Report: Ed Tech Startups Stink at Student Data Privacy

Education technology start-ups are doing a lousy job of protecting the data privacy of the students who use their products. That's not to say they've necessarily suffered data breaches as a result; it's primarily because privacy concerns just aren't a priority. That's the outcome of a research project undertaken by six graduate researchers in public policy and management at Carnegie Mellon's Heinz College. Granted, the sample size was small (six ed tech companies), so a summary of the findings calls them "exploratory, rather than empirically conclusive."

The project's initial intent was to "capture the status quo" of how ed tech startups interact with their stakeholders about student data privacy practices and to identify best practices for those companies and others in the industry in formulating communications plans on privacy.

The research team developed a database of 450 ed tech startups, which they winnowed down to 18 "finalists" based on criteria that included student data privacy risk, staff size, reputation and revenue growth. Ultimately, six companies agreed to participate, which involved going through multi-hour interviews on their privacy and communications practices.

What the master's students found was that aside from adhering to federal and state-level requirements, data privacy wasn't on the radar. What was more important during their first five years of operation was customer acquisition and product development. Concerns about privacy seemed to have no impact on innovation.

Also, because startups are notoriously shorthanded and there's little demand from prospects and customers, they don't bother developing "formal strategies" around their public-facing communications on student data privacy for their external stakeholders. Frequently, they'll "borrow" or adapt sections from competitors' privacy policies or build up their policies only when customers demand it or as compliance laws change.

School districts can influence how the start-ups they work with prioritize considerations related to data privacy. As the summary noted, "School districts were the greatest force for our startups to change their privacy behaviors." However, the report added, the researchers weren't persuaded that districts had the capacity to truly assess technology coming into their schools from the data privacy perspective.

Investors financing these start-ups can also play a role in helping them put "strong privacy practices" into place.

As for the ed tech companies themselves, the research paper advised them to become more proactive. By doing so, they "can position their vigilance as a key differentiator for their product, capture a broader market share, and share in the responsibility for protecting sensitive student data."

The summary of the report's findings can be found on the Heinz College website here.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • digital illustration of Estonia with glowing neural network-like connections spreading across the map

    Estonia to Roll Out ChatGPT Edu for all Secondary Schools

    In a nationwide artificial intelligence program dubbed "AI Leap 2025," the country of Estonia plans to provide free access to leading AI applications for all secondary school students and teachers. The initiative will launch with a rollout of ChatGPT Edu to 20,000 high school students in grades 10-11 and their 3,000 teachers, beginning Sept. 1.

  • three silhouetted education technology leaders with thought bubbles containing AI-related icons

    Ed Tech Leaders Rank Generative AI as Top Tech Priority

    In a recent CoSN survey, an overwhelming majority of ed tech leaders (94%) said they see AI as having a positive impact on education. Respondents ranked generative AI as their top tech priority, with 80% reporting their districts have gen AI initiatives underway, or plan to in the current school year.

  • AI microchip, a cybersecurity shield with a lock, a dollar coin, and a laptop with financial graphs connected by dotted lines

    AWS Survey: Generative AI Surpasses Cybersecurity in 2025 Tech Budgets

    Global IT leaders are planning to spend more on generative artificial intelligence than cybersecurity in 2025, according to new research by Amazon Web Services (AWS).

  • teenager interacts with a chatbot on a computer screen

    Character.AI Rolls Out New Parental Insights Feature Amid Safety Concerns

    Chatbot platform Character.AI has introduced a new Parental Insights feature aimed at giving parents a window into their children's activity on the platform. The feature allows users under 18 to share a weekly report of their chatbot interactions directly with a parent's e-mail address.