Most EdTech privacy conversations start and end with the product: what data does the app collect, and what does its own privacy policy say. But a growing share of student data risk doesn't originate inside the product at all. It lives in the cloud host processing enrollment records, the analytics tool measuring engagement, the AI model powering a tutoring feature, or the customer support platform storing parent emails. Every one of those is a third-party vendor, and every one of them is a door into the same data an EdTech company promised to protect.
Managing that risk starts with a strong privacy policy and depends on the practices across the organization that keep it accurate.
The Product Isn't the Only Attack Surface
Districts have learned this lesson the hard way. Recent incidents involving major platforms like Canvas and PowerSchool made clear that a district can lock down its own environment and still be exposed through a vendor relationship. The same dynamic runs in the other direction: an EdTech company can establish an airtight privacy posture for its own product and still inherit real risk from the subprocessors, cloud infrastructure, and AI tools it relies on to run that product.
That risk compounds with scale. A typical district now works with well over a hundred EdTech applications, and the vendors behind those applications often rely on dozens of subprocessors of their own: hosting providers, analytics SDKs, customer relationship platforms, and, increasingly, third-party AI models. Each link in that chain can touch student data without careful design, and each one can widen the gap between privacy promises and what actually happens to student data.
What "Organization-Wide" Actually Means
A privacy policy sets out a company's commitments to students and families. The practices behind it are what keep those commitments accurate as vendors, features, and laws change. The organizations that manage third-party risk well tend to share a few habits:
- A living inventory of every vendor and subprocessor, not just the ones named in the privacy policy, including what data each one touches and why.
- Risk tiering, so anonymized analytics information gets a different level of scrutiny than an AI vendor handling free-text student responses.
- Contractual guardrails, such as data use limitations, breach notification timelines, and deletion requirements, that flow down to subprocessors, not just the primary vendor.
- Ongoing monitoring, since a vendor's practices on day one of a contract are not a guarantee of its practices two years and three feature launches later.
- Cross-functional ownership, so privacy isn't solely a legal function bolted onto engineering decisions after the fact, but a shared responsibility across product, security, and procurement.
None of this is new. What's hard is doing it consistently, at the pace new tools and vendors get added, while the legal landscape keeps moving, from FERPA and COPPA to a growing patchwork of state student privacy and AI laws.
Where the Common Sense Privacy Dashboard Fits
Keeping up with that moving landscape is where the Common Sense Privacy Dashboard helps. The Dashboard gives EdTech organizations ongoing legislative tracking, tailored recommendations, and practical best practices, so privacy work doesn't stop once a policy is published. Teams get a standing view of where legal obligations are changing and where their own policies may need to catch up, rather than finding out during a district's procurement audit.
Where the Seal Comes In
The Privacy Seal is how a company's privacy commitments become visible to the people relying on them. The Privacy Seal evaluates a company's privacy policies against a rigorous, multi-hundred-question rubric covering data minimization, sharing restrictions, security, and tracking limits. It isn't a one-time review: a recipient's scorecard is monitored over time.
The bar for "enough" keeps rising. The Student Privacy Pledge has sunset, New York City and Los Angeles opened the school year by pausing student AI use and auditing their EdTech contracts, and Microsoft's new National AI Safety & Privacy Standard sets binding terms: no training AI on student data, no cross-tool tracking, human oversight, and plain-language transparency. Few companies can negotiate that kind of agreement on their own. What they can do is have their privacy policies independently evaluated against a comparable bar, which is exactly the evidence districts and families are now looking for.
Strong internal practices keep a privacy policy accurate. The Privacy Seal lets a district, which will never see a company's vendor inventory, know at a glance that the policy behind the product meets a high standard.
The Bar Is Rising, Not Holding Steady
Regulators are paying closer attention to how EdTech companies handle children's data, and that scrutiny is likely to continue as AI features become standard rather than novel. The companies best positioned for that environment will be the ones whose privacy policies are strong, clear, and accurate to how student data actually moves, including through every vendor that touches it.
EdTech companies ready to see where they stand can request a free Seal evaluation.

