What changed for classroom apps in 2025? State law moved. Ohio's new student-data-privacy requirements began phasing in on August 1, 2025, with broader obligations effective October 24, 2025, per the Ohio School Boards Association — including a duty for districts to give parents a notice listing the curriculum and online services their students use. Ohio joined a state regime that already ran deep: California's SOPIPA, the 2014 model law banning targeted advertising and profiling of students by app operators, has now been emulated in more than 20 states, according to the Future of Privacy Forum's tracker. The practical effect is that what an app may collect, and what a district must tell parents about it, is increasingly written in state statute rather than in vendor policy pages.
What does this change for classrooms?
The compliance work lands on technology departments, and it is procedural rather than dramatic. Districts in states with these laws must maintain inventories of the operators that receive student data, publish parent-facing notices, and in states like Illinois run their approvals through an official registry under SOPPA. The strain is real: a 2025 CoSN report found that most districts' privacy programs are run by administrators with limited privacy training, as reported by StateScoop — meaning the new legal duties arrive on desks that were already full. For teachers, the visible change is that the free app discovered on a Sunday night is no longer a private decision; it is a data flow the district must be able to name, justify, and disclose.
What is the detail most districts are missing?
Parent notification, not vendor vetting, is the part that actually bites. Districts have spent a decade building app-approval processes, so inventorying operators is familiar work. What the newer statutes add is a communication duty — the Ohio notice requirement, and similar transparency provisions elsewhere, put districts on the hook for telling families, in plain language, which services touch student data and for what purpose. That obligation renews whenever the tool list changes, which in a typical district is constantly. The districts handling it well publish a living page listing approved services rather than sending a single August letter nobody reads; the districts handling it poorly will discover the gap during a complaint or an audit, when the statute's deadlines have already been missed. The lesson of the 2025 wave is that the law now treats knowing what your apps do — and telling parents — as the baseline of running a school, not an extra.
For more context, read How app privacy evaluations work, and where they stop.
For more context, read state ai disclosure rules classrooms.
For more context, read What FERPA actually lets edtech vendors do with student data.
