The surveillance apparatus in the United States has dramatically expanded over the past few decades despite widespread recognition of its threat to American democracy. Especially following 9/11, the government has increasingly sacrificed Americans’ privacy ostensibly for safety purposes, including federal agencies spending millions of dollars on surveillance technologies to scale immigration enforcement efforts. Though this type of investment isn’t new, rapid technological development and the Trump administration’s heightened spending across security domains creates new and urgent policy questions that require thoughtful consideration and action.
These deliberations are especially important as school districts adopt similar surveillance practices: Administrators are increasingly granting companies access to students’ data in exchange for tools that purport to share insights into their performance and well-being. Personal and school-issued devices now come loaded with software and apps that continuously monitor children’s online activity and collect data, which are only growing more powerful in the age of artificial intelligence (AI). And even when these tools have no initial explicit surveillance purpose, loopholes still allow law enforcement and data brokers to procure sensitive information without consent or transparency about who is seeking the data, why they are seeking it, and how it is being used.
The digital dragnet Americans face today presents immense risks, especially to vulnerable populations who may face the weaponization of data collection. Grappling with this reality requires us to examine the unique risks students face by expanding surveillance practices into schools. Local and national conversations about children’s digital health and safety must acknowledge the risks inherent in expanded monitoring and surveillance without robust transparency and consider what guardrails can protect both children’s data and safety.
Data collection in the classroom
The average American student’s digital footprint has exploded in the 21st century, and the commercialization and commodification of that data creates unique challenges to ensure their privacy and safety.
A child’s digital trail often starts very early. A 2025 Common Sense Media survey found that 40% of American children have a tablet by age 2 and 23% have a cellphone by age 8. Every digital interaction creates a new data point that must be secured and protected. Even seemingly innocuous online activities, like streaming a movie, can create data that is tracked and used by companies. “When you watch Netflix, Netflix watches you,” warned Texas Attorney General Ken Paxton in a recent lawsuit against the streaming giant. Netflix vehemently denied the claims, but Paxton’s complaint that logging data on clicks and even where a young user might linger on the site constitutes a privacy violation illuminates a legal gray area.
Data collection within school walls is similarly complex. Technology supports teaching, learning, and school operations in many ways, including through learning management systems to organize classroom assignments and tasks, assessment tools to actively and passively gather real-time insights, curriculum platforms to share content, and a plethora of AI tools. According to a recent report, school districts and individual students accessed an average of 2,982 and 48 distinct edtech tools, respectively, during the 2024-25 school year. Each of these tools may introduce a new vendor, user agreement, and database to manage, and it can be costly and time consuming for districts to thoroughly and critically assess these tools as part of a procurement process. Reporting shows educators and administrators now receive dozens of emails daily from edtech companies, further complicating their ability to evaluate how each prospective tool might impact a student’s learning, well-being, privacy, and safety.
Increasingly, districts are also employing technologies with an explicit goal of tracking student behavior and movement. Student screen monitoring, web content filtering, and tracking of eye and body movements may seem helpful, but various instances of students being wrongly profiled, disciplined, or even arrested for their online behavior demonstrate the tension in this approach. Similarly, digital hall passes offer time-bound authorization to move around the school and data that turn “behavioral trends into AI-driven policies.” According to one survey, 88% of teachers report that their school uses some type of student activity monitoring technology, and a second shows 42% report that such monitoring continues off campus. For instance, Chicago Public Schools has monitored students’ social media accounts for “worrisome online behavior” that can trigger consequences at school.
Parents and districts may have good intentions when they turn to technology companies to gather information on students’ performances or assess behavior and well-being, but evidence suggests that a “more is more” approach to data collection at school can undermine health and safety goals: It can increase the risk of mishandling data, prematurely or unfairly involve law enforcement, inadvertently provide data on students to officers or immigration enforcement agents, or simply enable companies to use kids’ data to maximize engagement (and profits).
Districts lacking clear responsible data use policies or capabilities to thoroughly assess technology user agreements may unintentionally leave data exposed to third parties and law enforcement. This is especially a concern as the Trump administration’s immigration enforcement efforts carry out the “largest deportation operation in American history.” Immigration enforcement agencies expanding data collection practices and loosening rules governing agents’ access to schools further complicates student privacy. For example, a recent investigation revealed that police departments accessed school districts’ security footage to aid immigration enforcement efforts, in some cases without the districts’ knowledge, demonstrating how illusory student privacy can be as technology advances.
Privacy and safety implications also vary depending on personal or ancestral identities, and there is ample evidence that marginalized students are more susceptible to targeting. There are several recorded instances of immigration officers contacting students after their activity was flagged by monitoring software. This type of surveillance could further exacerbate students’ fears of being identified by immigration officials, as research has linked heightened immigration enforcement to chronic absenteeism, poorer mental health, lower test scores, and reduced college enrollment, especially for Latino and English learner students.
LGBTQ+ students also face unique risks, especially as more states pass legislation that requires schools to reveal students’ gender identity or sexuality to parents. Monitoring software and content safeguards frequently flag queer resources or content as inappropriate or sexually explicit and can thus lead to more alerts being issued to districts or law enforcement. This is especially concerning given that LGBTQ+ students are disproportionately at risk of attempting self-harm or suicide.
Research from the Center for Democracy and Technology reveals similar implications for students with disabilities, who are disproportionately subject to monitoring software—a pattern that may deepen their already-heightened rates of interaction with law enforcement. The same concerns exist for students of color, who are already disciplined at greater rates, especially given that schools predominately attended by Black and brown students are more likely to use surveillance technologies.
Despite these risks, laws and policies have struggled to keep pace with technology. A rapidly expanding surveillance economy, fueled by data produced from fast-evolving technologies, adds urgency to protecting children’s safety and privacy and makes it harder to do. Assessing how existing student privacy and safety laws interact with a child’s expansive data footprint can help illuminate areas to improve our policy approach.
Risks persist despite some protections
Though the U.S. lacks comprehensive privacy protections, multiple federal laws already govern children’s data and apply to various forms of digital surveillance. These laws include the Family Educational Rights and Privacy Act (or FERPA, passed in 1974), the Children’s Online Privacy Protection Act (or COPPA, passed in 1998 and updated via rulemaking on two occasions since), and the Protection of Pupil Rights Amendment (enacted in 1978 and last amended during the George W. Bush administration).
FERPA and COPPA remain the primary federal policy levers on privacy and digital safety for children and students, though they should be seen as the floor and not the ceiling. FERPA outlines how educational institutions or agencies that receive federal funding may or may not use or share students’ personally identifiable information (PII) from students’ education records but does not discuss how data is collected. COPPA sets forth rules on data collection for children under 13 by requiring website operators and online service providers to obtain “verifiable” parental consent before collecting, using, or disclosing personal information about a child (with some exceptions) and allowing parents to revoke their consent and delete information about their children. COPPA’s latest interpretation, which took effect in 2025, added opt-in consent requirements for targeted advertising and implemented restrictions on data retention, among other changes. Although COPPA does not apply to governmental entities or nonprofits like public and private K-12 schools, it does apply to for-profit vendors that provide their online platforms.
Staggering amounts of data are collected on children at home and at school, and the existing laws struggle to keep pace with unforeseen abuses: COPPA does not protect teenagers’ data, and neither FERPA nor COPPA comprehensively mandate data minimization practices—only collecting, using, and retaining the least amount of data necessary. In fact, one study found most education applications still exposed students’ data despite modest enforcement or protections, which allows companies to create detailed profiles on children’s online behavior that can follow them for decades and be used for targeted advertising or other algorithmic recommendations.
Consequently, none of these laws fully protect against the disclosure of students’ data. Some information is not sourced from students’ educational records—which FERPA defines as a record “directly related to a student” and “maintained by an educational agency or institution or party acting on behalf of the agency or institution”—and is thus excluded from FERPA protections. FERPA also permits disclosure without any consent in some situations. For instance, FERPA allows school officials to access education records without consent, provided that the school has determined the requesting officials have a “legitimate educational interest,” a highly subjective term that schools and agencies handling such information are required to define and share with parents annually. Further, FERPA permits—but does not require—the disclosure of PII from education records for a variety of other purposes: to state and local educational authorities in connection with audits, to state and local officials concerning the juvenile justice system, in response to a health or safety emergency, and to comply with a judicial order or lawfully issued subpoena.
Moreover, some data worth safeguarding may fall outside FERPA and COPPA’s protections altogether. For example, data may not be “from an education record,” such as metadata collected by online platforms. Similarly, videos of school grounds will constitute an education record only under specific circumstances. This murkiness is where real safety risks to children lie. A recent example involves Flock Safety, a technology company that markets its products and services to schools with a promise of continuous monitoring and early threat detection. Reports have found that some of Flock’s user agreements stipulated that the company can share video footage captured by their equipment with a simple and warrantless request, and recent reporting revealed this data was accessed by law enforcement agencies to aid immigration enforcement. Flock has stated that such access is controlled by customers, and earlier this year, the company added a feature for agencies to toggle off all federal sharing.
Murkier still is metadata that doesn’t constitute PII or a student record but still could be used to train AI models, such as data that tracks how long a student lingers on a specific page. Simply deleting the data after it has already helped train the model may not protect students, and no clear guardrails currently exist to prevent this.
Ongoing attempts by Congress to modernize children’s safety and privacy laws through a package of bills don’t address these loopholes or the broader societal shift toward greater surveillance. While bills like COPPA 2.0 (which amends the original law) expand the definition of personal information, include a broader definition of biometric identifiers, and restrict profiling further, the package does not include a fundamental “duty of care” requiring tech companies to build safe-by-design online platforms. This puts additional pressure on states, districts, principals, teachers, and parents to keep kids safe.
Some states have attempted to fill these policy gaps, including California, which passed the first comprehensive state law on student privacy over 10 years ago. Its Student Online Personal Information Act (SOPIPA) prohibits edtech vendors from using targeted advertising with any information that was acquired because of the use of that operator’s product, using information to amass a profile about a K-12 student beyond an educational purpose, selling students’ information, or disclosing covered information, among other requirements. At least 20 other states have since passed similar protections.
Minnesota has taken another approach, protecting against surveillance activities on school-issued devices. Its 2022 law prohibits a government entity or technology provider from accessing location-tracking features, any audio- or visual-receiving or recording features, and any other student interactions with a school-issued device, including web-browsing activity. Yet, these protections have a few notable exceptions for nondisclosure, including when activity is necessary to respond to an “imminent threat” or comply with federal or state law.
Other states have attempted to directly address how AI affects data collection. California considered amending its existing laws to prevent companies from using student data to train AI models, and Idaho clarified that its existing student data privacy laws apply to generative AI and require districts to adopt a policy that “include[s] safeguards for student privacy” and data security, among other requirements.
These risks are unlikely to be remedied amid the Trump administration’s largely deregulatory agenda, and especially as parts of the U.S. Department of Education—including its Office for Civil Rights, Office of Educational Technology, and Student Privacy Policy Office—are moved elsewhere, shuttered, or redeployed.
What should we make of this?
A student’s data footprint is vast and spans data collected by their personal devices, school-issued devices, and schools using tools with a stated goal of keeping learners and educators safe. Yet, it is increasingly clear how, in practice, this data can be used for several other purposes, lead to increased interactions between students and law enforcement, and place marginalized students in even more vulnerable positions.
Some lawmakers have fully recognized these risks, yet protections remain disparate across the country. Districts in many states continue to use tools without fully understanding their risks or having a clear perspective on student privacy in the age of AI and increasing state surveillance. It is necessary, however, to discuss how students can be best protected and how data collected on children may follow them into the future. Though software may put some parents or teachers at ease by giving them visibility into possibly concerning behavior, it may sacrifice their children’s well-being in the process, which undermines any safety or security goals.
This demonstrates how data privacy, minimization, and sovereignty are foundational to any safety protections schools or states might consider—protections that could be strengthened through measures already under consideration at the state and federal level.
Surveillance harms students in concrete ways. In conversations with students, the American Civil Liberties Union (ACLU) found that classroom surveillance “negatively impacted their interactions with school staff, communications with friends, activity online and on social media, what groups or clubs they consider joining, and how they feel at school broadly.” Other research shows students may not fully express themselves when they are aware of such monitoring.
As we’ve become more excited and more skeptical about technology, the boundaries of what we’re willing to accept have also changed. A central question is whether or not we want our children to live in a world in which they can expect to be monitored, observed, and assessed at all times. It may feel like the right thing to do to protect our children’s safety, but safety—or a feeling of safety—may cost our children their sense of agency and self-determination.
As former Sen. Robert Byrd (D-W.V.) said in response to President George W. Bush’s warrantless surveillance on U.S. citizens in 2006: “The question is not, is Big Brother watching? The question is, how many big brothers have we?”
The Brookings Institution is committed to quality, independence, and impact.
We are supported by a diverse array of funders. In line with our values and policies, each Brookings publication represents the sole views of its author(s).
Commentary
As surveillance grows, student privacy protections lag
September 3, 2026