Teacher/Classroom Mode: Roster Design, the FERPA/COPPA Consent Gap for a Non-School Teacher, and Safe Competition
Resumen ejecutivo
- Los productos consumer (Google Classroom, Kahoot!, ClassDojo) comparten un patrón: el profesor crea la clase y genera un código; el estudiante se une con ese código/enlace, y el profesor puede resetearlo o desactivarlo cuando quiera. Google Classroom documenta tres vías de unión (enlace, código, invitación por correo) y que "los estudiantes pueden darse de baja ellos mismos" [1].
- Hallazgo legal central: la excepción de "school official" de FERPA (34 CFR 99.31(a)(1)) exige que una institución determine el interés educativo legítimo del tercero y mantenga "control directo" sobre su uso de los registros — un profesor que actúa por su cuenta, sin distrito ni colegio que lo contrate o supervise, muy probablemente no puede invocar esta excepción, porque no existe la "institución" que ejerza ese control [6].
- Lo mismo con COPPA: el texto de la norma (16 CFR 312.5) no menciona escuelas; la doctrina de "la escuela consiente por los padres" es guía de política de la FTC, no la regla misma, y presupone una escuela real dando aviso previo — justo lo que describe ClassDojo: consentimiento escolar "only after providing the school with the required notices", y consentimiento parental directo para todo lo demás [2][7].
- Consecuencia de diseño: Math Challenge debe tratar el consentimiento del padre como consentimiento parental verificable directo (el estándar COPPA/GDPR sin escuela detrás), no como atajo institucional [7][8].
- El Student Privacy Pledge (FPF/SIIA, 2014) se retiró el 25 de abril de 2025, reemplazado por leyes estatales y el nuevo pledge de CISA — ya no es un sello de confianza vigente [9].
- El patrón de seguridad más citable es de ClassDojo: la conexión padre-hijo requiere aprobación de un profesor verificado, y antes de aprobar el padre solo ve "nombre y primera inicial" del estudiante [2]. Math Challenge necesita el patrón inverso: el padre debe ver la identidad verificada del profesor antes de aprobar.
- La competencia en el aula tiene efectos dependientes de la posición, no uniformes (detalle completo en docs/research/2026-07-31-mc-18-leaderboards-competition.md); aquí se suma evidencia de aula real: Domínguez et al. (2013) hallaron que estudiantes gamificados tuvieron menor participación y peor desempeño en tareas escritas, pese a mayor motivación reportada [10].
- Ningún producto investigado tiene un mecanismo que por sí solo impida que un adulto no autorizado abra una "clase" para intentar recolectar niños; la mitigación real es siempre una pila de fricciones — ver "The safeguarding question".
Este documento se escribió en inglés; su resumen ejecutivo también existe en español, y esa es la versión de arriba. El cuerpo de abajo es el original en inglés — no está traducido, y no se ofrece una traducción automática en su lugar.
Estado de verificación
Este documento no lleva ninguna marca [unverified]. Cada afirmación está atada a una fuente numerada de abajo.
[unverified] quiere decir que la afirmación está en la investigación pero no se confirmó contra una fuente primaria en la sesión que la produjo. Se publica en vez de borrarse, porque un corpus que esconde sus huecos no es verificable.
Cómo se produjo esta investigación
Los 47 documentos se hicieron el 2026-07-31 por agentes independientes, cada uno con instrucción explícita de no inventar citas y de marcar como [unverified] lo que no pudiera confirmar contra una fuente primaria. La cuota de búsqueda web de la sesión se agotó a media investigación y los agentes posteriores trabajaron por descarga directa contra fuentes primarias. Varios sitios (ftc.gov, ico.org.uk) bloquean la descarga automatizada, y por eso ciertas afirmaciones legales están marcadas a propósito.
Esto es investigación, no asesoría legal, médica ni financiera. Nada aquí reclama un resultado de aprendizaje de Math Challenge; ese estudio todavía no existe.
Findings
1. How consumer classroom products structure a class
Google Classroom: teacher creates a class, auto-generating a resettable/disable-able invite link and class code. Students join via link, code, or email invite; enrollment is self-join, and “students can unenroll themselves from classes” at will — a useful analogy for revocation. Classes use Google Groups underneath, up to 50 co-teachers [1].
ClassDojo: teacher builds a roster (manual, spreadsheet, or SIS import), then invites parents. A parent connection — via class link/code or a “proactive” search flow — is not final until a verified teacher/admin approves it, and pre-approval the parent sees only a partial identifier, never enough to identify a stranger’s child [2]. This teacher-approves-parent gate is the clearest safety pattern found, but it runs the opposite direction from what Math Challenge needs, since here the teacher recruits parents.
Kahoot!: students join a live session with a numeric PIN/QR, no account needed for the live game; “Kahoot! Challenge” (2017) is a separate self-paced, deadline-based homework mode distinct from the live, synchronous, scored game [3][4]. Kahoot markets teacher-facing “detailed reports and analytics” for post-session gap-spotting [4].
Khan Academy: teacher sets up a classroom, assigns library content, tracks “student’s progress as they work through the assigned tutorials” via a coach/student model [5]. Join-code/roster-import mechanics beyond this could not be independently re-verified live this session (support-site fetches failed).
Quizizz/Wayground, Blooket, Gimkit, Zearn, IXL: live fetches to these products’ own docs returned DNS/403 errors and could not be completed this session. Based on general product knowledge, not re-verified live and flagged as such: all follow the same broad shape (teacher-generated join code, live vs. assigned modes, teacher dashboard of aggregate/per-student results). Zearn is documented elsewhere in this project’s research (topic 18) as deliberately non-competitive and mastery-gated rather than leaderboard-driven — a real design alternative worth weighing, not just an outlier.
2. FERPA’s school official exception likely does not cover a school-less teacher
34 CFR 99.31(a)(1) permits disclosure without consent “to other school officials… within the agency or institution whom the agency or institution has determined to have legitimate educational interests.” Conditions: (a) legitimate educational interest tied to institutional role, (b) an outsourced party qualifies only if the institution maintains direct control over its use of records, (c) use/redisclosure limits under 99.33(a) apply throughout [6]. The structural requirement is an institution making the determination and exercising direct control — a lone teacher with no school/district as the contracting party is not “an institution,” and there is nothing for Math Challenge to be under the direct control of. This is a strong signal, not a confirmed legal conclusion (no lawyer or ED guidance specific to this scenario was consulted), that the school-official pathway is not safely available absent institutional sponsorship.
3. COPPA’s “school consent” doctrine is FTC policy, not rule text, and presumes a real school
16 CFR 312.5 lists accepted verifiable-parental-consent (VPC) mechanisms (signed forms, payment-card verification, toll-free calls, video conference, government ID, knowledge-based auth) and never mentions schools or educational context [7]. “A school can consent for parents” is FTC enforcement-policy guidance on top of the rule; this research could not re-fetch the FTC’s own COPPA FAQ live (403 both attempts), so its current exact wording is not independently re-verified here. What is directly confirmed, from ClassDojo’s own policy, is how a real vendor operationalizes the doctrine: school consent only “after providing the school with the required notices,” with direct parental consent reserved for any account outside a school context [2]. Even a vendor built around school-consent treats “no real school” as reverting to direct consent — a school-less Math Challenge teacher is, on that model, in the direct-consent bucket.
4. GDPR/UK: parental consent age threshold and the Children’s Code
GDPR Article 8 sets the default age of consent for information-society services at 16, with member states able to lower it to 13; below the threshold, “consent is given or authorised by the holder of parental responsibility,” verified by the controller with “reasonable efforts… taking into consideration available technology” [8]. The UK ICO’s Age Appropriate Design Code layers further standards (high-privacy defaults, restrictions on “detrimental use of nudge techniques,” data minimisation) for services likely accessed by children; both attempts to fetch ICO’s own pages returned 403, so exact standard wording is not independently re-verified live this session.
5. The Student Privacy Pledge is retired
FPF, which administered the Pledge jointly with SIIA since 2014, retired it on April 25, 2025, citing 40+ state student-privacy laws now codifying similar principles, and pointing signatories to CISA’s newer “K-12 Education Technology Secure by Design Pledge”; past signatories remain bound for their signed period, but the program no longer accepts new ones [9]. Any reference to it as a current trust badge would be citing a defunct program.
6. Classroom competition: effects specific to a teacher-run setting
Full psychological/rating-system literature already lives in topic 18 (Christy & Fox 2014 on social comparison outweighing stereotype threat; Festinger 1954 on upward/downward comparison; Deci & Ryan on competition as controlling vs. informational; Johnson & Johnson favoring cooperative goal structures). Additive here: Domínguez et al. (2013) studied a gamified university course and found gamified students scored higher on practical work but performed worse on written exams and showed lower class participation, despite higher initial reported motivation — direct evidence a competitive layer can crowd out the deeper engagement a teacher wants, even while self-reported motivation looks good [10]. Recent meta-analyses (Li, He & Yuan 2023; Zeng, Parks & Shang 2024) find large positive aggregate gamification effects, while Ortiz-Rojas et al. (2025) found leaderboards improved calculus performance but explicitly did not improve motivation or self-efficacy — “leaderboard present” and “leaderboard helps everyone equally” are different claims [10].
7. Teacher dashboards: what gets used vs. built
A primary source (Bodily & Verbert’s learning-analytics-dashboard review) returned 403 and could not be confirmed. Based on general, not live-verified, field knowledge: teacher dashboards tend to get used most for simple, actionable signals (completion %, time since last activity, a short “struggling/stalled” list) over rich comparative visualizations, and student-facing rank displays are a different design surface from teacher-facing progress displays — conflating them risks optimizing for the wrong signal.
8. Abuse prevention: the one confirmed mechanism, and its blind spot
The clearest source-confirmed control is ClassDojo’s teacher/admin approval gate on parent connections, plus partial-identifier previews [2]. This protects against a parent falsely claiming a child. It does not protect against the opposite risk Math Challenge cares about most — an unverified adult posing as “teacher” to recruit children’s accounts — since the gate runs teacher-approves-parent, not parent-approves-teacher. No source found describes a mechanism specifically verifying a self-declared teacher before they invite parents; treated here as an open industry gap, not a solved problem.
Design implications for Math Challenge
- Teacher-initiated class creation, code-based join — mirror the near-universal pattern: teacher creates a “salón,” gets a resettable/disable-able join code/link [1][2][4].
- No child joins on a code alone. A code produces a pending request routed to the child’s existing parent-controlled account, never instant enrollment — instant joining (Kahoot!/Classroom) assumes an identity layer our under-13 users don’t have unsupervised.
- Parent approval required before the child appears in the roster, with the approval screen showing the teacher’s verified identity, verification status, and affiliation (or “independent/unaffiliated”) — reversing ClassDojo’s teacher-approves-parent gate to fit our recruitment direction [2].
- Treat consent as direct verifiable parental consent, not “school consent.” Do not model a “teacher consents for the parent” flow on FERPA/COPPA school-official language unless a genuine school/district tier with a real contracting institution exists later — both doctrines structurally require institutional direct control an independent teacher lacks [6][7].
- One-click, immediate revocation. Parent removes their child anytime, effective immediately, no teacher approval needed to leave (cf. Google Classroom’s self-unenroll) [1]; teacher’s forward visibility into that child’s data stops immediately (access-cut, not necessarily deletion).
- Minimum viable teacher visibility. Show display name/alias, grade/level, aggregate practice metrics (streak, attempts, topic mastery, time-on-task), and a simple “needs attention” flag — never raw event logs, never data outside classroom math-practice scope, never another classroom the child belongs to.
- No direct teacher-to-child messaging. Route any teacher communication through the parent (notification, not chat) — removes the single highest-risk surface none of Google Classroom, Kahoot!, or ClassDojo let a teacher use unsupervised with a young child’s own account.
- Competitive display opt-in and rank-bounded, not raw public score. Given position-dependent effects (§6; topic 18), default to showing top performers by name without exposing a full bottom-ranked list, or lead with effort/streak recognition alongside or instead of raw accuracy rank — Domínguez et al.’s participation-suppression finding directly cautions against making the bottom of class publicly visible [10].
- A visible “leave the leaderboard” control independent of leaving the classroom — a child can keep practicing without appearing in any ranked view, preserving the informational (non-controlling) framing self-determination theory favors (topic 18, §3).
- Live and async modes as separate features, not one toggle. Kahoot!‘s live-PIN vs. Challenge split, and Zearn’s fully async/non-competitive design, serve different purposes: live is teacher-scheduled and inherently more social/competitive; async should default to non-comparative, mastery-oriented display even inside a classroom that also runs live sessions [3][4].
- Teacher-identity friction proportional to risk at classroom creation. No product researched verifies “is this adult safe to be given parents’ contact info,” and we cannot lean on a school’s own vetting; require at minimum verified email + phone, a stated real name, an optionally-checkable affiliation, and a visible “unverified/self-reported” badge for unchecked claims.
- Rate-limit and cap classroom creation/size per account. Absent institutional vetting, unbounded classroom/invite creation is the main lever an abuser would pull; cap size to a real-class-sized number and rate-limit creation, escalating to manual review past a threshold.
- Always-visible “report this teacher/classroom” control for parents, independent of the child, routed to human review — no product researched documents this exact mechanism, so treat it as a Math Challenge-specific addition, not an industry pattern being copied.
- Full audit log of join/approve/remove/reject events, visible to the parent as well as retained internally, so a parent can always see the complete history of who requested access and when.
The safeguarding question
What stops a stranger from opening a “classroom” to collect children? Honestly: nothing about any product researched, by itself, fully stops that. Every one (Google Classroom, Kahoot!, ClassDojo) assumes a prior trust layer Math Challenge, as a school-less consumer product, does not automatically have. Google Classroom borrows Google Workspace for Education’s institutional vetting; Kahoot!‘s live-PIN model assumes the PIN is shared in an already-trusted room; ClassDojo’s one documented mechanism (verified-teacher-approves-parent) solves the opposite direction of trust from what we need, and even its “school consent” language presupposes a real school issuing notices [1][2][3]. No source reached describes a mechanism independently verifying a self-declared “teacher,” or specifically stopping mass-inviting of unrelated children’s parents.
Given that gap, our posture must be a layered set of frictions, not a single gate: verified adult identity before classroom creation; approval in the parent’s hands with teacher identity shown first (reversing ClassDojo’s one confirmed pattern); capped size and creation rate; teacher visibility limited to aggregate data with no private child channel; a standing one-tap “report” control reaching a human; and a full audit trail. This is a mitigation stack, not a guarantee — how much manual review (e.g., a human reviewing every classroom above some child-count) the team is willing to staff is an explicit policy call for the owner, since no purely technical control found here closes the gap completely.
Open questions for the project owner
- Launch teacher/classroom mode school-affiliated-only first (unlocking the FERPA/COPPA school-official pathway cleanly), or as an unaffiliated “any adult” feature (requiring direct-to-parent VPC and the fuller safeguarding stack)?
- What teacher identity verification is acceptable at launch — email+phone only, a paid ID-check step, or a required school email domain?
- Should a classroom have a hard size cap (e.g., 30–40 students) at launch, and should creation itself be rate-limited per account?
- Is a human-review queue for new classrooms (above a child-count threshold, or all of them at launch scale) staffable, and who owns it?
- Should competitive display default opt-in or opt-out, given the position-dependent-harm evidence (topic 18; Domínguez et al. here)?
- Is a later school/district-sanctioned tier (with a real contract giving FERPA/COPPA school-official coverage) intended, and should the unaffiliated data model be built for non-breaking migration to it?
- Should the EU/UK version ship in v1 at all, given GDPR Article 8 and Children’s Code requirements this research could not fully verify live (ICO fetches blocked) — or should this launch US-only first?
Fuentes
- Google Classroom Help — Join a class ([support.google.com/edu/classroom/answer/6020282](
- ClassDojo Privacy Policy ([classdojo.com/privacy](
- Wikipedia — Kahoot! ([en.wikipedia.org/wiki/Kahoot!](
- Kahoot! for Schools ([kahoot.com/schools](
- Wikipedia — Khan Academy ([en.wikipedia.org/wiki/Khan_Academy](
- 34 CFR § 99.31(a)(1), Cornell Legal Information Institute ([law.cornell.edu/cfr/text/34/99.31](
- 16 CFR § 312.5, Cornell Legal Information Institute ([law.cornell.edu/cfr/text/16/312.5](
- GDPR Article 8 ([gdpr-info.eu/art-8-gdpr](
- Future of Privacy Forum — Student Privacy Pledge ([fpf.org/student-privacy-pledge](
- Wikipedia — Gamification of learning ([en.wikipedia.org/wiki/Gamification_of_learning](
- Wikipedia — ClassDojo ([en.wikipedia.org/wiki/ClassDojo](
- Wikipedia — Children's Online Privacy Protection Act ([en.wikipedia.org/wiki/Children%27s_Online_Privacy_Protection_Act](
- Math Challenge internal research — Leaderboards and Competition Design (docs/research/2026-07-31-mc-18-leaderboards-competition.md) — prior work in this repository, cross-referenced rather than duplicated for the psychology/rating-system literature
- UK ICO Age Appropriate Design Code (Children's Code) — attempted fetch at [ico.org.uk/for-organisations/childrens-code-hub](
- FTC COPPA compliance FAQ — attempted fetch at [ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions](
Preguntas que este documento le deja abiertas al dueño
Están sin responder a propósito. Se listan, no se resuelven — convertirlas en preguntas frecuentes obligaría a inventar respuestas que el documento no tiene.
- Launch teacher/classroom mode school-affiliated-only first (unlocking the FERPA/COPPA school-official pathway cleanly), or as an unaffiliated "any adult" feature (requiring direct-to-parent VPC and the fuller safeguarding stack)?
- What teacher identity verification is acceptable at launch — email+phone only, a paid ID-check step, or a required school email domain?
- Should a classroom have a hard size cap (e.g., 30–40 students) at launch, and should creation itself be rate-limited per account?
- Is a human-review queue for new classrooms (above a child-count threshold, or all of them at launch scale) staffable, and who owns it?
- Should competitive display default opt-in or opt-out, given the position-dependent-harm evidence (topic 18; Domínguez et al. here)?
- Is a later school/district-sanctioned tier (with a real contract giving FERPA/COPPA school-official coverage) intended, and should the unaffiliated data model be built for non-breaking migration to it?
- Should the EU/UK version ship in v1 at all, given GDPR Article 8 and Children's Code requirements this research could not fully verify live (ICO fetches blocked) — or should this launch US-only first?
Uno de 51 documentos de investigación, 168.346 palabras en total, contadas en el build sobre los archivos mismos. Leer este documento en el repositorio