection lessons from the ICO’s latest audit programme
This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.
The Information Commissioner’s Office (“ICO”) has published its Edtech examined report (24 June 2026), setting out the findings from audits carried out during 2024 and 2025 with 28 educational technology (Edtech) providers. The review covered a broad range of products used across UK primary and secondary schools, including management information systems, safeguarding tools, behaviour management platforms, learning management systems, classroom applications and data integration services.
In its foreword, the ICO report emphasises that, unlike many consumer technologies, children often have little choice over whether technology is used in schools. As a result, schools, families and pupils should be able to trust that Edtech products meet the highest standards of data protection.
It is worth noting that the audits were conducted before the Data (Use and Access) Act 2025 (“DUAA”) came into force, and the report expressly notes that it does not take account of changes introduced by DUAA, including the new "higher protection matters" under Article 25 UK GDPR.
The ICO noted examples of positive practice, particularly around information security, but also identified recurring compliance gaps relevant to Edtech suppliers and education organisations procuring or using these products and services.
What were the ICO’s main concerns?
The report identifies a number of recurring compliance shortfalls which we summarise below.
One of the key findings in the report is the extent to which providers misunderstood their role under data protection laws.
Although most providers considered themselves to be processors acting on the schools' instructions, the ICO found that almost 70% were acting as controllers for at least some processing activities. This was found, for example, where children's personal data was being used for product development, analytics, anonymisation or AI-related purposes. The finding is significant because it sat at the heart of many other compliance failings identified by the ICO. Where providers failed to recognise that they were acting as controllers, they had often also failed to identify a lawful basis, potentially an Article 9 condition, provide transparency information and/or assess risks to children appropriately.
The ICO expects providers and schools to assess each processing activity individually and clearly document whether the provider is acting as a processor, a controller or both.
A recurring theme throughout the report is the ICO's concern about secondary uses of children's personal data.
The ICO found that most of the audited providers were reusing children’s personal data for their own internal purposes, for instance, to monitor product performance, produce analytics information and to develop and test new features or other products.
In several cases, providers were also using children's personal data to train AI functionality or AI-powered adaptive learning components and producing anonymised data to share with third parties. In one example, a provider had previously created anonymised pupil profiles for sale to third-party education researchers.
Providers often could not demonstrate that this further processing was fair or based on an appropriate lawful basis, particularly where they had received the information in their capacity as processors.
Before using children's personal data for product improvement, analytics, AI development or any other secondary purpose, providers should assess whether the processing is compatible with the original purpose, identify an appropriate lawful basis and document that assessment. Particular caution should be exercised where special category data is involved.
Although almost all Edtech providers had written contracts with schools, the ICO found that around 70% had agreements that lacked sufficient detail or failed to include all of the requirements of Article 28 UK GDPR.
Common issues included vague descriptions of processing activities, unclear allocation of responsibilities and insufficient instructions from schools. The report reinforces that contracts are not simply a compliance documentation exercise. Insufficiently drafted or overly generic terms can contribute to confusion around controller/processor roles and responsibilities, limiting schools' ability to exercise meaningful control over how children's personal data is used in practice.
Contracts should clearly set out what personal data is processed, the purposes of processing, retention periods, security measures, sub-processor arrangements and the provider's obligations. Where the provider’s standard terms are used, schools should still be able to meaningfully control how children’s personal data is processed.
The ICO identified widespread shortcomings in data mapping and records of processing activities (ROPAs).
According to the report, almost every provider had incomplete data flow maps or insufficiently detailed ROPAs. Almost 90% were missing required information from their ROPAs or had failed to document all processing activities taking place.
The ICO found repeated gaps in ROPAs relating to international transfers, security measures, retention periods and secondary uses of children's personal data for the providers own purposes, including AI-related activities. Providers are expected to maintain comprehensive and regularly updated ROPAs and data flow maps, covering all uses of children's personal data.
Transparency was another area in which the ICO identified widespread shortcomings. The ICO found that around 80% of providers had privacy information that was not sufficiently detailed to explain how their products processed children's personal data. Many privacy notices contained generic descriptions that could apply to almost any technology service and failed to explain practices such as product development activities, anonymisation or AI training.
The ICO also noted that more than 25% of providers had not reviewed or updated their privacy information regularly.
Privacy information should be clear, accessible, age-appropriate and regularly updated. Providers should consider developing dedicated resources for children and making technical processing information available to schools to support their transparency obligations and compliance with the Children’s Code.
The ICO found that almost 50% of providers had not properly considered data minimisation, collecting information that was unnecessary for the operation of their products or being unable to justify why certain information was required. In addition, around 70% either failed to specify retention periods clearly or retained children's personal data for longer periods than necessary without adequate justification.
The ICO also identified uncertainty around what happened to data at the end of the retention period. In some cases, providers stated that information would be deleted, but in practice retained anonymised datasets instead of deleting them. In one case, information described as "anonymised" remained identifiable because it could be re-linked to individuals.
Providers should be able to explain why particular categories of personal data are collected, why it is necessary and how long they are retained. This includes applying clear retention rules and deleting or anonymising information when it is no longer required.
Over 40% of providers had not carried out a data protection impact assessment (DPIA) at all, often because they had incorrectly concluded that they were acting solely as processors, while around 80% had DPIAs that lacked sufficient detail for their use of personal data. In addition, around 70% of providers lacked proper oversight and governance for their DPIAs, including missing DPO input, limited consultation with key stakeholders or no agreed process for completing DPIAs.
DPIAs should be completed early in the development process, assess risks to children specifically, include appropriate consultation and governance, and be reviewed whenever products or processing activities change.
The findings in relation to supply-chain governance are equally noteworthy. Around 30% of providers had not obtained appropriate authorisation for sub-processors or failed to notify schools of changes, while around half had not undertaken meaningful due diligence or ongoing compliance checks regarding their sub-processors. The ICO also identified instances where sub-processor terms allowed children's personal data to be retained for AI training purposes, highlighting the importance of scrutinising third-party contractual arrangements.
Providers should carry out appropriate due diligence, maintain clear records of sub-processors and ensure that schools have sufficient visibility and authorisation over onward processing arrangements.
While information security controls were generally strong, the ICO found that over 70% of providers had failed to document breaches properly or were following incorrect breach reporting procedures. A recurring issue was misunderstanding the requirement for processors to report all personal data breaches to controllers without undue delay (rather than only high-risk or significant breaches).
Providers should have detailed breach response procedures, maintain breach logs, train staff regularly and ensure a clear understanding of the different obligations that apply to controllers and processors.
The ICO finally emphasised the need for data protection by design. The ICO found that nearly 80% of providers could not demonstrate how children's privacy had been embedded into product development decisions. Examples included AI functionality launched without adequate safeguards, non-essential features switched on by default and products that made it difficult to exercise data subject rights.
Providers should implement a structured governance framework that embeds children's privacy, rights and best interests throughout the product lifecycle, from design and development through to deployment and ongoing monitoring.
Why does this matter?
While the report focuses on Edtech, the issues identified are familiar and relevant across almost every other sector. As organisations continue to explore new uses of personal data and integrate AI into products and services, questions around transparency, accountability, purpose limitation and privacy by design are becoming central regulatory concerns.
Across the 28 audits, the ICO issued 596 recommendations, 139 advisory notes and 118 good practice notes, with providers accepting 98% of the recommendations made. The ICO has since continued to engage with 12 providers where the data protection risks were considered highest, seeking evidence that agreed remediation measures have been implemented and that risks to children have been reduced.
The ICO has also confirmed that its work in this area is ongoing and that it is engaging with the Department for Education and devolved authorities on the handling of children's personal data in schools.
Importantly, the findings from the audit programme will help inform the ICO's forthcoming statutory code on the processing of children's personal data in digital systems used in educational settings.
Comment
Interestingly, while cybersecurity is often highlighted as a key compliance challenge across many sectors, the ICO found that information security was encouraging across the Edtech providers it reviewed and highlighted a number of examples of good practice in this area. Instead, many of the compliance gaps related to more fundamental aspects of compliance such as understanding controller and processor roles, maintaining up-to-date ROPAs, providing meaningful transparency, and embedding effective governance and accountability measures.
The report serves as a reminder of the importance of getting the basics right. For organisations developing data-driven and AI-enabled educational tools, being able to demonstrate transparency, accountability and effective governance may prove just as important as the functionality of the product itself.
With a new statutory code on the horizon and a continuing regulatory focus on children's privacy, now would be a timely opportunity for providers and educational institutions alike to assess their compliance against the issues identified in the report.
For queries or advice on the content of this article, please contact Hamish Corner, Lucy Pegler, Amanda Leiu or a member of Burges Salmon's Commercial & Technology team.
This article was written by Fraser Campbell and Amanda Leiu.
Want more Burges Salmon content? Add us as a preferred source on Google to your favourites list for content and news you can trust.
Update your preferred sourcesBe sure to follow us on LinkedIn and stay up to date with all the latest from Burges Salmon.
Follow us