Thread · 5 tweets · 15 Sept 2022

Replying to @charleswlogan

To go a bit deeper into @natashanyt's suggestion: • What risks did you identify during the data protection impact assessment and how are they mitigated? • How much liability does the vendor take on if the tool is used in ways that harm the children?
• What are the rights to use and reuse the data collected through this process, who holds them, and under what conditions can the data terms be changed by the vendor? If they can change them unilaterally, what is your review process to ensure they remain aligned with principles?
• What data is collected? • How long is the data retained for and where? • Are there identifiers used in the data? If you consider the data to be "anonymous," what is the anonymising method? What processes are in place to avoid reidentification? • Does the vendor use vendors?
• Does the system use machine learning, and if so what algorithmic audits has it undergone? • Are the children profiled in the process (even if "anonymously" or "pseudonymously")? • What data is inferred in the process? I can think of more but that's a start I reckon :)
This made me think: we should develop a common questionnaire for parents to send superintendents systematically when this happens. I'm not an edu privacy expert, but I'm a parent and privacy nerd, and would love to help.