Third Party Access Granted : Postmortem on Student Privacy

Sharlene Toney

DEF CON 33 · Day 1 · Main Stage

Overview

In "Third Party Access Granted: Postmortem on Student Privacy," Sharlene Toney dissects the intricate and often opaque flow of student data from educational institutions to commercial data brokers, highlighting significant privacy concerns and the critical lack of student control. The talk exposes how amendments to federal privacy laws, coupled with the non-profit status of key intermediaries, create a vast loophole that allows personally identifiable student information to be collected, aggregated, and resold without explicit consent, ultimately impacting students' financial well-being and future opportunities.

Watch on YouTube

Visual summary for Third Party Access Granted : Postmortem on Student Privacy by Sharlene Toney
Visual summary for Third Party Access Granted : Postmortem on Student Privacy by Sharlene Toney

Key moments

  1. 0:00 Talk introduction and student data privacy problem
  2. 1:30 FERPA amendments broaden third-party access to student data
  3. 2:18 Nonprofit exemption in state privacy laws enables data use
  4. 5:00 EPIC lawsuit challenging FERPA definition changes dismissed
  5. 6:30 Introduction to National Student Clearing House
  6. 6:50 NSC holds data on 97% of students, $65M revenue
  7. 8:00 Argument: Regulate NSC like credit reporting agencies

Third Party Access Granted : Postmortem on Student Privacy

Speakers: Sharlene Toney

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=06CZrbjy9qM

Overview

In "Third Party Access Granted: Postmortem on Student Privacy," Sharlene Toney dissects the intricate and often opaque flow of student data from educational institutions to commercial data brokers, highlighting significant privacy concerns and the critical lack of student control. The talk exposes how amendments to federal privacy laws, coupled with the non-profit status of key intermediaries, create a vast loophole that allows personally identifiable student information to be collected, aggregated, and resold without explicit consent, ultimately impacting students' financial well-being and future opportunities.

Toney, with two decades of experience in higher education IT and an academic focus on cybersecurity risk management and privacy policy, brings a unique perspective to this complex issue. Her analysis reveals a sophisticated data pipeline where universities, through seemingly benign partnerships, facilitate the transfer of sensitive student data to entities like the National Student Clearinghouse, which then funnels it to commercial giants such as Equifax. This talk serves as a stark warning about the erosion of student privacy in the digital age and the urgent need for greater transparency and legislative reform.

The implications of this widespread data sharing are profound. Students are often unaware of where their data goes or how it is used, with little to no recourse for correcting inaccuracies or opting out of non-essential data sharing. The talk underscores that while students are diligently taught to protect their personal data online, the institutional frameworks meant to safeguard their information are, in practice, enabling its broad commercialization, creating significant risks ranging from financial aid eligibility issues to compromised employment prospects.

Background

▶ Watch: Talk introduction and student data privacy problem (0:00)

The foundation of student data privacy in the United States rests primarily on the Federal Educational Rights and Privacy Act (FERPA), enacted in 1974. Its original intent was clear: to grant parents, and later students themselves, greater control over their educational records by requiring consent before data disclosure to third parties. However, significant amendments in 2008 and 2011 dramatically altered FERPA's scope, inadvertently paving the way for the extensive data sharing observed today.

The 2008 amendment introduced the concept of "authorized parties," allowing personally identifiable information (PII) to be shared with entities performing functions that university employees would otherwise handle. While initially intended to facilitate partnerships with EdTech companies providing services like academic advising or career platforms (e.g., Handshake, Canvas), where data typically remains within the confines of the service and the university, this broadened definition set a precedent. The 2011 amendments further expanded this by clarifying the "study exception," permitting student data to be used for research aimed at developing predictive tests, improving financial aid programs, and enhancing instruction. Crucially, this allowed university "delegates" to conduct such research, further decentralizing data access.

Concurrent with these legislative changes, critical definitions within FERPA were broadened. The definition of a "student program" expanded to encompass virtually any program offered by an educational institution, and "directory information" – data that can be disclosed without consent – now explicitly included student IDs, provided the ID alone could not grant access to student records. These changes drew significant opposition, notably from the Educational Privacy Information Center (EPIC), which filed a lawsuit against the Department of Education. EPIC argued that these broadened definitions would expose "troves of student information" to previously unauthorized entities. Unfortunately, the lawsuit was dismissed, leaving these expanded definitions and their implications in place.

Adding another layer of complexity, most state-level consumer privacy laws, while growing in number and scope, typically include an exclusion for non-profit organizations. This exemption is a critical loophole that allows non-profit data brokers to operate outside the stricter privacy regulations that govern commercial entities. This legislative landscape forms the bedrock of the student data pipeline, where data can flow freely from universities through non-profit intermediaries to commercial data brokers, often without the student's knowledge or explicit consent, all while remaining "FERPA compliant."

Key Findings

▶ Watch: Nonprofit exemption in state privacy laws enables data use (2:18)

The central finding of Toney's talk is the revelation of a sophisticated, yet legally permissible, student data pipeline that significantly compromises student privacy. This pipeline leverages loopholes in federal and state regulations, enabling the widespread collection and commercialization of sensitive academic and personal information.

At the core of this system is the National Student Clearinghouse (NSC), a non-profit organization that Toney identifies as a major data broker. The NSC holds data on an astonishing 97% of university and college students in Title IX-eligible degree-granting institutions and 90% of secondary students across the United States. Despite its non-profit status, the NSC generates approximately $65 million in gross revenue annually from the sale of student data. This data is sold for various purposes, including enrollment verification for employers, aggregated data for research studies, and to loan providers who use it for student loan eligibility assessments. Critically, the NSC maintains full compliance with FERPA, and its non-profit classification exempts it from most state consumer privacy laws, creating a significant regulatory blind spot.

A particularly alarming discovery is the strategic and exclusive partnership announced on August 18, 2021, between the National Student Clearinghouse and Equifax Workforce Solutions. This partnership aims to enhance Equifax's "pre-employment verification services" through a new product called "Talent Report Education." This report incorporates "all available post-secondary degree information from participating Clearinghouse institutions," directly funneling comprehensive academic histories to HR professionals, employers, talent professionals, headhunters, and background screeners. This effectively extends the student data pipeline from universities, through the NSC, directly into the hands of one of the largest commercial data brokers in the U.S., significantly broadening the exposure of student data to the commercial realm.

The talk also highlights the profound lack of recourse for students. Under FERPA, students do not possess a "right to private action," meaning they cannot file a lawsuit if they believe their privacy rights have been violated. Their only avenue is to report concerns to the Department of Education, which, according to Toney, has never removed funding from a university for FERPA violations since the act's inception in 1974. This leaves students largely powerless to control their data once it enters this pipeline.

Finally, Toney underscores the tangible risks associated with inaccurate data. Studies suggest that up to 40% of financial information held by credit reporting agencies can be inaccurate. Given that NSC data is sold to loan providers, incorrect information can lead to severe financial consequences for students, including higher loan payments (potentially hundreds to thousands of dollars more) or the loss of eligibility for future financial aid. A lawsuit in Massachusetts, Robinson v. National Student Clearing House, resulted in a $1.9 million settlement due to NSC overcharging students for data access, further illustrating the financial implications of this system.

Technical Deep Dive

▶ Watch: EPIC lawsuit challenging FERPA definition changes dismissed (5:00)

The technical underpinning of this talk revolves around the intricate data pipeline for student information, enabled by specific interpretations and amendments to FERPA, and the operational models of data brokers. The flow begins at the university level, where student data is initially collected. This includes directory information—which, as FERPA definitions have expanded, can encompass not only names and addresses but also gender, first language, full legal guardian addresses, student ID pictures, and student identification numbers (provided the ID itself doesn't grant direct record access). Beyond directory information, universities also collect non-directory information, such as transcripts, enrollment statuses, and sensitive financial aid details.

The first critical junction in this pipeline is the transfer of this data to the National Student Clearinghouse (NSC). Universities typically integrate with NSC for mandatory reporting to the Department of Education (e.g., Title IX compliance), enrollment verification, and offering services like transcript ordering. NSC, in turn, collects both directory and non-directory information. Its privacy policy, though relatively concise at 20 pages, explicitly states that it collects both types of data. A key detail is that NSC will not correct inaccurate student data directly; students must approach their university to amend records, which are then re-sent to NSC. The policy also cites the FERPA clause that "directory information may be disclosed without consent as it consists of information that is generally considered not to be harmful or an invasion of privacy if disclosed," a statement Toney challenges given the expanded scope of what constitutes directory information.

NSC then acts as a central repository and broker. It sells two primary categories of data:

  1. Aggregated Data: This is packaged for research studies and data analytics, often used for "predictors of success" or tracking graduation rates. While theoretically anonymized, Toney warns of the persistent risk of de-identification, where seemingly innocuous data points, when combined with other datasets, could re-identify individuals.
  2. Granular, Identifiable Data: This is sold for specific, individual-level verification purposes. Examples include enrollment verification reports for employers and loan providers. Toney demonstrated this by purchasing her own enrollment verification report for $13, which included all her degree information and current enrollments. The terms of service for these reports, only accessible after initiating a purchase, specify that requests can come from a wide array of entities, including organizations providing products/services based on student status, employers, lenders, schools, state authorities, and self-verifying students. The talk raised questions about the level of proof required from non-student entities to access such sensitive, identifiable data.

The second major junction in the pipeline is the strategic partnership between NSC and Equifax Workforce Solutions. This exclusive agreement facilitates the transfer of "all available post-secondary degree information" from NSC to Equifax. Equifax then incorporates this data into its "Talent Report Education" service, targeting HR professionals, employers, and background screeners. This means a student's entire academic history, including degrees, enrollment dates, and potentially other directory information, becomes accessible through a commercial credit reporting agency known for its extensive data holdings.

This technical architecture, while seemingly compliant with current regulations, creates a systemic vulnerability for student privacy. The lack of granular consent mechanisms for students (especially for non-mandatory services), the difficulty in correcting inaccuracies across multiple data repositories, and the absence of a "right to be forgotten" (like that found in GDPR) mean that once student data enters this pipeline, it becomes a persistent, commercially exploited record with limited student control.

Demo / Proof of Concept

▶ Watch: NSC holds data on 97% of students, $65M revenue (6:50)

While the talk did not feature a traditional "proof of concept" involving hacking or exploiting vulnerabilities, Sharlene Toney provided a compelling user-level demonstration of how student data can be accessed and the terms under which it is shared.

Toney personally purchased an enrollment verification report for $13 from the National Student Clearinghouse (NSC) for her undergraduate degree. This act served to illustrate several key points:

  1. Accessibility of Data: It confirmed that detailed academic and enrollment information is readily available for purchase by various entities, including the student themselves.
  2. Cost of Access: Toney highlighted that NSC charges for this access, contrasting it with consumer privacy laws (like California's) that might mandate free access to one's own data. She noted the $13 cost for her personal report, and that employers or other entities might pay $19.95 for the same data.
  3. Terms of Service Opacity: Crucially, Toney revealed that the terms of service for accessing these reports were only made available after she had initiated the purchase process. This means users, including students or third-party requestors, must commit to buying the report before fully understanding the conditions and uses permitted for the data. She scrutinized these terms, noting the broad categories of entities (e.g., "an organization providing products or services based on an individual's status as an enrolled student") allowed to request information, raising questions about the specific types of products or services that qualify and the level of scrutiny applied to such requests.

This demonstration effectively underscored the commercial nature of student data held by NSC and the hoops individuals must jump through to even understand who might be accessing their information and for what purposes, thereby illustrating the practical challenges students face in managing their privacy.

Defensive Implications

▶ Watch: Argument: Regulate NSC like credit reporting agencies (8:00)

The detailed analysis of the student data pipeline presented by Sharlene Toney offers critical insights for both students and institutions to bolster their defenses against privacy erosion.

For Students:

  1. Be Proactive and Question: Students should move beyond passively accepting university privacy policies. They must actively inquire: "Where is my data going?" and "Which specific third-party vendors are receiving my information?" This demands transparency from universities.
  2. Understand Directory Information: Students need to be fully aware of what their specific university defines as "directory information," as this can vary widely and include sensitive details like gender, first language, and even legal guardian addresses, which can be shared without consent.
  3. Advocate for Opt-In Consent: For non-mandatory services, such as career platforms (e.g., Handshake) or student activity platforms, students should advocate for an opt-in consent model. Data should only be shared if the student explicitly chooses to participate, rather than being automatically included. Toney's personal experience of requesting removal from Handshake, despite not being offered as an option, highlights the potential for agency if students know to ask.
  4. Monitor Your Records: Students should regularly review their academic and financial records for accuracy. Given that data from the National Student Clearinghouse directly impacts loan eligibility and financial aid, and that errors can persist for years, vigilance is key. If inaccuracies are found, students must understand that corrections typically need to be initiated with their original university, not the data broker.
  5. Understand Your Rights (and Lack Thereof): Students should grasp the limitations of FERPA, particularly the absence of a "right to private action," which means they cannot sue for privacy violations. This knowledge can inform their advocacy efforts for stronger legislative protections.

For Universities and Educational Institutions:

  1. Enhance Transparency: Universities must drastically improve transparency regarding student data sharing. This means providing clear, accessible, and comprehensive lists of all third-party entities receiving student data, the specific types of data shared with each, and the explicit purpose for that sharing. This information should be readily available, not buried in lengthy privacy policies.
  2. Implement Granular Consent: For any service or partnership that is not absolutely essential to the student's core educational experience (e.g., learning management systems like Canvas), universities should implement granular, opt-in consent mechanisms. Students should have the clear choice to participate or not, with no adverse impact on their academic standing.
  3. Review Data Sharing Agreements: Institutions should meticulously review their data sharing agreements with entities like the National Student Clearinghouse and other EdTech vendors. They should question the necessity of sharing certain data types and explore contractual clauses that provide greater student control and data minimization.
  4. Advocate for Legislative Reform: Universities, as stewards of student data, have a responsibility to advocate for stronger privacy protections. This includes lobbying for the inclusion of non-profit data brokers in state consumer privacy laws, advocating for FERPA reform that grants students a "right to private action," and supporting the adoption of comprehensive rights akin to GDPR (e.g., right to access, right to correct, right to be forgotten).
  5. Data Minimization: Adopt a principle of data minimization, only collecting and sharing the absolute necessary data for a given purpose, and ensuring that data is retained only for as long as required.

The talk makes it clear that while students are often educated on personal cybersecurity hygiene, the systemic issues of institutional data sharing require a multi-pronged defensive strategy involving individual awareness, institutional transparency, and significant policy changes to truly protect student privacy.

Key Takeaways

  • FERPA's Evolution Undermines Consent: Amendments to FERPA in 2008 and 2011 significantly broadened definitions of "authorized parties" and "study exceptions," allowing widespread sharing of student Personally Identifiable Information (PII) without explicit student consent, shifting control from students to institutions.
  • Non-Profit Data Brokers Operate in a Regulatory Loophole: The National Student Clearinghouse (NSC), a non-profit organization holding data on 97% of university students, acts as a major data broker, generating $65 million annually from selling student data. Its non-profit status exempts it from most state consumer privacy laws, despite its commercial activities, leaving a significant regulatory gap.
  • Student Data Funnels to Commercial Giants: An exclusive partnership between NSC and Equifax Workforce Solutions (announced August 2021) now channels "all available post-secondary degree information" to employers, HR professionals, and background screeners via Equifax's "Talent Report Education," vastly expanding the commercial exposure of student academic histories.
  • Students Lack Effective Recourse: Due to FERPA's "no right to private action" clause, students cannot sue for privacy violations; their only recourse is to report to the Department of Education, a mechanism that has historically proven ineffective in enforcing compliance.
  • Inaccurate Data Carries Significant Financial Risks: The widespread sharing of student data, often with inaccuracies (up to 40% in financial data from credit agencies), can lead to severe financial consequences for students, including higher loan payments, loss of financial aid eligibility, and challenges in employment verification.
  • Urgent Need for Transparency and Legislative Reform: Protecting student privacy requires universities to provide clear, granular disclosures of all third-party data sharing and implement opt-in consent for non-essential services. Additionally, legislative changes are crucial to include non-profit data brokers under consumer privacy laws and grant students stronger rights to control and correct their data.

About the Speaker(s)

Sharlene Toney is a seasoned professional with extensive experience in higher education, spanning over two decades. For the past 12 years, she has served as an IT Business Analyst specializing in enterprise student systems, providing her with deep insights into the operational aspects of student data management within universities. Currently, she is advancing her expertise by pursuing an MS in Cybersecurity Risk Management, with a particular interest in privacy policy analysis. Her background uniquely positions her to critically examine the intersection of technology, policy, and student privacy.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Toney does real homework here — the NSC pipeline, the FERPA amendment history, and the Equifax partnership are documented with enough specificity to be genuinely useful. The talk earns its DEF CON slot as a policy/case-study hybrid, not as technical research, and judged on that lane it delivers competent, honest work without padding it into something it isn't.

Heather Calloway (CISO) — SOLID

Toney exposes a real and underappreciated structural problem — a FERPA-enabled data pipeline that launders student PII through non-profit intermediaries and into commercial credit infrastructure with no meaningful student recourse. The findings are credible and the policy analysis is competent, but the talk stays at the awareness level when the audience needed a harder push toward accountability and action.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33