More than half the educational apps used in Utah public school classrooms collected student data they were never authorized to take, and a new state law designed to stop it is now in effect for districts including Canyons, according to BYU News coverage published Tuesday, Aug. 18.
The findings come from a joint investigation by the Utah State Board of Education, Brigham Young University and the nonprofit Internet Safety Labs, which tested 100 apps used statewide. According to ABC4's report on the study, 52% of apps with signed Data Privacy Agreements collected at least one unauthorized data element. Thirty-six percent funneled student information directly to advertising companies.
The results are newly relevant for Canyons District families: students returned for the first day of school Monday, Aug. 17, and are actively logging into platforms flagged in the report. Canvas, Duolingo, Khan Academy, Quizlet, YouTube, coolmathgames.com and Loom were among apps named in the study. Canyons District is a confirmed Canvas user.
What was collected
Researchers set up accounts mimicking students under age 13, used each app for 15 to 20 minutes and captured every outgoing data transmission. They measured collection against 79 data elements tracked in state privacy contracts.
Many apps routinely harvested persistent unique user identifiers, which allow advertisers to build behavioral profiles of children even after they log out. Three individual apps sent student data to 32, 33 and 54 advertising entities respectively.
"It's a massive market — data brokers and resellers market — and the technology is increasing faster than people are aware of, as companies tie together data in ways that make it more useful without anybody knowing," BYU information systems professor Mark Keith, the lead researcher, said.
Overall, 61% of tested apps shared student data with third parties. While some third-party sharing with data sub-processors is allowed under state contracts, the advertising transmissions were not.
What vendors did when caught
State officials contacted 50 vendors about data-collection mismatches. Of those, 31 signed or committed to updated privacy agreements, 13 gave explanations that satisfied state reviewers and seven removed tracking pixels or changed analytics settings.
Keith said vendors fell into three groups: those fully compliant, those who didn't realize they were breaking the law and cooperated, and those who knew and ignored requests to fix it.
Seven vendors also revealed their privacy agreements covered only paid premium tiers, not the free versions students actually used in class.
New law and Canyons District response
In direct response to the investigation, Utah enacted H.B. 55 (Privacy Compliance for Education Technology Vendors), which took effect July 1, 2026. The law tightens privacy terms in EdTech contracts, gives districts the right to audit vendor network traffic and requires contracts to be terminated if violations aren't fixed within 30 days.
Canyons District's Board of Education unanimously approved updates to its data privacy and governance policy and adopted a new cybersecurity policy at its May 19 meeting. Board member Andrew Edtl moved to approve the package, seconded by Holly Neibaur Hayes.
The district has not issued a statement addressing the investigation or identified which flagged apps are used locally. Parents seeking more information can visit the district's data privacy page.
.png)


.jpg)
.png)
.jpg)
.png)
