Research Article
Rethinking data privacy for AI adoption in African higher education: A meta-synthesis of stakeholder perceptions and policy implications
Synthesis: Duncan (2026) conducted a qualitative meta-synthesis of 18 studies published between 2020 and 2025 on how students and educators in Sub-Saharan African higher education perceive data privacy in AI-enhanced learning and how that shapes adoption. Following PRISMA 2020 and the ENTREQ framework, a search of ERIC and PubMed identified 103 records; after duplicate removal 94 unique studies remained, 70 were excluded at title-and-abstract screening, 24 went to full-text assessment, and 6 more were excluded, leaving 18. Coding in ATLAS.ti used open, axial, and selective coding, interpreted through Privacy Calculus Theory and Contextual Integrity Theory. Students clustered around data security and control, transparency and consent, fear of misuse and surveillance, and infrastructural and data-literacy vulnerability. Educators emphasized institutional accountability, consent and student rights, capacity and training, and risk–benefit balancing. Both groups recognized risk and demanded stronger safeguards, but students foregrounded personal control while educators foregrounded AI Governance and compliance, with privacy concerns reducing Trust and constraining adoption.
Key Findings
- Students named four privacy concerns. Data security and control, transparency and consent, fear of misuse and surveillance, and infrastructural and data-literacy vulnerability recurred, with safeguards often seen as inadequate.
- Educators named four different emphases. Institutional accountability and governance, consent protocols and student rights, capacity and training needs, and balancing pedagogical benefits against risks.
- The groups converge on risk but diverge on priorities. Both recognized breaches, surveillance, and algorithmic bias, but students foregrounded personal control while educators foregrounded compliance and governance.
- Trust mediates the privacy–adoption link. Willingness to adopt rose where institutions showed transparency, meaningful consent, and visible accountability, and fell where governance was weak.
- Adoption follows a privacy calculus. Stakeholders weighed perceived benefits against privacy risks; students generally took a risk-oriented stance while educators balanced concerns against personalization and teaching efficiency.
- Structural constraints compound concern. Unreliable internet, limited cybersecurity protection, and low awareness of data protection laws increased perceived vulnerability and narrowed informed decision-making about AI use.
From Fragmented Studies to a Privacy-Driven Adoption Framework
The paper's claim is methodological as much as empirical: existing work examines isolated student attitudes, educator readiness, or policy gaps, and Duncan argues a meta-synthesis is what turns those fragments into theory. Following PRISMA 2020 for selection and ENTREQ for reporting qualitative synthesis, the review screened records against focus, context, stakeholder relevance, and method, then coded the included studies in ATLAS.ti through open, axial, and selective coding. The contribution is the Privacy-Driven AI Adoption Framework, which holds that adoption is shaped by three interacting mechanisms: privacy risk evaluation, contextual norm alignment, and institutional trust. Duncan pairs Privacy Calculus Theory, which models adoption as a benefit–risk judgment, with Contextual Integrity Theory, which holds that Privacy is preserved only when information practices match context-specific expectations.
Control Versus Governance: Two Stakeholder Positions
The synthesis's most useful move is comparing students and educators directly. Students experience AI-enhanced learning as the subjects whose data are collected and analyzed, so their concerns center on individual control, commercial exploitation, and protection from surveillance. Educators experience it as professionals responsible for implementing systems ethically, so their concerns center on institutional governance, legal compliance, consent protocols that respect student rights, and training that equips faculty for privacy challenges. Duncan reads the divergence as a reflection of role rather than disagreement about stakes: both groups call Privacy a critical concern, both flag breaches and algorithmic bias, and both want stronger safeguards. The convergence reflects shared exposure to weak regulation, limited institutional capacity, and reliance on providers outside the continent.
Capacity, Infrastructure, and Data Literacy
A recurring structural theme is that privacy risk is amplified by conditions outside the individual's control. Students in contexts with unreliable internet access and limited cybersecurity protection perceive heightened vulnerability to data breaches, and limited understanding of data practices and privacy policies reduces their ability to decide how to use AI. Educators describe the mirror-image gap: limited familiarity with data protection regulations and with how AI systems function, plus clear demand for training that integrates technical, pedagogical, and ethical dimensions. Duncan separates infrastructural limitations from governance failures: the first raises exposure to breaches, the second raises questions about transparency, consent, accountability, and oversight. The digital divide and low data literacy therefore function as privacy variables rather than as background context.
What this means for practice
- Instructors. Treat consent and transparency as teaching problems, not only administrative ones: students report limited awareness of data protection laws, and opaque privacy policies reduce their readiness to engage.
- Instructors and curriculum designers. Build privacy and data-literacy content into existing courses, since limited understanding of data practices constrains how students use AI.
- Administrators. Pair AI deployment with visible accountability — clear data-governance policies, informed-consent procedures, and a way for students to access, correct, or delete data held by AI platforms.
- Policymakers and institutions. Address cross-border data flows when adopting external Learning Analytics or AI providers, and fund continuous privacy training for staff.
Limitations
- No formal inter-coder reliability statistics were applied; rigor rested on documented coding decisions, so the thematic structure is interpretive rather than replicable.
- The search covered only ERIC and PubMed, limiting coverage of the wider literature on AI and privacy in African higher education.
- The synthesis covers 18 studies concentrated on a small set of countries and generated no new primary data, so findings report perceptions rather than measured effects.
Connected Concepts
Connected Articles
- Understanding ethical dimensions of AI in higher education: insights from faculty members and students — Understanding ethical dimensions of AI in higher education
- Artificial intelligence ethical awareness of university students in Ghana: A network and latent profile analyses — Artificial intelligence ethical awareness of university students in Ghana
- Policy Fragmentation or Institutional Alignment? Institutional Governance of AI in Universities and Business Schools — Policy fragmentation or institutional alignment in university AI governance
- Anticipatory governance and leadership for AI implementation in higher education: A scoping review — Anticipatory governance and leadership for AI implementation in higher education
- Artificial Intelligence in UK Higher Educational Policy and Institutional Decision Making — Artificial intelligence in UK higher education policy and institutional decision making
Citation
Duncan, E. (2026). Rethinking data privacy for AI adoption in African higher education: A meta-synthesis of stakeholder perceptions and policy implications. Computers and Education Open, 11, 100408.