evidoria

← Back to browse

Good practice Imported

Edtech Examined — the UK ICO's Audits of 28 School-Technology Providers and 596 Data-Protection Recommendations

United Kingdom · Wilmslow · See the United Kingdom profile

Evidence: Observational / pre–post Top 58% 47/100 · Ask Evidence Copilot about this practice

The UK's ICO audited 28 widely-used school-technology providers in 2024-2025, covering safeguarding, behaviour-management and classroom apps. Its June 2026 'Edtech examined' report found providers had implemented 98% of the 596 recommendations issued.

28
Edtech providers audited (2024-2025)
596
Data-protection recommendations issued (2024-2025)
98 %
Recommendations implemented by publication

Details

Maturity
Scaling
Promoter
Information Commissioner's Office (ICO)
Period
Audits conducted 2024-2025; report published Jun 2026
Keywords
EdTech regulation, children's data protection, regulator audits, safeguarding technology, data controller/processor compliance

Context

Between 2024 and 2025 the UK's Information Commissioner's Office (ICO) carried out consensual data-protection audits of 28 edtech providers whose products - management information systems, safeguarding tools, behaviour-management platforms, learning-management systems, classroom apps and data-integration services - are widely used across primary and secondary schools in England and beyond.

Objectives

The audits assessed providers' compliance with data-protection law, focusing on controller/processor roles, data-processing contracts, data-flow mapping, data minimisation and storage limitation, privacy notices, and data protection impact assessments, particularly around children's data.

Activities

ICO auditors reviewed the 28 providers and issued 596 recommendations in total, covering the compliance gaps identified. The ICO published its findings in the "Edtech examined" report in June 2026 and is now engaging with the Department for Education and devolved authorities to develop a statutory edtech code of practice under the Data (Use and Access) Act 2025.

Results

By publication, providers had accepted and implemented 98% of the 596 recommendations. Common problems identified included providers failing to correctly distinguish their role as data controller versus processor - particularly where children's data was reused for product development or analytics - insufficiently detailed data-processing contracts with schools, incomplete data-flow mapping, weak data-minimisation practice, outdated privacy notices, and gaps in data protection impact assessments.

Conclusions

The ICO itself flagged that this was a self-selected, consensual sample rather than a full-market audit. Child-rights groups such as 5Rights and the Digital Futures for Children Centre have argued that stronger, code-backed enforcement - not audits alone - is needed to stop commercially exploitative use of children's educational data, and the ICO's proposed statutory code aims to extend the improvements found in this cohort across the wider market.

Implementation

Indicative cost
Medium (€50k–€500k) — Regulator-funded audit programme covering 28 providers over roughly two years; specific budget not disclosed in source material.
Time to results
Medium (1–3 years) — Audits conducted 2024-2025; report published June 2026; a follow-on statutory code is now in development with the Department for Education.
Staffing & skills
ICO audit teams conducting on-site/desk-based data-protection audits, Provider compliance teams implementing recommendations, Department for Education and devolved authorities engaged in developing a follow-on statutory code

Conditions for success

  • Providers' willingness to participate in a consensual audit
  • Provider capacity to implement recommendations (98% implemented in this cohort)
  • Statutory backing (proposed edtech code under the Data (Use and Access) Act 2025) to extend standards beyond the audited cohort

Common failure modes

  • Self-selected, consensual sample rather than a full-market audit, so findings may not generalise to non-participating providers
  • No statutory enforcement mechanism yet in place; reliance on voluntary provider cooperation

Where it fits

Governance type
national regulator (ICO)
Scale
national (England, with UK-wide relevance)
Income level
high-income

Commonly funded by

National / regional programmes

Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Similar practices you may find useful