EdTech privacy & procurement: the pillar guide
This pillar exists because the person deciding which apps enter a classroom is usually a teacher with twenty minutes, facing a privacy policy written by people with billable hours. It's also the pillar where our interest is simplest to state: we built a product around collecting nothing, and we'd like that to become the standard buyers demand β so every argument here doubles as advocacy, which is declared now, once, and visible in everything below. The arguments still have to survive on their evidence; run them against any vendor, us first.
The one idea underneath everything
If this pillar compressed to a sentence: what's collected matters more than what's promised. Every safeguard β encryption, contracts, policies, certifications β protects data that exists; data that never existed needs none of them, and can't be breached, subpoenaed, sold in a bankruptcy, or quietly repurposed for model training. That's why our evaluation method starts at the inventory, why zero-PII architecture is the pillar's north star, and why the hashed-emails myth matters β it's the trick that makes a full inventory look empty.
The toolkit (start here)
- How to read an edtech privacy policy β the eleven questions, the phrases that sound protective but aren't, and the breach-cost paragraph that is any vendor's real posture. The pillar's most-shared page.
- Zero-PII architecture β how identity without personal data actually works (class codes, generated pseudonyms, offline rosters), the honest costs, and the structural test questions.
- The hashed-emails myth β five minutes that permanently upgrade your reading of "we only store hashedβ¦" claims.
The legal landscape, by jurisdiction
Same shape everywhere β minimization mandates converging on children's services β with local machinery worth knowing:
- Australia β the Privacy Act and APPs, state regimes for government schools, ST4S vendor assessments, the eSafety Commissioner, and the incoming Children's Online Privacy Code. (Our home market's page, and the most operationally detailed.)
- COPPA (US) β the school-consent doctrine and its two hard limits; Β§312.7's minimization mandate as the sleeper clause.
- GDPR-K (EU) β lawful-basis plumbing (why the DPA beats the privacy policy for school use), data-protection-by-design, the age patchwork.
- The UK Children's Code β the design code the world is copying: high-privacy defaults, minimization, no nudges. Evaluating against it today previews everyone's regulatory direction.
Coming next
FERPA basics; the vendor-questions checklist as a printable; edtech breach case studies (what actually leaked, what it cost children); data minimization as a design discipline; the procurement guide for principals; student data rights in practice.
How to use this pillar
Twenty minutes before any tool decision: run the eleven questions, add your jurisdiction's three, and write the two-line summary (data inventory + breach cost) that makes the leadership conversation short. The pattern you'll notice after a few rounds is the pillar's whole thesis: the products with good answers tend to have them because of what they didn't build β and the questions get easier the less there is to ask about.
Β© Glu IO Pty. Ltd. β Wiz Kids (wiz.kids). Link freely; republication requires permission β see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.