Safeguarding is not a side conversation in digital transformation. It is the condition that determines whether children can participate safely and whether trust in education technology can endure. At the 2025 ASEAN ICT Forum on Child Online Protection, this question sat at the centre of the agenda: how do we protect children and young people in an increasingly complex digital landscape, without limiting the benefits that technology can bring to learning and inclusion (UNICEF Malaysia, 2025)?
Held in Kuala Lumpur on 18-19 November 2025, and under the theme “Empowering Children and Strengthening ASEAN’s Commitment to a Safer Digital Future”, the Forum brought together policymakers, technology and digital industry leaders, civil society organisations, and young people from across the region. These stakeholders aimed to confront growing online risks, share emerging solutions, and shape emerging policy directions on child online protection (ASEAN Secretariat, 2025; ASEAN ICT Forum, 2025; UNICEF Malaysia, 2025).
Within the programme, EdTech Hub hosted a session titled ‘Ensuring rights and protection in and through the digital transformation of education’. The session aimed to do three things. First, to share what we are learning from EdTech Hub’s work on out-of-school children and youth (OOSCY), and on ethics, AI, and data privacy in education technology, including how provider policies compare with national and regional expectations. Second, to create a practical space for participants to work through what safeguarding challenges can look like in real education settings, and what effective responses require across government, industry, and civil society. Third, to hear directly from different stakeholders about where the biggest gaps and tensions sit, and what support or action is needed to move from shared commitments to consistent practice.
To ground the discussion in a multidisciplinary, multi-stakeholder perspective, we curated the session in conjunction with Dr Kruakae Pothong, a Visiting Fellow at the London School of Economics and Political Science and consultant at the Digital Futures for Children centre.
What Happened?
We opened with a short introduction that set out the session objectives and our co-creation approach. We explained that the session brought together youth, policymakers, providers, and civil society to connect evidence with lived experience, and that it aligned with what EdTech Hub has been seeing through our work on ethics, AI, and data privacy in education. We then handed over to youth representatives from the UNICEF Youth Advisory Group, Aisha Putri Safrianty and Allyzsa Zahril, who shared a video capturing the voices of young people across Southeast Asia. The video surfaced clear priorities: Young people wish to be safer online, but they also want adults to take their experiences seriously, not only as ‘users’ to be protected, but as rights holders whose views should shape policy and practice. Aisha and Allyzsa followed with reflections on what young people hope to see from governments, schools, and technology providers, including clearer accountability when harms occur and stronger safeguards built into the tools they are expected to use (ASEAN ICT Forum, 2025).
This was followed by a presentation from Dr Pothong, who discussed the holistic approach grounded in children’s rights to ensure child online safety in the context of education. She began by recognising the international efforts to mainstream children’s, sharing examples of research, guidance and toolkits for both policymakers and digital developers. Dr Pothong then proceeded to share a mix of positive and negative experiences of children’s use of technologies for learning. These experiences raised the question of whether there are tangible benefits in children’s use of EdTech that outweigh the risks.
In the context of education, imminent risks revolve around safety and privacy. These risks manifest, for example, in forms of data breaches, which could result in identity theft, and commercialisation of children’s education data, as part of the exploitative ad-tech infrastructure.
To counter these risks, Dr Pothong provided examples of rights-respecting EdTech that have gone the extra mile, beyond respecting children’s privacy, ensuring safety and regulatory compliance. These products have also taken into consideration children’s development, wellbeing, creativity, sociality and agency. The common threads across these examples are
- ethical commercial models (not entirely profit-driven) and
- the intention to design for children and their rights.
She concluded with a rights-based design guide to help developers navigate their competing priorities and enable them to design for children’s rights.
EdTech Hub then shared emerging insights from our work in the region on ethics, data privacy, and responsible governance in education technology. We drew on examples from our work on out of school children and youth (OOSCY) and our then-ongoing terms and conditions analysis, which compares the policies of private EdTech providers against national requirements and regional guidance, including ASEAN level principles and AI governance discussions. Across these strands of work, one message is consistent. Safeguarding will not improve through principles alone. What is often missing is the operational layer: clearer education specific frameworks, ongoing monitoring, and enforceable accountability across ministries, schools, and providers
This was followed by an interactive workshop led by EdTech Hub, designed to make safeguarding feel real rather than abstract. We wanted participants to see what a data privacy incident can look like in practice, and to work through the kinds of decisions that are less obvious until you are faced with a real situation. The exercise also created a structured opportunity for mixed conversations, with policymakers, EdTech providers, non-governmental organisations and other stakeholders working side by side to surface what each group assumes, knows, and needs when a breach occurs. The scenarios were inspired by issues we have encountered through our work on out of school children and youth (OOSCY) and our terms and conditions analysis, and they deliberately tested how responses might need to shift when the learner profile and context changes. Closing statements were then offered by MOE Malaysia, Pandai, and Antonia Mandry from UNICEF EAPRO, reinforcing the shared responsibility across government, industry, and regional partners to move from commitments to implementation.
What We Heard and Observed
- Participants were energised by the chance to work through realistic scenarios together, rather than staying at the level of general principles.
- Several people noted they had not had many opportunities to tackle these problems in mixed groups. Bringing different perspectives into the same discussion made the trade-offs clearer.
- The exercises also surfaced uneven levels of technical confidence. Policymakers sometimes struggled with the more technical aspects of data privacy and breach response, and it was helpful to have private sector participants at the table to explain how systems work in practice and what is feasible. This helped groups move from abstract concerns to concrete steps.
- We asked groups to compare their responses across two profiles: a “typical” school setting and an out of school children and youth (OOSCY) context. The OOSCY scenario was consistently seen as more challenging, but it made equity considerations a pivotal point of discussion, including who is most exposed when protections are weak and who has the least ability to report harm or seek redress.
What We Learned
We left the session with three practical lessons. First, principles are important, but people need operational guidance to act under pressure, especially when incidents involve children’s data. Second, a balance needs to be struck between sharing responsibility for safeguarding and ensuring accountability, with clearly defined roles to prevent mistakes from falling through the gaps. Third, equity cannot be an add on. In OOSCY contexts, risks are higher and routes to reporting and redress are often weaker, so safeguards need to be stronger, not lighter.
When thinking about online child protection through a lens of research, policy, and practice more broadly,
- Regulation is one of the keys to steer digital, including EdTech, design towards safety and child-rights-respecting. However, regulation tends to focus exclusively on the hygiene factors, leaving creativity, sociality, and agency, which form a core part of child development and wellbeing, insufficiently catered to.
- Research shows that developers tend to perceive designing for children and their rights as resource intensive. Some developers lack sufficient knowledge and expertise in designing for children and their rights.
- Therefore, governments must ensure that both the national laws and regulatory enforcement are robust to protect children’s rights in the digital environment. Equally, investors and funders can contribute to making a business case for designing for children and their rights, while international organisations continue their efforts to mainstream children’s rights, especially through capacity building
The combination of these recommendations is aimed at fostering child-rights respecting innovation. With the holistic, rights-based approach, digital technologies, including EdTech, will better serve children and allow them to equally benefit from opportunities that technologies can offer without or with minimal risks.
Linked Resource:
- AI in Southeast Asia: Ethical Governance of AI in Education. Assessing regional AI policy alignment and implications for learners and education systems
- EdTech for Out-of-School Children and Youth: A Rapid Evidence Review for the Southeast Asian Region
Acknowledgements:
Thank you to Haani Mazari, Jazzlyne Gunawan and Sangay Thinley from the EdTech Hub for supporting this work and to Alex Chernyavskaya and UNICEF for the opportunity. Aisha Putri Safrianty, Allyzsa Zahril, Pandai, Ministry of Education Malaysia and Dr Antonia Mandray for their contributions during the session.
This work is part of the portfolio of projects delivered by the ASEAN-UK SAGE programme. The ASEAN-UK SAGE programme is delivered by the British Council and SEAMEO Secretariat, in partnership with EdTech Hub and Australian Council for Educational Research (ACER), and is an ASEAN cooperation programme funded by the UK.