ICO edtech audit

What the ICO’s EdTech audit means for schools and MATs

What the ICO’s EdTech audit means for supplier assurance, DPIAs, AI governance and stronger evidence of control across schools and MATs.

Key findings

What the ICO found

The audit found repeated weaknesses across controller and processor roles, contracts, data flows, minimisation, DPIAs, transparency and AI governance.

Role clarity

Many providers described themselves as processors while also making independent decisions about analytics, product development, anonymisation, adaptive learning or AI use.

Contract terms

The audit highlighted vague contracts, weak Article 28 terms and agreements that did not clearly describe the real processing taking place.

ROPA evidence

Providers often had incomplete data flow mapping, weak records of processing and poor evidence around retention, sub-processors and international transfers.

DPIA quality

DPIAs were one of the weakest areas, with many providers having no DPIA at all or using assessments that were not detailed enough to evidence real risk to children.

Transparency

Many providers could not explain processing clearly enough for schools, parents or children, especially where product features, retention or AI use were involved.

AI safeguards

The ICO identified AI and adaptive functionality as a recurring risk area, especially where training, testing, profiling or default-enabled features were not properly governed.

Headline figures

The headline figures

The numbers show the scale of the governance gaps the ICO identified across the audited providers.

Audit findings

The ICO made 596 recommendations across the 28 audited edtech providers, showing the scale of the governance issues it found.

Advisory notes

The ICO also issued 139 advisory notes alongside its recommendations, adding further operational guidance for providers.

Good practice

Alongside weaknesses, the ICO identified 118 examples of good practice, giving schools a clearer view of what stronger governance looks like.

Accepted actions

Ninety-eight per cent of the ICO’s recommendations were accepted, reinforcing that the issues identified were substantive and actionable.

Why it matters

Why this matters for schools and MATs

Schools need evidence they can rely on — not vague supplier assurances or platform claims.

Without clear evidence of how a product uses children’s information, it is difficult to demonstrate proper controller oversight.

Schools need to know what data is used, what suppliers do with it, which roles apply, whether AI is involved, whether DPIAs are complete, how long data is kept and what contract terms control the processing.

Alignment

Where the ICO findings align with Tru Data Protection

The ICO findings point to the same pressure points we see in schools and trusts: weak evidence, unclear supplier roles, incomplete DPIAs, poor review cycles and limited visibility of AI-enabled processing.

Supplier assurance

Schools need more than marketing claims. They need clear evidence of roles, processing activities, sub-processors and contract controls.

DPIA and risk review

Higher-risk products need proper assessment, documented decisions and review points — not one-off approvals.

ROPA and evidence gaps

Processing records need to show what data is used, why it is used, where it goes and how long it is kept.

AI governance

AI-enabled features need visibility, safeguards and review, especially where children’s information is involved.

Review now

What schools should review now

Use the audit as a prompt to test whether your higher-risk edtech products are properly evidenced, assessed and governed.

  • Is the supplier acting as processor, controller, joint controller or different roles for different activities?
  • Do you have current contracts, DPA terms, sub-processor details, retention rules and security information?
  • Has the product been screened or assessed properly, especially where children’s data, profiling, AI or safeguarding data is involved?
  • Is there a clear owner, next review date and decision record for continued use?
  • Do you know whether AI or adaptive functionality is used, what data it relies on and what safeguards apply?
  • Is the product actually being used in the way the supplier documentation describes?

Governance workflow

Turn review into recorded decisions

Use the audit as a prompt to move from ad-hoc checks to a repeatable governance workflow: assess the product, record the evidence, decide what action is needed and set the next review point.

1Identify priority products

Start with higher-risk edtech, AI-enabled tools and products processing children’s sensitive information.

2Gather supplier evidence

Collect contracts, DPA terms, sub-processors, retention rules, security information and AI details.

3Assess risk and DPIA need

Confirm whether the product needs screening, a DPIA, DPO advice or additional safeguards.

4Schedule review

Set a review date and trigger points for changes in processing, suppliers, AI features or contract terms.

5Record the controller decision

Capture the decision, conditions, residual risk, owner and rationale.