A Wild 48 Hours for Federal Student Privacy
May 25, 2023
- The FTC also filed a brief stating that COPPA does not preempt state privacy laws that are consistent with COPPA;
- The Surgeon General brought up the need for “children’s privacy” as part of its recommendations in a new Advisory on Social Media and Youth Mental Health;
- The White House announced that the Department of Education “will promote and enhance the privacy of minor students’ data and address concerns about the monetization of that data by commercial entities, including by planning to commence a rulemaking under the Family Educational Rights and Privacy Act (FERPA);” and
- The White House and the Department of Education announced multiple new AI efforts, including guidance for education stakeholders on AI and an AI RFI that education stakeholders may want to respond to.
1. Edmodo - and, therefore, likely all other edtech companies - must obtain either Verifiable Parental Consent–in the school context, this would require parents to opt-in to each and every edtech use–or School Authorization (newly defined term) for the collection and use of student data. “School Authorization” is defined as “a School Representative authorizes an Operator to Collect Personal Information from a Child, on the condition that Personal Information is Collected only for an Educational Purpose and follows the School Representative’s receipt of Direct Notice from the Operator.” School Authorization is only allowed when data will be used exclusively for an educational purpose.
This sounds great! Except when you look at the narrow definitions of “School Representative” and “School.” School is defined as “an institutional day or residential school, including a public school, charter school, or private school, that provides elementary or secondary education, as determined by State law.” A “School Representative” is defined as “a School employee.” Bottom line? These definitions exclude all other LEAs–like districts or education service agencies–that often contract with edtech companies. This settlement says companies must either go through VPC or get School Authorization - and, therefore, companies can probably never receive School Authorization from an LEA other than a school. Instead, companies will likely need to contract individually with each and every school their product will be used in or will be required to obtain COPPA-compliant consent from each and every parent. This is a (likely unintentional) change: the current COPPA FAQs specifically reference school districts contracting with companies. When this settlement is finalized by the court, companies are likely to assume that they can only contract with individual schools, unless additional clarifications are made.
2. To complicate matters, there are new requirements for how an edtech provider must obtain “School Authorization.” School Authorization requires a written agreement (which is good for education stakeholders if the definition of “School” was fixed) that says:
- Personal information will only be used for educational purposes (this is great!);
- Describes all Personal information that is collected and how it will be used and disclosed (schools should receive that information!);
Provides the School a link to its online notice of information practices and recommends the School make it available on the School’s website (again, a good thing!);
Provides that any Personal Information Collected by Defendant is under the Direct Control of the School with regard to its use and maintenance (which will help schools comply better with FERPA!); and
Requires a School Representative to acknowledge and agree that they have authority to authorize the Collection of Personal Information from Children on behalf of the School, along with their name and title at the School. (wait a second…)
Subscribe to AASA's Blogs
Subscribe via RSS feed below. Learn more about RSS feeds here.