PogoWasRight.org

Menu
  • About
  • Privacy
Menu

White paper: The Evolution of the Student Data Privacy and Security Paradigm

Posted on June 19, 2015June 26, 2025 by Dissent

The Evolution of the Student Data Privacy and Security Paradigm:

Incorporating the Effective Data Privacy and Security Practices of Other Sectors in Education
A RESOURCE FOR EDUCATION POLICYMAKERS AND PRACTITIONERS

Authors: David F. Katz, Steven Y. Winnick, Reginal J. Leichty, & Katherine E. Lipper

… This publication first examines data privacy and security approaches in the financial services, healthcare, and software sectors. A landscape analysis of these three sectors is intended to help states, districts, and schools see how common issues are addressed in other fields as they consider how to best to address privacy and security in their unique contexts. The paper then makes recommendations regarding best practice standards for use in districts and schoolsi as follows:

1. Establishing internal ground rules by assessing your data collection practices; identifying privacy and security objectives; engaging key stakeholders and ensuring oversight of and accountability for data privacy and security compliance; conducting a risk assessment to identify security needs; implementing a security program; and ensuring compliance through background checks, training, monitoring individual and institutional activity, and accountability for all participants involved in the processing, exchange, transfer, or analysis of student data.

2. Managing third‐party vendor relationships by putting in place a vendor approval and governance framework; executing risk assessments before selecting vendors; relying on legal counsel and a technical expert to draft agreements that include appropriate data protections and constraints on the use of data; establishing baseline standards for privacy and data security of student data; declining “contracts of adhesion” that give vendors unrestricted access to and use of data and the authority to make unilateral changes in agreements (i.e., “take it or leave it” contracts); ensuring vendor compliance with security requirements; requiring audits, indemnification, and confidentiality; and establishing responsibilities in the event of data breach.

3. Committing to continuous improvement and transparency with respect to data practices to ensure public understanding and support and to maintain credibility for responsible collection and use of student data by monitoring legal requirements; leveraging information about data use and security to make improvements over time; dedicating budget dollars to maintain privacy and security controls; and promoting open communications with and educating parents, students, and educators regarding the need for secure and reasonable data collection, sharing, and use.

Download the paper from EducationCounsel.com.

h/t, Daniel Solove

No related posts.

Category: Youth & Schools

Post navigation

← Revenge porn trickster pleads guilty in California case as federal trial nears
Major Mac Flaw Spills Passwords on Apple Devices →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
  • EPIC Publishes New Whitepaper Detailing Privacy Risks of Government Data Mining Programs
  • Modern cars are spying on you. Here’s what you can do about it.
  • Attorney General James and Multistate Coalition Secure $5.1 Million from Education Software Company for Failing to Protect Students’ Data       
  • EU Parliament committee votes to advance controversial Europol data sharing proposal

RSS Recent Posts at DataBreaches.net

  • Short-term renewal of cyber information sharing law appears in bill to end shutdown
  • Yanluowang ransomware IAB pleads guilty
  • Lawsuit Alleges Ex-Intel Employee Hid 18,000 Sensitive Documents Prior to Leaving the Company
  • HIPAA, but for non-Covered Entities?
  • Manassas City Public Schools close on Monday due to cyberattack
©2025 PogoWasRight.org. All rights reserved.