Edtech procurement for school leaders: a defensible process
Most school edtech isn't procured; it accretes — a teacher finds an app, a free trial spreads, and two years later the school runs forty tools nobody assessed, each holding student data under terms nobody read. The fix isn't bureaucracy; it's a lightweight process that scales with stakes, run the same way every time so decisions are defensible to parents, auditors, and yourself in two years.
Step 0: the need test
Before evaluating any product, name the pedagogical need in one sentence — and check nothing already-approved covers it. Tool sprawl is itself a privacy cost (every product is an attack surface and a data relationship), so the cheapest risk reduction in edtech is fewer tools, used deeply.
Step 1: the desk review (an hour, most products fail here)
- Run the eleven policy questions — the data inventory, sharing, retention, breach terms.
- Australia: check for an ST4S assessment first. The Safer Technologies for Schools program (Education Services Australia, used across state and Catholic sectors) exists precisely so every school doesn't repeat the same due diligence; many state education departments also maintain approved-tools lists that settle the question for you — check yours before doing solo work your system already did.
- Check the tracker reality with devtools — five minutes, catches what the paperwork omits.
- Apply the why-do-you-have-it test (data minimisation): every collected field needs a purpose you'd repeat to a parent.
Step 2: the vendor conversation
The direct questions — inventory, password-reset flow, third parties, hosting country (APP 8, or IPP 9 for Victorian government schools), deletion in practice, breach history, business model, AI training. Written answers, kept with the file.
Step 3: the bounded pilot
One class, one term, defined success criteria set before it starts (what would make this worth adopting? what usage or outcome?), and minimum viable data — pilot accounts need not be real rosters if the product supports it. The pilot's job is to kill weak products cheaply, so let it: most honest pilots end in "no," and a process where every pilot converts is a rubber stamp with extra steps.
Step 4: the terms that go in writing
For anything holding student data: breach notification to the school within a defined short window; deletion on exit with backup-window honesty; no repurposing — data used to provide the service, not to improve products, build profiles, or train models, and no sale or transfer in bankruptcy; subprocessor disclosure with notice of changes; data location fixed or notified. Vendors serving schools at scale have these clauses ready; a vendor surprised by them is telling you their other school customers didn't ask.
Step 5: the register and the re-check
A one-page register — product, need, data held, assessment date, owner — reviewed annually: products still in use get a fresh look at changed terms (policies drift); products nobody used get retired and their data actually deleted. End-of-year offboarding (leavers' records, expired tools) belongs on the same calendar as report cards — student data rights are easiest to honor by routine.
What this doesn't cover
- It doesn't replace your system's rules — state and diocesan processes bind; this page fills the gaps they leave to schools.
- It doesn't make "free" special — free products get the same process, with question 7 (the business model) asked harder.
- It doesn't guarantee outcomes — process reduces risk; breaches happen to well-run vendors too, which is why the contract terms and the minimisation test matter more than any vendor's assurances, ours included.
References
- Education Services Australia — Safer Technologies for Schools (ST4S): the shared assessment framework and its sector adoption.
- Office of the Australian Information Commissioner — APP guidelines (esp. APPs 3, 8, 11) as they bear on school decisions.
- US Department of Education, PTAC — Protecting Student Privacy While Using Online Educational Services — the US procurement-guidance tradition this page parallels.
- Human Rights Watch (2022). "How Dare They Peep into My Private Life?" — the audit that documents what unprocessed accretion buys.
© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.