Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

What EdTech Companies Can Learn From FTC’s Recent Enforcement Action

Contributors

Anas Baig

Product Marketing Manager at Securiti

Adeel Hasan

Sr. Data Privacy Analyst at Securiti

CIPM, CIPP/Canada

Listen to the content

This post is also available in: Arabic

Introduction

The Federal Trade Commission (FTC) doesn’t shy away from enforcing actions against organizations that are violating laws put in place to protect the privacy of individuals.

On May 22, 2023, the Federal Trade Commission (FTC) announced a proposed order against Edmodo, an educational technology platform, for violations of the Children’s Online Privacy Protection Act (COPPA) Rule and Section 5 of the Federal Trade Commission Act (FTC Act). On June 28, 2023, Edmodo settled with the Department of Justice and the Federal Trade Commission, agreeing to a permanent injunction and a $6 million civil monetary penalty. However, the monetary penalty is suspended due to the company’s inability to pay as it shut down its operations on September 22, 2022.

Background

As per the FTC’s complaint, until its closure of business in September 2022, Edmodo offered a platform for virtual classes to schools and teachers in the United States and collected the personal information of students (e.g., name, email address, date of birth, phone number and persistent identifiers), which it used to provide advertisements. The organization allegedly violated the COPPA Rule by:

  1. failing to provide direct notice to parents of its information practices;
  2. failing to obtain verifiable parental consent prior to collecting, using, or disclosing children's personal information;
  3. retaining personal information collected online from children for longer than reasonably necessary to fulfill the purpose for which the information was collected. (COPPA prohibits storing children's personal information for any longer than is reasonably required to achieve the intended goal);
  4. failing to adequately disclose to the schools or the teachers what information the company collected and how they could go about obtaining parental consent; and
  5. relying on the consent of the schools or teachers for the collection of personal information which was used for non-educational purposes.

Additionally, the organization violated the FTC Act by unfairly requiring schools to follow the COPPA Rule on its behalf without providing them with the necessary information or assistance to do so. Online businesses and websites targeting children under the age of 13 are required by the COPPA Rule to inform parents about the personal information they collect and to obtain verifiable parental consent before doing so.

Enjoinments Issued to Edmodo

Even though Edmodo has ceased operations, its settlement with the Department of Justice and the Federal Trade Commission enjoins it from the following, sending a clear message regarding the expectations from the organizations and the importance of ensuring compliance with applicable regulations:

  • Collection of personal information from children in a manner that violates the COPPA Rule;
  • Retention of children’s personal information for longer than reasonably necessary to fulfill the purpose for which it was collected;
  • Collection of more personal information than reasonably necessary for a child to participate in any activity; and
  • Deletion of personal information improperly collected from children under age 13.

Notably, the FTC also requires Edmodo to delete models or algorithms developed using personal information collected from children without verifiable parental consent or school authorization. With the increasing use of artificial intelligence by businesses, it is crucial for organizations to comply with the applicable laws while collecting and using data for training their algorithms.

How to Become COPPA Compliant

To comply with COPPA and the FTC Act, organizations, particularly Edtech in this case, must adhere to a set of guidelines and best practices designed to protect the privacy and personal information of children under the age of 13. These consist of the following:

Stay Informed about Relevant Laws and Regulations

Be informed about any legal framework amendments that apply or may affect your organization. Doing this ensures you follow the COPPA rules or any other regulations and avoid enforcement actions and noncompliance penalties.

With a few exceptions, the general rule under COPPA is that organizations must directly notify parents/guardians of children and seek their verifiable consent "before" collecting children’s personal data on online platforms. The parental authorities should be allowed to approve the controller's collection of children's personal data for internal use but prohibited from disclosing that data to third parties unless the controller specifically notifies the parental authorities that the disclosure is absolutely necessary for the digital platform.

The COPPA Rule empowers schools to either act as parents' representatives and obtains consent on their behalf or to operate as an intermediary between operators and parents to directly obtain consent from parents. An organization can only utilize a child's personal information for educational purposes when the school acts as the parent's agent. An Edtech company may use the school as an intermediary to obtain consent if it intends to use a child's personal information for commercial (such as advertising) purposes, but only if it has provided the school with adequate information and monitors whether consent is obtained.

Publish Clear and Comprehensive Privacy Policies

Ensure that the organization's activities regarding the collecting and processing of children's personal data are clearly outlined in the privacy policy. The privacy policy should outline the data controllers, the categories of data collected, how that data is used and disclosed, and the parents' rights to review, update, or delete their child's personal data and prohibit further data collection and use. The privacy policy should not contain any irrelevant, contradicting, or confusing information.

Limit Data Collection

Edtech organizations, or other organizations in general, should only collect information that is necessary for the proper functioning of their services. Without the parents' explicit consent, they should refrain from collecting sensitive personal information such as social security numbers or addresses.

Limit Data Retention

Children's personal information should only be kept by organizations for as long as is necessary to achieve the purposes for which it was collected. When the data is no longer required, it should be safely deleted.

Secure Data Storage

To protect the personal information they collect from children, Edtech companies should implement the necessary security measures, including access controls, encryption, regular security audits, etc. Furthermore, only organizations qualified to uphold the security and confidentiality of the data should be given access to children’s personal information.

Empower Parents with Access and Control

Edtech organizations should provide parents with options to limit the collection and use of their children's information and the access to evaluate the personal information collected on their children.

Train Employees and Contractors

It is critical that organizations train their employees as well as third-party contractors about COPPA requirements and recommended procedures for safeguarding children's privacy, including training on data processing, security procedures, and the significance of upholding privacy standards.

Regularly Audit and Assess Compliance

Edtech companies should conduct regular audits, such as assessing data collection procedures, privacy policies, and security precautions, to find potential vulnerabilities or development opportunities.

Don’t Use Coercion to Obtain Children’s Personal Information

Children should not be required to provide more personal information than necessary to participate in any online activity.

Here’s more on the FTC’s COPPA compliance plan.

How Can Securiti Help

Protecting consumers’ data, especially children's, has never been more crucial. With data being collected and processed at an alarming rate, automation is the only way to ensure swift compliance with the requirements and obligations of evolving laws.

Securiti’s Data Command Center framework enables organizations to identify and classify data, protect data systems, establish sensitive data intelligence, govern access to sensitive data, ensure consent management, analyze the impact of data breaches and respond promptly, automate individual data requests, automate data privacy obligations, analyze data lineage, and so much more.

Request a demo to witness Securiti in action.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share

More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Spotlight 46:02
Building Safe Enterprise AI: A Practical Roadmap
Watch Now View
Latest
Securiti Names Accenture as 2025 Partner of the Year for Data+AI Security View More
Securiti.ai Names Accenture as 2025 Partner of the Year
In a continued celebration of impactful collaboration in DataAI Security, Securiti.ai, a Veeam company, has honored Accenture as its 2025 Partner of the Year....
View More
Introducing Agent Commander
The promise of AI Agents is staggering— intelligent systems that make decisions, use tools, automate complex workflows act as force multipliers for every knowledge...
Largest Fine In CCPA History_ What The Latest CCPA Enforcement Action Teaches Businesses View More
Largest Fine In CCPA History: What The Latest CCPA Enforcement Action Teaches Businesses
Businesses can take some vital lessons from the recent biggest enforcement action in CCPA history. Securiti’s blog covers all the important details to know.
View More
AI & HIPAA: What It Means and How to Automate Compliance
Explore how the Health Insurance Portability and Accountability Act (HIPAA) applies to Artificial Intelligence (AI) in securing Protected Health Information (PHI). Learn how to...
Consent Orchestration for Safe AI View More
Consent Orchestration for Safe AI
Access the whitepaper and learn how to operationalize consent across data and GenAI with a practical framework, enforceable controls, and a 30/60/90-day implementation roadmap.
View More
2026 Privacy Compliance Readiness Checklist
Access the whitepaper to unlock a practical guide to strengthening privacy readiness, featuring key insights, the 2026 privacy compliance checklist, and how to operationalize...
DataAI Security for Retail View More
DataAI Security for Retail
Download the brief and explore how retailers can securely scale Data & AI with Securiti DataAI Command Center and protect sensitive data, manage risk,...
Emerging AI Security Trends For 2026 View More
Emerging AI Security Trends For 2026
Securiti’s latest infographic provides security leaders with a walkthrough of all the emerging AI security trends for 2026 to help them assess and plan...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New