The Student Privacy Pledge and Security

The Student Privacy Pledge and Security

We know it is critical for ed tech companies to get security right.

The Student Privacy Pledge developed by FPF and SIIA requires signatories to maintain “a comprehensive security program that is reasonably designed to protect the security . . . of personal student information . . . appropriate to the sensitivity of the information.” “Reasonableness” in this context is not a subjective standard, open to interpretation by each company, but rather a standard used and interpreted across a range of contexts by the Federal Trade Commission. It is also the basis of California’s new Student Online Privacy Protection Act.

A company’s security and other commitments made under the Student Privacy Pledge are legally enforceable. Under Section 5 of the Consumer Protection Act, the Federal Trade Commission (FTC) can take action against companies that commit deceptive trade practices. It is a form of deception to make a public statement such as signing the Student Privacy Pledge but then implementing practices that do not conform to those public statements. The FTC and various State Attorneys General have brought enforcement actions against companies that made privacy promises to their consumers and then violated those promises.

Companies with security practices that fall short can therefore face legal liability. The pledge does not designate specific security technologies, because those measures need to be tailored to the service, context and sensitivity of the protected information.  What constitutes reasonable may depend on the specific company and nature of the data that it handles, and must evolve over time as new threats and solutions emerge.

For services that hold sensitive student data, login password encryption or equally protective measures are basic measures that companies must implement. Of course, effective security requires ongoing training of company employees, and toward that end, we have also kicked off a series of workshops starting next week to help companies further hone their security and privacy practices.

When a company signs the Pledge, they publicly commit to its responsible and appropriate standards for student privacy and data security, and the pledge allows the public – the media, parents, educators and federal regulators – to hold these companies accountable. It’s exactly this sort of public scrutiny that makes the pledge an effective means for ensuring data accountability. This accountability requires that all stakeholders understand its security standard, enforceability and other elements of the Student Privacy Pledge.

-FPF and SIIA

Leave a Reply


Privacy Calendar

Mar
10
Tue
6:00 pm CDT Annual Dinner “TechProm” 2015
CDT Annual Dinner “TechProm” 2015
Mar 10 @ 6:00 pm – 9:00 pm
Featuring the most influential minds of the tech policy world, CDT’s annual dinner, TechProm, highlights the issues your organization will be facing in the future and provides the networking opportunities that can help you tackle[...]
Mar
13
Fri
all-day BCLT Privacy Law Forum
BCLT Privacy Law Forum
Mar 13 all-day
This program will feature leading academics and practitioners discussing the latest developments in privacy law. UC Berkeley Law faculty and conference panelists will discuss cutting-edge scholarship and explore ‘real world’ privacy law problems. Click here[...]
May
27
Wed
all-day PL&B’s Asia-Pacific Roundtable (...
PL&B’s Asia-Pacific Roundtable (...
May 27 all-day
PROFESSOR GRAHAM GREENLEAF, Asia-Pacific Editor, Privacy Laws & Business International Report, will lead a roundtable on the countries of most interest to business in the Asia-Pacific region. Click here for more information.
Jul
6
Mon
all-day PL&B’s 28th Annual International...
PL&B’s 28th Annual International...
Jul 6 – Jul 8 all-day
The Privacy Laws & Business 27th Annual International Conference featured more than 40 speakers and chairs from many countries over 3 intensive days. At the world’s longest running independent international privacy event participants gained professionally by[...]
Jan
28
Thu
all-day Data Privacy Day
Data Privacy Day
Jan 28 – Jan 29 all-day
“Data Privacy Day began in the United States and Canada in January 2008, as an extension of the Data Protection Day celebration in Europe. The Day commemorates the 1981 signing of Convention 108, the first[...]
Jan
28
Sat
all-day Data Privacy Day
Data Privacy Day
Jan 28 – Jan 29 all-day
“Data Privacy Day began in the United States and Canada in January 2008, as an extension of the Data Protection Day celebration in Europe. The Day commemorates the 1981 signing of Convention 108, the first[...]

View Calendar