Wednesday, April 16, 2025

Understanding CIPA and COPPA: A Teacher and Parent's Perspective

As both a high school math teacher and a father of two kids (a 7th-grade son and a 4th-grade daughter), I often find myself thinking about how our kids interact with technology. From the classroom to the living room, the internet is everywhere, and while it opens up amazing opportunities for learning and creativity, it also presents real concerns when it comes to privacy and safety. That’s where two major laws come in: CIPA and COPPA.

Image Source: https://www.bark.us/blog/cipa-compliance/

What is CIPA?
The Children’s Internet Protection Act (CIPA) was enacted by Congress in 2000 to address concerns about children’s access to obscene or harmful content over the internet. CIPA applies primarily to schools and libraries that receive discounts through the federal E-rate program, which provides funding for internet access and infrastructure. To comply, institutions must:
  • Use filters to block obscene or harmful content
  • Monitor online activities of minors
  • Educate students about appropriate online behavior, including cyberbullying

Image Source: https://www.groovypost.com/explainer/what-you-need-to-know-about-coppa-and-whether-websites-are-using-it/

What is COPPA?
The Children’s Online Privacy Protection Act (COPPA), passed in 1998, is aimed at protecting the privacy of children under the age of 13. It requires websites, apps, and online services that are directed at children or knowingly collect data from children under 13 to:
  • Provide clear privacy policies
  • Obtain verifiable parental consent before collecting personal information
  • Allow parents to review and delete their child’s data

Do These Laws Do Enough?
As a teacher, I appreciate that CIPA mandates internet safety education. It’s a practical step that empowers students to be critical digital citizens. However, I also see that filters can be blunt tools. They often block legitimate educational content, which can hinder learning. Worse, the tech-savvy students often find ways around them anyway.

As a parent, I’m grateful COPPA exists to put some kind of boundary on data collection for younger children. But let’s be honest, many platforms don’t enforce these rules well, and plenty of kids under 13 are using apps like YouTube, TikTok, and Snapchat without meaningful oversight.

That leads me to danah boyd’s comment that COPPA teaches kids to lie, and I have to admit I think she’s right. Kids often create fake birthdates to sign up for accounts. They learn very early that the path to accessing the digital world is to fudge the truth. That’s not a great lesson.

Is 13 the Right Age?
Honestly? I’m not sure. Thirteen feels arbitrary. Developmentally, some kids are ready for more freedom and responsibility online at 11, while others may not be ready even at 15. The line has to be drawn somewhere, but what we really need is education and active parental involvement, not just age-based gatekeeping. We wouldn’t hand a kid car keys just because they turned 16. We train them. We supervise them. And we should take a similar approach with digital literacy and privacy.

The Bigger Picture
There are other efforts on the table, like the Kids Online Safety Act (KOSA), which aims to push platforms to design with children’s mental health in mind (read more here). While it’s well-intentioned, it also raises concerns about government overreach and potential censorship. Balancing safety, privacy, and freedom of expression is complicated. 

What I think we need most is a culture of digital responsibility in schools, in homes, and on the part of tech companies. That includes transparency about how data is used, better tools for parents and teachers, and real consequences for companies that violate these standards.

Image Source: https://www.tupeloschools.com/mental-health/mental-health/internet-safety

Final Thoughts
CIPA and COPPA are important, but they’re just the beginning. Our kids are growing up in a digital world we never experienced at their age. We need modernized laws, yes, but we also need ongoing conversations, tech education, and intentional parenting. As a teacher, I’ll keep talking to my students about how to stay safe online. As a dad, I’ll keep asking questions and trying (however imperfectly) to guide my kids through this world. And I hope lawmakers, educators, and tech companies will keep stepping up too.


Tuesday, April 8, 2025

What Happens to Our Digital Lives When We're Gone? Planning for a Digital Estate

Planning My Digital Afterlife: A Teacher, Parent, and Tech Guy’s Perspective

Like most people, I spend a big chunk of my life online. As a math teacher and budding technology specialist, I’m constantly juggling digital tools, grading on DeltaMath, sharing lessons through Google Drive, troubleshooting devices, and managing way too many logins. Add to that my personal life: family photos, YouTube playlists, online banking, cloud storage, and even the occasional forgotten subscription still quietly draining $4.99 a month. But what happens to all of that when we’re gone? If something were to happen to me, my digital life would become someone else’s puzzle to solve. And probably not an easy one. So I’ve started taking real steps toward digital estate planning, something I think all of us, especially parents and educators, should at least be thinking about.

Image Source: https://www.linkedin.com/pulse/5-steps-include-digital-assets-your-estate-plan-john-heck


Why It Matters

As a husband and father of two, the last thing I want is for my wife or kids to be stuck trying to access accounts or recover photos, documents, or even just manage the loose ends I’ve left behind online. This New York Times article about families struggling with this very issue opened my eyes to how complex it can get and how simple it is to start preparing.


Here’s what I’m doing:

1. Taking Inventory: The first step has been simply listing out my digital assets: email accounts, Google Drive files, YouTube playlists, digital photos, banking apps, social media profiles, subscriptions, etc. Just seeing it all in one place was eye-opening. I've started to compile a spreadsheet (stored securely, of course) that outlines my accounts and what I’d want done with each.

2. Exploring Google’s Inactive Account Manager: Since a lot of my digital life is tied to Google (Gmail, Photos, Docs), I used their Inactive Account Manager to choose a trusted contact who can access certain data if my account goes unused for a set time. It’s simple and secure, and honestly, it took me less than 10 minutes to set up. Google makes it easy to decide what happens if your account goes inactive.

Image Source: https://support.google.com/accounts/thread/61511601/inactive-account-manager-any-detailed-help-on-what-to-expect-when-starting-it?hl=en


3. Organizing Important Documents: Thanks to Death with Dignity’s “Life File”, I’ve started compiling important documents and instructions, like which accounts should be closed, which files should be saved, and who I trust to handle it.

4. Including It in My Legal Planning: I’m working on updating my will to include a digital executor, someone who’s legally able to manage my online accounts and data. If you’ve never heard of that role before, you’re not alone. But it’s becoming more common and more necessary. It is someone we trust who can legally act on my behalf when it comes to our online accounts and data.

5. Talking with Family: We’ve had early conversations at home, nothing morbid, just practical. My wife now knows how to access my password manager if needed, and I’ve talked with my kids about the idea that our online lives matter just as much as our physical belongings.


Why I'm Sharing This

I don’t think digital estate planning gets talked about enough. As teachers, we emphasize responsibility and preparation to our students every day. This is one small way I can live that lesson out. And as a parent, it gives me peace of mind knowing that I’m not leaving a mess for my family to sort through.

If you’re reading this and haven’t started thinking about your digital afterlife yet, now’s a great time to start. Even just making a list of your accounts or setting up a Google contact is a meaningful step. If you’ve taken steps of your own or have tools or tips to share, I’d love to hear them. The more we talk about this, the easier it becomes for everyone.


Saturday, March 29, 2025

Acceptable Use Policies and the Importance of Digital Security

Reviewing Our Acceptable Use Policy: Are We on Target?

Image Source: https://otter.ai/blog/what-are-ai-agents-a-guide-to-types-benefits-and-examples

Technology is woven into nearly every aspect of education, making Acceptable Use Policies (AUPs) essential for guiding responsible use. At my school, our AUP lays out clear expectations for students, but like many policies, it leans heavily on what they shouldn’t do rather than empowering them with best practices. The policy covers a wide range of digital behaviors, including internet usage, social media interaction, and device management. It is detailed and comprehensive, aligning with the requirements of the Children’s Internet Protection Act (CIPA) and addresses issues like cyberbullying, unauthorized access, and inappropriate content. However, it lacks substantial guidance on emerging technologies, most notably, Artificial Intelligence (AI). As AI tools become increasingly accessible, should our policy explicitly define appropriate AI use for learning? Without this clarity, students and faculty alike are left to navigate these tools without institutional guidance.

Faculty are also bound by an AUP, though it differs slightly from the student version. While we are trusted with more autonomy, the core principles remain the same. But are these policies comprehensive enough? And more importantly, do they adequately prepare us for the evolving risks of digital exposure?

The Reality of Data Exposure

Image Source: https://klik.solutions/great-info/top-internet-safety-rules/

To evaluate personal cybersecurity risks, I recently explored Have I Been Pwned, a site that reveals if an email has been caught in a data breach. What I found was unsettling: my personal email had been involved in three breaches, while my work email had been compromised six times. This raised immediate concerns. If my work credentials have been exposed that many times, what does that mean for my students?

Using this interactive tool, I traced the history of my data leaks. My first breach was in 2018 at Apollo, where information like my job title, email, and even social media profiles were exposed. A year later, LuminPDF followed, this time leaking passwords and authentication tokens. The breaches continued: People Data Labs in 2019, LinkedInScrape in 2021, and DemandScience in 2024. With each incident, more of my identity was exposed—email addresses, phone numbers, names, and job titles, all out there, potentially in the hands of bad actors.

Image Source: https://www.abc.net.au/news/2023-05-18/data-breaches-your-identity-interactive/102175688

This isn’t just an individual issue; it’s a systemic one. If educators and students aren’t actively protecting their data, we’re all at risk. Yet, our AUP barely touches on digital security beyond broad warnings against phishing scams. Shouldn’t we be teaching students how to actively safeguard their personal information?

Practical Steps for Stronger Security

After seeing my own data exposure, I turned to resources for improving security. One simple step is using stronger passwords. Instead of short, complex passwords that are difficult to remember, tools like Use a Passphrase generate long, easy-to-remember passphrases that are significantly harder to crack. Encouraging students and faculty to adopt passphrases over standard passwords could be a small but impactful addition to our AUP.

Image Source: https://proton.me/blog/what-is-passphrase

Additionally, we should explicitly incorporate guidance on managing personal data, recognizing the risks of data breaches, and using AI tools responsibly. Cybersecurity education shouldn’t just be an afterthought. It should be embedded into our policies and curriculum.

Moving Forward: Updating the AUP

Reflecting on my own experiences with data breaches, I feel a mix of anxiety and awareness. It’s unsettling to realize how much of my information has been compromised, but it also reinforces the need for vigilance. The reality is that we cannot simply abandon the internet; rather, we must take proactive steps to secure our digital presence. Just as we lock our doors or set house alarms for physical security, we must implement strong passwords, enable two-factor authentication, and remain cautious about sharing personal information online.

Our AUP should evolve to reflect this reality. We need to move beyond reactive policies that focus solely on restrictions and instead provide students and staff with actionable steps for responsible technology use. Cybersecurity experts, faculty, IT specialists, and even students should be involved in shaping these updates. A strong policy isn’t just about setting rules, it’s about equipping our school community with the tools to navigate an increasingly digital world safely and responsibly.