ICO edtech audit
What the ICO’s EdTech audit means for schools and MATs
What the ICO’s EdTech audit means for supplier assurance, DPIAs, AI governance and stronger evidence of control across schools and MATs.
Key findings
What the ICO found
The audit found repeated weaknesses across controller and processor roles, contracts, data flows, minimisation, DPIAs, transparency and AI governance.
Role clarity
Many providers described themselves as processors while also making independent decisions about analytics, product development, anonymisation, adaptive learning or AI use.
Contract terms
The audit highlighted vague contracts, weak Article 28 terms and agreements that did not clearly describe the real processing taking place.
ROPA evidence
Providers often had incomplete data flow mapping, weak records of processing and poor evidence around retention, sub-processors and international transfers.
DPIA quality
DPIAs were one of the weakest areas, with many providers having no DPIA at all or using assessments that were not detailed enough to evidence real risk to children.
Transparency
Many providers could not explain processing clearly enough for schools, parents or children, especially where product features, retention or AI use were involved.
AI safeguards
The ICO identified AI and adaptive functionality as a recurring risk area, especially where training, testing, profiling or default-enabled features were not properly governed.
Headline figures
The headline figures
The numbers show the scale of the governance gaps the ICO identified across the audited providers.
Audit findings
The ICO made 596 recommendations across the 28 audited edtech providers, showing the scale of the governance issues it found.
Advisory notes
The ICO also issued 139 advisory notes alongside its recommendations, adding further operational guidance for providers.
Good practice
Alongside weaknesses, the ICO identified 118 examples of good practice, giving schools a clearer view of what stronger governance looks like.
Accepted actions
Ninety-eight per cent of the ICO’s recommendations were accepted, reinforcing that the issues identified were substantive and actionable.
Why it matters
Why this matters for schools and MATs
Schools need evidence they can rely on — not vague supplier assurances or platform claims.
Without clear evidence of how a product uses children’s information, it is difficult to demonstrate proper controller oversight.
Schools need to know what data is used, what suppliers do with it, which roles apply, whether AI is involved, whether DPIAs are complete, how long data is kept and what contract terms control the processing.
Alignment
Where the ICO findings align with Tru Data Protection
The ICO findings point to the same pressure points we see in schools and trusts: weak evidence, unclear supplier roles, incomplete DPIAs, poor review cycles and limited visibility of AI-enabled processing.
Supplier assurance
Schools need more than marketing claims. They need clear evidence of roles, processing activities, sub-processors and contract controls.
DPIA and risk review
Higher-risk products need proper assessment, documented decisions and review points — not one-off approvals.
ROPA and evidence gaps
Processing records need to show what data is used, why it is used, where it goes and how long it is kept.
AI governance
AI-enabled features need visibility, safeguards and review, especially where children’s information is involved.
Review now
What schools should review now
Use the audit as a prompt to test whether your higher-risk edtech products are properly evidenced, assessed and governed.
- Is the supplier acting as processor, controller, joint controller or different roles for different activities?
- Do you have current contracts, DPA terms, sub-processor details, retention rules and security information?
- Has the product been screened or assessed properly, especially where children’s data, profiling, AI or safeguarding data is involved?
- Is there a clear owner, next review date and decision record for continued use?
- Do you know whether AI or adaptive functionality is used, what data it relies on and what safeguards apply?
- Is the product actually being used in the way the supplier documentation describes?
Governance workflow
Turn review into recorded decisions
Use the audit as a prompt to move from ad-hoc checks to a repeatable governance workflow: assess the product, record the evidence, decide what action is needed and set the next review point.
Start with higher-risk edtech, AI-enabled tools and products processing children’s sensitive information.
Collect contracts, DPA terms, sub-processors, retention rules, security information and AI details.
Confirm whether the product needs screening, a DPIA, DPO advice or additional safeguards.
Set a review date and trigger points for changes in processing, suppliers, AI features or contract terms.
Capture the decision, conditions, residual risk, owner and rationale.