Teachers use dozens of online tools every week — quiz apps, classroom management systems, random pickers, video tools, whiteboards. Every one of those tools is a potential data privacy risk if it collects or transmits student information.
The problem: most edtech tools bury their data practices in multi-page terms of service that few teachers have time to read. This guide walks through the key laws you need to know, what to look for in a tool, and how to make faster judgments about whether something is safe to use with your students.
The Three Laws You Need to Know
FERPA — Family Educational Rights and Privacy Act
FERPA protects the privacy of student education records. It applies to any institution that receives federal funding (i.e., all public schools).
What this means for teachers: Educational records — including student names associated with classroom activities — should not be disclosed to third parties without parental consent or an exception.
Using a tool that transmits student names to a server in another country, or shares them with advertising networks, could constitute a FERPA violation.
COPPA — Children's Online Privacy Protection Act
COPPA restricts online services from collecting personal information from children under 13 without parental consent.
What this means for teachers: If you teach K–7, any tool that collects student information (even just names) may fall under COPPA scrutiny. The FTC has clarified that schools can consent on behalf of parents in some contexts — but only if the tool is used strictly for educational purposes and doesn't collect more data than necessary.
State-Level Laws (California, Colorado, etc.)
Several states have added their own student privacy laws. For example:
- California: Student Online Personal Information Protection Act (SOPIPA)
- Colorado: Student Data Transparency and Security Act
- New York: Education Law § 2-d
These generally require edtech vendors to sign data privacy agreements, avoid targeted advertising to students, and delete student data on request.
The Real-World Test: Where Does Student Data Go?
You don't need to be a lawyer to spot risky tools. Ask one question: Where do student names go when I use this tool?
There are three possible answers, ranked from safest to riskiest:
✅ Answer 1: "Nowhere — data stays on my device"
The tool runs entirely in your browser. Student names are stored in local storage on your computer. Nothing transmits to any server.
Risk level: minimal. This is the safest category. Examples: local-only spreadsheet apps, offline calculators, and privacy-first tools like SelectAWheel.
⚠️ Answer 2: "Only to the tool's server, stored securely"
The tool requires an account and stores student names on its server. The vendor claims they don't share data with third parties and don't use it for advertising.
Risk level: depends on the vendor. Before using, look for:
- A signed Data Privacy Agreement (DPA)
- Compliance with the Student Privacy Pledge (a voluntary industry standard)
- Clarity about data retention and deletion
- Confirmation that data is not used for ad targeting
🚫 Answer 3: "Shared with third parties / used for ads"
The tool's terms of service allow it to share student data with advertisers, analytics providers, or other third parties.
Risk level: high. Do not use these tools with student rosters. Free tools that monetize via targeted ads frequently fall into this category.
How to Check Any Tool in 5 Minutes
- Read the privacy policy. Search for the words "third party," "advertisers," "share," and "sell." These words reveal what the tool does with data.
- Look for a "student privacy" or "education" section. Tools designed for schools will have one. If the policy doesn't mention education or students at all, that's a red flag.
- Check for a Data Privacy Agreement. Search for "DPA" or "Student Data Privacy Agreement" on the vendor's website. Tools used in K-12 often have one publicly available.
- Open the tool in an incognito browser. Use the browser's Network tab to see what requests the page makes. If it's sending data to dozens of external domains, that's cause for concern.
- Verify local-only claims. If the tool claims to store data locally, you can verify by clearing your browser cache and reloading. If your data survives, it was stored remotely.
What Privacy-First Tools Look Like
A tool designed with student privacy in mind typically has these properties:
- No account required — or optional accounts with no student data
- Local-only storage — data stays in your browser
- No advertising networks — no third-party trackers on the page
- No login for students — students don't need to create accounts
- Clear, short privacy policy — a page you can actually read in 2 minutes
- Offline capability — works without an internet connection
SelectAWheel was designed to meet all six criteria. You can read our{" "} full privacy policy or verify our claims yourself in any browser's DevTools.
Practical Guidelines for Teachers
Use first names or initials only
Even on locally-stored tools, use first names or student initials in place of full names where possible. This reduces risk regardless of the tool.
Prefer tools with no student logins
The fewer accounts your students need to create, the fewer places their data exists.
Check your district's approved list
Many districts maintain a list of approved edtech tools. Check it before introducing something new to your classroom.
Document your choices
If a parent or administrator asks why you use a particular tool, having a short rationale ready makes the conversation easier.
Clear browser data on shared devices
On shared classroom computers, clear the browser's local storage at the end of each session. On SelectAWheel, clicking{" "} Clear all in the wheel sidebar removes the stored roster.
What About the Student Privacy Pledge?
The Future of Privacy Forum maintains a{" "} Student Privacy Pledge that vendors can sign voluntarily. Signatories commit to:
- Not selling student data
- Not using student data for behavioral targeting
- Not using student data to build advertising profiles
- Not disclosing student data unless legally required
Look for the pledge on a vendor's website. It's not a legal guarantee, but it's a meaningful signal of intent.
Red Flags to Avoid
- Required email signup for students — creates FERPA and COPPA exposure
- "Free with ads" model — usually involves data monetization
- Privacy policy that mentions "marketing partners" — student data should never go to marketing
- No privacy policy at all — immediate red flag
- Terms of service longer than 5,000 words — usually means it's hiding something
- Requires third-party cookies — tracking across sites
- No offline mode — student data exists only remotely
Author
SelectAWheel Team — we build and maintain the free SelectAWheel wheel spinner, designed to be FERPA-friendly by storing student data only in the browser. This article is educational and not legal advice. Reach us at admin@selectawheel.com.
Try a Privacy-First Classroom Tool
Student names stay in your browser. No accounts, no cloud, no tracking.
Launch Classroom Wheel