Paper Type

Complete

Abstract

Educational technology (EdTech) vendors operate under U.S. federal laws like COPPA, FERPA, and PPRA that impose specific disclosure obligations for children’s and student data. Yet little is known about how well vendor privacy policies satisfy these requirements, particularly for tools actually deployed in U.S. schools. We coded the privacy policies of 1,694 EdTech applications sampled from a random set of local education agencies across all 50 U.S. states against ten U.S.-law-aligned disclosure categories using LLM-assisted classification with human validation (mean agreement 92.7%). A k-means cluster analysis identified three compliance profiles: Minimal (33.9%), General but child-silent (39.9%), and Substantive (26.2%). Parental consent disclosure (a core COPPA requirement) was absent from 73.6% of policies. Interpreting results through institutional theory and signaling theory, we show that privacy policies function as imperfect governance signals, shifting the vetting burden to district procurement staff who typically lack capacity to detect diluted disclosures.

Paper Number

1396

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

Symbolic, Selective, or Substantive? Compliance Patterns in EdTech Privacy Policies

Educational technology (EdTech) vendors operate under U.S. federal laws like COPPA, FERPA, and PPRA that impose specific disclosure obligations for children’s and student data. Yet little is known about how well vendor privacy policies satisfy these requirements, particularly for tools actually deployed in U.S. schools. We coded the privacy policies of 1,694 EdTech applications sampled from a random set of local education agencies across all 50 U.S. states against ten U.S.-law-aligned disclosure categories using LLM-assisted classification with human validation (mean agreement 92.7%). A k-means cluster analysis identified three compliance profiles: Minimal (33.9%), General but child-silent (39.9%), and Substantive (26.2%). Parental consent disclosure (a core COPPA requirement) was absent from 73.6% of policies. Interpreting results through institutional theory and signaling theory, we show that privacy policies function as imperfect governance signals, shifting the vetting burden to district procurement staff who typically lack capacity to detect diluted disclosures.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.