Protecting Student Data: Ensuring Privacy and Security
In a recent exploration of data privacy and security within USEP's enrollment process, our class unearthed several critical issues demanding immediate attention. As we delved into the subject, I found myself contemplating the profound importance of shielding sensitive data and the potentially dire consequences of any lapses in data protection.
One particularly concerning matter we uncovered relates to the College of Education's practice of housing student records in a shared Google Drive. While the intention may have been to streamline access and collaboration, this method poses significant privacy risks. Should the link to this drive fall into the wrong hands, it could precipitate a catastrophic data breach, exposing the personal information of countless students.
Equally alarming was the College of Information and Computing's habit of publicly posting room assignments. This inadvertent disclosure not only unveils students' schedules and attendance patterns but also leaves them vulnerable to exploitation by nefarious individuals.
Moreover, our discussions unveiled instances of data inaccuracy within the enrollment system. A classmate narrowly escaped being labeled as an irregular student due to a system glitch, underscoring the necessity for enhanced data integrity and quality control measures to safeguard students' academic records.
The reliance on student IDs without additional verification within the enrollment system also raises red flags regarding identity theft. Unauthorized access to a student's ID could potentially enable an imposter to manipulate their data, wreaking havoc on their academic journey.
Furthermore, the practice of sharing student records via a shared Google Drive exponentially heightens the risk of a data breach, potentially compromising the privacy of numerous students and inflicting irreparable harm.
A poignant example was our professor's action of capturing our images during the activity without prior consent. His observation regarding the potential violation of data privacy laws and erosion of institutional trust struck a chord, emphasizing the importance of securing individuals' consent before utilizing their personal information.
Drawing from our professor's wealth of experience as a former Data Privacy Officer and Systems and Data Management Division (SDMD) Director, we gleaned valuable insights into crafting effective security protocols. His collaboration with Sir Bong in developing a security manual presents a tangible resource for addressing these concerns and establishing robust data handling and storage practices.
Reflecting on our professor's time and motion study during his tenure as SDMD Director, which revealed an average enrollment time of 3.4 hours during face-to-face interactions, prompts considerations for enhancing efficiency in the current online system. Addressing data privacy and security concerns in tandem with process optimization could yield significant improvements in enrollment procedures.
In light of these revelations, it is imperative for USEP to prioritize stringent access controls, data accuracy, and identity verification protocols. By adhering to best practices for data handling and storage, the university can honor its commitment to fostering a secure and trustworthy environment conducive to students' academic pursuits.