Brainova Study smarter, not longer

EdTech & Schools

Collecting Less and Restricting More: Four Policies That Protect Student Data

Districts reduce risk by limiting data collection, using separate admin accounts, vetting temporary access, and having data stewards review reports.

By Brainova

Illustration from the source material
edtechmagazine.com

What does least-privilege access mean for a school district?

Least-privilege access means that every user begins with the most restrictive permissions, and access is granted only for a specific need. Jenn Judkins of Wayland Public Schools notes that once access is granted, it is hard to reverse: 'It becomes difficult to justify why you're pulling that back. You can't put the toothpaste back in the tube.' In practice, this requires a district to adopt a default-deny posture. Instead of assigning all staff a standard set of permissions, each role is mapped to the minimal functions it needs to perform. The mechanism is straightforward: when a new employee arrives, their account is created with no access to systems beyond the bare essentials (like email). Then, as they need to view attendance records or submit grades, those specific permissions are added one by one, each with a documented reason. The challenge is that once a permission is added, it tends to stick; it becomes the baseline for that user, and pulling it back later demands a justification that is often avoided. Therefore, the initial approval process must be rigorous—ask whether the access is truly necessary, and whether it can be scoped to a single task or a limited time. By starting narrow, the district avoids the messy process of trying to retract access after the fact.

Why should schools limit what student data they collect?

Limit the data you collect to what you actually use, and delete it when the purpose expires. Melissa Tebbenkamp, technology director for the Consortium for School Networking (CoSN), says districts should start with enrollment paperwork, where unnecessary documents tend to pile up. For example, residency proof like utility bills should be shredded once the student is registered, and Social Security numbers should never be collected unless state law or a specific program requires them. Judkins adds a simple maxim: "You don't have to protect what you don't collect." Collecting fewer fields reduces the cost of securing them and the likelihood of a breach, since a data thief can't steal information that never entered the system. It also trims the scope of open records requests and parent complaints. Tebbenkamp advises auditing every form: if a field isn't used for a legal or operational reason, remove it from next year's packet.

Advertisement
728 × 90 ad space
468 × 60 ad space
320 × 50 ad space
300 × 250 ad space

Why do administrators need separate accounts for daily work and system changes?

Administrative accounts should be separate from the accounts staff use for email, web browsing, and daily work. Melissa Tebbenkamp of CoSN says that separation limits the attack surface: if an employee clicks a phishing link in a daily-use account, the attacker only gets access to that account's limited permissions, not the elevated rights of an administrator. For K-12 IT teams, that means a technology director should have a standard account for email and a second account with admin credentials for making system changes. The same applies to principals who manage software licenses or teachers who reset passwords. Tebbenkamp recommends using different browsers or virtual machines for admin tasks, and never using the admin account to read email or visit websites. This practice contains a breach before it reaches the student information system, and it also improves audit trails because each action is traceable to a specific elevated session.

Advertisement
300 × 250 ad space

How should temporary employees be granted system access?

Temporary employees and staff with limited-time projects should receive access only for the exact duration of the work, with a calendar reminder set to revoke it. A teacher who assists with student scheduling for six weeks each year should get scheduling rights only for those six weeks, not for the entire school year. The same logic applies to substitute teachers, consultants, or tech vendors who need short-term access to a system. Set an expiration date on the account and put a reminder on the IT team's calendar to disable it when the project ends. Without that reminder, the access often remains, turning a temporary permission into a permanent risk. Unlimited access for temporary roles is particularly dangerous because those users may not be as familiar with security practices, and their accounts are more likely to be targeted.

Why should data stewards review state reports before submission?

Data stewards from the academic programs should review state reports before submission because they are the ones who can spot impossible numbers. The director of the English learner program will catch an error in the count of English learners that the IT department would never notice. IT might see a data point as correct because it follows the schema, but the program director knows that a classroom can't have more students than seats. Assign a named steward for each state reporting area, and have that person sign off on the report at least a week before the deadline. This ensures that the data reflects real-world conditions, not just what the database spits out. It also shifts accountability away from IT alone, making the whole district responsible for data quality and compliance.

What is access creep and how do you stop it?

Access creep happens when staff members change roles and keep the permissions from their previous jobs. This occurs because districts rarely revoke old access when an employee moves to a different department or takes on new responsibilities. Karen Winsper of Norton Public Schools recommends a proactive solution: review access at least annually. She asks, 'Once a year, are you going in and checking?' In practice, an annual audit means pulling a list of all active users and their permissions, then comparing it against each person's current job description. Any permissions that do not match the role should be removed. A former building administrator who now works in the central office might still have access to the school's discipline reporting system. Without the annual check, that leftover access remains, creating a potential risk. To implement this, assign a staff member—such as the IT director or a data steward—to run the audit and work with principals and department heads to verify the accuracy. The key is to make it a regular, scheduled event, not a one-time cleanup. By checking each year, the district can catch and eliminate stale permissions before they cause problems.

Advertisement
728 × 90 ad space
468 × 60 ad space
320 × 50 ad space
300 × 250 ad space