THANK YOU FOR SUBSCRIBING
Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Education Technology Insights
THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Education Technology Insights APAC Advisory Board.

Joseph A Catania, Director of Data Management & Technology

Seeing the People Behind the Data
Joseph A Catania
Student Success Advocate
Years ago, somebody approached me for a report and I almost generated it without a second thought. Then, I looked at what it contained. There was health information, family conditions, and other details that should never be shared casually through an email chain. That stopped me immediately because a "record" in a school district isn't a record. It's a kid, a family and sometimes, a safety concern
And honestly, that moment still shapes how I approach every decision, from vendor reviews, security calls to writing policies and procedures. I'm always asking who is behind this data
The other thing I've learned is that I'm a translator more than a technician. A principal does not need technical complexity. They want to understand the issue, what's at stake, and what steps are being taken to address it. If I can't explain a decision that way, I do not understand it well enough yet.
That same perspective also shapes how I view the biggest data management challenges facing K-12 organizations today. Try counting the systems in your district that touch student data sometimes. A typical district relies on the student information system, learning platforms, assessment tools, transportation, food service, and numerous applications that have accumulated over time and often remain in use without regular oversight. It's like cleaning out a garage. You don't realize how much has accumulated until you actually open every box, and every box turns out to be your responsibility.
Keeping Student Data Safe
Managing user access presents another significant challenge. Teams need quick information because that's how kids receive the help. However, outdated accounts and overly broad permissions are risky. Account cleanup might be boring, but it remains crucial. And then there's the human element. Phishing, a misdirected email and weak passwords are risks that technology cannot eliminate. Building a strong security culture requires continuous education, as one slide deck a year doesn't move the needle.
These challenges reinforce the importance of approaching data governance with a clear and consistent framework. Balancing data accessibility, security, and compliance starts with one question. Who needs access to information and why?
If I lock everything down, I've slowed the people helping kids. If I leave it open, I've put everyone at risk. So I lean on structure instead of instinct, using role-based access, MFA, account procedures tied to HR, vendor reviews, and documentation that can withstand an audit. None of it's fancy. The hard part is doing it every single time, even when I'm managing competing priorities.
“A technically correct answer that ignores that reality isn't a good answer.”
But compliance isn't the goal. Compliance is the floor.
Families hand us the most sensitive information that exists about their children, and you earn that trust daily through responsible stewardship, or you lose it. That same principle also shapes how I view the future of data governance and information security in K-12. One of the biggest drivers of that future is AI. What surprises people is that it is not one issue. It hits instruction, privacy, security, equity, and operations simultaneously, so if you treat it as only a teaching question, you've missed half of it.
The Next Priorities in K-12 Data Security.
Beyond AI, another important shift is taking place around digital identity. Your network perimeter is basically gone now. More accurately, the perimeter didn't disappear. It moved. The account is the perimeter, which is why MFA and least privilege aren't optional anymore. Third-party vendors are another non-negotiable consideration. We depend on third parties for nearly everything, so I ask the hard questions about how they handle data. I've walked away from vendors over unsatisfactory answers. Those conversations are never easy, but protecting student data has to come first.
For professionals entering the field, my advice is to develop both technical expertise and operational understanding. The technical side, including systems, privacy law, security, and governance. Then, spend time in a school building and watch how it actually runs. A technically correct answer that ignores that reality isn't a good answer.
Stay calm when things break. Write ideas down. Ask the question everybody else thinks is obvious or unnecessary, because honestly, three other people in the room have the same question.
And don't forget what's behind the data. It is students, staff, and families. Keep that at the center of your decisions, and the rest will follow naturally.
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

However, if you would like to share the information in this article, you may use the link below:
www.educationtechnologyinsightsapac.com/leadership-perspective/joseph-a-catania-nid-3894.html