🔒 EdTech Privacy & Procurement
COPPA, GDPR-K, reading privacy policies, and what zero-personal-data architecture makes impossible.
- Student privacy in Australian schools: the Privacy Act, ST4S, and the incoming Children's Code
The Australian legal landscape for school edtech — the Privacy Act and APPs, state school privacy regimes, the ST4S vendor assessment, the eSafety Commissioner, and the Children's Online Privacy Code now in development. - COPPA for schools: what it actually requires, in plain language
The US children's privacy law explained for educators — who it covers, what verifiable parental consent means, the school-consent exception and its limits, and the questions to ask vendors. - Data minimisation: the principle that does the most work
Collect only what the purpose requires — the legal duty (APP 3, GDPR, COPPA), why minimisation beats protection as a strategy, the why-do-you-have-it test, and what minimised edtech actually looks like. - Deletion in practice: what 'we deleted it' actually means
Backups, logs, derived data, and the anonymisation dodge — the honest anatomy of data deletion, the questions that expose the asterisks, and how schools make deletion routine instead of forensic. - Edtech breach case studies: what actually happened, and what each one teaches
Five real incidents — VTech, Edmodo, Blackbaud, Illuminate Education, PowerSchool — the facts as reported, and the design lesson each breach proves: collection sets the harm ceiling, and promises don't survive contact. - FERPA basics: the US school-records law, briefly
The 1974 law that governs US education records — inspection and amendment rights, the school-officials exception that admits edtech, directory information, and where FERPA famously falls short. - GDPR and children (GDPR-K): what European rules mean for school edtech
How the GDPR treats children's data — the lawful bases that actually work for schools, the age-of-consent patchwork, data-protection-by-design, and what it all means for tool selection anywhere. - The hashed-emails myth: why hashing an identifier doesn't anonymize it
'We only store hashed emails' sounds like not collecting emails. It isn't — a five-minute explainer of why deterministic hashes of identifiers are pseudonyms, membership-testable and linkable, not anonymous. - EdTech privacy & procurement: the pillar guide
The pillar map: reading policies, the legal landscape by jurisdiction, the architecture that makes trust less necessary — and why the best answer to every privacy question is an empty inventory. - Edtech procurement for school leaders: a defensible process
From 'a teacher found an app' to a decision you can defend — the need test, the shortlist, the privacy and security review (ST4S for Australian schools), the pilot, the contract terms, and the annual re-check. - Pseudonymous identity: the middle ground, mapped precisely
Pseudonymous is not anonymous — the legal and technical distinction, when pseudonymity genuinely protects children and when it's a fig leaf, and the design rules that keep a pseudonym from quietly becoming a name. - How to read an edtech privacy policy: a teacher's checklist
The eleven questions that expose what an edtech privacy policy is actually saying — the phrases that sound protective but aren't, the questions vendors hope you won't ask, and a printable checklist. - Student data rights: what families can actually demand
The access, correction and deletion rights that exist across jurisdictions — APPs 12–13 in Australia, GDPR's articles 15–17, FERPA's inspection rights — who holds them for a child, and how to exercise them without a lawyer. - Third-party trackers in edtech: what the audits found
The large-scale audits that opened school products and counted — Human Rights Watch's 2022 review, Internet Safety Labs' school-app study — what an SDK actually leaks, and the five-minute devtools check any teacher can run. - The UK Children's Code: the design code the world is copying
The ICO's Age Appropriate Design Code in plain language — its fifteen standards, why 'likely to be accessed by children' changed everything, and why it matters far beyond the UK (including for Australia's incoming code). - The vendor questions: what to ask an edtech company directly
The policy tells you what lawyers approved; the vendor conversation tells you what's true. The questions that expose real practice — asked live, with the verification steps that don't require trust. - Victorian schools and student privacy: the IPPs, OVIC, and the software gate
Victorian government schools don't sit under the federal Privacy Act — they answer to the PDP Act 2014, its Information Privacy Principles, and OVIC. What that changes for edtech decisions, the department's software assessment gate, and the IPP 9 offshore question, worked honestly. - Zero-PII architecture: how identity without personal data works
The design pattern behind accounts with no names, emails or birthdays — class codes, generated pseudonyms, picture-secrets, offline rosters — and why 'we can't leak it' beats 'we protect it'.
© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.