The Question of Privacy in Virtual Classrooms
The world has been moving online and education is no exception. The COVID-19 pandemic greatly accelerated the need for, and adaptation of, online learning technologies, with virtual classrooms becoming the new norm.
Yan Shvartzshnaider, an assistant professor in the electrical engineering and computer science department at the Lassonde School of Engineering, has been investigating the privacy and security risks that have accompanied the adoption of virtual classrooms.
Professor Shvartzshnaider, like many other faculty members, was instructing in a standard lecture hall prior to the pandemic but after the pandemic hit in March 2020, he was forced to move his lectures online. This abrupt shift prompted him and his colleagues to examine the privacy implications of remote educational platforms.
The authors discuss the new threat model and the results of this investigation in the paper titled “Virtual Classrooms and Real Harms: Remote Learning at U.S. Universities” which is to appear as part of the proceedings of The Seventeenth Symposium on Usable Privacy and Security (SOUPS 2021).
“In an emergency situation, our norms and privacy expectations change. We started using technologies like Zoom without fully considering all the privacy risks because we wanted to ensure our students finished their courses and studies,” said Shvartzshnaider. “The question now is what to do going forward and how can we avoid a ‘tyranny of the norm’ situation where these technologies are accepted everywhere but we haven’t spent the time to address their surrounding issues.”
Shvartzshnaider and his colleagues analyzed universities’ Data Protection Addenda, platforms’ privacy policies and over 100 US state educational privacy laws, in addition to performing a security analysis of the software to understand the information handling practices involving 23 different popular platforms.
“Many of these technologies were not designed with an educational context in mind. These platforms collect and share a lot of data and, despite being compliant with existing regulations, they could violate privacy norms and expectations. As universities adopt these technologies it is important that they consider privacy and other potential harms when they use them to replicate the traditional lecture hall experience.”
The paper outlines several recommendations for mitigating potential harms from the use of virtual classrooms.
The authors encourage administrators to proactively seek feedback from instructors about their concerns and expectations about the major platforms the universities adopt. The universities should use this feedback to negotiate terms with platforms that address their specific needs. It is also vital for regulators and universities to collaborate to battle non-compliance and establish appropriate incentives for the platforms that would address potential harms.
Professor Shvartzshnaider sees strong parallels with Canadian educational institutes where many of these platforms are also heavily used. He plans to examine the Canadian privacy regulation and other information governing institutions in his future work.
Full paper: “Virtual Classrooms and Real Harms: Remote Learning at U.S. Universities”
Cohney Shaanan, Ross Teixeira, Anne Kohlbrenner, Arvind Narayanan, Mihir Kshirsagar, Yan Shvartzshnaider, and Madelyn Sanfilippo https://arxiv.org/abs/2012.05867
About Yan Shvartzshnaider:
Yan Shvartzshnaider joined the electrical engineering and computer science program at the Lassonde School of Engineering at York University in 2021 and has established the Privacy Rhythm Research Lab where he and his team focus on Useable Privacy, Sociotechnical Systems, Contextual Integrity and Information Technology Policy. He was also the recent co-recipient of the Lee Dirks Award from iConference 2021.