The evidence for learner data privacy is considered with the basis for a reliable conclusion and the limits beyond which it must not extend.
Evidence relevant to learner data privacy
Review of the conclusion should address both system-level conditions and institutional practice. In reviewing learner data privacy, education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period.
- Limit and review access before using it to determine a learner or provider outcome.
- Minimise collection.
- Control third-party processing, identifying the accountable function and affected scope.
- Assign accountable data owners.
- Provide accessible correction and complaint routes.
Application to learner data privacy
Scope should identify the people, decisions, services, locations and periods to which the arrangement applies. Exclusions require an objective reason and should not be inferred from organisational custom or the absence of an earlier complaint. For decisions concerning learner data privacy, any condition preventing complete assurance should appear with the evidence on which the judgement relies.
When examining learner data privacy, assurance of the matter should draw on more than one form of evidence. Useful records include supplier and transfer arrangements, lawful authority and consent records where relevant, incident response and notification records, a register of information assets and purposes, and role-based access and access reviews.
For the applicable requirement, governing bodies should receive a concise account of the intended result, affected scope, principal risks, evidence limitations and unresolved exceptions. Across the defined scope, the action record should identify who is responsible and when implementation is due. For learner data privacy, an action may be complete while the underlying condition remains, and the two determinations should be recorded separately.
The final record on the applicable expectation should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion. The approving record should explain how an alternative approach satisfies the governing requirement.
Controls for learner data privacy
The method for the control is to begin with the intended public or educational outcome, map every activity capable of affecting that outcome, and record where responsibility passes between functions or organisations. Test boundary cases before confirming the scope.
Failure in relation to the applicable requirement may arise even where the stated policy is reasonable. Material concerns include secondary use without adequate authority, collection without a defined educational or legal purpose, retention beyond an identified need, and excessive access to learner information. In the context of learner data privacy, the assessment of an exception should address severity, persistence and the likelihood that the condition is more widely present.
The assurance record for the control should retain the date of the evidence, the source responsible for it, the scope examined and the version of any instrument or definition applied. When examining learner data privacy, traceable source and version information allow genuine improvement to be distinguished from administrative revision.
For the applicable requirement, security, privacy and data quality are related but distinct.