Utah HB 55: 5 Things K-12 Schools Need to Know About New EdTech Privacy Requirements

Utah HB 55 strengthens edtech privacy requirements for K-12 schools. Here are five key takeaways on vendor compliance, contracts, student data deletion, and ongoing technology vetting.

Utah HB 55: 5 Things K-12 Schools Need to Know About New EdTech Privacy Requirements

Utah has strengthened its requirements for how schools and education technology vendors handle student data privacy.

HB 55, Privacy Compliance for Education Technology Vendors, passed during Utah’s 2026 legislative session and took effect July 1, 2026. The law adds new requirements affecting edtech vendor compliance, contracts, student data deletion, and how schools respond when certain privacy violations occur.

For Utah school districts and charter schools, the important takeaway is that edtech privacy compliance does not necessarily end when a tool is initially reviewed and approved.

Here are five things Utah schools should know about HB 55.

1. Certain Vendor Privacy Violations Can Require Contract Termination

One of the most significant provisions of HB 55 concerns what happens when an education technology vendor violates student privacy requirements.

When an LEA discovers a covered violation, the LEA must notify the third-party contractor.

The vendor then has an opportunity to remedy the violation and establish a process designed to prevent the violation from occurring again.

If the vendor fails to do so, the LEA must terminate the contract within 30 days after providing notice.

This creates an important operational consideration for Utah schools: identifying a privacy problem with an edtech vendor may now trigger specific responsibilities beyond documenting the concern.

Schools need a process for identifying applicable violations, notifying vendors, tracking remediation, and determining whether further action is required.

2. EdTech Contracts Need to Address Privacy-Related Termination

HB 55 also affects the contracts Utah schools enter into with education technology vendors.

Contracts must account for the LEA's obligation to terminate an agreement when the conditions established under the law are met.

Importantly, when termination is required under these provisions, the contract must protect the LEA from financial consequences associated with that termination.

That includes provisions preventing the contractor from imposing a termination fee, seeking damages, or creating other financial liability for the LEA because the contract was terminated as required by law.

For Utah schools, this makes student privacy an important part of both edtech vetting and contract review.

Districts should consider whether their current vendor agreements contain language consistent with the new requirements and whether contract templates need to be updated for future purchases.

3. Vendors Must Delete Student Data When Certain Contracts End

HB 55 also strengthens requirements surrounding student data after an edtech relationship ends.

When a contract is completed and is not renewed, the third-party contractor generally must delete personally identifiable student data obtained through the relationship unless the student or parent has provided the consent required for the vendor to retain it.

This is an important part of the student data lifecycle that can easily be overlooked.

Schools frequently focus on what information an application collects while students are actively using it. But privacy responsibilities don't necessarily disappear when the district stops using the application.

Utah schools should have a process for confirming what happens to student information when an edtech contract expires or a product is discontinued.

4. Suspected Vendor Violations Can Lead to State Review

HB 55 also increases oversight of education technology privacy compliance.

The Utah State Board of Education is required to establish a process through which suspected violations involving third-party contractors can be reported to its student data privacy team.

Reports can undergo an initial credibility review, and credible concerns may result in additional compliance activity, including an audit or investigation.

This creates another reason for schools to maintain clear documentation around their edtech decisions.

Districts should be able to understand and document why a technology was approved, what student information it handles, what contractual protections are in place, and whether the vendor continues to satisfy applicable requirements.

5. EdTech Privacy Vetting Is Becoming an Ongoing Process

Perhaps the biggest practical takeaway from HB 55 is that edtech privacy compliance cannot always be treated as a one-time checklist.

A vendor may satisfy a district's requirements when an application is first approved, but circumstances can change.

Privacy policies change. Vendors add new subprocessors. Advertising and tracking technologies change. Products introduce AI functionality. Data practices evolve. Contracts expire.

And under HB 55, certain compliance problems can require action from the school itself.

That makes ongoing visibility into edtech vendor practices increasingly important for Utah schools.

What Should Utah Schools Do Now?

With HB 55 now in effect, Utah school districts and charter schools should consider reviewing their existing EdTech governance processes.

That includes:

  • Reviewing edtech contract templates for the required termination protections.
  • Confirming procedures for deleting student data when vendor relationships end.
  • Establishing a process for documenting and responding to applicable vendor privacy violations.
  • Maintaining records of vendor privacy and contract reviews.
  • Reassessing previously approved applications when vendor practices or legal requirements change.

Schools should also consider how these requirements fit alongside their existing obligations under Utah's Student Data Protection Act and applicable federal requirements such as FERPA and COPPA.

Keeping Up With EdTech Compliance

HB 55 reflects a broader change occurring across K-12 education.

Schools are increasingly responsible not simply for selecting useful technology, but for understanding how hundreds or thousands of applications handle student information — and determining whether those practices continue to comply with changing privacy, AI, security, and accessibility requirements.

EdPrivacy helps K-12 schools evaluate edtech applications and websites for student data privacy, AI risk, and accessibility in one platform.

Instead of manually reviewing privacy policies and vendor practices tool by tool, districts can use EdPrivacy to identify potential compliance concerns, understand why they matter, and make more informed technology decisions.

For Utah schools, that can help turn edtech compliance from a periodic manual review into a more consistent, manageable process.

Learn more about EdPrivacy and instantly review an edtech tool at edprivacy.com.

This article is provided for informational purposes and does not constitute legal advice. Schools should consult legal counsel regarding the application of HB 55 to their specific circumstances.

Share this post