In the digital age, protecting data and, privacy has become increasingly important. Hackers,
whether internal or external to an organization, could cause significant damage by stealing
sensitive data, causing financial loss, compromising the privacy of individuals, or damaging the
organization’s reputation. Because of this, effective measures are needed to protect data privacy
against internal and external threats.
Ensuring data privacy and security is crucial in today’s digital age, where personal and corporate
data are often prime targets for breaches, theft, and misuse. Data security describes the protections
to prevent unauthorized access to or acquisition of personal student and staff information.
(Czuprynski & Smith, 2017). Data security seeks to safeguard digital information throughout its
life cycle to protect it from corruption, theft, or unauthorized access. Data security covers
everything – hardware, software, storage devices, and user devices; access and administrative
controls; and the organization’s policies and procedures. (Fortinet.com). It also includes using
encryption when transmitting personal data electronically, requiring employees of educational
institutions to use passwords to access files containing personal data, and installing software that
detects intruders in the computer network to help improve data security. Due to this, various tools
and technologies are used to ensure the visibility of data and its use; encryption, masking, and
redaction of sensitive information.
On the other hand, as defined by (Czuprynski & Smith, 2017), Data privacy relates to the collection
and use of personal information of both students and staff. Data privacy involves handling,
processing, storage, and usage of personal information in ways that are consistent with the users’
expectations and relevant legal requirements. The right of individuals to control their personal
information, and how information is collected and used by organizations are the key focus of data
privacy. Leaving data unprotected is akin to leaving one’s wallet on the front seat of an unlocked
car. School districts face very real security threats because they collect, use, maintain, disclose,
and discard valuable personal information about students, teachers, and employees. (Czuprynski
& Smith, 2017).
Data leakage is a serious threat to enterprise operations, such as corporations and government
agencies. The loss of sensitive information can lead to significant reputational damage and
financial losses and even can be detrimental to the long-term stability of an organization. (L. Cheng
et al., 2017). According to IBM’s 2016 as cited in (L. Cheng et al., 2017), the Cost of Data Breach
Study, the average consolidated cost of a data breach has reached $4 million. Juniper Research’s
forecast also cited (L. Cheng et al., 2017) in suggests that the global annual cost of data breaches
will be over $2.1 trillion globally by 2019, due to the rapid digitization of consumers’ lives and
enterprise records. Data leakage can be caused by internal and external information breaches,
either intentionally (e.g., data theft by intruders or sabotage by insider attackers) or inadvertently
(e.g., accidental disclosure of sensitive information by employees and partners). (L. Cheng et al.,
2017). Hackers use phishing emails sometimes consisting of poor grammar and spelling, and a
sense of urgency to trick individuals into voluntarily providing access to their personal
information, usually by masquerading as a legitimate sender. This act allows unallowed users to
gain access to computer systems making valuable information stored vulnerable. (Czuprynski &
Smith, 2017).
Given this, educational institutions must be very mindful and implement policies and measures to
ensure that the data entrusted in their care are safe and well accounted for taking into consideration
legal, ethical compliance, and practical strategies. Protecting data privacy is urgent and complex.
This protection is necessary because of the ubiquity of the technology-driven and information intensive environment
