Privacy, Transparency, Trust

Back to Basics: Student Data Privacy is an Obligation, Not an Obstacle

Back to Basics: Student Data Privacy is an Obligation, Not an Obstacle

The conversation about education and workforce data moves fast: new reports, new discussions, new debates. But the issues that determine whether data actually improves people’s lives don’t change nearly as often as the headlines suggest. Back to Basics is DQC’s ongoing series on the fundamentals: the data policies, practices, and principles that have always mattered—and still do. Each post steps back from the moment to explain what’s really at stake—and why getting it right is worth the sustained effort. This post is the third installment of Back to Basics; read the other posts in this series here.

Data about schools and how well they serve students is a valuable tool that state and local education leaders can and should use to make decisions that support students. As stewards of this data, education agencies hold two complementary responsibilities: using data effectively and ethically to help students and protecting the privacy of that data. But too often, leaders use privacy as an excuse not to engage with data at all, positioning privacy as an obstacle to data use, rather than an essential requirement for making data use happen. Fortunately, leaders don’t have to choose between using data to improve schools and protecting students’ privacy. 

Leaders must focus on how to safeguard data while ensuring that data works for those supporting students. They must prioritize being transparent about what data they’re collecting, how it’s used, and why it matters and place appropriate guardrails and accountability around data use to ensure that bad actors are penalized. 

There’s risk in everything we do, but there’s enormous risk in leaders not using the resources—especially data—at their disposal to help students. By being intentional about centering privacy, leaders can protect against the risk that comes from inaction. While it’s impossible to completely eliminate risk in any area of our lives, what matters most is how leaders address any incidents and move forward to continue to safeguard student data. Above all else, action is a requirement for keeping data secure.

Centering privacy is part of effective data use. Take healthcare, for example: When people go to the doctor, doctors run tests, ask personal questions, and examine areas of concern. Every one of those tests generates sensitive information about the patient, but in return, patients receive information about the status of their health, context about how those results impact their lives, and see trends in their health over time. Often, these results are accessible through online portals that allow individuals to see their information at a moment’s notice. 

Like education data, health data privacy is protected by numerous laws and technological solutions that reduce the risk of data being inappropriately accessed. And, as in the education field, people continue to get value from trusted professionals seeing their results and using online portals to share and receive actionable information. 

Centering privacy is about building trust. Protecting privacy requires much more than robust laws and security measures. People won’t value data they can’t trust is being protected and used appropriately. Leaders must build this trust by showing the public their agencies and staff have the policies and expertise needed to keep data safe. 

In recent years, some state legislators have explored legislation that would require parents to give consent for almost any daily use of student data. While these bills have the appearance of giving parents more agency in decisions about their student data, their actual impact is usually to push complex privacy decisions into the hands of parents and allow leaders to shirk their responsibilities and treat privacy as an obstacle that parents alone were tasked with navigating. Instead of viewing privacy as the responsibility of parents, decisions about what data to collect and how to use it are the responsibility of education leaders to make in conversation with parents. Policymakers can’t build trust by hiding data practices or by pushing consent issues onto parents. Instead, leaders must focus on being transparent, listening to educators and parents across their state, consulting with data experts, and making informed decisions. 

Centering privacy is never “complete.” Data practices are always evolving, requiring policymakers to regularly revisit and revise privacy policies. One striking example of this evolution is Louisiana, a state whose overly-restrictive education data privacy law left its leaders unable to automatically administer emergency funds to families at the height of the pandemic. The law prevented state agencies from connecting data across systems, making it nearly impossible to link free and reduced-price lunch data to the systems used to distribute welfare benefits. Legislators had to scramble to find a short-term fix for the problem and were left with additional challenges moving forward. State and local leaders must recognize when privacy policies and practices are outdated and move to update these policies to ensure that they work for leaders and communities alike.  

The work to improve our schools is critical; inaction isn’t an option. But leaders don’t need to walk away from data in order to protect privacy. First and foremost, privacy is an obligation, not an obstacle. 

Secret Link