Authors :
Kavunga Tembo Joseph; Ali Najib; Anthony Bua; David Kakeeto
Volume/Issue :
Volume 11 - 2026, Issue 7 - July
Google Scholar :
https://tinyurl.com/4shnaxs5
Scribd :
https://tinyurl.com/33wesnr5
DOI :
https://doi.org/10.38124/ijisrt/26jul1810
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
Educational institutions increasingly rely on e-learning platforms that store large volumes of sensitive student and
staff data, yet many of these platforms continue to lack robust technical safeguards and effective privacy-compliance
mechanisms. This study designed and proposed an encryption-based security framework to enhance data privacy and
support compliance with Uganda's Data Protection and Privacy Act (DPPA) 2019 in higher education the e-learning system
in Uganda, guided by three objectives: assessing the current state of data privacy and DPPA 2019 compliance; establishing
the effectiveness of a proposed encryption-based security framework in enhancing confidentiality, integrity, and access
control; and determining the degree to which the framework would facilitate regulatory compliance. The study adopted a
mixed-methods design combining a quantitative correlational survey and a qualitative case study. A structured
questionnaire was self-administered to 120 , and semi-structured interviews were conducted with four key informants from
the ICT department. Quantitative data were analysed SPSS using, descriptive statistics, Pearson correlation, and
Cronbach's alpha reliability testing; interview data were analysed thematically using Braun and Clarke's six-phase reflexive
thematic analysis. The study was theoretically grounded in the Protection Motivation Theory, the CIA Triad, and the NIST
Cybersecurity Framework. The study findings revealed moderate data-privacy awareness coupled with high breach anxiety:
concern about data breaches and unauthorized use exceeded respondents' confidence in existing protections, while
knowledge of who accesses their data of breach-reporting procedures remained low. All inter-objective correlations were
statistically significant, with the strongest relationship observed between framework effectiveness and compliance.
Reliability across the three objective scales ranged from acceptable. Interviews with ICT staff confirmed that encryption is
present but technically opaque, that access controls are undermined by voluntary credential sharing, and that consent is
reduced to a click-through formality. Notably, 80.8% of respondents indicated they would increase their e-learning
engagement if given greater control over their data. The study concludes that Uganda’s higher education data privacy
challenges are fundamentally socio-technical, requiring simultaneous technical reinforcement and human-centred
governance. It proposes and recommends the urgent deployment of a six-layer encryption-based security framework
comprising data collection and consent, data-at-rest and in-transit encryption (AES-256-GCM, TLS 1.3), role-based access
control and multi-factor authentication, integrity and audit logging, compliance and governance, and a user-empowerment
dashboard, phased over 36 months and anchored in mandatory data-privacy training and a DPPA 2019-aligned institutional
policy.
Keywords :
Encryption, Data Privacy, E-Learning Security, Data Protection Compliance, Uganda DPPA 2019, Access Control, Protection Motivation Theory, Higher Education Cybersecurity.
References :
- Agbeko, K., A., E., & O.-D., K. (2022). Data privacy awareness among university students in sub-Saharan Africa: An empirical investigation. Journal of African Information Systems.
- Ali, R., & Zafar, H. (2017). A security and privacy framework for e-learning. International Journal for E-Learning Security, 7(2), 556-566.
- Alier, M., Guerrero, M. J. C., Amo, D., Severance, C., & Fonseca, D. (2021). Privacy and e-learning: A pending task. Sustainability, 13(16), 9206.
- Alkalbani, A., Deng, H., & Kam, B. (2016). Investigating the role of socio-organizational factors in the information security compliance in organizations.
- Bacharach, S. B. (1989). Organizational theories: Some criteria for evaluation. The Academy of Management Review, 14(4), 496.
- Blazevic, A. N., Mugalula, P., & Wandera, A. (2021). Towards operationalizing the Data Protection and Privacy Act 2020: Understanding the draft data protection and privacy regulations, 2020. SSRN Electronic Journal.
- Bygrave, L. A. (2014). Data privacy law. Oxford University Press.
- Davis, F. D. (1989). Perceived usefulness, perceived ease of use, and user acceptance of information technology. MIS Quarterly, 13(3), 319-340.
- Dinev, T., & Hart, P. (2006). An extended privacy calculus model for e-commerce transactions. Information Systems Research, 17(1), 61-80.
- El-Sofany, H., El-Seoud, S., Karam, O., Bouallegue, B., & Ahmed, A. (2024). A proposed secure framework for protecting cloud-based educational systems from hacking. Egyptian Informatics Journal.
- Grassi, P. A., Garcia, M. E., & Fenton, J. L. (2017). Digital identity guidelines: Revision 3. National Institute of Standards and Technology.
- Greenleaf, G. (2021). Global data privacy laws 2021: Despite COVID delays, 145 laws show GDPR dominance. SSRN Electronic Journal.
- Mihailescu, M., Nita, S., & Pau, V. (2020). E-learning system framework using elliptic curve cryptography and searchable encryption. eLearning and Software for Education.
- Moore, J. L., Dickson-Deane, C., & Galyen, K. (2011). e-Learning, online learning, and distance learning environments: Are they the same? The Internet and Higher Education, 14(2), 129-135.
- Mou, J., Cohen, J., Bhattacherjee, A., & Kim, J. (2022). A test of protection motivation theory in the information security literature: A meta-analytic structural equation modeling approach. Journal of the Association for Information Systems, 23(6).
- Mtebe, J. S., & Raisamo, R. (2014). Investigating students' behavioural intention to adopt and use mobile learning in higher education in East Africa. International Journal of Education and Development Using ICT, 10, 4-20.
- Muhiddinov, M. (2025). Privacy-aware information security for e-learning platforms in history using attribute-based encryption algorithm. Journal of Internet Services and Information Security, 15, 305-315.
- Mumford, E. (2006). The story of socio-technical design: Reflections on its successes, failures and potential. Information Systems Journal, 16(4), 317-342.
- NIST. (2024). The NIST Cybersecurity Framework (CSF) 2.0. National Institute of Standards and Technology.
- Prinsloo, P., & Kaliisa, R. (2022). Data privacy on the African continent: Opportunities, challenges and implications for learning analytics. British Journal of Educational Technology, 53(4), 894-913.
- Rogers, R. W. (1975). A protection motivation theory of fear appeals and attitude change. The Journal of Psychology, 91(1), 93-114.
- Shadmanova, S., et al. (2024). Ensuring the security of an internet-based e-learning system through the use of integrated encryption methods. Journal of Internet Services and Information Security, 14, 389-400.
- Smith, H. J., Milberg, S. J., & Burke, S. J. (1996). Information privacy: Measuring individuals' concerns about organizational practices. MIS Quarterly, 20(2), 167-196.
- Stallings, W. (2017). Cryptography and network security: Principles and practice. Pearson.
- Ubaka-Okoye, M. (2020). Blockchain framework for securing e-learning system. International Journal of Advanced Trends in Computer Science and Engineering.
Educational institutions increasingly rely on e-learning platforms that store large volumes of sensitive student and
staff data, yet many of these platforms continue to lack robust technical safeguards and effective privacy-compliance
mechanisms. This study designed and proposed an encryption-based security framework to enhance data privacy and
support compliance with Uganda's Data Protection and Privacy Act (DPPA) 2019 in higher education the e-learning system
in Uganda, guided by three objectives: assessing the current state of data privacy and DPPA 2019 compliance; establishing
the effectiveness of a proposed encryption-based security framework in enhancing confidentiality, integrity, and access
control; and determining the degree to which the framework would facilitate regulatory compliance. The study adopted a
mixed-methods design combining a quantitative correlational survey and a qualitative case study. A structured
questionnaire was self-administered to 120 , and semi-structured interviews were conducted with four key informants from
the ICT department. Quantitative data were analysed SPSS using, descriptive statistics, Pearson correlation, and
Cronbach's alpha reliability testing; interview data were analysed thematically using Braun and Clarke's six-phase reflexive
thematic analysis. The study was theoretically grounded in the Protection Motivation Theory, the CIA Triad, and the NIST
Cybersecurity Framework. The study findings revealed moderate data-privacy awareness coupled with high breach anxiety:
concern about data breaches and unauthorized use exceeded respondents' confidence in existing protections, while
knowledge of who accesses their data of breach-reporting procedures remained low. All inter-objective correlations were
statistically significant, with the strongest relationship observed between framework effectiveness and compliance.
Reliability across the three objective scales ranged from acceptable. Interviews with ICT staff confirmed that encryption is
present but technically opaque, that access controls are undermined by voluntary credential sharing, and that consent is
reduced to a click-through formality. Notably, 80.8% of respondents indicated they would increase their e-learning
engagement if given greater control over their data. The study concludes that Uganda’s higher education data privacy
challenges are fundamentally socio-technical, requiring simultaneous technical reinforcement and human-centred
governance. It proposes and recommends the urgent deployment of a six-layer encryption-based security framework
comprising data collection and consent, data-at-rest and in-transit encryption (AES-256-GCM, TLS 1.3), role-based access
control and multi-factor authentication, integrity and audit logging, compliance and governance, and a user-empowerment
dashboard, phased over 36 months and anchored in mandatory data-privacy training and a DPPA 2019-aligned institutional
policy.
Keywords :
Encryption, Data Privacy, E-Learning Security, Data Protection Compliance, Uganda DPPA 2019, Access Control, Protection Motivation Theory, Higher Education Cybersecurity.