e-Literate

Present is Prologue

Tag: FERPA

  • Piazza Makes Three Significant Changes To Deal With Privacy Issues

    Piazza Makes Three Significant Changes To Deal With Privacy Issues

    For those following the Piazza privacy issues, we have a new update where the company has made three significant changes in their response to privacy concerns from several universities. They are now using true opt-in for their Careers product, they have stopped the practice of using university logos without permission, and they are now offering an easier process to enter into no-cost agreements. For those who have not followed, read here here and here for background. And remember that this case of Piazza’s usage of student data can be seen as a case study on third-party learning apps as we move closer to the Next Generation Digital Learning Environment / LMS as Hub concept.

    Opt-In vs Opt-Out

    In my original post, one of the key issues I called out was that Piazza did not offer with their Q&A platform a true opt-in method for students to choose to allow their personal data to be shared with recruiters through the Careers product.

    What does that opt-in look like in practice? Faculty assign usage of the platform, and during setup students see a pre-checked box labeled “Sign me up” for opting into the Careers service. (more…)

  • University Responses to Piazza: Some good, some bad, some web site changes

    After our reporting from Nov 10 on “Popular Discussion Platform Piazza Getting Pushback For Selling Student Data”, I was invited by Piazza CEO Pooja Sankar to visit the Piazza offices. During my visit, we had an open conversation where I got to meet pretty much the entire staff and have a direct conversation with Sankar and Sunthar Premakumar. After that meeting, Piazza provided a statement that we published in “Piazza Response To Blog Post On Student Privacy”. The statement primarily dealt with a mea culpa from Piazza about working directly with institutions to form agreements around privacy policies and terms of use, including this section:

    We are committed to fixing this. In fact we already have started. We have entered into agreements with Georgia Tech and Brown, and have ongoing engagement with Stanford, UBC and UC Davis[1]. In our conversations universities have been very happy with our policies, practice, and compliance. We are fully committed to entering into contracts with universities that protect students, professors, and the institutions including FERPA, accessibility, and more.

    I have subsequently had conversations with staff from several of the schools mentioned above to verify the information. Some of the responses were good (as in positive review for Piazza and their willingness to work with the school), some were bad, and in parallel I noticed several web site changes that appear to be related to this reporting and follow-up. (more…)

  • Piazza Response To Blog Post On Student Privacy

    Based on Thursday’s blog post “Popular Discussion Platform Piazza Getting Pushback For Selling Student Data”, Piazza’s CEO Pooja Sankar invited me to meet at their offices Friday afternoon. Given the nature of Thursday’s post, I offered to publish any statement that Piazza had in response here at e-Literate, an offer they accepted. I will defer further analysis for a few days.  – PH

    Update: In the process of making copy-editing changes, we accidentally temporarily removed links accessibility and FERPA compliance documentations. They have been restored to the current draft.

    Sorry about that.

    Statement From Piazza CEO Pooja Sankar

    We at Piazza take our obligations to our community of students, professors, and institutions of higher education very seriously. We cherish and safeguard the privacy of our community. But we made a mistake by not engaging and responding to a way befitting of the trust placed in us. Many of our 1500 Universities reached out quite reasonably to enter into legal agreements for the free service. But as a lean, sub-30 person company without in-house legal, we were overwhelmed with all the (expensive) requests for one-off contracts (for a free Q&A service). We handled it poorly. This unfortunately gave people the impression that we were arrogant. You deserve better. We can do better. (more…)

  • Popular Discussion Platform Piazza Getting Pushback For Selling Student Data

    Update– Please see follow-on posts addressing changes since this post:

    Piazza is a collaborative question-and-answer platform that is “completely free” and can easily integrate into an institutional LMS, or in some cases replace the LMS. In our interviews for e-Literate TV, we have heard several glowing reviews about student engagement increasing thanks to the nature of the collaborative discussions. But in a case study of the aphorism that “if you’re not paying for the product, you are the product”, there are some significant privacy concerns around student data being sold, and several universities are pushing back.

    The source of the dispute is not one of a vendor getting caught selling or sharing data behind the scenes, however. Piazza is quite open about their ongoing usage of student data to generate revenue – in their privacy policy, in their click-through terms of service, and throughout their web site. The source of the dispute is Piazza’s lenient interpretation of privacy concerns and their apparent unwillingness to comply with institutional policies or guidance on student data privacy. (more…)

  • Empowering Students in Open Research

    Phil and I will be writing a twice-monthly column for the Chronicle’s new Re:Learning section. In my inaugural column, “Muy Loco Parentis,” I write about how schools make data privacy decisions on behalf of the students that the students wouldn’t make for themselves, and that may even be net harmful for the students. In contrast to the ways in which other campus policies have evolved, there is still very much a default paternalistic position regarding data.

    But the one example that I didn’t cover in my piece happens to be the one that inspired it in the first place. A few months back at the OpenEd conference, I heard a presentation from CMU’s Norm Bier about that challenges of getting different schools to submit OLI student data to a common database for academic research. Basically, every school that wants to do this has to go through its own IRB process, and every IRB is different. Since the faculty using the OLI products usually aren’t engaged in the research themselves, it generally isn’t worth the hassle to go through this process, so the data doesn’t get submitted and the research doesn’t get done. Note that Pearson and McGraw Hill do not have this problem; if they want to look at student performance in a learning application across various schools, they can. Easily. Something is wrong with this picture. I proposed in Norm’s session that maybe students could be given an option to openly publish their data. Maybe that would get around the restrictions. David Wiley, who does a lot more academic research than I do, seemed to think this wasn’t a crazy idea, so I’ve been gnawing on the problem since then.

    I have talked to a bunch of researchers about the idea. The first reaction is often skepticism. IRB is not so easy to circumvent (for good reason). What generally changed their minds was the following thought experiment:

    • Suppose that, in some educational software program, there was a button labeled “Export.” Students could click the button and export their data in some suitably anonymized format. (Yes, yes, it is impossible to fully de-identify data, but let’s posit “reasonably anonymized” as assessed by a community of data scientists.) Would giving students the option to export their data to any server of their choosing trigger the requirement for IRB review? [Answer: No.]
    • Suppose the export button offered a choice to export to CMU’s research server. Would giving students that option trigger the requirement for IRB review? [Answer: Probably not.]

    There are two shades of gray here that are complications. First, researchers worry about the data bias that comes from opt in. And the further you lead students down the path toward encouraging them to share their data, such as making sharing the default, the more the uneasiness sets in. Second and relatedly, there is the issue of informed consent. There was a general feeling that, even if you get around IRB review, there is still a strong ethical obligation to do more than just pay lip service to informed consent. You need to really educate students on the potential consequences of sharing their data.

    That’s all fair. I don’t claim that there is a silver bullet. But the thought experiment is revealing. Our intuitions, and therefore our policies, about student data privacy are strongly paternalistic in an academic context but shift pretty quickly once the institutional role fades and the student’s individual choice is foregrounded. I think this is an idea worth exploring further.

  • Policy Updates on FERPA and Net Neutrality

    Two policy debates that could have a significant impact on education – updates on FERPA and data privacy & FCC proposals on Net Neutrality – both entered the next stage this week.

    FERPA Modernization

    I recently wrote about the new federal moves to update FERPA to handle the age of Big Data (should I have used scare quotes there?).

    Yesterday the White House released its report on big data and privacy implications. The focus was broadly on big data, but there will be implications for ed tech, with several key recommendations specifically focused on the education sector. Specifically, there will be a push to update and revise the Family Educational Rights and Privacy Act (FERPA, enacted in 1974) and Children’s Online Privacy Protection Act (COPPA, enacted in 2000).

    I was quite optimistic about the federal approach based on this report, and yesterday we got some more apparently good news – a bipartisan approach to improve data privacy and update FERPA made in a reasonable fashion (dogs and cats, living together). As reported by THE Journal, Senators Markey (D-MA) and Hatch (R-UT) introduced the “Protecting Student Privacy Act”, getting even a warm reception from the Software and Information Industry Association (SIIA), which had objected to the earlier version discussed in January. THE Journal summarized the key parts of the legislation (full text here): (more…)

  • White House report on big data will impact ed tech

    Yesterday the White House released its report on big data and privacy implications. The focus was broadly on big data, but there will be implications for ed tech, with several key recommendations specifically focused on the education sector. Specifically, there will be a push to update and revise the Family Educational Rights and Privacy Act (FERPA, enacted in 1974) and Children’s Online Privacy Protection Act (COPPA, enacted in 2000). Education Week set the context quite well in its article:

    FERPA, which was written before the Internet existed, is intended to protect disclosure of the personally identifiable information contained in children’s education records. And COPPA, which requires parental consent under certain conditions for the online collection of personal information from children under age 13, was written before the age of smartphones, tablets, apps, the cloud, and big data.

    Think Progress, part of a group founded by John Podesta, who also led the White House study, summarized the key findings as follows:

    1. Giving consumers more protection and control over their private data with a bill of rights

    2. Pass a singular data breach law to prevent the next Target fiasco

    3. Strengthen outdated and archaic laws, such as the Electronic Communications Privacy Act (ECPA), which dictates how the government accesses emails

    4. Give non-citizens the same privacy protections

    5. Ensure data collected on students is used only for educational purposes

    Ed Tech Sections of the Report Itself:

    First, there is a description of the situation in pages 24 – 26 that is too long to quote but worth highlighting: (more…)