Chief Privacy Officers: Who They Are and Why Education Leaders Need Them
To respond to new demands to protect student data, the education system would benefit from deploying a strategy that has been successful in other sectors and industries: hiring a chief privacy officer (CPO) who is responsible for the organization’s privacy policies and practices.
The current model distributes privacy duties across an education organization and has resulted in excessive data collection and access, untrained staff with little support in protecting student data, retaining data past its usefulness, and lax controls on third party management and use of student data. Everyone plays a role in protecting student privacy, but a CPO can improve privacy protections by centralizing the strategy, policies, roles, and responsibilities for protecting data that ultimately result in preventing data incidents, establishing trust, and ultimately ensuring that information is not used to harm students.
This issue brief focuses on a variety of practices that can support such a role, and is divided into two sections: first, the role that education organizations can play in making CPOs successful, and second, the role that CPOs should play in protecting student privacy across the organization. Specifically, organizational leadership should establish the CPO as a senior position, ensure multi-disciplinary support for the CPO, and provide financial resources. Once hired, the CPO should serve as a resource to staff, collaborate with the chief information security officer, cultivate privacy advocates, and respond to current events.
Coalition Urges Senate Not to Let Companies Waive Financial Regulations for AI
CDT joined AI Now Institute, American Civil Liberties Union, and several organizations dedicated to tech policy, consumer protection, and civil rights in a letter to Senate leadership and the Senate Banking, Housing, and Urban Affairs Committee opposing the “AI Innovation Labs” language in Sec. 10509 of the CLARITY Act.
The Privacy Paradox: How Government Data Has Become Less Private and Less Useful
Providing ready access to information collected and maintained by the government promotes accountability, innovation, and research, making transparency a core responsibility of serving as a steward of the public’s data. Public agencies must also safeguard sensitive information when making data publicly available.
Defending State Data: Lessons from California v. USDA
As the federal government increasingly seeks access to state administrative data, policymakers should consider not only legal authority and privacy implications, but also the practical effects on public confidence, program effectiveness, and states’ ability to fulfill their obligations to residents.
CDT and Partners Urge Passage of the California Location Privacy Act of 2025 (AB 322)
Location data is particularly sensitive, and when collected across time it can reveal a broad range of intrusive insights such as medical conditions, sexual orientation, political activities, and religious beliefs.