Search  


Privacy Evaluation for Moodle.com 
Tuesday, October 17, 2023, 04:47 PM
Posted by Administrator
https://privacy.commonsense.org/evaluation/Moodle.com

Overview
Moodle is an open source learning platform that enables educators, administrators, and learners to create personalized learning environments. The privacy policy clearly states that interactions between users of Moodle.com on forums will be moderated by forum moderators. The policy clearly states the "special categories" of personal data processed by Moodle.com, but otherwise fails to disclose other types of personal information collected by Moodle. The Privacy Notice does not disclose what information is shared to third parties and further indicates that users are subject to both contextual ads and personalized ads on Moodle.com. The policy states that security measures are compatible with the GDPR, but does not provide more details on compatibility. The Privacy Notice does not clearly state whether Moodle.com is directed toward students in K-12 education or whether Moodle or a school obtains parental consent from child users under the age of 13.

Moodle is open source software and may be hosted by moodle.com, or by anyone who wishes to manage their own separate Moodle installation. This privacy evaluation is for use of moodle.com and their services. Moodle can be accessed through its website. The Privacy Notice and Site Policy used for this evaluation can be found on Moodle’s website. Additionally, other policies used for this evaluation include: Cookies Policy. This evaluation only considers policies that have been made publicly available prior to an individual using the application or service.

Safety
The terms are unclear whether Moodle itself monitors user content or whether private individuals monitor specific forums. The terms do not disclose whether users are restricted to interacting with trusted users, or whether any user can interact with any other user. The terms fail to state whether users’ personal information can be displayed publicly or whether a user has any control over how their personal information is displayed to others. The Site Policy provides that users can report spam, unsolicited adverts, or any other content that is inappropriate using a “Report to moderator” link.

Privacy
The Privacy Notice discloses that personal information is collected by Moodle but does not specifically disclose the types of personal information collected, other than “special categories” under article 9 of the GDPR. The Privacy Notice does not clearly disclose whether geolocation data is collected, but discloses that health or biometric information, behavioral or activity related data, sensitive personal information, and usage data are all collected by Moodle. The Privacy Notice says Moodle limits the collection of information to only data specifically required for the product. The Privacy Notice also states that Moodle shares personal information and specifically states under the "Marketing" section: "We love to share." The Privacy Notice further states "you can opt out and we will not sell your information." However, the Privacy Notice states that Moodle does not sell users’ personal information.

The Privacy Notice discloses that third party services are used to support Moodle. The Privacy Notice indicates that information is shared with third parties for analytical, research, and marketing purposes. The Privacy Notice clearly states that third parties with whom Moodle has shared personal data with “are obliged to keep your personal data secure and use it only for necessary service delivery.” The Privacy Notice fails to disclose whether Moodle will transfer user data in the event of a merger, acquisition, or bankruptcy, and further fails to provide whether users will be notified, can request that their data be deleted, or whether the third-party successor will be contractually required to provide the same level of privacy compliance as required by Moodle during such an event. The Cookies Policy discloses that Google Analytics cookies are integrated into Moodle, which indicates that third parties are collecting information of users for their own advertising purposes, including personalized advertisements on other third-party websites or services. The terms do not clearly disclose whether third parties can engage in data enhancement. The Privacy Notice indicates that Moodle will send promotional communications to users, and that users can opt out of such communications.

Security
The Privacy Notice indicates that Moodle implements physical security measures in protecting users’ personal information. However, the Privacy Notice fails to disclose whether Moodle encrypts user information when it is at rest or in transit. The Privacy Notice clearly states that Moodle will verify a user’s identity before Moodle processes a request if the request is not made while a user is logged in to Moodle. The terms do not clearly disclose whether an account is required to use the product or whether a user’s account is protected by multi-factor authentication.

Compliance
While Moodle is advertised as a learning platform, the terms fail to provide any clear information on whether Moodle is intended to be used by a K-12 education institution, or whether Moodle can be directed to students or users under the age of 13 with or without parental consent. The Privacy Notice indicates that organizations can implement a security measure for “their Moodle Installation” including a system to check for users who are under the age of consent. However, nothing in the terms describes whether Moodle or a school will obtain parental consent for users under the age of 13. The Privacy Notice includes a section of “Children and Personal Data” which simply states that “It is not our intention to collect personal data from a child” and provides individuals with a method of contacting Moodle if the individual believes a child has disclosed personal data to Moodle. The Privacy Notice does not clearly disclose if Moodle knowingly collects personal information from children under the age of 13, or whether Moodle will delete the personal information of a child if Moodle discovers that the user is under 13 years of age.

The Site Policy indicates that users can create or upload content to Moodle but fails to provide any information on whether the user retains any ownership over the content posted to the website, or whether Moodle receives any license over the content. While the Privacy Notice provides that, under the GDPR, users have the right to correct their data, the Privacy Notice fails to disclose whether users who are subject to the CCPA, and not the GDPR, have the right to modify their data.

Rating
This product received a Warning rating based on the following details:
Personal information is not sold or rented to third parties.
Personal information is shared for third-party marketing.
Personalised advertising is displayed.
Data are collected by third-parties for their own purposes.
User's information is used to track and target advertisements on other third-party websites or services.
Unclear whether this product creates and uses data profiles for personalised advertisements.
add comment ( 38 views )   |  permalink   |  $star_image$star_image$star_image$star_image$star_image ( 3 / 120 )

<<First <Back | 311 | 312 | 313 | 314 | 315 | 316 | 317 | 318 | 319 | 320 | Next> Last>>







Share CertificationPoint & Stay Informed Socially About EduTech?