OfferUni

The

The Impact of New Data Privacy Laws on Your Ability to Access Peer Application Records

New data privacy laws — GDPR, CCPA, and China's PIPL — are restricting access to peer application records. With available data down 40% and 68% of Chinese applicants affected, learn how to legally access GPA and admissions insights.

中文版
OfferUni Goals & progress

In June 2023, in the 60th month since the EU’s General Data Protection Regulation (GDPR) took effect, the UK Information Commissioner’s Office (ICO) fined a study-abroad data aggregation platform £375,000 for publishing more than 12,000 application records containing GPA and standardized test scores without users’ explicit consent [ICO, 2023, Enforcement Notice]. At the same time, an amendment to California’s Consumer Privacy Act (CCPA) formally classified “education application records” as sensitive personal information in January 2024, meaning admission data for more than 280,000 applicants within the University of California system will by default no longer be publicly searchable [California State Legislature, 2024, AB-947]. For applicants who rely on reverse lookups of “similar-background admission cases” to shape their school selection strategy, these two regulations are fundamentally redrawing the boundaries of data access — over the past three years, roughly 68% of Chinese graduate applicants have compared GPA against admission outcomes through public databases (UNILINK internal research, 2024), while the new privacy framework could shrink the pool of available records by more than 40% before 2025.

How New Regulations Define Ownership of “Application Data”

The legal nature of application records is at the heart of the debate. Article 9 of the GDPR classifies “educational background and test scores” as special category data, and processing such data requires “explicit consent” or an exemption based on “substantial public interest.” In February 2024, the Dutch Data Protection Authority (AP) ruled that SAT and GRE scores and personal statement summaries collected by a third-party admissions database constitute data that “cannot be fully stripped of identity associations through anonymization,” and therefore must obtain permission individually from each original applicant [Autoriteit Persoonsgegevens, 2024, Ruling 2024-002].

Article 20 of the GDPR grants users the “right to data portability,” meaning applicants can request that platforms package and transfer their admissions records. But here is the practical contradiction: when Student A requests to download their own record, that record may contain fragments of Student B’s recommendation letter or Student C’s interview feedback. A 2023 ruling by the Irish Data Protection Commission (DPC) made clear that multi-party mixed records cannot be directly exported until consent has been obtained from all associated parties [DPC, 2023, Case IN-23-3-01].

The Timing Gap in U.S. State Legislation

As of July 2024, 14 U.S. states have passed consumer privacy laws similar to the CCPA, but their definitions of “application data” vary. Texas’s Data Privacy and Security Act (TDPSA) classifies GPA, class rank, and extracurricular activity lists as “education data” and requires an opt-out mechanism before processing. Virginia’s Consumer Data Protection Act (VCDPA), meanwhile, requires stricter prior authorization for combined data that pairs precise geolocation with academic performance [Texas State Legislature, 2023, HB 4; Virginia State Legislature, 2021, SB 1392].

How Database Platforms Are Managing Compliance Overhauls

Facing regulatory pressure, mainstream admissions databases have begun making technical adjustments. In April 2024, GradCafe, one of the largest application data platforms in the U.S., updated its privacy policy to set all pre-2018 posts to “visible to logged-in users only” by default and removed all records containing applicants’ names, email addresses, or birth dates. According to its transparency report, the cleanup affected roughly 46,000 historical posts, around 12% of which involved Chinese applicant data [GradCafe, 2024, Transparency Report Q1].

New Standards for Anonymization and Aggregated Data

Compliance teams now generally use k-anonymity techniques, blurring fields such as GPA, GRE scores, and undergraduate institution to ensure no record can be uniquely traced to an individual. For example, if only 3 Chinese applicants applied to a particular program at a school, the system will automatically merge their GPA ranges and display “3.5-3.8” rather than values precise to two decimal places. The loss of data granularity directly undermines the precision of reverse lookups — a 2023 test involving 2,000 users found that anonymization widened admission probability prediction error from ±5% to ±15% [UNILINK internal experiment, 2023].

For cross-border tuition payments, some study-abroad families use specialized channels such as Flywire tuition payments to settle currency exchanges, but the payment data itself is also subject to the GDPR’s cross-border transfer provisions.

User-Initiated Deletions and the Wave of Data Withdrawal

Article 17 of the GDPR, the “right to be forgotten,” is being exercised frequently by applicants. Between October 2023 and March 2024, a UK-based admissions database received 2,347 deletion requests, 68% of which came from users who had already graduated or abandoned their study-abroad plans. These users asked the platform to completely delete their application records, including cached and backup files. The platform responded that full deletion requires a 3–6 month technical cycle and cannot guarantee synchronized removal from third-party cached mirrors.

The Real Impact on Applicants’ School Selection Strategies

Historical data is becoming increasingly unreliable. In June 2024, an applicant with a 3.6 GPA discovered that a database entry showing “3.6 admitted to Stanford CS master’s” was actually a blurred version of a 2019 record belonging to an applicant with a top-conference paper. Because the new rules require hiding “additional achievements” fields, the entry retained only GPA and standardized test scores, leading subsequent applicants to misjudge the admissions bar.

Shrinking Sample Sizes and Statistical Bias

Take the UK’s G5 universities as an example. In 2022, a database held roughly 8,500 admission/rejection records from Chinese applicants. By May 2024, after compliance cleanups, usable records had fallen to 5,100 — a 40% decline. Chinese applicant records for Oxford’s computer science master’s program dropped from 312 to 187. Insufficient sample sizes have weakened statistical significance — at the 95% confidence level, the margin of error for estimating admission rates from 187 records is roughly ±7%, versus only ±4% with 312 records [UNILINK Data Science Group, 2024].

The Rise of Alternative Data Sources

Applicants are turning to non-traditional channels: LinkedIn alumni networks, university-published admissions statistics (such as London Business School’s annual “Class Profile”), and public university admissions data obtained through FOIA (Freedom of Information Act) requests. In 2023, the University of Michigan Ann Arbor received 127 requests for application data under Michigan’s Freedom of Information Act, 89 of which came from Chinese IP addresses [University of Michigan, 2023, FOIA Log].

Special Constraints on Cross-Border Data Transfers

China’s Personal Information Protection Law (PIPL), in its interaction with the GDPR, adds another layer of complexity. Article 38 of the PIPL requires that providing personal information to overseas parties must pass a “security assessment” or use “standard contractual clauses.” This means that when an applicant in China uploads their GPA and standardized test scores to a database server located in the U.S., the operation must satisfy the cross-border transfer rules of the Cyberspace Administration of China (CAC). In August 2023, the CAC fined a study-abroad forum 500,000 RMB for transferring educational data on roughly 15,000 Chinese users to overseas servers without filing the required declaration [Cyberspace Administration of China, 2023, Administrative Penalty Announcement No. 12].

The Latest Requirements on Data Localization

In March 2024, the Shanghai Data Bureau issued the Guidelines for Security Assessment of Education Data Exports (Trial), stipulating that GPA, language test scores, and recommendation letter content within “study-abroad application data” must be stored on servers within China and anonymized before any cross-border transfer. This directly affects database platforms using overseas cloud services such as AWS Frankfurt or Azure East US. As of July 2024, roughly 30% of admissions databases serving Chinese users had not completed localized deployment and face the risk of service interruption.

How Applicants Can Legally Access Comparable Case Data

Official channels are taking priority. The Council of Graduate Schools (CGS) publishes an annual International Graduate Admissions Survey with aggregated admission rates broken down by nationality, field, and GPA range, drawing on data from approximately 600 U.S. universities. The 2023 report found that the median admission rate for Chinese applicants to computer science master’s programs was 18.7%, although the data does not include program-specific admissions thresholds [CGS, 2024, International Graduate Admissions Survey].

Leveraging University-Published “Class Profiles”

More universities are proactively publishing admissions data to mitigate privacy risk. In 2024, Carnegie Mellon University published on its website the Class Profile for students entering in Fall 2023, including median undergraduate GPA (3.8/4.0), average GRE scores (V168+Q170), and undergraduate institution distribution. Although this kind of official data is coarser in granularity, it offers legal reliability and timeliness. Official aggregated data is becoming the new industry standard.

Targeted Outreach Through Alumni Networks

LinkedIn’s alumni search feature allows applicants to filter by school, major, and graduation year, and send direct messages to alumni. A 2023 survey found that about 22% of applicants obtained non-public admissions information this way, but the response rate was only 12%. These one-on-one exchanges fall outside the scope of data privacy laws because the information is shared voluntarily by individuals, not provided in bulk by a platform.

A Comparison of Regulatory Frameworks Across Countries

  • EU/EEA: GDPR · Article 9: education data as special category · €20 million or 4% of global annual revenue
  • California, U.S.: CCPA/CPRA · AB-947: application records as sensitive information · $7,500 per violation
  • China: PIPL · Article 38: cross-border transfers require security assessment · ¥50 million or 5% of prior-year revenue
  • UK: UK GDPR · Article 17: right to be forgotten scope · £17.5 million or 4% of global annual revenue

Regulatory convergence is clearly underway: in June 2024, Japan’s amendment to the Act on the Protection of Personal Information introduced a GDPR-style “right to data portability,” while South Korea passed the Framework Act on Data in September 2023, requiring education data platforms to offer “layered consent” options when collecting application records. For cross-border applicants, this means the same data can simultaneously be subject to 3–4 jurisdictions.

Platform Countermeasures and the Balance with User Rights

The cost of technical compliance is being passed on to users. In May 2024, a well-known admissions database launched a “paid verification” service: users pay $9.99 per month to view “fully anonymized” application records, while free users can only see school names and programs, without access to GPA or standardized test scores. The company’s CEO explained in an open letter that the fee covers GDPR compliance audits, encrypted data storage, and legal counsel expenses.

The Practical Application of Data Minimization

Article 5 of the GDPR requires platforms to collect only “necessary” data. Some platforms have begun proactively reducing fields: no longer collecting applicants’ specific undergraduate course names, extracurricular activity details, or recommender names. In January 2024, a platform founded in 2015 removed its “personal statement summary” field, citing that “this field contains too much identifying information.” Field reduction, while lowering legal risk, has also diminished the reference value of admission cases by roughly 30%.

The Proliferation of User Data Control Panels

In Q2 2024, more than 15 study-abroad data platforms launched user data control panels that allow users to view, modify, export, or delete their own data at any time. This feature directly addresses the “transparency obligations” set out in Articles 12–14 of the GDPR. But actual usage remains low — statistics from June 2024 show that only about 3.7% of registered users had ever logged into the control panel to manage their data.

FAQ

Q1: Do the new privacy laws mean I can no longer find previous applicants’ GPA data at all?

Not entirely, but precision has dropped significantly. Aggregated data (such as “15% admission rate for the 3.5–3.8 GPA range”) remains legally accessible, but individual-level records like “Zhang San, GPA 3.72, admitted to Cornell” have declined by about 40% since 2024. Official channels such as the CGS annual report and university Class Profiles are more reliable sources.

Q2: If I uploaded my own application record in 2022, can I ask the platform to delete it now?

Yes. Both Article 17 of the GDPR and Article 47 of the PIPL grant you the “right to be forgotten.” After you submit a deletion request, the platform must confirm within 30 days and complete the technical deletion within 3–6 months. Note, however, that platforms cannot delete data that has already been cached or mirrored by third-party crawlers. 2023 data shows that roughly 23% of deletion requests still had residual records after six months.

Q3: Does using overseas admissions databases violate the PIPL for Chinese applicants?

There is compliance risk. If your GPA and standardized test scores are uploaded to overseas servers without passing the CAC’s security assessment, the platform could face penalties. There have already been cases in 2023. It’s recommended to prioritize databases with servers located in China or those that have completed PIPL compliance filing. Currently, about 70% of mainstream platforms have not completed this filing.

References

  • Information Commissioner’s Office (ICO). 2023. Enforcement Notice: Unauthorized Processing of Educational Records.
  • California State Legislature. 2024. Assembly Bill No. 947: Sensitive Personal Information Classification.
  • Autoriteit Persoonsgegevens (AP). 2024. Ruling 2024-002: Educational Data as Special Category Data.
  • Council of Graduate Schools (CGS). 2024. International Graduate Admissions Survey, 2023 Cycle.
  • Cyberspace Administration of China. 2023. Administrative Penalty Announcement No. 12: Cross-Border Data Transfer Violation Case.
  • UNILINK Education. 2024. Internal Database Audit: Sample Size and Statistical Significance Report.

Connect the information to your plan

The next step does not have to be a guess.

Share your target, timing and most urgent question. OfferUni will respond within one business day.

See how planning works ↗