Skip to main content
Intellect

New Utah law protects student privacy after BYU research found K-12 apps were collecting and sharing data

Report for Utah's board of education found leaks in student digital footprints

An AI illustration of a student holding a tablet that is displaying a educational game.
Utah public school students' data is safer thanks to BYU research on educational technology apps. This illustration was created using AI tools.
Photo by BYU Photo

Educational technology (EdTech) is big business — rapidly growing with AI despite data privacy risks. Utah K-12 schools currently support thousands of educational apps, including the widely known Canvas, Duolingo, Khan Academy, Quizlet, YouTube, coolmathgames.com and Loom.

Most parents, teachers and administrators are confident that students are using kid-friendly versions of these apps. Laws and safety practices are certainly in place. The proactive 1998 Children's Online Privacy Protection Act (COPPA) bans online companies from collecting children’s personal data. Utah reinforces this federal law with the Student Data Protection Act (2016), a dedicated digital analysis team, app-specific contracts, privacy pledges and more.

However, BYU research finds that EdTech vendors don’t always meet their student privacy obligations; that research has led to new Utah legislation that tightens up the privacy issues.

In an August 2025 investigation report prepared for the Utah State Board of Education (USBE), BYU information systems professors Mark Keith and Justin Giboney found major leaks in student digital footprints. Such privacy violations leave children vulnerable to unauthorized profiling, commercial exploitation, and safety concerns, including potential exposure to harmful online content.

“It’s a massive market — data brokers and resellers market — and the technology is increasing faster than people are aware of, as companies tie together data in ways that make it more useful without anybody knowing,” Keith said.

Commissioned by the USBE to investigate concerns about student data privacy, Keith and Giboney hired three BYU student researchers, and partnered with the non-profit Internet Safety Labs (ISL) to analyze network traffic generated by the 100 most commonly used apps in Utah schools.

Using test student accounts, the team simulated 15-20 minutes of use per app while conducting analyses. They found that many apps collected and even shared information beyond what their agreements permitted

  • 52% of EdTech companies with data privacy agreements were collecting student data.
  • 36% of EdTech companies with data privacy agreements were sharing data with advertisers, often using unique identifiers for digital profiling.

“Once a person is associated with a unique identifier, logging into a website is no longer necessary for profiling to continue,” Keith said. “The likelihood is high that nearly every website you visit afterward contributes to your overall profile.”

The researchers classified EdTech vendors into three categories based on their compliance status. Companies found in violation of privacy requirements had the opportunity to work with the USBE digital analysis team through a reconciliation process. After they successfully addressed the problems, the vendors' names were redacted from the list of companies identified as being out of compliance.

“There were three general groups of results,” Keith said. “First, those companies that were completely safe. Second, those who didn’t realize they were breaking the law. Third, those who knew what they were doing and ignored our requests.”

The researchers recommend that school entities use a “trust but verify” approach when approving educational apps — verifying network traffic results before deciding what to adopt and then following up with regular audits.

Utah lawmakers have been following the EdTech study. Effective July 1, 2026, H.B. 55 Privacy Compliance for Education Technology Vendors, establishes stricter privacy terms in the TechEd contracts, gives educational entities the right to perform audits, and requires contracts to be terminated if privacy violations are found and not remedied within 30 days.

“I give credit to the state of Utah for caring enough to find out if the COPPA-certified apps were living up to their data privacy promises,” Keith said.

While recognizing that the vision is up to each state, the BYU team hopes Utah’s new law will encourage other states to strengthen oversight of EdTech and create their own systems for protecting students’ privacy and well-being.

MEDIA COVERAGE

Related Articles

overrideBackgroundColorOrImage= overrideTextColor= promoTextAlignment= overrideCardHideSection=false overrideCardHideByline=true overrideCardHideDescription=false overridebuttonBgColor= overrideButtonText= promoTextAlignment=
overrideBackgroundColorOrImage= overrideTextColor= promoTextAlignment= overrideCardHideSection=false overrideCardHideByline=true overrideCardHideDescription=false overridebuttonBgColor= overrideButtonText= promoTextAlignment=
overrideBackgroundColorOrImage= overrideTextColor= promoTextAlignment= overrideCardHideSection=false overrideCardHideByline=true overrideCardHideDescription=false overridebuttonBgColor= overrideButtonText= promoTextAlignment=
overrideBackgroundColorOrImage= overrideTextColor= promoTextAlignment= overrideCardHideSection=false overrideCardHideByline=true overrideCardHideDescription=false overridebuttonBgColor= overrideButtonText=