e-Literate

Present is Prologue

Tag: Family Educational Rights and Privacy Act

  • Piazza Makes Three Significant Changes To Deal With Privacy Issues

    Piazza Makes Three Significant Changes To Deal With Privacy Issues

    For those following the Piazza privacy issues, we have a new update where the company has made three significant changes in their response to privacy concerns from several universities. They are now using true opt-in for their Careers product, they have stopped the practice of using university logos without permission, and they are now offering an easier process to enter into no-cost agreements. For those who have not followed, read here here and here for background. And remember that this case of Piazza’s usage of student data can be seen as a case study on third-party learning apps as we move closer to the Next Generation Digital Learning Environment / LMS as Hub concept.

    Opt-In vs Opt-Out

    In my original post, one of the key issues I called out was that Piazza did not offer with their Q&A platform a true opt-in method for students to choose to allow their personal data to be shared with recruiters through the Careers product.

    What does that opt-in look like in practice? Faculty assign usage of the platform, and during setup students see a pre-checked box labeled “Sign me up” for opting into the Careers service. (more…)

  • University Responses to Piazza: Some good, some bad, some web site changes

    After our reporting from Nov 10 on “Popular Discussion Platform Piazza Getting Pushback For Selling Student Data”, I was invited by Piazza CEO Pooja Sankar to visit the Piazza offices. During my visit, we had an open conversation where I got to meet pretty much the entire staff and have a direct conversation with Sankar and Sunthar Premakumar. After that meeting, Piazza provided a statement that we published in “Piazza Response To Blog Post On Student Privacy”. The statement primarily dealt with a mea culpa from Piazza about working directly with institutions to form agreements around privacy policies and terms of use, including this section:

    We are committed to fixing this. In fact we already have started. We have entered into agreements with Georgia Tech and Brown, and have ongoing engagement with Stanford, UBC and UC Davis[1]. In our conversations universities have been very happy with our policies, practice, and compliance. We are fully committed to entering into contracts with universities that protect students, professors, and the institutions including FERPA, accessibility, and more.

    I have subsequently had conversations with staff from several of the schools mentioned above to verify the information. Some of the responses were good (as in positive review for Piazza and their willingness to work with the school), some were bad, and in parallel I noticed several web site changes that appear to be related to this reporting and follow-up. (more…)

  • Piazza Response To Blog Post On Student Privacy

    Based on Thursday’s blog post “Popular Discussion Platform Piazza Getting Pushback For Selling Student Data”, Piazza’s CEO Pooja Sankar invited me to meet at their offices Friday afternoon. Given the nature of Thursday’s post, I offered to publish any statement that Piazza had in response here at e-Literate, an offer they accepted. I will defer further analysis for a few days.  – PH

    Update: In the process of making copy-editing changes, we accidentally temporarily removed links accessibility and FERPA compliance documentations. They have been restored to the current draft.

    Sorry about that.

    Statement From Piazza CEO Pooja Sankar

    We at Piazza take our obligations to our community of students, professors, and institutions of higher education very seriously. We cherish and safeguard the privacy of our community. But we made a mistake by not engaging and responding to a way befitting of the trust placed in us. Many of our 1500 Universities reached out quite reasonably to enter into legal agreements for the free service. But as a lean, sub-30 person company without in-house legal, we were overwhelmed with all the (expensive) requests for one-off contracts (for a free Q&A service). We handled it poorly. This unfortunately gave people the impression that we were arrogant. You deserve better. We can do better. (more…)

  • Popular Discussion Platform Piazza Getting Pushback For Selling Student Data

    Update– Please see follow-on posts addressing changes since this post:

    Piazza is a collaborative question-and-answer platform that is “completely free” and can easily integrate into an institutional LMS, or in some cases replace the LMS. In our interviews for e-Literate TV, we have heard several glowing reviews about student engagement increasing thanks to the nature of the collaborative discussions. But in a case study of the aphorism that “if you’re not paying for the product, you are the product”, there are some significant privacy concerns around student data being sold, and several universities are pushing back.

    The source of the dispute is not one of a vendor getting caught selling or sharing data behind the scenes, however. Piazza is quite open about their ongoing usage of student data to generate revenue – in their privacy policy, in their click-through terms of service, and throughout their web site. The source of the dispute is Piazza’s lenient interpretation of privacy concerns and their apparent unwillingness to comply with institutional policies or guidance on student data privacy. (more…)

  • Protecting the Security of Student Data: CollegeNet v XAP, A Case Study

    In her blog “Law, Policy and IT” Tracy Mitrano expressed a concern: protecting student privacy as colleges and universities outsource information processing with external servicers. To ensure education records are protected, she writes, outsourcing contracts must explicitly detail the protection to be provided student data. She suggested contract provisions should require an entity comply with federal law including the Federal Education Rights Privacy Act. FERPA is one of the United States’ earliest public privacy laws enacted more than thirty years ago. She said “the Department of Education has already made clear that outsourcing these records does not alleviate the institution of its obligations under this law.” Her recommendation would build a “chain of responsibility” for the privacy and security of student education records. She observes these records have become “an important and permanent marker of an individual in a competitive society currently plagued by high unemployment rates even among college and professional school graduates in an era where corporations and firms routinely amass information from a variety of sources in the course of hiring.”

    Student data have been disclosed and sold without permission by external vendors. One example is described in the court records of CollegeNet Inc. v XAP Corporation, U.S. District Court for the District of Oregon.

    (more…)

  • A “Bold Idea” Essential for Student Privacy

    In Tracy Mitrano’s October 31, 2001 blog “FERPA, GLBA and HIPAA In Vendor Contract,” there was “a bold proposal.” She posited that most important action that can be taken to protect student privacy is a contractual requirement that contractors follow the same privacy requirements—including FERPA (Federal Education Rights and Privacy Act)—as colleges and universities themselves follow. Mitrano, is a lawyer in Cornell University’s Office of VP for Information Technology. She has written about intellectual property issues in universities.

    Mitrano warns this will not be easy: “Contract lawyers associated with Internet companies have heard of these laws, but are not knowledgeable about them.”

    (more…)

  • Restructuring higher education: NCES Stats-DC 2010 Conference

    This is a guest post by Jim Farmer.

    As you know, the Statewide Longitudinal Data Systems program is funding states’ work to improve their data systems. Over the past four years, 41 states and the District of Columbia have received more than half a billion dollars from this program. It has supported states as they link data from preschool, K-12, and postsecondary education. In some states, it supports their work to track students into the workforce. We’re committed to helping all states.

    Keynote presentation – Secretary of Education, Arne Duncan

    For 40 years institutional and policy researchers and information technologist have met with staff from the U.S. Department of Education’s National Center for Education Statistics to learn and advise on NCES data collection efforts. NCES is a source of useful statistics on K-12 and higher education. As described by Secretary Duncan, this year NCES staff and consultants provided detail data on the anticipated changes in higher education being implemented through the state agencies and conditions for any federal funding.

    At last year’s STAS-DC conference the primary focus of the 600 participants was qualifying to receive federal grants to develop statewide longitudinal data systems (SLDS). The $500 million was for in grants to state education agencies. Higher education did not receive any of those funds directly or via the state higher education executive officers.

    Now NCES has become the leader of perhaps the largest information technology (IT) implementation ever attempted in the U.S. It spans 4.339 colleges and universities and 98,916 public schools with annual revenue of $1.1 trillion. The Stats-DC 2010 conference, held 26-30 July in Bethesda, Maryland, focused on this implementation.

    This year’s conference provided evidence of the Department’s perspective of higher education and the requirements that would be placed on public colleges and universities and incentives for private non-profit and for-profit colleges to participate as well. Statewide Longitudinal Data Systems (SLDS) have become an unfunded mandate for higher education through new state-required data reporting requirements and data exchanges among colleges, universities, and schools. States that received funding agreed to build state-level data warehouses of these data; the model was centralization within each of the states or the use of servicers.

    In the long term higher education will be restructured by the metrics used to represent the success of college and university management and teaching faculty. The Stats-DC Conference offered an opportunity to learn the underlying assumptions about education and perception of the value and use of data. A caution: The U.S. Department of Education has a number of knowledgeable, dedicated, and hard-working educators. This is also true of the state education agencies. But the design and beginning implementation of a national education data system within the available time does not permit the thoughtful planning that would have reduced the risks of unintended consequences.

    (more…)