
Student Data Protection: The Part Schools Often Overlook
Student Data Protection: The Part Schools Often Overlook

Article by
Milo
ESL Content Coordinator & Educator
ESL Content Coordinator & Educator
All Posts
When a school reviews its cybersecurity, the conversation usually starts with passwords, phishing emails, and staff training. Those are important discussions. What often receives far less attention is where student records actually live once they are stored and who is responsible for protecting the infrastructure underneath them.
That distinction matters more than most schools realise, and the consequences of overlooking it are showing up in incident reports with increasing regularity.
Still grading everything by hand?
EMStudio is a free teaching management app — manage your classes, students, lessons, and more!
Learn More

Still grading everything by hand?
EMStudio is a free teaching management app — manage your classes, students, lessons, and more!
Learn More

Table of Contents
The Scale of the Problem
Education has become one of the most targeted sectors for cyberattacks. According to the 2024 Sophos State of Education report, 85 percent of ransomware attacks on K-12 schools involved data encryption, with recovery costs doubling in recent years. In 2023, the MOVEit ransomware attack affected over 800 educational organizations and compromised the personal information of nearly 1.7 million individuals. Ransomware attacks on K-12 schools increased by 92 percent between 2022 and 2023.
These were not attacks that bypassed a weak password. They targeted the infrastructure holding the data.
School leaders clearly recognise the issue. The CoSN 2024 State of EdTech District Leadership survey found cybersecurity ranked as the number one priority for K-12 edtech leaders, with data privacy and security at number two. 75 percent said they were extremely or very interested in Data Governance and Data Privacy as a professional learning topic. The harder challenge has been turning that awareness into long-term investment in infrastructure and governance.
What Gets Missed at the Infrastructure Level
A school may have strong password policies and mandatory phishing training, yet still rely on an ageing server room with limited redundancy and little physical oversight. Those are different layers of security, but both affect the same student records.
Student data is more sensitive than it is often treated. Names, dates of birth, addresses, medical histories, disability status, behavioral logs, and the learning data generated by classroom edtech tools are all collected in the course of normal school operations. A name combined with a school ID number and disability status is enough to identify a student, particularly in smaller districts. This information has real value to bad actors.
When that data sits on hardware in a school building that was not designed with data center requirements in mind, the physical security of those records depends entirely on the school's own facilities and maintenance schedule. In many cases, nobody has formally assessed whether that environment meets the standard the data requires.
Where EdTech Platforms Come In
The apps and platforms teachers use every day collect and store student data too. In many cases, significantly more of it than the school's own systems.
When a teacher adopts an edtech tool, that platform stores student information on its own infrastructure. The security of that data depends entirely on the decisions that platform made about how and where to host it.
Platforms that take infrastructure seriously typically host their systems in enterprise-grade environments, whether through professionally managed colocation facilities or cloud providers configured to meet strict security and compliance requirements. A professionally managed data centre provides redundant power systems, physical access controls, continuous monitoring, and independent certifications like ISO 27001 that verify controls are working rather than simply documented.
Teachers cannot audit the infrastructure behind every platform they use. But there are signals worth checking. Does the platform publish a privacy policy that explains specifically where data is stored? Does it hold independent security certifications? Is it FERPA compliant for US schools? Does it have a documented process for notifying schools if a breach occurs?
The number of new cybersecurity and data privacy laws enacted by US states in 2023 increased by 620 percent compared to 2020, according to CoSN's 2024 Education Cybersecurity Policy report. Regulatory expectations are rising. The platforms that have already invested in infrastructure rather than waiting for pressure to arrive are the ones worth trusting with student data.
What Teachers Can Actually Do
Teachers are not infrastructure engineers and should not need to be. But they do influence which platforms enter the classroom and what student information those platforms collect. Asking a few additional questions before adopting a new tool can prevent far more difficult conversations later if something goes wrong.
Before using a new edtech tool with students, check whether the platform has a clear privacy policy that addresses data storage, retention, and deletion. Vague answers about where data lives are worth taking seriously.
Check whether the tool is on your district's approved vendor list. Many districts now vet edtech platforms specifically for data privacy compliance before approving them for classroom use. Using unapproved tools, even with good intentions, creates data protection obligations the school cannot manage because it does not know the data is there.
Minimize what you share. If a platform asks for student data it does not obviously need for the function it provides, that is worth questioning. A quiz tool does not need a student's date of birth.
Report concerns promptly. If you suspect a platform has handled student data poorly, your school's data protection officer or IT team needs to know. The same applies if you receive any communication suggesting a breach or unauthorized access.
A Practical Frame for the Classroom
Student data protection involves multiple layers: the policies schools put in place, the access controls they enforce, the platforms they approve, and the infrastructure those platforms rely on. Most school-level conversations focus on the first two. The latter two are where gaps tend to form quietly.
Teachers who ask a few extra questions when adopting new tools, and who flag concerns when something does not look right, contribute more to student data protection than most formal training programs acknowledge.
Data figures referenced in this article are sourced from the 2024 Sophos State of Education report, ThreatDown's 2024 State of Ransomware in Education report, CoSN's 2024 State of EdTech District Leadership survey, and CoSN's 2024 Education Cybersecurity Policy report.
The Scale of the Problem
Education has become one of the most targeted sectors for cyberattacks. According to the 2024 Sophos State of Education report, 85 percent of ransomware attacks on K-12 schools involved data encryption, with recovery costs doubling in recent years. In 2023, the MOVEit ransomware attack affected over 800 educational organizations and compromised the personal information of nearly 1.7 million individuals. Ransomware attacks on K-12 schools increased by 92 percent between 2022 and 2023.
These were not attacks that bypassed a weak password. They targeted the infrastructure holding the data.
School leaders clearly recognise the issue. The CoSN 2024 State of EdTech District Leadership survey found cybersecurity ranked as the number one priority for K-12 edtech leaders, with data privacy and security at number two. 75 percent said they were extremely or very interested in Data Governance and Data Privacy as a professional learning topic. The harder challenge has been turning that awareness into long-term investment in infrastructure and governance.
What Gets Missed at the Infrastructure Level
A school may have strong password policies and mandatory phishing training, yet still rely on an ageing server room with limited redundancy and little physical oversight. Those are different layers of security, but both affect the same student records.
Student data is more sensitive than it is often treated. Names, dates of birth, addresses, medical histories, disability status, behavioral logs, and the learning data generated by classroom edtech tools are all collected in the course of normal school operations. A name combined with a school ID number and disability status is enough to identify a student, particularly in smaller districts. This information has real value to bad actors.
When that data sits on hardware in a school building that was not designed with data center requirements in mind, the physical security of those records depends entirely on the school's own facilities and maintenance schedule. In many cases, nobody has formally assessed whether that environment meets the standard the data requires.
Where EdTech Platforms Come In
The apps and platforms teachers use every day collect and store student data too. In many cases, significantly more of it than the school's own systems.
When a teacher adopts an edtech tool, that platform stores student information on its own infrastructure. The security of that data depends entirely on the decisions that platform made about how and where to host it.
Platforms that take infrastructure seriously typically host their systems in enterprise-grade environments, whether through professionally managed colocation facilities or cloud providers configured to meet strict security and compliance requirements. A professionally managed data centre provides redundant power systems, physical access controls, continuous monitoring, and independent certifications like ISO 27001 that verify controls are working rather than simply documented.
Teachers cannot audit the infrastructure behind every platform they use. But there are signals worth checking. Does the platform publish a privacy policy that explains specifically where data is stored? Does it hold independent security certifications? Is it FERPA compliant for US schools? Does it have a documented process for notifying schools if a breach occurs?
The number of new cybersecurity and data privacy laws enacted by US states in 2023 increased by 620 percent compared to 2020, according to CoSN's 2024 Education Cybersecurity Policy report. Regulatory expectations are rising. The platforms that have already invested in infrastructure rather than waiting for pressure to arrive are the ones worth trusting with student data.
What Teachers Can Actually Do
Teachers are not infrastructure engineers and should not need to be. But they do influence which platforms enter the classroom and what student information those platforms collect. Asking a few additional questions before adopting a new tool can prevent far more difficult conversations later if something goes wrong.
Before using a new edtech tool with students, check whether the platform has a clear privacy policy that addresses data storage, retention, and deletion. Vague answers about where data lives are worth taking seriously.
Check whether the tool is on your district's approved vendor list. Many districts now vet edtech platforms specifically for data privacy compliance before approving them for classroom use. Using unapproved tools, even with good intentions, creates data protection obligations the school cannot manage because it does not know the data is there.
Minimize what you share. If a platform asks for student data it does not obviously need for the function it provides, that is worth questioning. A quiz tool does not need a student's date of birth.
Report concerns promptly. If you suspect a platform has handled student data poorly, your school's data protection officer or IT team needs to know. The same applies if you receive any communication suggesting a breach or unauthorized access.
A Practical Frame for the Classroom
Student data protection involves multiple layers: the policies schools put in place, the access controls they enforce, the platforms they approve, and the infrastructure those platforms rely on. Most school-level conversations focus on the first two. The latter two are where gaps tend to form quietly.
Teachers who ask a few extra questions when adopting new tools, and who flag concerns when something does not look right, contribute more to student data protection than most formal training programs acknowledge.
Data figures referenced in this article are sourced from the 2024 Sophos State of Education report, ThreatDown's 2024 State of Ransomware in Education report, CoSN's 2024 State of EdTech District Leadership survey, and CoSN's 2024 Education Cybersecurity Policy report.
Still grading everything by hand?
EMStudio is a free teaching management app — manage your classes, students, lessons, and more!
Learn More

Still grading everything by hand?
EMStudio is a free teaching management app — manage your classes, students, lessons, and more!
Learn More

2026 Notion4Teachers. All Rights Reserved.
2026 Notion4Teachers. All Rights Reserved.
2026 Notion4Teachers. All Rights Reserved.









