ICO Edtech Audit 2026: What Schools and Suppliers Must Fix in Their Data Protection Paperwork
The term has started. Your management information system is live, the safeguarding platform is logging concerns, and whatever new classroom app you signed up for over the summer is already holding pupil data. Which makes this a good moment to ask a question most schools skip: does the paperwork behind those tools actually hold up?
ICO Edtech Audit Programme
28 providers · ~70% fell short
Around 70% of the data processing agreements the ICO examined were not fully compliant with UK GDPR processor requirements — and almost 70% of providers were acting as a controller for at least some children's data without saying so.
What the ICO Found
The Information Commissioner's Office published Edtech examined on 24 June 2026. It sets out the results of a consensual audit programme run with 28 edtech providers during 2024 and 2025 — companies supplying management information systems, safeguarding and behaviour platforms, learning management systems, classroom apps and data integration services used right across UK primary and secondary schools.
The headline figures are blunt:
- Around 70% of the data processing agreements audited lacked sufficient detail or were not fully compliant with the requirements for processor contracts under the UK GDPR.
- Almost 70% of providers were acting as a controller for at least some of their processing of children's personal information — even where they described themselves, and were treated by schools, as a processor only.
- Almost 70% could not demonstrate that schools had authorised the reuse of children's data for product development, analytics or AI training.
- Nearly 80% could not show how data protection had been embedded into product design, or that children's specific needs had been meaningfully considered in design decisions.
It was not all bad news. The ICO found genuinely good practice around information security, and providers accepted and implemented 98% of the 596 recommendations made across the programme. The regulator has also said it is exploring how a new edtech code could better protect children's data across the tools schools rely on.
But the controller/processor finding is the one that should make school leaders sit up. If a supplier is a controller for some of its processing and nobody has written that down, a whole set of obligations — transparency to pupils and parents, a lawful basis for that processing, retention decisions — is sitting in a gap between two organisations, each assuming the other owns it.
Why This Lands on Schools, Not Just Suppliers
The ICO audited suppliers. The legal exposure does not stop there.
A school or trust remains the controller for the pupil data it holds. Article 28 of the UK GDPR puts the duty on the controller to use only processors that provide sufficient guarantees, and to have a written contract covering the required terms. If 70% of audited agreements fell short, a meaningful share of schools are relying on paperwork that would not survive scrutiny.
The Department for Education's guidance on procuring educational technology already expects schools to carry out this due diligence before signing. The ICO's report removes any remaining doubt about how often it gets skipped.
There is a safeguarding dimension too. Ofsted inspects how well a setting keeps children safe, and information governance is part of that picture. Where the data goes, who can see it and how long it is kept stops being an administrative question when the platform handles behaviour records, SEND information or safeguarding concerns.
If your setting uses any of these, the education & childcare sector page and the wider document library set out the data protection and information governance documentation that sits behind them.
A Six-Point Check for Schools and Trusts
You do not need to wait for a renewal date to do any of this:
Ask every supplier to state their role in writing
For each type of processing, ask the supplier to confirm whether it acts as controller or processor — and to spell out any processing it carries out for its own purposes, including service improvement, benchmarking or model training. Vague reassurance is not an answer.
Read the contract against Article 28
Documented instructions, confidentiality, security measures, sub-processor authorisation, assistance with data subject rights, deletion or return at the end of the contract, audit rights. If any of those are missing or boilerplate, raise it now rather than at renewal.
Map the sub-processors
Where is the data hosted? Which third parties touch it? Do you have visibility, and a right to object, when the supplier swaps one out?
Complete or refresh your DPIA
Profiling pupils, biometrics, large-scale monitoring or any AI-driven feature will normally require a data protection impact assessment. If a tool went live this term without one, that is the gap to close first — and revisit it whenever the product changes.
Check you can actually answer a rights request
Subject access, rectification, erasure, objection and portability all have to be deliverable through the supplier's platform, within statutory timescales. Autumn term is when subject access requests from parents tend to arrive.
Make sure your complaints route is documented
The Data (Use and Access) Act 2025 requires UK controllers to have an accessible, documented complaints procedure. Suppliers are already being asked for evidence of theirs during due diligence — expect the same question from parents.
What Edtech Suppliers Should Take From It
If you build software used in schools, the direction of travel is unmistakable. Data protection by design is not something you retrofit; the ICO explicitly criticised providers who could not evidence it. The Children's code sets the expectation that children's best interests are a primary design consideration, and a future edtech code would formalise that further.
The practical fix is documentary: a defensible record of your controller/processor analysis, a DPIA that pre-dates the build, a sub-processor register, and processing terms that genuinely meet Article 28 rather than restating it. The software & health technology sector page covers the governance documentation buyers increasingly expect to see.
Worth knowing: the ICO has signalled it is exploring a dedicated edtech code. Schools and suppliers who get their controller/processor analysis and Article 28 terms straight now will be starting from a far better position than those waiting to see what the code says.
Where ProPolicyForge Fits In
Most of what the ICO flagged is a documentation failure rather than a technology failure. The systems were reasonably secure. The governance around them was thin.
ProPolicyForge generates regulation-aligned data protection and information governance documents — data protection policies, DPIA procedures, records of processing, retention schedules and complaints procedures — written against current UK legislation and your own organisational details rather than pulled from a static template. You can see how the platform works on our features page, with plans detailed on our pricing page.
Check Your Paperwork This Term
Generate regulation-aligned compliance documents in minutes
Generate your data protection policy and DPIA procedure, then read them side by side with what you currently hold. 30-day free trial — full access, no card required.
Start Your Free TrialSources & disclaimer: This article provides general guidance only and does not constitute legal or regulatory advice. See the ICO's Edtech examined report (published 24 June 2026) and its accompanying statement at ico.org.uk, the ICO's Children's code guidance, and the Department for Education's guidance on data protection in schools and procuring educational technology at gov.uk. Details reflect published guidance as of September 2026. Schools, trusts and edtech suppliers should refer directly to current ICO and DfE guidance and seek specialist advice for their specific setting.
