Public postsecondary institutions requirement to keep certain student information private establishment; consent requirement before collecting student location data
SF 710 amends Minnesota’s government data practices and higher education laws to add privacy protections for students at public and private postsecondary institutions. It limits how public postsecondary institutions may treat certain directory information, prohibits public disclosure of students’ email addresses, physical addresses, telephone numbers, and ID card photographs through directory-information policies, and requires institutions to keep documentation of large requests for directory information for four years. Students whose directory information is requested must be allowed to review the institution’s documentation of that request.
The bill also creates a new section governing student location data. Postsecondary institutions may not collect a student’s location data without the student’s consent, and consent cannot be required as a condition of enrollment, financial aid, housing, dining, campus Wi‑Fi, or other basic university services. Institutions must provide annual notice of any technology-provider contracts that gather location data, identify the provider and the data collected, and publish the contract online. Technology providers are restricted from selling, sharing, or using location data for commercial purposes, must maintain security procedures and logs, must return or destroy the data when the contract ends, and must disclose breach information needed for compliance with Minnesota’s data-breach law.
The bill’s impact on state law is to expand student privacy protections in chapter 13 and create new obligations in chapter 135A for both institutions and technology vendors. It applies to public and private postsecondary institutions for the location-data provisions, but the directory-information changes mainly affect public postsecondary institutions and existing education-data practices under Minnesota Statutes section 13.32. The bill also makes technology-provider security procedures public data unless another law makes them not public.
Overall, the bill appears to reflect a strong privacy-protection sentiment, with the text emphasizing consent, transparency, data minimization, and limits on commercial use of student data. Because there are no committee transcripts or recorded votes provided, there is no documented public debate in the supplied materials. Based on the bill’s structure, likely support would come from privacy advocates and students concerned about surveillance or data commercialization, while potential concerns could come from institutions and vendors about compliance burdens, contract transparency, and operational limits on campus technology systems.
Notable points of contention likely include whether requiring affirmative consent for location tracking could interfere with campus services, how broadly “location data” and “basic university service” are interpreted, and the administrative burden of notice, contract publication, logging, and retention requirements. Another possible issue is the restriction on using location data for marketing or advertising, which would limit common vendor data practices and could draw opposition from technology providers or institutions relying on integrated digital services.
SF 710 would amend Minnesota Statutes section 13.32 and add a new chapter 135A section to impose new privacy, notice, retention, and security requirements for postsecondary student data. It restricts public postsecondary institutions’ ability to classify certain contact and identification information as directory information, requires documentation of large directory-information requests, and bars public disclosure of specified personal contact details through institutional directory-information policies. It also creates a consent-based framework for collecting student location data, applies vendor restrictions and breach-response duties, and requires contract publication and data-destruction/return rules.
The bill’s overall tone is strongly privacy-oriented and protective of students, with the statutory language favoring consent, transparency, and limits on data sharing and commercial exploitation. No committee testimony or votes were provided, so there is no recorded legislative debate in the supplied materials. Based on the bill text alone, the measure appears designed to address concerns about student surveillance and data misuse rather than to expand institutional discretion.
The main likely points of contention are the consent requirement for location data, especially the prohibition on making consent a condition of enrollment, aid, housing, dining, or campus Wi‑Fi, which could be viewed as limiting institutional technology practices. Institutions and technology providers may also object to the burden of annual notices, public posting of contracts, logging of data access, and mandatory destruction or return of data at contract end. Privacy advocates would likely support these provisions, while vendors and some higher education administrators may be concerned about compliance costs, operational flexibility, and the scope of the restrictions on data use.