What School-Required Technology Means for Your Family’s Privacy
A plain-language guide from the Bend Privacy Alliance
Last fact-checked: July 10, 2026This guide is one of several from the Bend Privacy Alliance. See the full collection — including the Family Action Checklist, Grandparents’ Guide, Youth Guide, and ready-to-send letter templates for your district or your child’s team or club.
The situation many families are in
Kids today are often required to use a school-issued email account or device just to turn in homework, communicate with a teacher, or take part in a class, club, or sports program. For families who care about privacy, this can feel like an impossible choice: either your child participates using an account you didn’t choose and don’t fully control, or they don’t participate at all.
This guide won’t tell you to switch email providers and call it solved — because that’s not actually true. What it will do is walk through what’s really in your control, what isn’t, and what BPA thinks schools and districts should be required to change.
Can a private personal email fix this? Only partly.
You may have seen Proton Mail’s “Born Private” program, which lets a parent reserve a private email address for a child and keep it sealed for up to 15 years, until the child is ready to use it. Proton states that while the reserved inbox remains sealed, it contains no inbox data or activity logs and is not used for profiling. That’s Proton’s own representation about its product, not something BPA has independently tested.
This kind of tool is genuinely useful for one specific purpose: giving your child a personal digital identity that isn’t built around advertising from the very start, for things your family actually gets to choose — a personal inbox for family communication, hobby sign-ups, or accounts they’ll use once they’re older.
- It cannot replace or override a school-issued account that the school requires for Classroom, assignments, or communication.
- It cannot stop a school-required app or platform from collecting data once your child uses it under the school’s account.
- It doesn’t make messages invisible after they leave Proton. Once the address is activated, an ordinary message sent from Proton to Gmail is generally encrypted while traveling between providers, but it is not end-to-end encrypted by default. The recipient’s email provider may therefore be able to access and process its copy.
So: a private personal email is one good piece of a bigger picture, not a substitute for it. BPA isn’t endorsing any single company here — the point is to separate what a personal account can do (protect your family’s own choices) from what it can’t (override a mandatory school system).
Not all “Google” accounts are the same thing
This is the part most families never get explained to them, and it matters more than which email provider you use.
A school-issued Google Workspace for Education account is not the same as an ordinary personal Gmail account, and even within that school account, different parts of it follow different rules.
Google Core Services — Gmail, Calendar, Classroom, Drive, Docs, and a few AI tools like the Gemini app and NotebookLM — are, according to Google’s own published policies, free of ads, and student information in these services is not used to build advertising profiles, sold to third parties, or used to train Google’s AI models. Google specifically requires schools to obtain parental consent before enabling Additional Services for users under 18; it does not impose that same consent requirement on Core Services. Schools still remain responsible for complying with applicable law and their own district policies.
Google Additional Services — things like YouTube or Google Maps — are different. Google requires the school to get parental consent before enabling these for a student under 18. Ads can appear here, though Google says account information tied to K-12 Workspace accounts still isn’t used to target those ads specifically.
Third-party applications — the games, quiz tools, tutoring platforms, monitoring software, and other apps a teacher or district connects to the school account — are not governed by one uniform Google parental-consent rule. Whether consent is required depends on the specific service, your child’s age, applicable federal law (COPPA, FERPA), the district’s contract with that vendor, and district policy. There’s no one blanket answer.
| Type of service | Example | Who mainly controls access | The question worth asking |
|---|---|---|---|
| Google Core Service | Classroom, Drive, Gmail | District administrator | What is enabled, what data is retained, and for how long? |
| Google Additional Service | YouTube, Maps | District administrator | Was under-18 consent actually obtained? |
| Third-party education app | Quiz tool, tutoring platform | District and vendor together | What does the contract allow the vendor to do with the data? |
| General-audience service | A regular consumer website | The service provider and the user | Is this actually covered by school-specific privacy law at all? |
| Device monitoring / filtering tool | Classroom-management or content-filtering software | District | What can staff see, and how long is it retained? |
A word of caution: “no ads” does not mean “no data collection.” Additional Services and third-party apps can still collect account, activity, device, and usage information to operate or improve the product, even when that information isn’t used to target ads at your child.
And one more important caveat: these are Google’s own published policies and contracts, not something BPA has independently audited line by line. Google does report outside security certifications for parts of its program, but that doesn’t confirm every claim, and it definitely doesn’t tell you how your specific district has configured its account. That’s a local question, and it’s one BPA thinks families are entitled to an answer to (more on that below).
The legal protections that already exist — and their real limits
Several laws already apply here. None of them are a complete answer by themselves, but they matter, and knowing what they actually say helps you ask better questions.
FERPA (federal) gives parents the right to inspect their child’s education records and seek amendment or correction of information they believe is inaccurate or misleading — though the school isn’t necessarily required to agree to the change. It does not give parents a blanket right to refuse any school technology or demand every record be deleted. FERPA also allows schools, under specified conditions, to share education-record information with a contractor performing a school function. Those conditions include keeping the contractor under the school’s direct control, limiting the contractor’s use and redisclosure of the information, and requiring the contractor to qualify under the district’s own criteria for a “school official” with a legitimate educational interest — which is exactly why it matters whether your district is actually holding vendors to that full standard, rather than just taking a vendor’s word for it.
COPPA (federal) mainly protects children under 13, and it’s aimed at commercial companies, not schools directly. A school can sometimes provide consent on a parent’s behalf for a service used in the educational context — but not when the company also intends to use the child’s information for an unrelated commercial purpose.
Oregon’s Student Information Protection Act (OSIPA), ORS 336.184, applies to covered operators of services designed and marketed for K-12 school purposes. It prohibits those operators from using covered student information for targeted advertising, building noneducational profiles, or selling the information, and it requires reasonable security practices. Its express deletion requirement is triggered when the school or district requests deletion of information under its control — the law does not create a comparable direct parent-to-vendor deletion process, though contracts or other laws may provide additional rights. It also doesn’t cover everything: it’s mainly aimed at services specifically designed and marketed for K-12 use, not every general-audience website a student might visit while logged into a school account, and it still permits certain uses of information that’s been stripped of anything identifying, including some product-improvement uses.
The pattern across all of these: many of the most consequential operational levers — service configuration, vendor contracting, retention rules, and OSIPA deletion requests — sit with the school district. Families still retain important access, correction, consent, and advocacy rights of their own. That’s not a reason to give up — it’s the reason BPA thinks the right target for pressure is the institution that chose the technology, not just the individual product a family might personally switch to.
What this means, practically
You can’t single-handedly rewrite your district’s technology contracts. But you’re not stuck, either. Two things follow directly from everything above:
- There are real, immediate steps families can take today to reduce unnecessary exposure and keep a school identity from becoming a child’s whole digital identity. (See the companion Family Action Checklist.)
- There are real, specific questions worth putting to your school district, because the district — not any individual vendor’s privacy page — is where the actual answers live: which services are enabled, what’s been consented to, what a third-party app actually receives, and how long any of it is kept. (See the companion “Ask Your District” letter and the formal Oregon public records request, for when a more complete answer is needed.)
None of this requires becoming a lawyer or a network engineer. It requires knowing which questions are actually answerable, and by whom.
If your child already has a school account
If you’re reading this after your child is already enrolled and already using a school account, you haven’t missed a window — most of what matters here is about limiting what happens next, not undoing what’s already occurred.
- Take stock. Identify the school account itself, any school-managed device, and — as best you can tell — which apps or browser extensions are currently connected to that account.
- Stop the login from spreading. Don’t use the school login to create any new personal or optional account going forward.
- Review what’s already connected. For anything linked to the school account, ask whether it’s still actually required.
- Ask the district what’s kept and for how long. Retention and deletion rules apply whether or not you asked about them at signup.
- Ask about removal and alternatives. For anything optional, ask whether it can be turned off and whether an equivalent alternative exists.
- Ask whether the district will request deletion of covered information under its control that is no longer needed. Oregon’s OSIPA requires a covered operator to delete the covered information within a reasonable time when the school or district makes a qualifying request — the law requires the operator to honor that request, though it doesn’t obligate the district to make every deletion request a parent asks for.
- Before the account closes (a school change or graduation), save anything your child is authorized to keep, and ask what happens to the rest.
This isn’t a special track separate from the rest of this guide — it’s the same explainer and the same checklist, just read with “start today, not from scratch” in mind.
What an “equivalent alternative” might actually look like
This guide repeatedly suggests asking whether an equivalent, less intrusive alternative exists. That’s deliberately vague until you know your situation — but here are concrete examples of things families can ask for. None of these is guaranteed in every case; they’re starting points for a conversation with the district, not entitlements the law promises you.
- A district-managed account or device instead of installing management software on a family-owned device.
- Browser-based access instead of installing an application.
- A school-controlled login instead of requiring the student to create their own consumer account.
- An account-free access code or a pseudonymous student identifier, where the activity doesn’t actually require a personal identity.
- A paper, offline, or teacher-submitted version of an assignment.
- A non-AI assignment option, when student work would otherwise be submitted to an AI service.
- Email, text, or a plain webpage instead of a mandatory team- or club-communication app.
Everything above is about preventing future exposure. If something has already gone wrong — a child’s account looks compromised, sensitive information has been exposed, a monitoring tool has captured something concerning, information was shared with a service that shouldn’t have received it, an app’s output contributed to a disciplinary decision, or the district or a vendor has reported a breach — the immediate steps are a little different:
- Preserve what you have: screenshots, notices, dates, and who you’ve already talked to.
- Stop any further optional disclosure while you sort out what happened.
- Contact the district’s privacy or technology office in writing, and ask what incident-response process applies.
- Ask directly whether this is being treated as a reportable breach and what notification obligations apply.
- If the harm to your child is serious — financial, reputational, safety-related, or otherwise significant — this is a point to seek qualified legal help rather than relying on this guide alone.
A quick note on sports, clubs, and other non-district activities
Everything above concerns technology the school district itself operates or requires. A private sports league, booster club, independently run club, or volunteer-run team communication tool is often not subject to the same FERPA rules, public-records access, or district control described here — it may be its own separate organization with its own (or no) privacy practices. If your family is navigating a privacy concern with one of these, it’s worth first figuring out whether you’re dealing with the district or with an independent organization, since the tools in this guide mainly apply to the former. (See the companion “Ask Your Team, Club, or Program” email for that situation specifically.)
When any new account, app, or sign-up form shows up for your child, four questions cover most of what matters:
- Is this required, or optional?
- Which category does it fall into — Google Core Service, Google Additional Service, third-party app, or something else entirely?
- What information does it receive, and who approved it?
- What happens if consent is withheld or the service is declined — is there an equivalent alternative?
Sources
- Proton’s “Born Private” program: proton.me/blog/born-private
- Proton’s explanation of encryption for messages sent to non-Proton recipients: proton.me/support/proton-mail-encryption-explained
- Google Workspace for Education Core/Additional Services and AI-training/advertising policies: edu.google.com/our-values/privacy-security/frequently-asked-questions
- U.S. Department of Education, FERPA guidance for parents and the “school official” exception (lists all four conditions): studentprivacy.ed.gov/faq/who-school-official-under-ferpa
- Federal Trade Commission, COPPA guidance concerning schools: ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions
- Oregon Student Information Protection Act, ORS 336.184 (official Oregon Legislature text): oregonlegislature.gov/bills_laws/ors/ors336.html
- Oregon Public Records Law, ORS 192.311–192.478, including response timelines (official Oregon Legislature text): oregonlegislature.gov/bills_laws/ors/ors192.html
- Oregon Department of Justice guidance on local-government public-records appeals: doj.state.or.us/oregon-department-of-justice/public-records