The pandemic has forced many educational institutions to turn to apps and online tools to continue classes. However, these digital tools use children's data to a large extent, resulting in massive breaches.
See also: COVID-19 and WFH increased cyberattacks on banks and insurance companies

And now, according to a new report released Tuesday by the Me2B Alliance, it has found that the majority of school-use apps are sharing some of their student data with third-party marketing companies. The Me2B team surveyed several “utility” apps for school districts that students and parents use to check the school calendar or bus schedules and found about 60 percent of them are sharing everything from a student’s location to their entire contact list with companies that students and their parents have likely never heard of.
See also: Google: Limits apps that track other apps
To find out what kind of data these apps were sharing, Me2B analyzed the software development kits (or SDKs) that these apps came with. While SDKs can do all sorts of things, these small libraries of code often help developers monetize their free-to-download apps by sharing some kind of data with third-party ad networks. Facebook has some extremely popular SDKs, as does Google. Of the 73 apps investigated in the report, 486 SDKs were discovered in total, with an average of just over 10 SDKs per app.
Of these 486 total pieces of code, nearly 63% (306) were owned and operated by either Facebook or Google. The remaining SDKs shared data with a few lesser-known third parties, with names like AdColony and Admob.

See also: Google: Saved over $1 billion in a year through telecommuting
But the data sharing doesn’t stop there. As the report points out, these lesser-known SDKs often shared data pulled from these student apps with dozens—if not hundreds—of third-party companies. What’s interesting here is that these SDKs, in particular, were found in Android apps, but much less in iOS apps (91% vs. 26%, respectively).
Although Android has its own vetting process for apps, we've seen some insecure apps manage to bypass the protections. There's also a good chance that many apps developed for Android transmit some degree of data directly to Google.
The issue of student protection, however, remains and large companies must take more drastic measures to limit these applications.
