Ferpa And Coppa
Go deeperRead the long-form companion article: Ferpa And Coppa →The laws that protect student data were written before the internet existed.
This is not a metaphor. The main piece of American legislation governing school records was passed in 1974. The law protecting children online came in 1998, before most people had even heard of a smartphone. They were written for a world in which a school record was a paper folder, or at most a row in a database, and protecting it meant controlling who got to see it. The underlying idea was that student data is a thing that exists in files, and the job of the law is to govern access to those files. It is a reasonable idea for the world that was. In the world we now live in, it protects a category of information that is getting smaller every year.
Modern educational technology does not mostly produce records. It produces behaviour data, engagement metrics, clickstreams, predictions, probability scores, and inferences. Whether a student's predicted risk of failing qualifies as a student record in the legal sense of 1974 is, at best, an unresolved question. Most companies err on the side of concluding that it does not, and most schools are compliant with the old law while collecting and sharing a category of data the old law barely recognises. The protection is not being deliberately stripped away. It is quietly failing to cover what has become most of the material. The law has not caught up, and until it does, compliance does not equal protection. When you consented to your own data being used somewhere, how sure are you that what was actually collected matches what the consent form described?
Last week we said meanings move underneath models. This week we look at the laws written for paper records, and at what happens to them in a world of behaviour data.