🧙 Wiz Kids
LearnEdTech Privacy & Procurement

Student data rights: what families can actually demand

Evidence grade: legal reference, plain-language. This page summarises rights as they generally stand; jurisdictions differ in detail, school sectors differ in which laws bind them, and none of this is legal advice. Its job is smaller and useful: most families never exercise these rights because nobody told them the rights exist.

Data about a child accumulates across a school career — school systems, dozens of edtech products, each holding records the family has typically never seen. Every jurisdiction this pillar covers grants rights over that data: to see it, to correct it, and — with more caveats — to delete it. The rights are real, mostly free, and mostly unused; this page is the missing user manual.

The rights, by regime

Australia: APP 12 grants access — an entity holding personal information must, on request, give the individual access (with limited exceptions); APP 13 grants correction of inaccurate, out-of-date, incomplete or misleading information. For children, parents generally exercise these rights on their behalf, with the child's own say growing with maturity. Government schools run on the state track instead: state privacy principles plus FOI regimes for the records themselves (Victoria's IPP 6 and OVIC, for our first-market readers), with complaints to state privacy bodies rather than the OAIC — the fuller Australian picture.

GDPR (EU/UK): the strongest set — Article 15 access (a copy of the data, plus what it's used for and who receives it), Article 16 rectification, Article 17 erasure ("right to be forgotten," strongest where the child's own consent was the legal basis), Article 20 portability. The UK Children's Code adds design duties on top.

United States: FERPA gives parents the right to inspect and review education records, request amendment of inaccurate ones, and consent to most disclosures (rights transferring to the student at 18) — the FERPA page unpacks it; COPPA adds parental review/deletion rights against operators for under-13 data, and state laws (California's SOPIPA line among them) layer deletion duties on edtech directly.

The gaps the rights don't cover

Honesty about the limits: access is stronger than deletion everywhere — school records needed for legitimate educational purposes generally can't be erased on demand; deletion rights bite hardest against vendors holding data past its purpose (minimisation is retention's law too). The vendor maze is the real obstacle: rights run against each data holder, and after years of accretion, nobody — school included — has the list (the register is the fix). And "deleted" needs interrogating — backups, logs and derived data give deletion its asterisks (deletion in practice).

How to actually exercise them

  1. Start with the school, in writing, specific: "under APP 12 I request access to the personal information held about [child] in [system]" outperforms a vague records request; schools route written, statute-citing requests properly.
  2. For edtech data, ask the school first anyway — the school is usually the data's controller-equivalent and can demand it from vendors under their contract; going vendor-direct is the fallback.
  3. Correction requests should carry the correct version — the right is to accuracy, and arriving with evidence makes granting easy.
  4. Escalation paths exist and are free: the OAIC (Australia), the ICO (UK), FERPA complaints to the US Department of Education — and naming the path politely in a stalled request tends to unstall it.
  5. The best time is exit: end of schooling or leaving a school is the natural moment to ask what's held and what will be deleted on departure — schools should make this routine rather than wait to be asked.

What this means for schools and vendors

For schools: every right your families hold is a request you'll one day process — the register, retention schedule, and offboarding routine convert statutory duties into calendar items. For vendors: rights-readiness is a design property — a minimised, pseudonymous architecture makes access requests trivial and deletion real, while a data-rich one makes every right a project. (Our own answer: the access request for a Wiz Kids student returns game state under an animal name — which is the point.)

References


© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.