K-12 App & Website Vetting Checklist: Proactively Protecting Student Data Privacy
School districts are being asked to approve more apps, websites, extensions, AI tools, and online resources than ever before.
Some requests come through official channels. Others start informally when a teacher finds a helpful classroom tool, a curriculum team recommends a supplemental website, or a vendor offers a free trial. Many of these tools are useful. Some are excellent. But even well-intentioned resources can create privacy, security, accessibility, and compliance risks if they are used before the district understands what data is being collected and how that data is being used.
For the school district administrator responsible for vetting online resources, this creates a difficult balancing act.
You are expected to support innovation, respond quickly to staff, protect student data, comply with federal and state privacy requirements, manage contracts, reduce duplication, evaluate accessibility, and keep track of hundreds or even thousands of digital resources across the district.
That is not a small task.
A single app approval may require reviewing the privacy policy, terms of service, student data practices, third-party sharing, security controls, advertising language, accessibility documentation, age restrictions, and contract requirements. Multiply that by the number of schools, departments, grade levels, and teacher requests in a district, and it becomes clear why informal or manual review processes often break down.
This is why districts need a proactive, documented, and repeatable vetting process.
The goal is not to say “no” to technology. The goal is to make better decisions before student data is exposed.
Below is a practical K-12 app and website vetting checklist designed for district administrators, technology leaders, curriculum teams, privacy officers, and anyone responsible for reviewing digital resources before they are approved for classroom or district use.
1. Start With the Purpose of the Resource
Before reviewing privacy policies or contract terms, start with a basic question: Why does the district need this resource?
Every app or website should have a clear instructional or operational purpose. Is it being used for classroom instruction, assessment, intervention, enrichment, communication, productivity, special education, professional learning, or district administration? Is it replacing an existing tool, supplementing instruction, or duplicating something the district already pays for?
This first step is important because districts often accumulate digital tools over time without a clear inventory or approval structure. A teacher may request a new math app without knowing that another department already approved a similar resource. A school may begin using a free website that collects student information even though the district already has a contracted solution that meets the same need.
Do not begin with the vendor’s marketing claims. Begin with the district’s need. If the purpose is unclear, the review should pause until the requester can explain who will use the resource, why it is needed, and what problem it solves.
2. Determine Whether Students Will Use It Directly
The next question is one of the most important: Will students use the app or website directly?
There is a major difference between a teacher using a tool to plan a lesson and a student logging into a platform, submitting work, uploading files, answering questions, participating in chats, or being tracked through a persistent identifier.
If students will use the resource, especially students under age 13, the review should be more rigorous. The district needs to understand whether students will create accounts, whether single sign-on will be used, whether classroom rosters will be shared, and whether the vendor will collect personally identifiable information.
A practical approval framework should separate resources into clear use categories. For example, a tool may be approved for staff use only, approved for student use, approved only without student accounts, or approved only if no student personally identifiable information is entered.
This distinction helps prevent one of the most common problems in K-12 technology management: a tool that is safe for teacher planning is later used with students in a way the district never reviewed.
3. Understand What Data Is Collected
Districts cannot protect student data unless they know what data is being collected.
Some data collection is obvious. A vendor may collect student names, email addresses, school names, grade levels, assignments, assessment results, uploaded documents, or classroom roster information. Other data collection is less visible, such as IP addresses, device identifiers, cookies, usage logs, search activity, click behavior, metadata, analytics data, audio, video, images, or behavioral inferences.
This is where many reviews become complicated. A website may appear simple on the surface but still include third-party analytics, embedded media, advertising scripts, tracking pixels, or social media integrations. A free app may not charge the district money, but it may still collect valuable data from users.
Administrators should look for data minimization. The vendor should collect only the information necessary to provide the educational service. If a basic classroom tool requires extensive student profile information, broad device access, or permissions unrelated to the instructional purpose, that should raise concern.
A good internal question is: Would we be comfortable explaining this data collection to a parent, board member, or superintendent?
If the answer is no, the district should slow down before approving the resource.
4. Confirm How the Data Is Used
Knowing what data is collected is only half of the review. The district also needs to know how the data is used.
This is often where vendor language becomes vague. Privacy policies may say data is used to “improve services,” “personalize the experience,” “support business operations,” “analyze trends,” or “develop new features.” Those phrases may sound harmless, but in the K-12 context they require careful review.
District administrators should determine whether student data is used only to provide the educational service requested by the district. Student data should not be used for targeted advertising, behavioral profiling, unrelated marketing, resale, or product development that falls outside the district-approved purpose.
This issue is becoming even more important as vendors add AI features. Districts should specifically ask whether student prompts, uploaded files, chats, assessment data, or other student information are used to train, fine-tune, or improve AI models.
A resource should not be approved for student use unless the district understands and accepts the vendor’s data use practices.
5. Review Third-Party Sharing and Subprocessors
Most online tools rely on other companies to operate. These may include cloud hosting providers, analytics services, payment processors, customer support platforms, authentication tools, video services, AI providers, or advertising networks.
That means the district is not only reviewing the main vendor. In many cases, it is also reviewing the vendor’s ecosystem.
Administrators should look for a clear list of subprocessors or third-party providers. The vendor should explain what data is shared, why it is shared, and whether those third parties are allowed to use the data for their own purposes.
This is a practical pain point for districts because third-party sharing can be buried deep inside privacy policies. It is also an area that can change over time. A vendor may add a new AI provider, analytics service, or advertising partner after the district initially approves the product.
As a best practice, districts should document whether third-party sharing is acceptable and whether the vendor must notify the district before adding new subprocessors.
6. Look Closely at Advertising and Tracking
Advertising and tracking are among the most important issues in student data privacy reviews.
A website may claim to be educational while still displaying ads, using third-party ad networks, collecting persistent identifiers, or allowing tracking across websites. This is especially concerning when students are the users.
District administrators should look beyond broad claims like “we do not sell student data.” That statement alone does not answer whether the resource uses cookies, pixels, analytics tools, retargeting, or behavioral advertising. A vendor can say it does not sell data while still using tracking technologies that are inappropriate for student use.
The practical recommendation is to treat advertising and tracking as a high-priority review area. If a resource is student-facing and includes advertising, social media pixels, behavioral tracking, or retargeting, the district should carefully consider whether it should be approved at all.
At minimum, approval should clearly state any restrictions, such as “not approved for student use” or “approved for staff use only; do not enter student data.”
7. Evaluate Security Practices
Privacy promises are not enough if the vendor cannot protect the data.
Security review does not always need to be complicated, but the district should understand the basics. Does the vendor encrypt data in transit and at rest? Does it use secure authentication? Does it support role-based access controls? Are administrator accounts protected? Are access logs maintained? Does the vendor have an incident response process? What happens if there is a breach?
For higher-risk resources, especially those collecting student records, assessment information, health-related information, communications, or large amounts of roster data, districts may need additional documentation such as a SOC 2 report, ISO certification, penetration test summary, or written security questionnaire.
The level of review should match the risk. A low-risk staff-only website does not need the same review as a districtwide student platform integrated with the student information system. But any vendor collecting student data should be able to explain how that data is secured.
8. Confirm Data Retention and Deletion
One of the most overlooked parts of vendor review is what happens to the data later.
Many districts focus on whether a tool can be used today, but student data may remain with a vendor long after a teacher stops using the app, a contract expires, or a free trial ends.
Administrators should determine how long data is retained, whether the district can request deletion, what happens when the agreement ends, how backups are handled, and whether parent or eligible student access and correction requests can be supported through the district.
The district should also consider internal cleanup. If a tool is no longer used, it should not remain indefinitely on the approved list with active student accounts and stored data.
A proactive privacy program should include periodic review of expired, unused, duplicate, or abandoned resources.
9. Make Sure the Right Contractual Protections Are in Place
For resources that collect student data, public terms of service are often not enough.
Districts may need a data privacy agreement, contract, addendum, or other written terms that clearly define the vendor’s obligations. The agreement should address data ownership, authorized use, advertising restrictions, redisclosure, security, breach notification, retention, deletion, subcontractors, parent and district rights, and compliance with applicable student privacy laws.
This is an area where administrators often feel pressure. Teachers may want to use a resource immediately. Vendors may say their standard terms are sufficient. Free tools may not offer customized agreements. But if the resource collects student data, the district needs to decide whether the legal and privacy protections are adequate before approval.
A practical recommendation is to create approval pathways. Low-risk staff-only resources may require a lighter review. Student-facing tools that collect personal information should require stronger documentation and, where appropriate, a district-approved agreement.
10. Review Age Appropriateness and Terms of Use
Not every educational-looking website is appropriate for every grade level.
Some tools prohibit use by children under 13. Others require parental consent. Some allow school consent. Some include public profiles, comments, chats, direct messaging, user-generated content, or interaction with unknown users.
Administrators should carefully review whether the resource is appropriate for the intended age group and use case. A tool may be acceptable for high school students but not elementary students. A resource may be appropriate for teacher demonstration but not for student account creation. A website may be safe for research but not for students to post content publicly.
The approval decision should reflect these distinctions. Instead of a simple yes or no, districts should document the conditions under which the resource may be used.
11. Review AI Features Separately
AI has changed the vendor review process.
Even if an app or website was previously approved, the addition of AI features may require a new review. AI tools may collect prompts, chats, uploads, images, audio, student work, or assessment data. They may generate feedback, summaries, recommendations, classifications, or other outputs that influence instruction or decision-making.
District administrators should ask whether the product uses AI, whether students interact directly with AI, whether data is used to train or improve models, whether third-party AI providers are involved, and whether AI features can be disabled.
The district should also consider accuracy, bias, explain-ability, and human oversight. AI-generated content can be incorrect or inappropriate, and AI should not be used for important student decisions without appropriate review by qualified staff.
AI does not automatically make a resource unacceptable, but it does change the risk profile. Districts should treat AI as a specific review category, not as a minor product feature.
12. Include Accessibility in the Vetting Process
Accessibility should be reviewed before a resource is approved, not after staff or students encounter barriers.
Districts should ask whether the vendor provides a current VPAT or Accessibility Conformance Report, whether the product aligns with WCAG standards, whether it works with screen readers, whether it supports keyboard navigation, whether videos are captioned, and whether accessibility issues can be reported and remediated.
This is especially important for resources that will be used districtwide or required as part of instruction. If a tool is not accessible, the district may need an alternative plan or may need to delay approval until the vendor can address the issue.
For administrators, the key recommendation is to make accessibility part of the standard review workflow. Privacy, security, and accessibility should be evaluated together because all three affect whether a digital resource can be responsibly used in schools.
13. Assign a Clear Approval Status
A vetting process is only useful if the final decision is clear.
Too often, districts complete a review but fail to communicate the result in a way that teachers and staff can easily understand. The result is confusion. Some staff assume a tool is approved because someone reviewed it. Others use a resource with students even though it was only approved for staff planning. Some continue using tools that were denied, expired, or never fully reviewed.
Each resource should have a clear approval status. Common statuses include approved for student use, approved for staff use only, approved with restrictions, not approved, pending contract, pending vendor response, requires parent consent, duplicate resource available, or vendor refused to provide sufficient information.
The status should include plain-language guidance. For example: “Approved for grades 6-12 using district single sign-on,” or “Staff use only; do not enter student information,” or “Not approved for student use due to advertising and tracking concerns.”
Clear statuses reduce risk and make the process more useful for educators.
14. Communicate Decisions and Make the Process Easy for Staff
One of the biggest pain points for districts is staff adoption of the vetting process.
If the process is confusing, slow, or hidden, teachers may work around it. If the approved list is hard to search, staff may not use it. If request forms disappear into a black hole, teachers may assume the district is simply saying no.
District administrators should make the process as simple and transparent as possible. Staff should know where to search for approved resources, how to request a new app or website, what information is needed, and how long the review may take.
It also helps to explain the reason for the process. Most teachers are not trying to create privacy risk. They are trying to help students. When districts frame vetting as a way to protect students and support responsible technology use, staff are more likely to participate.
A good system should help teachers answer three questions quickly: Is this tool approved? Can I use it with students? Are there any restrictions?
15. Monitor Approved Resources Over Time
Approval is not the end of the process.
Apps and websites change constantly. Vendors update privacy policies, add AI features, change subprocessors, introduce advertising, modify terms of service, expand data collection, or change security practices. A resource that was acceptable two years ago may not meet the district’s current requirements.
Districts should periodically review approved resources and monitor changes over time. This includes contract expiration dates, policy updates, security incidents, accessibility changes, teacher feedback, duplicate tools, and resources that are no longer actively used.
This is where many districts struggle because ongoing monitoring requires time and organization. But without it, approved lists become stale and unreliable.
A proactive vetting program should be treated as a living process, not a one-time checklist.
Practical Recommendations for District Administrators
For district administrators tasked with vetting online resources, the challenge is not a lack of concern. Most districts care deeply about protecting student data. The challenge is capacity.
Manual review takes time. Vendor policies are long and often unclear. Teachers need answers quickly. Legal requirements vary by state. AI features are changing rapidly. Accessibility documentation can be incomplete. Free tools may not respond to contract requests. Meanwhile, the number of digital resources used across a district continues to grow.
That is why districts should focus on building a process that is repeatable, documented, and easy to follow.
Start by creating a single intake process for app and website requests. Require requesters to explain the purpose, intended users, grade levels, whether students will log in, and whether student data will be entered. Then use a consistent review framework to evaluate privacy, security, contracts, accessibility, AI, and instructional need.
Next, create clear approval categories. Not every resource needs the same level of review, but every resource should have a documented decision. A staff-only tool should not be treated the same as a student-facing platform that collects roster data. A free website with advertising should not be treated the same as a contracted districtwide instructional system.
Districts should also maintain a public or internal approved resources list that staff can actually use. The list should be searchable, current, and written in plain language. Teachers should not have to interpret legal terms to understand whether a resource is approved for student use.
Finally, district leaders should recognize that proactive vetting reduces future risk. It may take time up front, but it can prevent larger problems later, including parent complaints, data exposure, contract disputes, accessibility concerns, inconsistent classroom practices, and loss of trust.
Final Thoughts
Protecting student data privacy is no longer something districts can manage informally.
The number of apps, websites, extensions, AI tools, and online resources used in schools has grown too large. The risks are too significant. The expectations from parents, regulators, boards, and communities are too high.
A strong vetting process helps districts make better decisions before student data is collected, shared, retained, or exposed. It gives teachers a clear path to request tools. It gives administrators documentation to support decisions. It gives families more confidence that the district is taking student privacy seriously.
Most importantly, it moves the district from reactive problem-solving to proactive protection.
For school district administrators responsible for reviewing online resources, that shift matters. Because the best time to protect student data is before an app or website is approved for use.
