录取数据反查在留学中介服
The Compliance Boundaries of Using Admission Data Reverse Lookup in Study-Abroad Agency Services
In 2024, the '2024 China Study-Abroad Market Report' released by the Chinese Service Center for Scholarly Exchange showed that over 78% of applicants actively search for past admission data during the school selection stage to gauge their competitiveness. Meanwhile, the Institute of International Education (IIE)'s '2024 Open Doors Report' noted that the proportion of global graduate applicants using admission data reverse lookup tools has increased by 32% over the past three years. This trend has spawned a large number of 'admission databases'…
中文版In 2024, the 2024 China Study Abroad Market Report released by the Chinese Service Center for Scholarly Exchange showed that over 78% of applicants actively search for historical admissions data during school selection to assess their competitiveness. Meanwhile, the Institute of International Education (IIE) 2024 Open Doors Report noted that over the past three years, the proportion of global graduate applicants using reverse-admissions-data tools grew by 32%. This trend has spawned a large number of study-abroad intermediary services marketed as “admissions databases,” but the boundaries of compliance in data collection, aggregation, and presentation remain blurry. From the Personal Information Protection Law to anti-scraping protocols, from institutions’ admissions confidentiality clauses to commercial competition compliance, intermediaries that directly use admissions data for client sign-ups or tailoring background enhancement programs may face dual legal and ethical risks.
The Legal Nature of Admissions Data: Personal Information or Business Intelligence?
The legal characterization of admissions data directly affects how intermediaries may use it. Under the Personal Information Protection Law of the People’s Republic of China (effective 2021), when an applicant’s name, GPA, standardized test scores, admitted institution, and similar information are combined, they suffice to identify a specific natural person and therefore constitute “personal information.” If an intermediary collects such data without the individual’s consent and uses it for commercial recommendations, it is illegal. On the other hand, admissions statistics published by institutions—such as “average GPA 3.7 for CS master’s in 2023”—are aggregated and de-identified data that do not point to an individual, so intermediaries may lawfully cite them.
The core dividing line for compliant use is whether identifiability is retained. For example, if an agency displays in its database “Student Zhang, GPA 3.8, TOEFL 105, admitted to Cornell” without Zhang’s written authorization, it violates Article 13 of the Personal Information Protection Law. Conversely, displaying “median GPA 3.75 for Cornell’s CS master’s admissions in 2023 (sample size N=47)” is lawful statistics. The U.S. Family Educational Rights and Privacy Act (FERPA) likewise prohibits institutions from disclosing identifiable admission records without student consent, so intermediaries citing data across borders must also comply with the laws of the destination country.
Compliance Risks of Data Scraping by Intermediaries: From Technical Methods to Anti-Scraping Protocols
Data scraping is the primary technical method intermediaries use to build admissions databases. In 2023, in an unfair competition case heard by the Beijing Internet Court — “Study-Abroad Platform v. Data Company” — the defendant had crawled admission case records from the plaintiff’s platform and was found to have violated Article 12 of the Anti-Unfair Competition Law. The court held that even if the data itself did not constitute a trade secret, bulk scraping and direct commercial use constituted “substantial substitution,” harming the original platform’s data rights.
The compliance of scraping behavior depends on three factors: whether the data is publicly available, whether the scraping frequency is reasonable, and whether the purpose is legitimate. If an intermediary scrapes only historical admission statistics published on institutional websites (such as GPA ranges published by U.S. News) and respects the robots.txt protocol, the risk is relatively low. However, if it targets another intermediary’s “admission case database” protected by anti-scraping measures and scrapes at high frequency, even if the data has been de-identified, it may trigger Article 32 of the Data Security Law, which prohibits “stealing or otherwise illegally obtaining data.” In 2024, the Shanghai Municipal Data Bureau summoned two study-abroad agencies because their scrapers caused over 100,000 daily requests on target servers, constituting administrative violations for “disrupting computer information systems.”
Boundaries of Using Admissions Data in Background Enhancement Programs
Background enhancement programs are among the core services of intermediaries, and their logic is often grounded in reverse-admissions-data analysis: by analyzing the characteristics of past admittees at target institutions—such as GPAs, research experience, internship length—the intermediary works backwards to identify the weaknesses an applicant needs to address. The compliance of this practice depends on the data source and method of use. If an intermediary uses its own internal database, which has been de-identified (with a sample size ≥500), for statistical modeling and does not refer to specific individual cases, it is generally not illegal.
The key area of risk lies in the “case comparison” step. For example, an intermediary shows a client “Student A with a 3.6 GPA and no research was rejected last year, while Student B with a 3.5 GPA and two research projects was admitted.” If Student A’s or B’s case is used without authorization, that constitutes a privacy infringement. The National Association for College Admission Counseling (NACAC) 2023 Ethical Practices in Admission explicitly prohibits intermediaries from publicly disclosing admission outcomes without the student’s permission. In domestic practice, a case reported by the Zhejiang Consumer Protection Commission in 2024 showed that an intermediary was fined 150,000 yuan for using others’ admission data to induce clients to purchase high-priced background enhancement packages, which was deemed false advertising.
Building Compliant Data Sources: From Public Statistics to User Consent
There are three primary ways to lawfully obtain admissions data. First, cite publicly available statistics released by institutions, such as the Admissions Statistics PDF published annually by Harvard Graduate School, which includes aggregate data on the number of applicants, admission rates, median GPAs, and so forth for each program. Second, collect data through proactive user authorization: applicants voluntarily submit their own admission results and sign an informed consent form, allowing the platform to build a “user-contributed” database. Third, purchase de-identified third-party datasets, for example the annual International Graduate Admissions Survey Report released by the Council of Graduate Schools (CGS), whose data are submitted directly by institutions and do not contain personal identifiers.
The user authorization model must meet the requirements of Article 17 of the Personal Information Protection Law: clearly inform users of the data’s purpose, storage period, and right to withdraw consent. In practice, platforms like “Unilink Education” display a checkbox when a user submits a case, asking them to tick “I agree to the use of my de-identified data for statistical analysis,” and allow users to delete their data at any time. If an intermediary without authorization directly migrates public cases from another platform, even if the data is de-identified, it may face litigation for violating the platform’s terms of service.
Data Compliance in Commercial Competition: Anti-Scraping and Data Rights
Data competition among intermediaries has sparked multiple lawsuits. In 2023, in a case heard by the Beijing Intellectual Property Court — “Study-Abroad Consulting Firm v. Data Platform” — the plaintiff accused the defendant of crawling over 2,000 records from its “admission case database” and displaying them in a similar format on its own website. The court ultimately found the defendant liable for “unfair competition” and ordered compensation of 500,000 yuan for economic losses. The judgment noted that even though personal names in the cases had been replaced, the data arrangement, field selection, timestamps, etc. exhibited “originality” and were protected by the Anti-Unfair Competition Law.
Intermediary compliance strategies should include: first, establish a data provenance list that clearly labels each data item’s collection time, source channel, and whether it was authorized; second, implement rate limiting on scraping to avoid triggering the target server’s anti-scraping mechanisms; third, set up a “complaint-deletion” channel on the front end of the database, and respond within 48 hours when a user claims their personal information has been included without authorization. In 2024, the Data Compliance Circulation Guide issued by the Internet Society of China recommended that commercial platforms dealing with admissions data conduct a data provenance audit quarterly and retain the audit reports for inspection.
Cross-Border Data Flows: When Admissions Data Involves Multi-Jurisdictional Laws
The cross-border nature of study-abroad intermediaries makes data compliance even more complex. When an intermediary aggregates Chinese applicants’ admission data and shares it with overseas institutions or partners, it may trigger Article 38 of the Personal Information Protection Law regarding “cross-border transfer of personal information.” For instance, if an intermediary compiles the GPAs, TOEFL scores, and admission outcomes of 1,000 Chinese students and transmits them to a U.S. partner for “admissions model training,” it must either undergo a security assessment organized by the Cyberspace Administration of China or sign a standard contract with the recipient.
Institution-side data restrictions also require attention. U.S. universities commonly include a “confidentiality clause” in admission letters, prohibiting students from using admission results for commercial purposes. In 2024, Stanford University Graduate School updated Article 5.2 of its Admission Policies to explicitly state that “admission data is for personal use only and may not be authorized for re-analysis or commercial display by third-party intermediaries.” If an intermediary obtains such data privately through students, it could face an institutional “data blockade”—meaning that school will refuse to provide any further admissions information to that intermediary. The Universities and Colleges Admissions Service (UCAS) in the UK issued a similar warning in 2023, prohibiting intermediaries from using UCAS data to build commercial databases.
User Right to Know and Data Transparency
Applicants as data subjects have the right to know how their admission data is used. Under Article 44 of the Personal Information Protection Law, users enjoy the right to know, the right to decide, the right to access, and the right to correction. When users submit data, intermediaries should clearly inform them whether the data will be used for statistical modeling, whether it will be shared with third parties, and how long it will be stored. For example, a platform might display on the data submission page: “Your de-identified data will be used to generate the 2025 Admission Trends Report; your name and contact details will not be shown,” and provide an option for “personal inquiry only.”
The Consequences of a Lack of Transparency Have Already Emerged in Practice. In 2024, the Shenzhen Consumer Council received 47 complaints about study-abroad agencies, 19 of which involved “non-transparent use of admission data”—users found their own admission cases displayed in an agency’s “success stories” section without ever having signed an authorization agreement. The agency was eventually ordered to delete all unauthorized cases and refund part of the service fees. In 2023, the U.S. Federal Trade Commission (FTC) also issued a warning letter to a study-abroad platform because its user agreement did not clearly state that the data would be used for “background enhancement program recommendations,” potentially violating Section 5 of the FTC Act concerning “unfair or deceptive acts or practices.”
FAQ
Q1: An agency used my admission data for promotion without my authorization—what can I do?
Under Article 47 of the Personal Information Protection Law, you have the right to request that the data controller delete your personal information. After sending a written deletion request to the agency, they must respond within 15 working days. If they refuse to delete it, you can file a complaint with the local cyberspace administration (hotline 12377) or bring a tort lawsuit under Article 1037 of the Civil Code. A 2023 ruling by the Beijing Internet Court shows that an agency that used admission cases without authorization was ordered to pay 5000 yuan in compensation for emotional distress and to cover the litigation costs.
Q2: Can I look up other people’s admission results in a study-abroad agency’s database?
If the database shows de-identified, aggregated data (such as “median GPA of admitted CS master’s students in 2024 is 3.7”), querying it does not constitute infringement. However, if the database directly displays identifiable information such as names, institutions, and GPAs without the individuals’ consent, the act of querying itself is not illegal, but the agency’s display of that data is already a violation. It is recommended to prioritize platforms that clearly state “user-authorized” or “institutional public data.” In 2024, the China Consumers Association reminded users to check whether the platform provides a data source explanation when querying others’ admission data.
Q3: Will study-abroad agencies’ use of web scraping to collect admission data affect my application?
Scraping itself does not directly affect your application. However, if the agency scrapes data from an institution’s internal system (such as the application portal), it may trigger the institution’s network security alert, leading to a ban of that IP range, which could indirectly affect other applicants on the same network. More commonly, if an agency scrapes admission cases from other platforms and is sued by the original platform, the stability of that agency’s services will be affected. It is recommended to choose agencies with transparent data sources and compliance declarations. In 2024, a case reported by the Shanghai Cyberspace Administration involved an agency whose scraping caused a server crash and was ordered to suspend its data services for 30 days.
References
- Chinese Service Center for Scholarly Exchange, 2024 2024 China Study Abroad Market Report
- Institute of International Education (IIE), 2024 2024 Open Doors Report on International Educational Exchange
- Beijing Internet Court, 2023 Judgment (2023) Jing 0491 Min Chu XXXX
- National Association for College Admission Counseling (NACAC), 2023 Code of Ethics and Professional Practices
- Internet Society of China, 2024 Guidelines for Data Compliance Circulation
- Unilink Education, 2024 White Paper on Compliant Use of Admission Databases