🧙 Wiz Kids
LearnEdTech Privacy & Procurement

Edtech procurement for school leaders: a defensible process

Position note: a vendor is telling you how to buy from vendors — calibrate accordingly. The process below is deliberately vendor-hostile in the right places; we publish it because a sector that buys well is the sector we'd rather sell into. Australia-first, as with the rest of this pillar's local pages.

Most school edtech isn't procured; it accretes — a teacher finds an app, a free trial spreads, and two years later the school runs forty tools nobody assessed, each holding student data under terms nobody read. The fix isn't bureaucracy; it's a lightweight process that scales with stakes, run the same way every time so decisions are defensible to parents, auditors, and yourself in two years.

Step 0: the need test

Before evaluating any product, name the pedagogical need in one sentence — and check nothing already-approved covers it. Tool sprawl is itself a privacy cost (every product is an attack surface and a data relationship), so the cheapest risk reduction in edtech is fewer tools, used deeply.

Step 1: the desk review (an hour, most products fail here)

Step 2: the vendor conversation

The direct questions — inventory, password-reset flow, third parties, hosting country (APP 8, or IPP 9 for Victorian government schools), deletion in practice, breach history, business model, AI training. Written answers, kept with the file.

Step 3: the bounded pilot

One class, one term, defined success criteria set before it starts (what would make this worth adopting? what usage or outcome?), and minimum viable data — pilot accounts need not be real rosters if the product supports it. The pilot's job is to kill weak products cheaply, so let it: most honest pilots end in "no," and a process where every pilot converts is a rubber stamp with extra steps.

Step 4: the terms that go in writing

For anything holding student data: breach notification to the school within a defined short window; deletion on exit with backup-window honesty; no repurposing — data used to provide the service, not to improve products, build profiles, or train models, and no sale or transfer in bankruptcy; subprocessor disclosure with notice of changes; data location fixed or notified. Vendors serving schools at scale have these clauses ready; a vendor surprised by them is telling you their other school customers didn't ask.

Step 5: the register and the re-check

A one-page register — product, need, data held, assessment date, owner — reviewed annually: products still in use get a fresh look at changed terms (policies drift); products nobody used get retired and their data actually deleted. End-of-year offboarding (leavers' records, expired tools) belongs on the same calendar as report cards — student data rights are easiest to honor by routine.

What this doesn't cover

References


© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.