
Challenges to Opt-Out Privacy Policies at Colleges? 23
jmaxlow asks: "It's that time of year again when my university sends out mailers informing students that their personal information will be compiled and released in a student directory unless students register objections in writing by the deadline. This info includes name, address, date of birth, and email address, among other items, and there is nothing to prevent them from selling the information to third parties without vested interests. The Buckley Amendment allows them to do this, so of course it isn't illegal. But my question is: has anyone ever petitioned their university to change to an opt-in policy? I'd like to know what responses schools have given, if any, when challenged, before I bring it up with my own registrar."
Don't get it. (Score:2, Insightful)
Generally, "Opt-in" services are where you pay someone to provide you a service. "Opt-out" is where you bitch at them to stop charging you, or raping and pillaging you, or whatever. I can't see any possible benefit to an "Opt-in" service of this type, unless you are a masochist.
Re:Don't get it. (Score:1)
I think what the original poster meant was that the current default *is* an opt-out version. In other words, you must make the effort to be left alone.
Some students are willing to give out their information in order to receive freebie samples from various corporations in their mailbox, or to get cute little letters about their favorite pop-stars, or free "magazines" targetting at college students. That is "opt-in". There do actually happen to be companies who I *want* to receive information from, because I find it useful to me. That is "opt-in" as well.
The question is whether the school could have a default of "we won't give away your information" and then have a form where a student can sign a statement that says, "I don't mind if you give my name to advertising corporations."
Re:Don't get it. (Score:2)
Then again, students also get the ability to go in and edit most of their LDAP entry [rit.edu].
Re:Don't get it. (Score:2)
Levels of Information (Score:1)
For instance, I would *want* all of my personal information to be in the student directory, so friends of mine at the school would be able to contact me easily. On the other hand, I would *not* want any of that information to fall into the hands of companies trying to target the student market.
I do recall that starting sophomore year or thereabouts, my school stopped listing the extension numbers of students living on campus. This mean that if you wanted to find out the phone number of a fellow student living on campus, you had to trudge over to the main office, show your student id, and then ask (no, they would not give the information over the phone!). This was very annoying, though it was clearly thought necessary to protect the privacy of the students, especially women.
Nevertheless, we still had a few obscene crank callers that got a hold of some of the numbers anyhow...
Re: (Score:2)
What we have at my Uni... (Score:2)
Here (Canada, so obviously different laws apply), my Uni does collect that info, if only to send us the necessary things to attend classes (registration, etc.). I don't recall anything about selling those informations to other entities though.
The students of my faculty do have a student directory. The old way of getting the info was by passing sheets in each class, where people could modify their current information at the beginning of the semester. So if you didn't want to be listed, you just didn't filled it (opt-in). Now, that has changed a bit: the info for the directory is channeled from the Uni's info to the paper directory. But again, sheets are passed at the beginning of each semester to get the approbation of students to be listed in the directory.
To get back closer to the subject, I recall that some insurance company was sponsoring an event for coop students, so they had to send a letter to each of them. The way it was handled was that the insurance company gave us what they wanted us (the student's association) to send, and we handled the "put it in an envelope, put the address sticker and repeat" part. They never had access to the list of students, or to their info.
Re:What we have at my Uni... (Score:1)
The nice thing about the act is that it also gives access to information the previously would have been kept quite confidential. For example if I felt that I was turned down for a job under unfair conditions, I can ask to see the interview records to see if the interview process was done in a fair manner, ie was I asked to recite 25 lines of code verbatim from the eepro100 net driver from linux kernel 2.2.6, while the other guy was just asked to describe how he would send an email to someone.
It's too bad sometimes that this Act only applies to public insitutions. It'd be real nice if a applied to everyone.
College Student Apathy (Score:1)
However, I agree with Opt-In policies for all identity information repositories. So the real question becomes -- should this service be offered at all? DO most students want their information shared? DO they understand the risks? Should they? Should such repositories allow only authenticated access, no public access?
Thoughts?
Opt-in practical? (Score:1)
Opt-Out is a Cop-Out (Score:4, Interesting)
Just a friendly public service reminder for those of you in the USA:
When your bank or brokerage sends you a copy of its privacy policy, full of ambiguous language, and saying "Since we protect your privacy, there's no need for you to opt out of our information sharing among our family of companies", do two things:
1) Opt-out. Yes, it means writing a letter and putting a stamp on it. Deal with it.
2) In your letter, mention that you're opting-out because it's your only option available under the law, but that you're doing so under protest - and that you consider anything less than opt-in a violation of your privacy rights. Congratulate the bank on coming up with a wording ("information sharing") that sounds so harmless that most consumers are unlikely to realize what it really means.
3) Print out a second copy and send it to your Representative and Senator. Use proper "Cc:" snail-mail etiquette -- you want your bank to know you're telling your Congresscritter, and you want your Congresscritter to know that your bank knows.
Thank the critter (especially if he or she voted for it) for the new privacy law that's forced banks to do this very small ("opt-out") notification. Tell them that you realize the bank (or more accurately, the DMA, on request of its members) to use a low response rate to this "you have an opportunity to opt-out" mailing campaign as "evidence" that the consumers really do like to eat their spam, "or they'd opt-out, but since 0.00001% actually bothered to opt-out, the other 99.99999% must like receiving special offers through the mail and telephone and email!".
Tell your congresscritters that silence does not imply assent.
You know the argument's bogus. But the DMA, with millions of dollars in lobby funds, is gonna try to make it. And they'll succeed, unless you - yes, you there, behind the keyboard - get off your ass and do something.
Silence does not imply assent. But the DMA is going to try very hard to convince your congresscritter that it does.
The logical response is to deny the DMA the silence it needs to pull off the scam.
Problem (Score:2)
Secondly, your university is most likely a non-profit organization, which grants it certain tax benefits. I believe selling student data to marketing droids would challenge the university's non-profit status, which means big bucks. You should look into this because the university's non-profit status determines a lot of policy decisions.
Um, what? (Score:2)
Try some research.
Regards,
levine
Re:Problem (Score:3, Insightful)
Universities of all types are money grubbing bastards. Even when I opted out of the student directory, my name was sold to a slew of companies, I got special student credit card offers, and all sorts of adds for graduation stuff, rings, invitations etc...
And as a former university employee, let me tell you WHY they do this. Government money is regulated, it can only legally be spent on what it is earmarked for. Once in my employment, we had 250k for equiptment but our other accounts were nearly depleted, we could hardly pay our employees and bills and we couldn't cheat. I ordered 100k worth of sun servers (which we also needed badly), but when we got them we couldn't afford the 900$ to have the power receptacles installed (3 prong 210V dealies), because that money had to come from out general fund not our equiptment fund.
So here's why universities are money grubbing bastards (atleast in the US). Money they get from ripping off students is *FREE MONEY*. They can put it in "discretionary funds" and do whatever the fuck they want with it. At my university "the money runs uphill and the shit runs downhill" (to quote the Sopranos). The chancelor stole money from wherever he could to the tune of like 2 mill a year in his discretionary fund. With a student body of about 15,000 you can see thats about 134$/year in fees per student, easily accomplished.
Re:Problem (Score:2)
When a server which housed our primary username/password database was comprimised, they went through a huge rigamarole, having all 20000+ students, staff, faculty, etc change passwords. They said they were "obliged by federal law" to protect student records, and they took it seriously (IANAL).
Of course, they ripped off students in various ways.
I'm fairly certain my information was never sold, and I would be enraged if they did such a thing. I never received any credit card offers after I opted out with the credit reporting agencies. I didn't get any advertisements for any graduation stuff (only official university stuff - even the offers for graduation pics and videos came through the University, not the company that did the photos). The only junk mail (postal) that I got was from people who got my address through other means (Dr. Dobbs subscription, ordering electronics equipment online, etc). I also received zero spam (electronic) as I took various precautions to ensure my primary email address was not available off-campus. The online student directory (which I had a part in writing) had various features to prevent spambot harvesting. Our telephone system blocked caller ID (PITA for those with "privacy manager").
Buckley amendment explained... (Score:3, Informative)
The other big exception is for "directory" information. What comprises this information is up to the discretion of the university. You would think what sirectory info was would be obvious, or at least standard, but at least at the university I work at, a leading online university, does not count email address as directory information (because otherwise other online universities (read "for-profit") might be able to request, and we'd be required to provide, this information, and then PU spam is just a click away).
There was recently a story in the news of an elementary school in Texas somewhere who was publishing student info in this way. They were just following the letter and spirit of the law.
So opt out. Your school is following the law. If they put you in a student directory, then they have to give that info to anyone who asks.
Maybe they could publish a student directory with everyone assigned a code number, which you could then input to a student-restricted website to get the address of that hottie you've been wanting to stalk?
What about employee's? (Score:2)
That said, for the students, this kind of selling could be against the FERPA law. Family Education Rights and Privacy Act should prevent this kind of selling of student information. If it doesn't, why doesn't it? I remember when I was setting up a printer in the Records and Registration area and things are so tight with FERPA that they have to have to separate 75 page per minute printers (or ones similar to it). One prints schedules and the other is the only one they use for transcripts because the one for schedules anyone can get to including other students. The address could be considered different then say evidence that you took a certain course, but I don't think it should be that way.
Re:What about employee's? (Score:1)
leave it. (Score:2)
the list started out as a gopher and ph service, but now it is more accessible through a web form:
http://www.osu.edu/cgi-bin/Inquiry