Standards of Care, Negligence, and Institutional Liability under PDPL
The application of the Personal Data Protection Law to learning analytics in public universities exposes critical doctrinal tensions surrounding institutional liability and data processing standards. Legal analyses demonstrate that the statutory definition of appropriate measures remains broad, creating an ambiguous standard of care that complicates institutional compliance during automated monitoring [1]. When public universities aggregate diverse behavioral metrics, including virtual classroom engagement, assessment records, and platform access logs, they assemble extensive profiles that heighten institutional exposure to negligence claims in the event of unauthorized access or mishandling [1]. From a technical perspective, this regulatory ambiguity is compounded by the persistent risk of re-identification through quasi-identifier linkage attacks across integrated campus information systems [4]. Academic records containing demographic attributes and timestamped behavioral telemetry can enable external actors to isolate individual student identities even after direct identifiers have been removed [4]. Consequently, public higher education authorities cannot rely solely on basic masking or traditional de-identification techniques to satisfy statutory requirements. Maintaining lawful predictive analytics requires implementing robust privacy-preserving mechanisms, such as localized perturbation and formal privacy budgeting, to prevent unauthorized linkability while preserving sufficient data utility for pedagogical intervention [1], [4].