JCPS uses hundreds of ed tech products. How safe is student data?
Students and staff in Jefferson County Public schools are getting acquainted this year with more than 600 technologies: from household names like Google Classroom, to testing software like i-Ready, to niche applications that let students interact with digital 3D models of human organs or take virtual Taebo lessons.
That technology is getting acquainted with students too.
JCPS allows tech firms to collect or process a range of deeply personal information about students: their birthdates, ethnicity, disabilities, and medical history, whether they are homeless or in foster care, their family’s economic status, how well they’re doing at reading and math, and their answers to writing assignments, according to a Kentucky Center for Investigative Reporting review of data sharing agreements with 49 companies signed last school year.
While the agreements provide a glimpse into the world of tech-company-fueled data collection within JCPS, the full scope is more vast. Officials at the state’s largest school district have approved 663 tech products for use, and staff have requested access to hundreds more. A KyCIR analysis of JCPS financial records shows the district spent more than $41 million on software alone since the 2022-2023 school year.
Since the district lacks a list of all active district contracts — a problem noted by Kentucky State Auditor Allison Ball in her 2026 JCPS audit — KyCIR combed through 12 months of meeting materials on the Jefferson County Board of Education webpage to find a sample of recently signed agreements and get an idea of how tech companies are mining student data — and what they do with it.
We found that few companies detail why they need the data they collect, or where they share it. And experts worry that while JCPS uses a nationally recognized standard agreement, it isn’t without gaps and may not prevent de-identified data from being traced back to students.
In a time when school districts weave digital technologies into nearly every aspect of teaching and learning, parents and activists worry that the companies who make those digital products may be buying and trading personal data for profit and, if not properly protected, the information could be used to market products to students, shape their worldview online and discriminate against them.
“One of the risks is that you have, you know, a behavioral profile, a psychological profile, about a child that's being developed…essentially from five years old,” said Andrew Liddell, an attorney who is suing several ed tech giants over privacy concerns. “And that's not being used to benefit them, it's being used against them.”
Meta’s recent $17.1 billion settlement with states nationwide highlighted growing fears that big tech is prioritizing profits over kids’ safety and privacy. The fears extend to schools, where for-profit tech companies, often backed by private equity, have rapidly expanded their footprint in K-12 education since the pandemic and have done so with little oversight from districts.
In February, Chicago Public Schools and ed tech giant PowerSchool agreed to pay out $17.25 million to students over allegations PowerSchool’s career and college readiness software, Naviance, improperly harvested student data and monitored students’ and teachers’ private communications. PowerSchool and Chicago Public Schools denied any wrongdoing.
Activist parents have filed similar lawsuits against several tech companies who provide services to JCPS, including Curriculum Associates, maker of i-Ready, Google, IXL Learning, PowerSchool and Renaissance Learning. All of the companies have filed motions to dismiss the claims and deny wrongdoing.
JCPS officials declined multiple requests to discuss the district's data privacy practices or how they vet potential technology providers. JCPS Superintendent Brian Yearwood cut 19 positions from the district’s IT department earlier this year as part of an effort to patch a massive budget shortfall. The district has been searching since July for an Executive Officer of Information Technology, now the highest technology position in JCPS under a new organizational chart that removed a cabinet-level position for IT. Don Bacon, a former teacher and technology specialist is serving in that role in an interim capacity. The executive officer of IT will report to the Chief Business Officer position, which is also unfilled.
In an emailed statement, JCPS spokesperson Barnard Baker said that while a staff member was not prepared to speak on data privacy “in a media interview setting,” the district carefully controls access to student data, tracks all vendor agreements and aligns its privacy practices with nationally recognized standards.
“JCPS does not provide vendors with unfettered access to student records, and data sharing is governed by contractual agreements and privacy requirements designed to protect student information,” Baker wrote.
Baker said the district is asking the Jefferson County Board of Education to adopt a version of the National Data Privacy Agreement as its new standard data privacy contract at the next board meeting on Sept. 22.
“This reflects JCPS's ongoing commitment to using established frameworks that are widely recognized for addressing student data privacy and security,” Baker said.
What student data is JCPS sharing?
Taken together, the dozens of tech firms JCPS signed agreements with in the 2025-2026 school year know where kids are, how often they come to school, what their learning challenges are, what they write on assignments and how they feel about school.
Some applications peer into the most intimate corners of kids’ lives. Edmentum, marketed as an accelerated learning software, is one of nine tech companies that can know whether students are coping with tenuous living situations, like foster care or homelessness.
Another major education technology company, Pearson, gathers student responses to mental health surveys.
Panorama Education, which uses AI to create a “panoramic view” of each student and develop action plans, can build a sweeping record of the students JCPS allows it to track: their attendance, what language they speak at home, how often they get in trouble, their grades, test scores, disabilities, medical conditions, survey responses and more.
A behavior threat management software made by Public Consulting Group is one of 18 applications that captures kids’ standardized test scores or other assessment data.
Everway, a software program for students with learning differences, is one of 15 applications that process student work on assignments. More than a dozen companies can access student and staff communications.
Nearly 3 out of 4 companies said they process the student’s or teacher’s IP address or cookies, which can translate to a rough location. Other vendors also collect demographic information, such as gender, race, whether a student is an English Language Learner or family income.
The data privacy agreements, or DPAs, KyCIR reviewed are a recommended practice for school districts when sharing data with third-party vendors, said David Sallay, director of data privacy at Access 4 Learning, a Massachusetts-based nonprofit focused on ed tech policy. The documents should detail what information is collected, how it is used, and what the protocols are in case of a data breach.
“These are important as legal documents, but they're also very helpful for that parent transparency,” said Sallay, who is also the former Chief Privacy Officer for the Utah Board of Education.
Sallay said some states require school districts to publicly list all third-party vendors that receive student data, including New York. Kentucky does not have the same requirements.
Companies told KyCIR the data they are collecting under the DPAs is necessary for the functionality of their programs. Everway, for example, said through a spokesperson that “capturing [student work] digitally helps educators understand what is working and where instruction may need to change.” Edmentum said through a spokesperson that capturing demographic information can help districts meet reporting requirements for special populations under federal regulations.
“For example, customers may choose to use fields such as foster care or homeless status when needed to support reporting under the Every Student Succeeds Act or other requirements. This information can also help districts evaluate whether products are effectively serving specific student populations,” Edmentum spokesperson Romano Ross said in an email.
But digital privacy activists and experts caution that DPAs might not always have enough guardrails to ensure companies aren’t collecting more data than necessary. Some warn that tech companies may be exploiting loopholes or flouting privacy agreements to commercialize data or share it with third parties.
“The schools are so outgunned because all they can do is take the manufacturer at their word,” said Lisa LeVasseur, founder of Internet Safety Labs, which tests software and advocates for more online privacy.
LeVasseur points to a study her team conducted along with Brigham Young University for the Utah State Board of Education in 2024 which found that 52% of the top 100 education technologies being used by Utah schools were collecting or sharing data beyond the scope listed in their own terms of service or DPAs.
“Nobody ever looks at this, and industry knows nobody's looking,” LeVasseur said.
JCPS DPAs list more than 60 data elements companies can collect and it’s up to each company to mark which information they capture. KyCIR’s review suggests tech companies may be collecting more data than they indicate on their contract. In a Pearson contract for testing software for nonverbal students, the company marked that it uses several sensitive data items, such as standardized test scores, birth dates and disability information — but in the same agreement the company noted it was not using any confidential data. In a separate JCPS contract with Ron Clark Academy — the maker of an app that tracks student behavior — the box for student conduct is unchecked. Seven contractors marked boxes labeled “other,” but never specified what student data they intended to collect or use.
In an email response to KyCIR, a spokesperson for Pearson said company employees erred when they indicated they would not collect confidential data. A Ron Clark Academy spokesperson told KyCIR the behavior and conduct tracking is an “optional” feature of the app, which is designed to reward digital points to students for good behavior.
Bill Fitzgerald, a privacy consultant who has done product testing for Common Sense Media and Consumer Reports, told KyCIR that often the employees filling out the form are salespeople or other “non-technical staff” who don’t actually know what data will be used. There may also be confusion about the purpose of the checklist. Jim Siegl, a privacy consultant and former Senior Fellow at the Future of Privacy Forum, said some companies may interpret it as a list of what the district needs to send them to set up student or staff accounts.
Many JCPS DPAs have audit clauses that allow the school district to audit the company’s privacy and security measures. But LeVasseur and other experts told KyCIR most school districts don’t have the in-house expertise or funding to adequately audit the hundreds of tech firms that process student data. Siegl called audit clauses “largely meaningless.”
“I have never, ever, ever heard of a district using this,” Siegl said of the audit clause that’s become standard in many DPAs between schools and tech firms.
Baker, with JCPS, said he is not aware of any instance in which JCPS has audited ed tech providers.
LeVasseur, with ISL, told KyCIR that in addition to disclosing the data items companies collect, it's “almost more important” for vendors to specify where that student data is shared. Siegl and LeVasseur said DPAs should require tech firms to list each external party that receives the data, including all “suprocessors” — other firms tech companies use to operate, like Amazon Web Services or Google Analytics.
But no JCPS DPA required the vendor to say who they share student data with or why they need it. Only two vendors voluntarily listed the subprocessors that receive JCPS student data: Chartflow, which makes a training version of a medical charting software, and Navex Global which provides hotline services.
And out of 49 agreements, only two vendors provided any explanation for why they needed specific elements: local photography company Craig W. Davis and Associates, which uses student enrollment data to facilitate picture day, and ebook provider OverDrive.
“It's a question of data minimization. Are they collecting more information than they need to for the purpose?” Siegl said.
Baker, with JCPS, told KyCIR that while the district’s DPAs may not detail the rationale for each data element collected, district staff ensure that all requested data is “appropriate and aligned with the educational or operational purpose of the product.” He also noted that JCPS’ agreement requires all subprocessors “be bound by privacy and security requirements that are at least as restrictive as those imposed on the primary vendor.”
With some of the biggest tech companies, like Google and Adobe, JCPS does not have a DPA, and instead relies on the companies’ terms of service and privacy statements. Sallay said that was a common practice among school districts when it comes to tech giants, complex organizations with little desire to sign one-off agreements with the thousands of individual districts they serve.
A big loophole
While JCPS’s standard DPA is based on a nationally used model, that model contains “an enormous loophole” for so-called “de-identified data,” according to Fitzgerald.
Most JCPS contracts require tech companies to delete students’ personally identifiable information at the end of services, but companies are allowed to keep de-identified data on JCPS students after the contract has expired and use it for “research and development” of their product. Most contracts also say that anyone who receives that data must agree in writing not to re-identify it.
The problem, experts said, is that with the computing power available today, lots of de-identified data can easily be traced back to individual students.
“It's a pinky promise. Of course, it's re-identifiable,” LeVasseur said.
LeVasseur called de-identification a “myth” and pointed to research showing people can be re-identified with just a couple data points. LeVasseur said companies in the identity resolution industry are paid to mine de-identified data for patterns linking it to specific people, which is often used for targeted advertising.
Many state privacy laws and nationally recognized contracts have this exemption for de-identified data, Fitzgerald said, in large part because they are based on the 1974 Family Educational Rights and Privacy Act, or FERPA, which does not cover student information once it’s de-identified.
“It's one thing to say that you are living up to the requirements of a law that was drafted in 1974 when our notion of privacy was radically different. It's another thing to say that you are living up to that same law in 2026,” Fitzgerald said.
Fitzgerald and LeVasseur said contracts should specify which pieces of data are to be de-identified and how — not let the vendor decide.
Separate from the concerns over how student data is shared externally is another debate about how companies should be able to use that data for their own product development.
“A kid in the second grade doesn't go to school so a vendor can aggregate their data and improve a product,” Fitzgerald said.
That is a key issue in a privacy lawsuit against Curriculum Associates, maker of i-Ready. Ed Tech Law Firm’s Liddell, who is the attorney for the plaintiffs, said ed tech companies are turning kids into "unpaid software testers.”
“We shouldn't be experimenting on kids with a half-baked product,” Liddell told KyCIR. “We should be disclosing that the product is in a certain developmental stage, and if parents would like for their kids to, you know, help the company, then they should be informed and compensated accordingly.”
Correction: A previous version of this story misspelled Andrew Liddell's name.

