Overview
ISO/IEC TS 20748-4:2019 - "Information technology for learning, education and training - Learning analytics interoperability - Part 4: Privacy and data protection policies" specifies privacy and data protection requirements and attributes to inform the design and operation of learning analytics (LA) systems and practices. It is part of the ISO/IEC 20748 series and targets schools, universities, workplace learning and blended learning settings. The Technical Specification frames privacy as a combined social and technical concern (privacy and data protection) and provides attribute-level guidance to support interoperable, privacy-aware LA solutions.
Key topics and technical requirements
- Scope and purpose: Defines privacy and data protection principles tailored to the learning, education and training (LET) context.
- Privacy concepts and definitions: Clear definitions for terms such as PII (personally identifiable information), PII controller/processor, anonymization, pseudonymization, consent, sensitive PII, and accountability - drawn from ISO vocabularies and related frameworks (e.g., ISO/IEC 29100, ISO/IEC 20889).
- Requirements structure: Organized into:
- Clause 5 - privacy and data protection requirements (general and LET-specific issues)
- Clause 6 - LA privacy and data protection attributes
- Clause 7 - detailed attribute specifications (core characteristics, information collection/processing/dissemination principles, consent, governance and accountability)
- Consent and documentation: Principles for consent as an ongoing process, timing of consent, consent frameworks and minimum data requirements to document consent for LA data sharing.
- Data handling techniques: Guidance on anonymization, pseudonymization and limited use of sensitive data to reduce privacy risk.
- Accountability and governance: Requirements for institutional codes of practice, roles of data controllers/processors, and governance models that support transparency and explainability.
Practical applications and users
This specification is practical for:
- System developers building learning analytics platforms who need to embed privacy-by-design attributes and interoperable metadata about privacy characteristics.
- Educational institutions (schools, universities, corporate training) drafting LA privacy policies, consent workflows, and institutional codes of practice.
- Third-party providers and vendors delivering analytics services who must document processing roles, guarantees (anonymization/pseudonymization), and consent handling.
- Compliance and governance teams aligning LA operations with legal and ethical frameworks (e.g., GDPR, FERPA, OECD/APEC principles).
Practical uses include producing privacy attribute specifications, designing consent UIs and audit trails, defining minimal PII collection, and formalizing accountability arrangements.
Related standards and frameworks
- ISO/IEC 20748 series (LA interoperability)
- ISO/IEC TR 20748-1 and TR 20748-2 (LA process and terminology)
- ISO/IEC 29100 (privacy framework), ISO/IEC 20889 (de-identification)
- Legal/sector frameworks referenced for context: GDPR, FERPA, OECD, APEC
Keywords: ISO/IEC TS 20748-4:2019, learning analytics, privacy, data protection, PII, consent, anonymization, pseudonymization, educational data governance.