New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
SaaS & technology
Privacy & Security for Edtech Platforms
Edtech platforms sell software to public institutions, not ordinary businesses, so a school board's privacy law reaches into your contract the moment a student record crosses your rostering feed. Privacy Horizon builds the vCISO, VPO, and assurance work that lets a Canadian edtech vendor answer an Ontario board's PIA, a BC district's FOIPPA questions, or a first US district's FERPA clause without stalling the deal. Most engagements start when a board RFP, the PowerSchool aftershock, or a new AI feature puts privacy paperwork ahead of the sale.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
Edtech platforms answer to a founder or CEO, a CTO, a VP Product, and in scaled vendors a compliance or student-privacy lead, often pulled in when a signed deal stalls on missing privacy paperwork. Most Canadian vendors we see sit between ten and three hundred employees, small enough that nobody owns this full-time.
The niche spans learning management systems and courseware, student information system vendors, assessment and proctoring tools, classroom communication apps, tutoring and adaptive-learning products, and campus-operations SaaS. Each sells into the same kind of buyer: a public institution answerable to a regulator the vendor never faces directly.
Ontario school boards buy under MFIPPA, BC districts under FOIPPA, Alberta boards under its own public-sector privacy regime, and Quebec service centres under provincial public-body rules layered on Law 25. A vendor selling across provinces is running several playbooks at once, not one PIPEDA program stretched thin.
Signing a first US district adds FERPA's school-official terms and COPPA's consent and retention duties for anything touching a child under thirteen. An AI feature raises the stakes again, pulling in a board's own AI review on top of everything else.

Services
Privacy & security services for edtech platforms
Each service below is scoped for how edtech platforms actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Edtech Platforms
Virtual CISO for edtech platforms: security leadership for SIS and LMS vendors preparing for board RFPs, renewals and the PowerSchool aftershock.
Virtual Privacy Officer
Virtual Privacy Officer for Edtech Platforms
Virtual Privacy Officer for edtech companies: run PIPEDA and Law 25 internally while answering MFIPPA and FOIPPA questions from school boards.
Penetration Testing
Penetration Testing for Edtech Platforms
Penetration testing for edtech platforms: test SIS integrations, parent portals and rostering APIs before a September launch or a board RFP.
Incident Response Planning
Incident Response Planning for Edtech Platforms
Incident response plans for edtech vendors: board notification timelines, roles and evidence built around the PowerSchool breach findings.
Privacy & Security Policy Development
Privacy & Security Policy Development for Edtech Platforms
Privacy policy development for edtech vendors: student data retention, destruction and no-advertising policies that satisfy board and IPC expectations.
Privacy & Security Training
Privacy & Security Training for Edtech Platforms
Privacy and security training for edtech vendors: role-specific sessions for support teams and developers who handle student and minors' data.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Edtech Platforms
Vendor security review preparation for edtech companies: answer school board PIAs, BC FOIPPA questionnaires and privacy schedules without stalling a deal.
SOC 2 Readiness
SOC 2 Readiness for Edtech Platforms
SOC 2 readiness for edtech vendors: scope Trust Services Criteria that shorten school board procurement and higher-ed enterprise-training deals.
ISO 27001 Readiness
ISO 27001 Readiness for Edtech Platforms
ISO 27001 readiness for edtech vendors: build an ISMS for SIS and LMS platforms and decide when certification beats SOC 2 for education buyers.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Edtech Platforms
AI Privacy Impact Assessments for edtech platforms: review AI tutors and proctoring tools against OPC child-safeguard guidance and board AI rules.
What you hold
What edtech platforms are trusted with on behalf of students
The trust boundary here is unusual for SaaS: the paying relationship is with a public institution, but the data subject is almost always a minor who never chose the vendor.
Enrolment and identity records
Student names, an Ontario Education Number or a BC Personal Education Number, enrolment status and demographic fields arrive the moment a rostering feed goes live.
Academic and behavioural history
Grades, transcripts, attendance, and behavioural or disciplinary notes that a teacher or administrator enters directly into the platform across a school year.
Special-education and health flags
IEP status and related accommodation notes, plus health details a guardian discloses for safety reasons, both categories regulators treat as heightened risk.
Guardian contacts and custody details
Parent and guardian contact information, and in some products custody flags that determine who may receive messages or collect a report card.
Classroom content and media
Messages between teachers, students and parents, plus photos or video captured for assignments, portfolios or remote-learning sessions.
Proctoring and telemetry data
Biometric signals from assessment or proctoring tools, alongside general usage telemetry the platform logs for product analytics.
Staff records riding the same systems
Teacher and administrator accounts, credentials and sometimes payroll-adjacent details sit inside the same SIS or LMS tenant as student records.
Regulatory map
The regulatory map a Canadian edtech vendor actually sits inside
PIPEDA governs a vendor's own conduct, but almost every real deal is shaped by the public-sector statute governing the buyer, not by PIPEDA alone.
MFIPPA for Ontario school boards
Ontario boards are institutions under MFIPPA, which limits how they collect, use and disclose records and holds the board, not the vendor, accountable for what a contracted platform stores.
FOIPPA for BC districts
BC districts answer to FOIPPA's reasonable-security duty, its limits on disclosing personal information outside Canada, and mandatory notice to individuals and the Commissioner once harm crosses a significant threshold.
Alberta's public-sector privacy regime
Alberta school boards fall under the province's Protection of Privacy Act framework, a third statute a nationally selling vendor tracks alongside Ontario and BC.
Quebec's public-body rules and Law 25
Quebec school service centres are public bodies under provincial rules, while a vendor's own processing and any Quebec consumer product answer to Law 25's PIA and profiling-default requirements.
PPM 164 and the ministry's own VLE
Ontario's PPM 164 requires boards running remote learning to hold cybersecurity and privacy policies, and supports use of the ministry-provided virtual learning environment, the incumbent a new LMS has to unseat.
The IPC's Digital Privacy Charter for Ontario Schools
Twelve commitments covering vendor contracts and breach transparency, published alongside a blunt warning that boards cannot outsource accountability for what their edtech vendors do.
FERPA and COPPA once a US district signs
FERPA's school-official exception requires direct control, limited use and no redisclosure, and COPPA adds verifiable parental consent, security-program and retention duties for users under thirteen.
What goes wrong
Where edtech incidents actually start
The clearest incident pattern in this niche runs through one vendor and out to every institution it serves at once, exactly what happened at scale in December 2024.
The PowerSchool-style SIS mega-breach
A single compromised support credential without multi-factor authentication exposed decades of student and teacher data across North America, including many Canadian boards, and paying the ransom did not stop later extortion.
Regulators naming vendor contracts as the gap
Ontario and Alberta's commissioners found in November 2025 that boards lacked reasonable contractual and oversight measures over their SIS vendor, a finding already reshaping what RFPs demand from suppliers.
Ransomware timed to the school year
Attackers target boards and their vendors during term time, and because one platform typically serves hundreds of institutions, a single vendor compromise becomes a supply-chain event overnight.
Rostering and portal flaws exposing class lists
Misconfigured rostering integrations and IDOR-style flaws in parent portals can expose class lists and guardian contacts, the same access-control pattern behind a widely reported hiring-chatbot breach elsewhere.
AI features logging what minors type
Chatbot tutors and proctoring analytics have been shown to retain children's conversations, and in one August 2025 incident, leave shareable transcript links exposed to search-engine indexing.
Credential stuffing on teacher and parent logins
Phishing that impersonates the vendor, combined with credential stuffing against teacher and parent accounts, remains a routine entry point into classroom systems.
When organisations call us
The moments that start a privacy or security project
Edtech privacy work rarely begins from ambition. It begins from a procurement deadline, a renewal, or a feature that just shipped.
A board RFP or ministry licensing round lands
Privacy schedules, PIA questions and a demand for Canadian hosting answers arrive attached to a procurement document, usually between March and August ahead of a September rollout.
A renewal after the PowerSchool aftershock
Existing board customers return to a contract renewal asking for terms their own commissioners said they were missing, terms your last agreement never contemplated.
A first US school district signs
FERPA's school-official language and COPPA's consent and retention duties move from theoretical to contractual the moment a district south of the border joins the customer list.
An AI tutor or proctoring feature ships
Adding an AI-driven feature invites a board's own AI review process and draws the kind of public scrutiny the IPC has already applied to edtech.
Cyber-insurance renewal or investor diligence
Insurers and investors ask many of the same posture questions boards do, and a vendor already organized for one audience answers the other faster.
Summer becomes the only window left
Because deployments run on a September start date, whatever a spring PIA or a renewal turns up has to be fixed inside the same short summer every other vendor is racing through too.
Edtech Platforms: privacy & security questions, answered
Both, in layers. PIPEDA governs your own conduct as a commercial organization, but the institution buying from you, a school board or district, answers to its own public-sector statute: MFIPPA in Ontario, FOIPPA in BC, a comparable regime in Alberta. Your contract, PIA answers and breach clauses need to satisfy that statute too, because the board stays accountable for records it hands you even once you are holding them.
The December 2024 breach itself was a vendor-side failure, but the commissioners' November 2025 findings landed on the buyer side: boards were told their contracts and oversight of vendors like yours were not reasonable. Expect that finding to travel into your next RFP and your next renewal as harder contract language, not as a one-time news cycle.
Functionally, yes. MFIPPA, FOIPPA, Alberta's public-sector regime and Quebec's public-body rules layered on Law 25 each set their own security, disclosure and breach-notice expectations, so one generic privacy policy will not answer all four consistently. Most vendors build a single internal program and translate it into board-specific language per province rather than writing four programs from scratch.
FERPA's school-official exception requires you to operate under the district's direct control, use data only for the authorized purpose, and never redisclose it, while COPPA adds verifiable parental consent and retention limits for any user under thirteen. Both usually show up as specific contract clauses rather than general terms, so a US deal deserves a dedicated review before it closes.
In Ontario, yes, in a specific way. The ministry provides Brightspace free to every publicly funded board under PPM 164, and two online-learning credits are a graduation requirement, which makes that provincially licensed VLE the incumbent in any board conversation about a competing LMS. Positioning against that platform, not another startup, is often the real sales conversation.
Start with whichever gap is actively blocking a deal or renewal: a vCISO or VPO if no one owns the program, a vendor security review if a board's questionnaire is due, or an incident response plan if a board recently asked how fast you would tell them about a breach. Most vendors end up needing several of these within a year of their first serious board customer.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- How does a startup pass an enterprise vendor security review?
- What should I do after a data breach?
- VPO vs vCISO: do you need one, the other, or both?
- What privacy and security assessments are required before selling to government?
- SOC 2 vs ISO 27001 — which should we pursue first?
- Building a Third-Party Vendor Risk Assessment Program That Scales
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- Writing an Incident Response Plan Your Team Will Actually Use
- How a Startup Passes Its First Enterprise Vendor Security Review
- Selling to Canadian Government? The Assessments Buyers Expect
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.