The Electronic Frontier Foundation claims Google collects information when school kids use Chromebooks and Google apps, and the potentially sensitive data could eventually make its way into the hands of third-party advertisers. Credit: Thinkstock Google gives free software and sells low-priced Chromebook computers to thousands of American schools. In return, it collects alarming amounts of data on students without asking permission from their parents, according to the Electronic Frontier Foundation (EFF), a privacy-focused consumer advocacy group.“Minors shouldn’t be tracked or used as guinea pigs, with their data treated as a profit center,” says Nate Cardozo, an EFF attorney. “If Google wants to use students’ data to ‘improve Google products,’ then it needs to get express consent from parents.” In the past, Apple owned the elementary, middle, and high school markets, but in recent years affordable Chromebooks and Google’s free software tools won the company a large share of the K-12 education market.Google violating its own ‘Student Privacy Pledge’?Google currently collects information on student browsing histories and mines other data, which violates the search giant’s “Student Privacy Pledge” against such actions, Cardozo says. The Google for Education software suite also lets school administrators share student data with Google as if the company’s personnel were “school officials,” according to an EFF complaint filed against Google with the U.S. Federal Trade Commission (FTC) on December 1, 2015. Google, the complaint says, is able “to track, store on its servers, and data mine for non-advertising purposes, records of every Internet site students visit, every search term they use, the results they click on, videos they look for and watch on YouTube, and their saved passwords.” Some, but not all, of that data becomes accessible when students sign into their Google accounts via Chrome and use the “sync” feature, which imports personal account settings and preferences, and is turned on by default.In response to queries from the EFF, Google promised to change the Chrome-sync setting so it’s off by default, but it didn’t say when it would make that change. And school officials would still be able to turn it back on at will. Jonathan Rochelle, director of Google Apps for Education, defended the company’s practicies in a blog post and claimed student data is aggregated and not personally identifiable. “We have always been firmly committed to keeping student information private and secure,” he wrote.Google could share student data with advertisersEFF’s filing with the FTC also claims administrative settings in Google for Education allow students’ personal information to be shared with third-party websites, another Student Privacy Pledge violation. Whenever children use Chrome to log into their Google accounts, whether on a parent’s Apple iPad, friend’s smartphone or home computer, the browser collects potentially sensitive information that could then be shared, the foundation claims.Nearly everything Chromebook users do occurs online, so the issue of privacy is particularly pressing. Google says it doesn’t use the information it collects to push tailored advertisements to children, but the third-party companies that utilize Google’s extensive ad networks may not be as scrupulous.At the very least, parents with children who use Chromebooks at school should speak with administrators and ask them to clarify their policies on sharing information with Google and anyone else. Related content news Okta launches Cybersecurity Workforce Development Initiative New philanthropic and educational grants aim to advance inclusive pathways into cybersecurity and technology careers. By Michael Hill Oct 04, 2023 3 mins IT Skills Careers Security news New critical AI vulnerabilities in TorchServe put thousands of AI models at risk The vulnerabilities can completely compromise the AI infrastructure of the world’s biggest businesses, Oligo Security said. By Shweta Sharma Oct 04, 2023 4 mins Vulnerabilities news ChatGPT “not a reliable” tool for detecting vulnerabilities in developed code NCC Group report claims machine learning models show strong promise in detecting novel zero-day attacks. By Michael Hill Oct 04, 2023 3 mins DevSecOps Generative AI Vulnerabilities news Google Chrome zero-day jumps onto CISA's known vulnerability list A serious security flaw in Google Chrome, which was discovered under active exploitation in the wild, is a new addition to the Cybersecurity and Infrastructure Agency’s Known Exploited vulnerabilities catalog. By Jon Gold Oct 03, 2023 3 mins Zero-day vulnerability Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe