Uncovering Privacy and Security Challenges In K-12 Schools

Honorable Mention
Privacy by Design & User ControlPrivacy Perception & Decision-MakingSmart Home Privacy & SecurityK-12 TeachersOnline Course DesignersSpecial Education TeachersGovernment Officials & Civil ServantsPrivacy Policy Makers

Title of the Paper

Revealing Privacy and Security Challenges in K-12 Schools

Bibliographic Information

  • Subject Areas: Educational Technology, Privacy and Data Security
  • Keywords: Student Data Privacy, Educational Technology, K-12, EdTech, Data Security, Privacy Training, Privacy Risks, Data Breaches, Policies and Regulations, Web Scraping

Research Background and Issues

  • Identified Problems or Challenges:

    1. K-12 schools are increasingly reliant on educational technology (EdTech), but this has led to issues surrounding student data privacy and security, including data commercialization, data breaches, and expanded tracking.
    2. Schools lack resources and training to address privacy and security concerns, while educational technology is often insufficiently regulated.
    3. Privacy issues in most educational technologies have not been quantitatively studied.
  • Significance:
    Violations of K-12 students' data privacy can lead to commercial exploitation, exposure of sensitive student information, and even adverse impacts on future employment opportunities. These issues are critical to safeguarding students' privacy rights and data security.

  • Research Motivation and Related Work:

    1. Existing studies have analyzed vulnerabilities in educational technology products, particularly in certain countries, but there is a lack of quantitative analysis of the specific educational technologies used within U.S. public schools and their associated privacy risks.
    2. While much research has focused on the perceptions of teachers, parents, and students regarding privacy and security, little is known about the privacy considerations of decision-makers such as technology administrators and district officials.

Solutions

  • Proposed Solutions:
    This study employs a mixed-methods approach:

    1. Conducting semi-structured interviews with 18 district officials and IT staff to understand privacy and security issues in educational technology, procurement processes, and considerations for student privacy.
    2. Scraping and analyzing educational technology links from 15,573 public school/district websites to identify privacy risks.
  • Innovations:

    1. Providing empirical evidence of district officials' and IT staff's limited capacity to manage privacy.
    2. Identifying the most commonly recommended educational technologies by schools and highlighting their potential privacy risks.
    3. Offering a detailed technical analysis of privacy issues on educational technology login pages and websites.
  • Implementation Steps and Key Techniques:

    1. Interview Component: Analyzing interview transcripts using thematic coding to extract common privacy and security issues and practices.
    2. Technical Analysis Component: Using Python web crawlers to collect links to third-party educational technology websites and employing advanced browser tools (e.g., Puppeteer and Blacklight) to analyze privacy risks such as third-party cookies, session recorders, and Meta Pixel.

Research Findings

  • Specific Findings:

    1. Key Discoveries:

      • Schools experience privacy and security incidents but have limited resources and lack effective responses and management.
      • District officials, IT staff, and teachers have insufficient awareness and training regarding privacy risks.
      • Privacy and security considerations in the procurement process for educational technology are minimal, with contract terms often being templated.
      • School websites link to many domains not traditionally considered "educational technology," yet these may still collect student data.
    2. Privacy Risks:

      • Many educational technology websites use third-party tracking technologies, including third-party cookies, Meta Pixel, and session recorders.
      • Login pages may expose sensitive student information, such as email addresses entered during login.
  • Advantages Over Existing Solutions:

    • Provides quantitative data for assessing privacy risks in educational technology.
    • Supports policymakers and the education sector in developing stricter privacy regulations.
  • Limitations and Future Directions:

    1. Limited sample size and geographic scope may introduce selection bias.
    2. Excludes non-public educational technology services used by schools.
    3. Privacy risk analysis is restricted to publicly accessible website content; future studies could focus on detailed investigations of actual data flows at the user data level.
    4. Recommends conducting large-scale surveys, creating national privacy training standards, and exploring improvements to policies and regulations.

Additional Information

The authors call on the CHI research community, policymakers, and educators to collaborate in addressing privacy and security issues in educational technology through policy improvements, data transparency, and resource investment.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/96299/2023

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3580777
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
Honorable Mention
group
Authors
7 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making, Smart Home Privacy & Security
work
Professions
K-12 Teachers, Online Course Designers, Special Education Teachers, Government Officials & Civil Servants
article
Content Status
Full text indexed
hub
Related Papers
3 related papers