Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal data is retained only as long as necessary to provide services, with retention periods determined by factors including account maintenance, legal requirements, and business needs. De-identified or anonymized data may be retained for longer periods for research and analytics purposes.
This analysis describes what Khan Academy's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes Khan Academy's retention framework, including the conditions under which data is deleted or de-identified and the permissible extended retention of anonymized data. The policy does not specify fixed retention periods for particular data categories, which may be relevant for compliance evaluation under GDPR, CCPA, and student privacy laws.
Interpretive note: The policy does not specify fixed retention periods for individual data categories, and the adequacy of the stated retention framework depends on applicable jurisdictional requirements that vary by regulation and data type.
Under this provision, the agreement states that personal data is retained as long as necessary for service provision and legal or business purposes, after which it is deleted or de-identified. De-identified and anonymized data may be retained indefinitely for product development and research purposes.
Cross-platform context
See how other platforms handle Data Retention Policy and similar clauses.
Compare across platforms →Monitoring
Khan Academy has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Our practice is to retain your personal data only for as long as necessary to provide our services to you, including maintaining your account on Khan Academy. In determining how long we retain your personal data, we consider how keeping the information will assist the learner (or the school, in the case of school accounts), our legal requirements and other business needs. When we have no ongoing legitimate business need to process your personal Information, our policy is to delete or de-identify the data. We may retain and use de-identified or anonymized data for longer periods for purposes such as product development, research, analytics and for demonstrating the impact of our Service.Excerpt from Khan Academy's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages GDPR's data minimization and storage limitation principles (Article 5), COPPA's data retention requirements for children's information, FERPA's provisions on the retention and destruction of student records, and CCPA's requirements regarding data retention disclosures. The policy does not specify retention periods for individual data categories, which GDPR guidance suggests should be documented in the record of processing activities. 2. GOVERNANCE EXPOSURE: Medium. The absence of specific retention timelines for individual data categories (account data, learning activity data, payment data, student records) creates a compliance documentation gap under GDPR and applicable state privacy laws. The policy's allowance for extended retention of de-identified data for research and analytics should be evaluated against applicable definitions of de-identification under GDPR, CCPA, and FERPA. 3. JURISDICTION FLAGS: GDPR requires that personal data not be kept longer than necessary and that retention periods be documented. COPPA requires deletion of children's personal information when it is no longer needed for the purpose for which it was collected. FERPA has specific provisions regarding the retention and destruction of student education records. California's CCPA requires disclosure of retention periods or the criteria used to determine them. 4. CONTRACT AND VENDOR IMPLICATIONS: School and district procurement teams should confirm that their contracts with Khan Academy specify retention and deletion timelines for Student Personal Data, particularly upon account termination or at the end of a school year or contract term. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should request Khan Academy's data retention schedule for specific data categories to evaluate GDPR storage limitation compliance and CCPA retention disclosure requirements. Schools should confirm that student data deletion is operationally triggered upon account closure or contract termination consistent with the policy's stated framework.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes Khan Academy's retention framework, including the conditions under which data is deleted or de-identified and the permissible extended retention of anonymized data. The policy does not specify fixed retention periods for particular data categories, which may be relevant for compliance evaluation under GDPR, CCPA, and student privacy laws.
Under this provision, the agreement states that personal data is retained as long as necessary for service provision and legal or business purposes, after which it is deleted or de-identified. De-identified and anonymized data may be retained indefinitely for product development and research purposes.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Khan Academy.