Shades of Gray Evolution of Data Privacy Standards Huron Higher Education
Shades of Gray Evolution of Data Privacy Standards Huron Higher Education
In today’s highly connected higher coming in at numbers one and two, respectively.
Over the last decade, the trend toward
education institutions, there is
technology-enabled “smart” campuses brought
increasing emphasis placed on with it heightened scrutiny around the ethics
information security and data and strategy of using student data appropriately.
privacy. While the two are inherently To create formal guidelines for educational
linked, they aren’t one and the same. institutions, the federal government passed
the Family Educational Rights and Privacy
Information security focuses on the prevention Act (FERPA) in 1974, but in today’s climate,
and recovery of data breaches; privacy deals more most experts agree it is outdated and must
with the applications of personal information, and be revamped to keep pace with a constantly
laws or institutional ethical standards that govern evolving industry.
how it is used. To date, a fair amount of focus and
investment has been made to better understand Since 2013, 41 states have enacted more than
the intricacies of information security, but despite 120 supplemental laws. But even these legislative
this, the privacy landscape in higher education is advancements struggle to keep pace with the
still relatively unexplored. current rate of technological innovation, driven by
rising adoption rates of artificial intelligence and
data analytics tools, which often render potentially
successful strategies null and void before they can
Privacy: Safeguarding ever be executed.
institutional constituents’
privacy rights and Data is the lifeblood of any higher education
institution’s strategic planning activities, providing
maintaining accountability both evidence of success and justification for
for protecting all types of new initiatives. And colleges and universities are
Ed Tech and Big Tech members of their community as part of their daily
operations that fall outside of the research realm.
Higher education’s increasingly common Some data may still be formally regulated or
partnerships with third-party vendors and big governed, but the challenge is that often it is not.
technology (e.g., Amazon, Facebook, Google, etc.)
further complicate the matter. The involvement For instance, consider the myriad data collection
of these companies exposes institutions to public points encountered by college or university
scrutiny, fueled by several recent, high-profile students on an average day. Getting home late
violations, as well as ambiguity in terms of who is from a night out, a student may use a campus ID
responsible for what happens to harvested data. card to enter her dorm. The next morning, feeling
pangs of hunger, she uses her dining plan card
Shadow IT, smart campuses, the internet of to pay for breakfast at the cafeteria. Later, she
things and further proliferation of third-party reserves a conference room for that afternoon’s
systems pose a new set of questions at the organic chemistry study group session. After
intersection of privacy and civil liberties, ethics, classes are over, she heads to the soccer field
ownership and autonomy. where her performance is tracked by an athlete
data management system. And at each stop
Take, for example, the public outcry over the throughout the day, automated license plate
Facebook data sold to Cambridge Analytica, a reader (APLR) technology tracks where her
political consulting firm that allegedly used the vehicle is parked. Multiply these interactions by
information to target American voters in the 2016 thousands of students, and one gets a clearer
presidential election. The blowback from this picture of the sheer amount of daily data being
scandal has caused leaders in nearly every industry collected by these institutions.
to pause and consider the ethical implications of
data collection and its potential uses. Some states
are even getting in on the action, with Vermont
Data Collected on the Average
and others approving legislation that governs the Student on a Typical Day
sale of citizens’ personal data.
Automated License Plate Technology
Higher education leaders should be mindful of Tracks Location of Student’s Vehicle
how these types of third-party platforms are used
and take initiative to proactively educate students,
faculty and staff on what is being collected and
Campus ID Card Used
how it may be leveraged.
to Enter Dorm
While the data collected can be helpful when community and the public at large in a dynamic
developing a student success strategy, it can also conversation about privacy, real progress
be potentially problematic given the implications can take place.
of tracking individual students wherever they go
on campus. To be truly successful, these administrators need
the tools and sponsorship to create practical
Gray data challenges can even impact students’
guidelines and policies that can translate into daily
post-graduation prospects. Consider the difficult
practices and procedures.
position of athletic administrators determining
whether to share a promising student athlete’s
But CPOs should not be the sole arbiters of an
history of serious head injuries with professional
institution’s privacy policy. They must be willing
league recruiters.
and able to bring in other internal and external
The use of gray data may conflict with campus experts to help them make informed and educated
privacy standards and notions of academic decisions. At the same time, they must also be
freedom. But with little to no formal guidance viewed as a valuable, accessible resource for
on these types of scenarios, institutions are often stakeholders across the institution.
left to determine the ethical path forward on
their own.
Privacy Governance Boards
Today, most institutions are just beginning to • Assess the institution’s potential risks
invest in the resources required to respond related to data privacy to help prioritize
effectively to these developments. Privacy offices, opportunities for improvement.
while increasingly common in higher education, • Clearly define ownership for key
are still relatively rare. And those that are in place privacy areas to ensure role clarity
are often understaffed and mired in everyday and effective execution.
activities, including breach response, contract
reviews and compliance activities.
Act differently.
Empower your privacy office and/or data
huronconsultinggroup.com governance board to create supplemental
© 2019 Huron Consulting Group Inc. and affiliates. Huron is a global consultancy and not a CPA guidance and policies to cover gray
firm, and does not provide attest services, audits, or other engagements in accordance with
standards established by the AICPA or auditing standards promulgated by the Public Company
Accounting Oversight Board (“PCAOB”). Huron is not a law firm; it does not offer, and is not
data concerns.
authorized to provide, legal advice or counseling in any jurisdiction. Huron is the trading name of
Pope Woodhead & Associates Ltd.
19-1975