Report: Ed Tech Startups Stink at Student Data Privacy

Education technology start-ups are doing a lousy job of protecting the data privacy of the students who use their products. That's not to say they've necessarily suffered data breaches as a result; it's primarily because privacy concerns just aren't a priority. That's the outcome of a research project undertaken by six graduate researchers in public policy and management at Carnegie Mellon's Heinz College. Granted, the sample size was small (six ed tech companies), so a summary of the findings calls them "exploratory, rather than empirically conclusive."

The project's initial intent was to "capture the status quo" of how ed tech startups interact with their stakeholders about student data privacy practices and to identify best practices for those companies and others in the industry in formulating communications plans on privacy.

The research team developed a database of 450 ed tech startups, which they winnowed down to 18 "finalists" based on criteria that included student data privacy risk, staff size, reputation and revenue growth. Ultimately, six companies agreed to participate, which involved going through multi-hour interviews on their privacy and communications practices.

What the master's students found was that aside from adhering to federal and state-level requirements, data privacy wasn't on the radar. What was more important during their first five years of operation was customer acquisition and product development. Concerns about privacy seemed to have no impact on innovation.

Also, because startups are notoriously shorthanded and there's little demand from prospects and customers, they don't bother developing "formal strategies" around their public-facing communications on student data privacy for their external stakeholders. Frequently, they'll "borrow" or adapt sections from competitors' privacy policies or build up their policies only when customers demand it or as compliance laws change.

School districts can influence how the start-ups they work with prioritize considerations related to data privacy. As the summary noted, "School districts were the greatest force for our startups to change their privacy behaviors." However, the report added, the researchers weren't persuaded that districts had the capacity to truly assess technology coming into their schools from the data privacy perspective.

Investors financing these start-ups can also play a role in helping them put "strong privacy practices" into place.

As for the ed tech companies themselves, the research paper advised them to become more proactive. By doing so, they "can position their vigilance as a key differentiator for their product, capture a broader market share, and share in the responsibility for protecting sensitive student data."

The summary of the report's findings can be found on the Heinz College website here.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • students using digital devices, surrounded by abstract AI motifs and soft geometric design

    Ed Tech Startup Kira Launches AI-Native Learning Platform

    A new K-12 learning platform aims to bring personalized education to every student. Kira, one of the latest ed tech ventures from Andrew Ng, former director of Stanford's AI Lab and co-founder of Coursera and DeepLearning.AI, "integrates artificial intelligence directly into every educational workflow — from lesson planning and instruction to grading, intervention, and reporting," according to a news announcement.

  • toolbox featuring a circuit-like AI symbol and containing a screwdriver, wrench, and hammer

    Microsoft Launches AI Tools for Educators

    Microsoft has introduced a variety of AI tools aimed at helping educators develop personalized learning experiences for their students, create content more efficiently, and increase student engagement.

  • laptop displaying a red padlock icon sits on a wooden desk with a digital network interface background

    Reports Point to Domain Controllers as Prime Ransomware Targets

    A recent report from Microsoft reinforces warns of the critical role Active Directory (AD) domain controllers play in large-scale ransomware attacks, aligning with U.S. government advisories on the persistent threat of AD compromise.

  • Two hands shaking in the center with subtle technology icons, graphs, binary code, and a padlock in the dark blue background

    Two Areas for K-12 Schools to Assess for When to Work with a Managed Services Provider

    The complexity of today’s IT network infrastructure and increased cybersecurity risk are quickly moving beyond many school districts’ ability to manage on their own. But a new technology model, a partnership with a managed services provider, offers a way forward for schools to overcome these challenges.