Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

SaaS & technology

Privacy & Security for Edtech Platforms

Edtech platforms sell software to public institutions, not ordinary businesses, so a school board's privacy law reaches into your contract the moment a student record crosses your rostering feed. Privacy Horizon builds the vCISO, VPO, and assurance work that lets a Canadian edtech vendor answer an Ontario board's PIA, a BC district's FOIPPA questions, or a first US district's FERPA clause without stalling the deal. Most engagements start when a board RFP, the PowerSchool aftershock, or a new AI feature puts privacy paperwork ahead of the sale.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

Edtech platforms answer to a founder or CEO, a CTO, a VP Product, and in scaled vendors a compliance or student-privacy lead, often pulled in when a signed deal stalls on missing privacy paperwork. Most Canadian vendors we see sit between ten and three hundred employees, small enough that nobody owns this full-time.

The niche spans learning management systems and courseware, student information system vendors, assessment and proctoring tools, classroom communication apps, tutoring and adaptive-learning products, and campus-operations SaaS. Each sells into the same kind of buyer: a public institution answerable to a regulator the vendor never faces directly.

Ontario school boards buy under MFIPPA, BC districts under FOIPPA, Alberta boards under its own public-sector privacy regime, and Quebec service centres under provincial public-body rules layered on Law 25. A vendor selling across provinces is running several playbooks at once, not one PIPEDA program stretched thin.

Signing a first US district adds FERPA's school-official terms and COPPA's consent and retention duties for anything touching a child under thirteen. An AI feature raises the stakes again, pulling in a board's own AI review on top of everything else.

Studying with video online lesson at home

Services

Privacy & security services for edtech platforms

Each service below is scoped for how edtech platforms actually operate — their systems, their regulators and the reviews they face.

What you hold

What edtech platforms are trusted with on behalf of students

The trust boundary here is unusual for SaaS: the paying relationship is with a public institution, but the data subject is almost always a minor who never chose the vendor.

Enrolment and identity records

Student names, an Ontario Education Number or a BC Personal Education Number, enrolment status and demographic fields arrive the moment a rostering feed goes live.

Academic and behavioural history

Grades, transcripts, attendance, and behavioural or disciplinary notes that a teacher or administrator enters directly into the platform across a school year.

Special-education and health flags

IEP status and related accommodation notes, plus health details a guardian discloses for safety reasons, both categories regulators treat as heightened risk.

Guardian contacts and custody details

Parent and guardian contact information, and in some products custody flags that determine who may receive messages or collect a report card.

Classroom content and media

Messages between teachers, students and parents, plus photos or video captured for assignments, portfolios or remote-learning sessions.

Proctoring and telemetry data

Biometric signals from assessment or proctoring tools, alongside general usage telemetry the platform logs for product analytics.

Staff records riding the same systems

Teacher and administrator accounts, credentials and sometimes payroll-adjacent details sit inside the same SIS or LMS tenant as student records.

Regulatory map

The regulatory map a Canadian edtech vendor actually sits inside

PIPEDA governs a vendor's own conduct, but almost every real deal is shaped by the public-sector statute governing the buyer, not by PIPEDA alone.

MFIPPA for Ontario school boards

Ontario boards are institutions under MFIPPA, which limits how they collect, use and disclose records and holds the board, not the vendor, accountable for what a contracted platform stores.

Primary source →

FOIPPA for BC districts

BC districts answer to FOIPPA's reasonable-security duty, its limits on disclosing personal information outside Canada, and mandatory notice to individuals and the Commissioner once harm crosses a significant threshold.

Primary source →

Alberta's public-sector privacy regime

Alberta school boards fall under the province's Protection of Privacy Act framework, a third statute a nationally selling vendor tracks alongside Ontario and BC.

Primary source →

Quebec's public-body rules and Law 25

Quebec school service centres are public bodies under provincial rules, while a vendor's own processing and any Quebec consumer product answer to Law 25's PIA and profiling-default requirements.

Primary source →

PPM 164 and the ministry's own VLE

Ontario's PPM 164 requires boards running remote learning to hold cybersecurity and privacy policies, and supports use of the ministry-provided virtual learning environment, the incumbent a new LMS has to unseat.

Primary source →

The IPC's Digital Privacy Charter for Ontario Schools

Twelve commitments covering vendor contracts and breach transparency, published alongside a blunt warning that boards cannot outsource accountability for what their edtech vendors do.

Primary source →

FERPA and COPPA once a US district signs

FERPA's school-official exception requires direct control, limited use and no redisclosure, and COPPA adds verifiable parental consent, security-program and retention duties for users under thirteen.

Primary source →

What goes wrong

Where edtech incidents actually start

The clearest incident pattern in this niche runs through one vendor and out to every institution it serves at once, exactly what happened at scale in December 2024.

  • The PowerSchool-style SIS mega-breach

    A single compromised support credential without multi-factor authentication exposed decades of student and teacher data across North America, including many Canadian boards, and paying the ransom did not stop later extortion.

    Source →

  • Regulators naming vendor contracts as the gap

    Ontario and Alberta's commissioners found in November 2025 that boards lacked reasonable contractual and oversight measures over their SIS vendor, a finding already reshaping what RFPs demand from suppliers.

    Source →

  • Ransomware timed to the school year

    Attackers target boards and their vendors during term time, and because one platform typically serves hundreds of institutions, a single vendor compromise becomes a supply-chain event overnight.

  • Rostering and portal flaws exposing class lists

    Misconfigured rostering integrations and IDOR-style flaws in parent portals can expose class lists and guardian contacts, the same access-control pattern behind a widely reported hiring-chatbot breach elsewhere.

    Source →

  • AI features logging what minors type

    Chatbot tutors and proctoring analytics have been shown to retain children's conversations, and in one August 2025 incident, leave shareable transcript links exposed to search-engine indexing.

    Source →

  • Credential stuffing on teacher and parent logins

    Phishing that impersonates the vendor, combined with credential stuffing against teacher and parent accounts, remains a routine entry point into classroom systems.

    Source →

When organisations call us

The moments that start a privacy or security project

Edtech privacy work rarely begins from ambition. It begins from a procurement deadline, a renewal, or a feature that just shipped.

  • A board RFP or ministry licensing round lands

    Privacy schedules, PIA questions and a demand for Canadian hosting answers arrive attached to a procurement document, usually between March and August ahead of a September rollout.

  • A renewal after the PowerSchool aftershock

    Existing board customers return to a contract renewal asking for terms their own commissioners said they were missing, terms your last agreement never contemplated.

  • A first US school district signs

    FERPA's school-official language and COPPA's consent and retention duties move from theoretical to contractual the moment a district south of the border joins the customer list.

  • An AI tutor or proctoring feature ships

    Adding an AI-driven feature invites a board's own AI review process and draws the kind of public scrutiny the IPC has already applied to edtech.

  • Cyber-insurance renewal or investor diligence

    Insurers and investors ask many of the same posture questions boards do, and a vendor already organized for one audience answers the other faster.

  • Summer becomes the only window left

    Because deployments run on a September start date, whatever a spring PIA or a renewal turns up has to be fixed inside the same short summer every other vendor is racing through too.

Edtech Platforms: privacy & security questions, answered

Both, in layers. PIPEDA governs your own conduct as a commercial organization, but the institution buying from you, a school board or district, answers to its own public-sector statute: MFIPPA in Ontario, FOIPPA in BC, a comparable regime in Alberta. Your contract, PIA answers and breach clauses need to satisfy that statute too, because the board stays accountable for records it hands you even once you are holding them.

The December 2024 breach itself was a vendor-side failure, but the commissioners' November 2025 findings landed on the buyer side: boards were told their contracts and oversight of vendors like yours were not reasonable. Expect that finding to travel into your next RFP and your next renewal as harder contract language, not as a one-time news cycle.

Functionally, yes. MFIPPA, FOIPPA, Alberta's public-sector regime and Quebec's public-body rules layered on Law 25 each set their own security, disclosure and breach-notice expectations, so one generic privacy policy will not answer all four consistently. Most vendors build a single internal program and translate it into board-specific language per province rather than writing four programs from scratch.

FERPA's school-official exception requires you to operate under the district's direct control, use data only for the authorized purpose, and never redisclose it, while COPPA adds verifiable parental consent and retention limits for any user under thirteen. Both usually show up as specific contract clauses rather than general terms, so a US deal deserves a dedicated review before it closes.

In Ontario, yes, in a specific way. The ministry provides Brightspace free to every publicly funded board under PPM 164, and two online-learning credits are a graduation requirement, which makes that provincially licensed VLE the incumbent in any board conversation about a competing LMS. Positioning against that platform, not another startup, is often the real sales conversation.

Start with whichever gap is actively blocking a deal or renewal: a vCISO or VPO if no one owns the program, a vendor security review if a board's questionnaire is due, or an incident response plan if a board recently asked how fast you would tell them about a breach. Most vendors end up needing several of these within a year of their first serious board customer.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.