Education platforms hold a category of data with no equivalent in commercial software: learning analytics reveal learning difficulties, health-adjacent patterns, family circumstances, and cognitive profiles — attached to minors, recorded longitudinally, and readable decades later. A browsing history embarrasses; an assessment history at age eleven can follow a person to a job interview at thirty. That asymmetry defines the duty of care, and most of the industry is still below it.
The baseline every platform must clear #
- Data minimization by default: collect what teaching requires, not what analytics could someday want
- Role-scoped visibility: teachers see their learners, admins see aggregates — nobody sees everything
- Retention with a clock: behavioral detail expires on a defined schedule, not on storage convenience
- Training-data firewall: student content and behavior never enter external model training, contractually and architecturally
- Export and deletion that work: a family's data request is a workflow, not a legal negotiation
Why compliance frameworks are the floor, not the ceiling #
FERPA, GDPR, and the regional equivalents define what is legal; they do not define what is safe for a child whose struggling semester becomes a permanent data point. The platforms worth trusting demonstrate posture beyond compliance: published data dictionaries stating exactly what is stored, breach histories disclosed voluntarily, and privacy designs — like on-device processing of sensitive signals — that make entire categories of leak structurally impossible rather than merely prohibited.
For institutions, the procurement translation is a short, brutal questionnaire: What exactly do you store per student? Who inside your company can read it? What happens to it when we leave? Any vendor that answers with certifications instead of specifics has told you what you needed to know.