Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Mastery Manager is a web based K-12 assessment platform that lets schools and districts create, administer, score and report on student assessments. Because it processes pupil and educator personal data, including assessment results about children, it carries a high privacy risk and calls for careful GDPR and ePrivacy handling.
Mastery Manager is a web based assessment and test management platform used by K-12 schools and districts to create, administer, score and report on student assessments. Operated from the United States, it handles personal data about pupils and educators, including standards based assessment results. Because much of this data concerns children, schools and providers must treat it with particular care under data protection law.
Mastery Manager lets teachers build assessments, align them to standards, administer them online or on paper, score responses and run real time reports on pupil progress. Administrators use it to track achievement across classrooms, schools and districts. The platform is delivered as a subscription service to education institutions, which act as the data controllers for the pupil information they upload and generate.
The platform processes pupil records, educator accounts and assessment results, which together form sensitive information about, often, children. To run the authenticated service it relies on first party session and login cookies that keep users signed in and protect each session. These functional cookies are essential to the service, while any additional analytics or preference cookies would be non essential and require a separate legal basis.
Under the GDPR the school is the controller and the provider is a processor acting on documented instructions. The ePrivacy Directive governs the cookies set in the browser, requiring information and, for non essential cookies, consent. Because the data concerns children, the GDPR expects extra safeguards, clear information aimed at parents and pupils, and a cautious approach to any profiling or marketing, which should not occur in an assessment context.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Essential session and login cookies do not need consent because they are strictly necessary to deliver the assessment platform the user has requested. Any non essential cookies, such as analytics, must not be set until the user has given informed and freely given consent. Schools should make clear to staff, parents and pupils what is collected, why, and how consent can be withdrawn, using language that is easy to understand.
Because Mastery Manager is hosted in the United States, pupil and educator data from the European Economic Area is transferred to a third country. These transfers can rely on the EU US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses supported by a transfer risk assessment and supplementary measures. Schools should confirm which mechanism applies before sending any pupil data abroad.
Schools should sign a data processing agreement with the provider, complete a Data Protection Impact Assessment, and apply strict data minimisation so that only necessary pupil data is processed. Retention periods, access controls and breach procedures should be agreed in writing, and safeguards for children must be documented. Parents and pupils should receive clear privacy information, and staff should be trained on how the platform handles assessment data.
Websites using Mastery Manager must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is strongly recommended because Mastery Manager processes assessment data about pupils, who are often children, on a large scale across schools and districts. The assessment should examine the lawful basis, US data transfers, retention periods and the rights of pupils and parents. Particular attention must be paid to safeguards for children, data minimisation and the role of the school as controller.
Sample consent text
We use Mastery Manager to deliver and report on assessments; essential session cookies keep you signed in, and we ask for your consent before setting any non essential cookies.
Third-party domains contacted
masterymanager.comwww.masterymanager.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| PHPSESSID | Functional | Session | Maintains the authenticated user session while a teacher, administrator or pupil is signed in to the assessment platform. |
| mm_auth | Functional | Session | Keeps the user securely logged in and protects the session against unauthorised reuse during assessment activities. |
| mm_csrf | Functional | Session | Provides cross site request forgery protection to keep form submissions and assessment actions secure. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
Mastery Manager mainly sets first party session and login cookies that keep users signed in and protect each authenticated session. These functional cookies are essential to delivering the assessment platform. Any additional analytics or preference cookies would be non essential and should only be set with consent.
Consent is not required for the essential session and login cookies because they are strictly necessary to provide the service the user has requested. However, consent under the ePrivacy Directive is required before any non essential cookies, such as analytics, are set. Schools should obtain that consent in a clear and freely given way.
The provider processes pupil and educator data to perform its contract with the school under Art. 6(1)(b) GDPR. The school, as controller, usually relies on a public task or legitimate interest under Art. 6(1)(e) or (f) GDPR, while consent under Art. 6(1)(a) applies to any non essential cookies. Because pupils may be children, extra safeguards apply.
Mastery Manager is operated from the United States, so pupil and educator data from the European Economic Area is transferred there. These transfers rely on the EU US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses with supplementary measures. Schools should confirm the mechanism in the contract before sending pupil data abroad.
Yes, a Data Protection Impact Assessment is very likely required. The platform processes assessment data about pupils, who are often children, on a large scale, which is exactly the kind of high risk processing that triggers a DPIA. The assessment should cover lawful basis, US transfers, retention and safeguards for children.
Sign a data processing agreement with the provider, complete a DPIA, and apply strict data minimisation so only necessary pupil data is processed. Agree retention periods, access controls and breach procedures in writing, document safeguards for children, and give parents and pupils clear privacy information. Train staff on how the platform handles assessment data.
Several K-12 assessment platforms exist, some hosted in the European Union, which can reduce international transfer concerns. When comparing alternatives, look at hosting location, data protection terms, support for children safeguards and the strength of the data processing agreement. The right choice depends on your data protection requirements and educational needs.
List the essential session and login cookies set by Mastery Manager, explain their purpose and duration, and state that they are strictly necessary. Disclose any non essential cookies and how consent is collected and withdrawn. Reference the US data transfers and link to the provider information so parents, pupils and staff can understand how their data is used.