Aimee Guidera, executive director of the Data Quality Campaign (DQC) said it’s important for schools and districts to remember why data is being collected.
“It’s important to remember that we’re going through all of this to turn the data into actionable results,” she explained. “Data can help with transparency and accountability, improving system performance, and increase student achievement. It can also help scale best practices.”
[See “Major ed data report reveals states’ improvements.”]
Guidera said that as states and districts move toward empowering stakeholders with actionable data, they are also increasing focus on safeguarding and privacy issues.
Yet, many states, districts, schools, and the public may have misconceptions or “myths that can be busted” about student data privacy in the cloud, said Guidera:
Myth #1: Third Party Providers (TPPs) can sell data or misappropriate the data for non-educational purposes.
According to Kathleen Styles, chief privacy officer for the U.S. Department of Education, the Family Educational Rights and Privacy Act (FERPA) protects student data from TPP misappropriation.
FERPA, passed in 1974, gives parents and eligible students the right to access and seek to amend their children’s education records. It also protects personally identifiable information (PII) from education records from unauthorized disclosure, and requires written consent before sharing PII, unless an exception applies.
“FERPA covers education records directly related to a student and records maintained by an educational agency or institution or a party acting for the agency or institution. Many people are now asking if new types of data count as education records,” said Styles. “They’re wondering what happens to things like digital breadcrumbs.”
Styles explained how schools or local education agencies (LEAs) can use the School Official Exemption (SOE) to disclose education records to a TPP if the TPP:
- Performs a service or function for the school or district for which the education organization would otherwise use its own employees;
- Is under the direct control of the organization with regard to the use or maintenance of the education records;
- Uses the data in a manner consistent with the definition of the “school official with a legitimate educational interest” specified in the school LEA’s annual notification of rights under FERPA;
- Does not re-disclose or use the data for unauthorized purposes.
“It’s important to remember that for schools and LEAs, TPPs must meet the criteria under [SOE],” said Styles. “However, state education agencies cannot use the [SOE]; therefore, they must designate TPPs as ‘authorized representatives’ under the Audit and Evaluation Exception.”
Specifically regarding cloud services, FERPA allows the use of cloud services, but the arrangement must meet the SOE requirements, noted Styles.
“Schools and districts own the data, regardless of the TPP, and are always responsible for it, even when shared” stressed Styles. “The IT provider must comply with both FERPA and the terms of the school or district contract. The provider never ‘owns’ the data, and can only act at the direction of the school or district.”
Another safeguard exists at the state level, said Styles, as SEAs are under the same FERPA requirements as TPPs if they provide centralized IT services, such as Student Information Systems, to LEAs in their state.
(Next page: It’s an all-staff effort)
- #4: 25 education trends for 2018 - December 26, 2018
- Video of the Week: Dealing with digital distraction in the classroom - February 23, 2018
- Secrets from the library lines: 5 ways schools can boost digital engagement - January 2, 2018

Comments are closed.