Education and privacy MUST go hand in hand.

Estimated reading time: 2 minutes

Summary

In May 2022, a traditional American higher education institution closed its doors after 157 years of operation following a ransomware attack.

In October 2024, a municipal employee of a daycare center in the Brazilian state of Tocantins was arrested on suspicion of stealing personal data from parents of students and coworkers to commit bank fraud.

In January 2025, a giant American cloud-based educational software company, operating primarily in the United States and Canada, as well as Brazil, informed the schools it serves (operating the personal data of students and parents/guardians) that it had suffered a cyber incident involving the exfiltration of personal data.

What do these educational institutions have in common?

Without going into the specifics of each situation described, what these institutions have in common is that they all suffered information security incidents resulting in the compromise of personal data. 

The large volume of personal data processed, the high level of digitization in recent years, low investment in effective preventative measures, the use of legacy and outdated systems, little or no employee training, and a lack of belief that they could become targets are some of the reasons why schools, colleges, and universities are vulnerable to incidents of this type.

The weaknesses of educational institutions are known and exploited, primarily by cyber attackers.

What happens in schools and universities?

One of the issues that can be observed in these businesses is the lack of clarity about their processes, even for those involved in them. It is common to find inadequate control over access to the personal data of students and their guardians; data sharing based on trust; teachers taking photos of underage students with their own cell phones; social media posts without explicit consent; and the hiring of suppliers who are not committed to their role as data operators.

How to act to make the educational environment safer 

Investment – ​​that's the key word. In what? In an IT environment with robust technical measures; in training for pedagogical and administrative staff; in secure partnerships and well-drafted contracts with suppliers (data operators); in the appointment of a DPO knowledgeable in privacy and data protection matters, the LGPD (Brazilian General Data Protection Law), and the business; in a well-established communication channel with data subjects and the ANPD (Brazilian National Data Protection Authority). Finally, in transparency.

It is up to basic and higher education institutions to embrace their role as controllers of personal data and understand the responsibility that this entails. Personal data is an input for the educational business; there is no school or university that does not process data from students, parents/guardians, and employees, and this happens in large volumes. 

Considering the protection of personal data as a priority in educational and administrative processes, in addition to being a legal obligation, can be a competitive advantage in a country that holds the title of world champion in data breaches.

About the Author

Meet the author of this article.

  • Certified EXIN DPO working in the educational field, specializing in Data Protection and Privacy, Process Management, BPM, ISO 27001 Information Security, ISO 9001 Quality Management, Postgraduate Professor in Digital Law. Specialist and postgraduate in Cybersecurity and Data Governance.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also