This practice note explains how assurance and improvement in learner data privacy should be scoped, implemented and verified, with closure dependent on demonstrated effect.
Evidence relevant to assurance and improvement in learner data privacy
Its relevance to learner data privacy should be assessed against the affected jurisdiction, learner population and form of provision.
For learner data privacy, broad intentions should be converted into decisions capable of review.
For decisions concerning learner data privacy, the evidential record should be limited to material that can answer the question under review. For corrective action, the most relevant material is likely to include incident response and notification records, data-quality and correction controls, retention and secure disposal evidence, and a register of information assets and purposes.
Application to assurance and improvement in learner data privacy
For learner data privacy, the public interest is not confined to institutional compliance.
Risk assessment should give particular attention to excessive access to learner information, inaccurate data affecting decisions, and retention beyond an identified need. A provider should also consider uncontrolled supplier access or transfer and collection without a defined educational or legal purpose.
- Verify accuracy where information affects learners, with responsibility, scope and timing recorded.
- Provide accessible correction and complaint routes before it is relied on for a decision with material effect.
- Control third-party processing.
- Test incident and recovery arrangements.
- Assign accountable data owners.
Controls for assurance and improvement in learner data privacy
The review method for learner data privacy should be reproducible. Review of the corrective action should prioritise actions by learner impact and control weakness, establish dependencies, test implementation at suitable intervals and retain unresolved items until effectiveness is verified.
A decision to close improvement work on learner data privacy should be made by a person with authority and sufficient independence from implementation.
Records relating to the corrective action should preserve both the conclusion and its limits. When examining learner data privacy, if further evidence changes the position, the correction should identify its scope and any earlier decision requiring reconsideration.
Review of assurance and improvement in learner data privacy
Public reporting on learner data privacy should distinguish established fact, analytical judgement and planned action.
Amend the plan where evidence does not support the original causal assumption.
An improvement plan should connect a verified problem with a specific intervention, accountable ownership, resources, milestones and a measure of effect.
In examining assurance and improvement in learner data privacy, education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period.