Your kid's school district used an average of 2,982 different edtech tools last year. Not the district next door — the average one. That's up nearly 9% from the year before, and it's the number to hold in your head as the school year starts, because no parent is reviewing 2,982 privacy policies.
The law didn't arrive in time
COPPA 2.0 — the Children and Teens' Online Privacy Protection Act — passed the Senate unanimously on March 5, 2026. Five months later it still isn't law. The school year starts without it.
What did change: COPPA itself got its first major overhaul in years. New rules took effect June 23, 2025, with full compliance required by April 22, 2026, and they tightened the requirements around explicit parental consent before children's data goes to third parties.
So there is a stronger federal floor than last year. It's just narrower than the one Congress keeps almost passing.
Where it actually breaks
The failures aren't dramatic. Nobody hacks the gradebook. Student data privacy tends to come apart in small operational gaps — one app added mid-year outside the approval process, one parent form filed and never entered, one vendor account nobody has reviewed since the teacher who set it up left, one record shared before someone checked the consent box.
Multiply that across nearly 3,000 tools and the math stops being reassuring. The gap isn't between schools that care and schools that don't. It's between the pace of adoption and the pace of review.
Three things worth doing this week
Ask for the list. Ask your child's teacher which apps and programs your child is actually using. This sounds obvious and almost nobody does it. You cannot evaluate what you don't know exists, and the list is usually longer than parents expect.
Opt out of directory information. Schools can disclose "directory information" — name, address, photo, activities — to third parties unless you say otherwise. Ask the school not to. It's typically a single form and it's the highest-leverage thing on this list.
Check the settings that exist. Many school apps and school-issued devices have privacy controls parents can adjust. They ship on defaults chosen for convenience, not privacy. Ten minutes in the settings of the two or three apps your child uses daily is worth more than reading a policy.
The parts you can't fix from home
Some of this is structural. Schools are choosing tools under time pressure, often without dedicated privacy staff, and consent management at that scale is genuinely difficult. Districts that handle it well have a process — a review step before adoption, a periodic audit of dormant vendor accounts, a single place parent consent lives.
If your school has that, good. If it doesn't, asking whether it does is itself useful. Questions from parents move faster through a district than policy memos.
Keep the frame right
None of this means edtech is bad, or that your child's data is being sold tomorrow. Most of these tools do something useful and most districts are trying. The point is that the volume has grown faster than the oversight, and the regulation that would close the gap keeps stalling one step short.
Until it doesn't, the practical protection is the boring version: know the list, opt out of directory disclosure, check the settings. Twenty minutes, once, at the start of the year.
Image: Yan Krukau, via Pexels





