Math Challenge
Mais

Teacher/Classroom Mode: Roster Design, the FERPA/COPPA Consent Gap for a Non-School Teacher, and Safe Competition

mc-28 · Publicado: · por Math Challenge Research · 3.178 palavras · 15 fontes citadas

Resumo executivo

Consumer classroom products (Google Classroom, Kahoot!, ClassDojo) share one pattern: the teacher creates the class and a join code is generated; students join with that code/link, and the teacher can reset or disable it at will. Google Classroom documents three join paths (link, code, email invite) and that "students can unenroll themselves" [1].

Central legal finding: FERPA's "school official" exception (34 CFR 99.31(a)(1)) requires an institution to determine the third party's legitimate educational interest and maintain "direct control" over its use of records — a teacher acting independently, with no district or school contracting/supervising them, almost certainly cannot invoke this exception, since there is no "institution" exercising that control [6]. The same gap exists under COPPA: the rule text (16 CFR 312.5) never mentions schools; "school consents for parents" is FTC policy guidance, not the rule, and presupposes a real school giving prior notice — exactly what ClassDojo describes, reserving school consent for after "providing the school with the required notices" and direct parental consent for everything else [2][7].

Design consequence: Math Challenge should treat consent as direct verifiable parental consent (the school-less bar under COPPA/GDPR), not an institutional shortcut [7][8]. The Student Privacy Pledge (FPF/SIIA, 2014) retired April 25, 2025, superseded by state law and a new CISA pledge — no longer a live trust signal [9]. The most citable safety pattern is ClassDojo's: a parent-child connection needs a verified teacher's approval, with the parent seeing only "first name and last initial" pre-approval [2]. Math Challenge needs the mirror image: the parent sees the teacher's verified identity before approving.

Classroom competition has position-dependent effects — helps on average, reliably hurts the bottom of the board (full treatment in docs/research/2026-07-31-mc-18-leaderboards-competition.md); added here, Domínguez et al. (2013) found gamified students had lower class participation and worse written-task performance, despite higher reported motivation [10]. No product researched has a single mechanism stopping an unauthorized adult from opening a "classroom" to collect children; real mitigation is a stack of frictions — see "The safeguarding question."

332 palavras

Este documento não está traduzido para o idioma desta página. Ele é publicado na íntegra no idioma original, inglês. Mostrar o texto real é o objetivo: uma tradução automática de um documento de pesquisa com fontes citadas não seria citável.

Estado de verificação

Este documento não traz nenhuma marca [unverified]. Cada afirmação está ligada a uma fonte numerada abaixo.

[unverified] significa que a afirmação está na pesquisa mas não foi confirmada contra uma fonte primária na sessão que a produziu. É publicada em vez de removida, porque um corpus que esconde suas lacunas não é verificável.

Como esta pesquisa foi produzida

Os 47 documentos foram produzidos em 2026-07-31 por agentes independentes, cada um com instrução de não inventar citações e de marcar como [unverified] o que não pudesse confirmar contra uma fonte primária. A cota de busca na web da sessão se esgotou no meio do caminho e os agentes seguintes trabalharam por download direto de fontes primárias. Vários sites (ftc.gov, ico.org.uk) bloqueiam download automatizado, e por isso certas afirmações jurídicas estão marcadas de propósito.

Findings

1. How consumer classroom products structure a class

Google Classroom: teacher creates a class, auto-generating a resettable/disable-able invite link and class code. Students join via link, code, or email invite; enrollment is self-join, and “students can unenroll themselves from classes” at will — a useful analogy for revocation. Classes use Google Groups underneath, up to 50 co-teachers [1].

ClassDojo: teacher builds a roster (manual, spreadsheet, or SIS import), then invites parents. A parent connection — via class link/code or a “proactive” search flow — is not final until a verified teacher/admin approves it, and pre-approval the parent sees only a partial identifier, never enough to identify a stranger’s child [2]. This teacher-approves-parent gate is the clearest safety pattern found, but it runs the opposite direction from what Math Challenge needs, since here the teacher recruits parents.

Kahoot!: students join a live session with a numeric PIN/QR, no account needed for the live game; “Kahoot! Challenge” (2017) is a separate self-paced, deadline-based homework mode distinct from the live, synchronous, scored game [3][4]. Kahoot markets teacher-facing “detailed reports and analytics” for post-session gap-spotting [4].

Khan Academy: teacher sets up a classroom, assigns library content, tracks “student’s progress as they work through the assigned tutorials” via a coach/student model [5]. Join-code/roster-import mechanics beyond this could not be independently re-verified live this session (support-site fetches failed).

Quizizz/Wayground, Blooket, Gimkit, Zearn, IXL: live fetches to these products’ own docs returned DNS/403 errors and could not be completed this session. Based on general product knowledge, not re-verified live and flagged as such: all follow the same broad shape (teacher-generated join code, live vs. assigned modes, teacher dashboard of aggregate/per-student results). Zearn is documented elsewhere in this project’s research (topic 18) as deliberately non-competitive and mastery-gated rather than leaderboard-driven — a real design alternative worth weighing, not just an outlier.

2. FERPA’s school official exception likely does not cover a school-less teacher

34 CFR 99.31(a)(1) permits disclosure without consent “to other school officials… within the agency or institution whom the agency or institution has determined to have legitimate educational interests.” Conditions: (a) legitimate educational interest tied to institutional role, (b) an outsourced party qualifies only if the institution maintains direct control over its use of records, (c) use/redisclosure limits under 99.33(a) apply throughout [6]. The structural requirement is an institution making the determination and exercising direct control — a lone teacher with no school/district as the contracting party is not “an institution,” and there is nothing for Math Challenge to be under the direct control of. This is a strong signal, not a confirmed legal conclusion (no lawyer or ED guidance specific to this scenario was consulted), that the school-official pathway is not safely available absent institutional sponsorship.

16 CFR 312.5 lists accepted verifiable-parental-consent (VPC) mechanisms (signed forms, payment-card verification, toll-free calls, video conference, government ID, knowledge-based auth) and never mentions schools or educational context [7]. “A school can consent for parents” is FTC enforcement-policy guidance on top of the rule; this research could not re-fetch the FTC’s own COPPA FAQ live (403 both attempts), so its current exact wording is not independently re-verified here. What is directly confirmed, from ClassDojo’s own policy, is how a real vendor operationalizes the doctrine: school consent only “after providing the school with the required notices,” with direct parental consent reserved for any account outside a school context [2]. Even a vendor built around school-consent treats “no real school” as reverting to direct consent — a school-less Math Challenge teacher is, on that model, in the direct-consent bucket.

GDPR Article 8 sets the default age of consent for information-society services at 16, with member states able to lower it to 13; below the threshold, “consent is given or authorised by the holder of parental responsibility,” verified by the controller with “reasonable efforts… taking into consideration available technology” [8]. The UK ICO’s Age Appropriate Design Code layers further standards (high-privacy defaults, restrictions on “detrimental use of nudge techniques,” data minimisation) for services likely accessed by children; both attempts to fetch ICO’s own pages returned 403, so exact standard wording is not independently re-verified live this session.

5. The Student Privacy Pledge is retired

FPF, which administered the Pledge jointly with SIIA since 2014, retired it on April 25, 2025, citing 40+ state student-privacy laws now codifying similar principles, and pointing signatories to CISA’s newer “K-12 Education Technology Secure by Design Pledge”; past signatories remain bound for their signed period, but the program no longer accepts new ones [9]. Any reference to it as a current trust badge would be citing a defunct program.

6. Classroom competition: effects specific to a teacher-run setting

Full psychological/rating-system literature already lives in topic 18 (Christy & Fox 2014 on social comparison outweighing stereotype threat; Festinger 1954 on upward/downward comparison; Deci & Ryan on competition as controlling vs. informational; Johnson & Johnson favoring cooperative goal structures). Additive here: Domínguez et al. (2013) studied a gamified university course and found gamified students scored higher on practical work but performed worse on written exams and showed lower class participation, despite higher initial reported motivation — direct evidence a competitive layer can crowd out the deeper engagement a teacher wants, even while self-reported motivation looks good [10]. Recent meta-analyses (Li, He & Yuan 2023; Zeng, Parks & Shang 2024) find large positive aggregate gamification effects, while Ortiz-Rojas et al. (2025) found leaderboards improved calculus performance but explicitly did not improve motivation or self-efficacy — “leaderboard present” and “leaderboard helps everyone equally” are different claims [10].

7. Teacher dashboards: what gets used vs. built

A primary source (Bodily & Verbert’s learning-analytics-dashboard review) returned 403 and could not be confirmed. Based on general, not live-verified, field knowledge: teacher dashboards tend to get used most for simple, actionable signals (completion %, time since last activity, a short “struggling/stalled” list) over rich comparative visualizations, and student-facing rank displays are a different design surface from teacher-facing progress displays — conflating them risks optimizing for the wrong signal.

8. Abuse prevention: the one confirmed mechanism, and its blind spot

The clearest source-confirmed control is ClassDojo’s teacher/admin approval gate on parent connections, plus partial-identifier previews [2]. This protects against a parent falsely claiming a child. It does not protect against the opposite risk Math Challenge cares about most — an unverified adult posing as “teacher” to recruit children’s accounts — since the gate runs teacher-approves-parent, not parent-approves-teacher. No source found describes a mechanism specifically verifying a self-declared teacher before they invite parents; treated here as an open industry gap, not a solved problem.

Design implications for Math Challenge

  1. Teacher-initiated class creation, code-based join — mirror the near-universal pattern: teacher creates a “salón,” gets a resettable/disable-able join code/link [1][2][4].
  2. No child joins on a code alone. A code produces a pending request routed to the child’s existing parent-controlled account, never instant enrollment — instant joining (Kahoot!/Classroom) assumes an identity layer our under-13 users don’t have unsupervised.
  3. Parent approval required before the child appears in the roster, with the approval screen showing the teacher’s verified identity, verification status, and affiliation (or “independent/unaffiliated”) — reversing ClassDojo’s teacher-approves-parent gate to fit our recruitment direction [2].
  4. Treat consent as direct verifiable parental consent, not “school consent.” Do not model a “teacher consents for the parent” flow on FERPA/COPPA school-official language unless a genuine school/district tier with a real contracting institution exists later — both doctrines structurally require institutional direct control an independent teacher lacks [6][7].
  5. One-click, immediate revocation. Parent removes their child anytime, effective immediately, no teacher approval needed to leave (cf. Google Classroom’s self-unenroll) [1]; teacher’s forward visibility into that child’s data stops immediately (access-cut, not necessarily deletion).
  6. Minimum viable teacher visibility. Show display name/alias, grade/level, aggregate practice metrics (streak, attempts, topic mastery, time-on-task), and a simple “needs attention” flag — never raw event logs, never data outside classroom math-practice scope, never another classroom the child belongs to.
  7. No direct teacher-to-child messaging. Route any teacher communication through the parent (notification, not chat) — removes the single highest-risk surface none of Google Classroom, Kahoot!, or ClassDojo let a teacher use unsupervised with a young child’s own account.
  8. Competitive display opt-in and rank-bounded, not raw public score. Given position-dependent effects (§6; topic 18), default to showing top performers by name without exposing a full bottom-ranked list, or lead with effort/streak recognition alongside or instead of raw accuracy rank — Domínguez et al.’s participation-suppression finding directly cautions against making the bottom of class publicly visible [10].
  9. A visible “leave the leaderboard” control independent of leaving the classroom — a child can keep practicing without appearing in any ranked view, preserving the informational (non-controlling) framing self-determination theory favors (topic 18, §3).
  10. Live and async modes as separate features, not one toggle. Kahoot!‘s live-PIN vs. Challenge split, and Zearn’s fully async/non-competitive design, serve different purposes: live is teacher-scheduled and inherently more social/competitive; async should default to non-comparative, mastery-oriented display even inside a classroom that also runs live sessions [3][4].
  11. Teacher-identity friction proportional to risk at classroom creation. No product researched verifies “is this adult safe to be given parents’ contact info,” and we cannot lean on a school’s own vetting; require at minimum verified email + phone, a stated real name, an optionally-checkable affiliation, and a visible “unverified/self-reported” badge for unchecked claims.
  12. Rate-limit and cap classroom creation/size per account. Absent institutional vetting, unbounded classroom/invite creation is the main lever an abuser would pull; cap size to a real-class-sized number and rate-limit creation, escalating to manual review past a threshold.
  13. Always-visible “report this teacher/classroom” control for parents, independent of the child, routed to human review — no product researched documents this exact mechanism, so treat it as a Math Challenge-specific addition, not an industry pattern being copied.
  14. Full audit log of join/approve/remove/reject events, visible to the parent as well as retained internally, so a parent can always see the complete history of who requested access and when.

The safeguarding question

What stops a stranger from opening a “classroom” to collect children? Honestly: nothing about any product researched, by itself, fully stops that. Every one (Google Classroom, Kahoot!, ClassDojo) assumes a prior trust layer Math Challenge, as a school-less consumer product, does not automatically have. Google Classroom borrows Google Workspace for Education’s institutional vetting; Kahoot!‘s live-PIN model assumes the PIN is shared in an already-trusted room; ClassDojo’s one documented mechanism (verified-teacher-approves-parent) solves the opposite direction of trust from what we need, and even its “school consent” language presupposes a real school issuing notices [1][2][3]. No source reached describes a mechanism independently verifying a self-declared “teacher,” or specifically stopping mass-inviting of unrelated children’s parents.

Given that gap, our posture must be a layered set of frictions, not a single gate: verified adult identity before classroom creation; approval in the parent’s hands with teacher identity shown first (reversing ClassDojo’s one confirmed pattern); capped size and creation rate; teacher visibility limited to aggregate data with no private child channel; a standing one-tap “report” control reaching a human; and a full audit trail. This is a mitigation stack, not a guarantee — how much manual review (e.g., a human reviewing every classroom above some child-count) the team is willing to staff is an explicit policy call for the owner, since no purely technical control found here closes the gap completely.

Open questions for the project owner

  1. Launch teacher/classroom mode school-affiliated-only first (unlocking the FERPA/COPPA school-official pathway cleanly), or as an unaffiliated “any adult” feature (requiring direct-to-parent VPC and the fuller safeguarding stack)?
  2. What teacher identity verification is acceptable at launch — email+phone only, a paid ID-check step, or a required school email domain?
  3. Should a classroom have a hard size cap (e.g., 30–40 students) at launch, and should creation itself be rate-limited per account?
  4. Is a human-review queue for new classrooms (above a child-count threshold, or all of them at launch scale) staffable, and who owns it?
  5. Should competitive display default opt-in or opt-out, given the position-dependent-harm evidence (topic 18; Domínguez et al. here)?
  6. Is a later school/district-sanctioned tier (with a real contract giving FERPA/COPPA school-official coverage) intended, and should the unaffiliated data model be built for non-breaking migration to it?
  7. Should the EU/UK version ship in v1 at all, given GDPR Article 8 and Children’s Code requirements this research could not fully verify live (ICO fetches blocked) — or should this launch US-only first?

Fontes

  1. Google Classroom Help — Join a class ([support.google.com/edu/classroom/answer/6020282](
  2. ClassDojo Privacy Policy ([classdojo.com/privacy](
  3. Wikipedia — Kahoot! ([en.wikipedia.org/wiki/Kahoot!](
  4. Kahoot! for Schools ([kahoot.com/schools](
  5. Wikipedia — Khan Academy ([en.wikipedia.org/wiki/Khan_Academy](
  6. 34 CFR § 99.31(a)(1), Cornell Legal Information Institute ([law.cornell.edu/cfr/text/34/99.31](
  7. 16 CFR § 312.5, Cornell Legal Information Institute ([law.cornell.edu/cfr/text/16/312.5](
  8. GDPR Article 8 ([gdpr-info.eu/art-8-gdpr](
  9. Future of Privacy Forum — Student Privacy Pledge ([fpf.org/student-privacy-pledge](
  10. Wikipedia — Gamification of learning ([en.wikipedia.org/wiki/Gamification_of_learning](
  11. Wikipedia — ClassDojo ([en.wikipedia.org/wiki/ClassDojo](
  12. Wikipedia — Children's Online Privacy Protection Act ([en.wikipedia.org/wiki/Children%27s_Online_Privacy_Protection_Act](
  13. Math Challenge internal research — Leaderboards and Competition Design (docs/research/2026-07-31-mc-18-leaderboards-competition.md) — prior work in this repository, cross-referenced rather than duplicated for the psychology/rating-system literature
  14. UK ICO Age Appropriate Design Code (Children's Code) — attempted fetch at [ico.org.uk/for-organisations/childrens-code-hub](
  15. FTC COPPA compliance FAQ — attempted fetch at [ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions](

Perguntas que este documento deixa em aberto

Ficam sem resposta de propósito. São listadas, não resolvidas — transformá-las em FAQ exigiria inventar respostas que o documento não tem.

Um de 51 documentos de pesquisa, 168.346 palavras no total, contadas na compilação a partir dos próprios arquivos. Ler este documento no repositório