← Blog Post အားလုံးကြည့်ရန်

Data, Privacy & Risk · Public Disclosure

Certificate စစ်လို့ရအောင် Student Data အကုန်ပြရမလား?

Verification page က public ဖြစ်တာနဲ့ student record တစ်ခုလုံးကို public ဖြစ်စရာမလိုပါဘူး။ ယုံကြည်မှုတည်ဆောက်တာက data များများပြခြင်းမဟုတ်ဘဲ claim ကိုစစ်နိုင်လောက်သော minimum data ပဲပြခြင်းဖြစ်ပါတယ်။

Myanmar school privacy team separating public credential fields from private student data
အတိုချုံးအဖြေ — Public credential မှာ issuer၊ recipient display name၊ achievement၊ issue date၊ purpose-specific credential ID နဲ့ current status ကဲ့သို့ verification-essential fields ပဲပြပါ။ Contact၊ identity document၊ payment၊ private assessment၊ login/security နဲ့ case notes မပြပါနဲ့။

Data Classification ၃ အဆင့်

PublicAnyone က link သိရင်ကြည့်နိုင်သော approved fields
InternalAuthorized school workflow အတွက်သာ
RestrictedNeed-to-know၊ extra control/audit လိုသော sensitive records
TemporaryPurpose ပြီးလျှင်ဖျက်ရမည့် upload/export/cache

Field တစ်ခု public လုပ်မည့်သူ၊ အကြောင်းရင်း၊ authority/consent၊ review date နဲ့ removal path ကိုမှတ်ပါ။ Default ကို private သတ်မှတ်ပါ။

ပုံမှန်အားဖြင့် Public မပြသင့်သော Data

  • Email၊ phone၊ home address နဲ့ emergency contact
  • National ID/passport၊ birth date အပြည့်နဲ့ signature image
  • Payment detail၊ invoice၊ scholarship/financial hardship information
  • Password၊ reset link၊ token၊ internal account ID နဲ့ device data
  • Detailed marks၊ failed attempts၊ assessor notes၊ appeal/complaint records
  • Attendance detail၊ health၊ disability/accessibility information
  • Disciplinary record၊ revoke reason နဲ့ investigation evidence
  • Unredacted spreadsheet၊ form response နဲ့ admin-only comments

Public Credential မှာ ဘာတွေပြနိုင်လဲ?

Purpose နဲ့ policy ပေါ်မူတည်သော်လည်း minimum verification set အဖြစ် issuer name/verified status၊ recipient-approved display name၊ award/course title၊ issue date၊ non-sensitive completion/result label၊ random credential ID၊ active/revoked/expired status နဲ့ public verification URL ကိုစဉ်းစားနိုင်ပါတယ်။ Field တစ်ခုစီကို “ဒီ claim ကိုစစ်ဖို့ တကယ်လိုသလား?” မေးပါ။

Credential ID ကို Privacy-safe လုပ်ပါ

Phone၊ date of birth၊ NRC၊ student database primary key သို့မဟုတ် predictable sequence ကို public ID မလုပ်ပါနဲ့။ Random၊ sufficiently hard-to-guess၊ purpose-specific ID သုံးပြီး public endpoint မှာ rate limiting/monitoring နဲ့ bulk enumeration risk စစ်ပါ။ ID က secret မဟုတ်သော်လည်း အခြား systems နဲ့အလွယ်တကူ join မဖြစ်စေသင့်ပါ။

Social Post နှင့် Screenshot Review

  1. Recipient consent နဲ့ approved usage scope စစ်ပါ။
  2. Image ထဲ QR၊ ID၊ email၊ signature၊ grade/notes ကို zoom စစ်ပါ။
  3. File name၊ EXIF/metadata နဲ့ hidden layers/comments ဖယ်ပါ။
  4. Background computer screen၊ paper list နဲ့ name tag စစ်ပါ။
  5. Caption မှာ health၊ finance၊ complaint သို့ exceptional result မဖော်ပြပါနဲ့။
  6. Withdrawal contact နဲ့ takedown workflow ထားပါ။

Shared Sheet သည် Public Page မဟုတ်

“Anyone with the link”၊ published CSV၊ embedded table နဲ့ accidentally indexed file က public disclosure ဖြစ်နိုင်ပါတယ်။ View-only ဖြစ်လည်း copy/screenshot ရနိုင်ပါတယ်။ Approved users အတွက်သာ share လုပ်၊ link/access review လုပ်၊ export ကို minimal fields နဲ့ expire/delete လုပ်ပါ။ Student Data Protection Guide ကိုတွဲသုံးပါ။

Revoked Credential ကို ဘယ်လိုပြမလဲ?

Public page မှာ status၊ effective date နဲ့ neutral verification instruction လောက်ပဲပြပါ။ Cheating၊ payment dispute၊ disciplinary reason၊ identity evidence နဲ့ staff notes မဖော်ပြပါနဲ့။ Reason အတိအကျလိုသူအတွက် authorized appeal/support process သီးခြားထားပါ။

Publish မလုပ်မီ Minimum Test

Necessity — မပြရင် verification မဖြစ်ဘူးလား?
Expectation — Learner က ဒီလို public ဖြစ်မယ်လို့နားလည်ထားလား?
Harm — Search၊ screenshot၊ reuse ဖြစ်ရင် ဘာထိခိုက်နိုင်လဲ?
Control — ပြင်၊ revoke၊ expire၊ remove လုပ်နိုင်လား?
Evidence — Approval၊ notice/consent နဲ့ version record ရှိလား?

Legal and Operational Note

Applicable law၊ contract နဲ့ cross-border rules သည် context အလိုက်ကွာနိုင်ပါတယ်။ Data minimization၊ purpose limitation၊ storage limitation နှင့် security principles အတွက် ICO guidance ကို reference အဖြစ်ကြည့်နိုင်သော်လည်း ဒီဆောင်းပါးက legal advice မဟုတ်ပါ။ Local qualified professional ထံအတည်ပြုပါ။

FAQ

Public credential မှာ email/phone ထည့်လို့ရလား?

ပုံမှန်အားဖြင့် verification အတွက်မလိုပါ။ Contact data ကို public မပြဘဲ recipient-controlled sharing သို့ authenticated support channel သုံးပါ။

Student ID နဲ့ Credential ID တူလား?

မတူသင့်ပါ။ Internal student ID သည် system account/record နဲ့ဆက်နိုင်ပြီး public credential ID ကို random၊ non-sequential၊ purpose-specific identifier အဖြစ်သုံးတာပိုကောင်းပါတယ်။

Grade ကို public ပြလို့ရလား?

Need၊ learner expectation/consent၊ policy နှင့် risk စစ်ရပါတယ်။ Detailed score၊ failed attempts၊ assessor notes ကို public မပြသင့်ဘဲ award classification လို minimum field ကိုသာသုံးနိုင်ပါတယ်။

Certificate screenshot ကို social media တင်လို့ရလား?

Recipient consent ရှိပြီး private fields၊ QR destination၊ signatures/IDs နဲ့ metadata ကိုစစ်ပြီးမှတင်ပါ။ Consent မရှိလျှင် anonymized sample သုံးပါ။

Revoke reason ကို public ပြရမလား?

မပြသင့်ပါ။ Public status နဲ့ effective date လောက်သာပြပြီး reason/evidence ကို restricted case record ထဲထားပါ။

← Blog ဆောင်းပါးအားလုံးသို့ ပြန်သွားရန်