
In mid-September 2026, a part-time tutor for a course at The Chinese University of Hong Kong notified students via a teaching assistant’s email that, starting from the next class, attendance would be recorded by scanning a QR code through WeChat, with mobile location services required to be enabled. The system would only accept check-ins from within designated classroom areas (including the CUHK Faculty of Law, Library Road, or Lee Shau Kee Building); otherwise, the attendance would be deemed invalid. The email also included a test QR code, instructing students to install WeChat and enable location services in advance, while prohibiting the sharing or forwarding of the QR code.
Students promptly shared the email on social media platforms, questioning whether the use of a third-party application for location tracking constituted an invasion of privacy, and noting that the university already provided official attendance systems. The incident quickly sparked discussion.
University Response
CUHK later clarified that the arrangement was initiated independently by a part-time tutor for an individual class, requiring students to use a non-official system to record attendance, and was not an official university measure. Upon learning of the matter, the relevant department immediately reminded the tutor to switch to the university’s official systems.
The university emphasised that it places great importance on information security and has long maintained internal systems for staff to record student attendance, including uReply Attendance and the CUHK Registration and Attendance System (RAS).
Issues Raised by the Incident
- Privacy and Data Security Risks, and the Non-Mainstream Nature of the Tool
Requiring students to install WeChat and mandatorily enable location services involves the collection of location data. WeChat is operated by Tencent, and the data may be processed across borders. More importantly, WeChat is not a mainstream or essential communication app in Hong Kong—many local students primarily use WhatsApp, Signal, or other tools. Forcing the installation and activation of location services amounts to imposing an unnecessary third-party platform on everyone. This practice sits in tension with the spirit of Hong Kong’s Personal Data (Privacy) Ordinance, as well as the university’s IT guidelines (which generally advise against using social platforms such as WeChat to collect personal data). Even if used solely for attendance purposes, it raises concerns about how the data is stored, who can access it, and whether it might be used for other purposes. - Disconnect Between Official Systems and Frontline Practice
Despite CUHK already having multiple internal attendance systems, a part-time tutor still independently introduced a non-official tool. This reflects insufficient training, monitoring, or enforcement of guidelines. Given the higher turnover of part-time tutors, without clear policies and timely review mechanisms, similar “independent arrangements” can easily recur. - Imbalance of Trust and Integrity: The Fundamental Problem of the Attendance System
The incident exposes a more fundamental tension: teachers should prioritise trust, while students should check in with integrity. If a teacher has doubts about specific students, they should investigate those cases targeted rather than exercising authority to force all students to use WeChat location-based check-in. Problems such as class-skipping, proxy sign-ins, and remote check-ins have long existed, but the solution should not be placing everyone under surveillance. If paper-based attendance similarly lacks on-the-spot verification, neither WeChat nor official systems can truly confirm whether a student is physically present in the classroom. Attendance risks becoming a formality rather than a genuine verification of learning participation, undermining the system’s credibility and eroding the trust that should exist between teachers and students, thereby affecting the campus atmosphere. Against the backdrop of high societal sensitivity in Hong Kong toward data security, mandating a non-mainstream tool is more easily interpreted as unnecessary monitoring and deepens students’ doubts about whether the university genuinely prioritises privacy.
Directions for Improvement
- Strengthen the Accessibility, Convenience, and Privacy Safeguards of Official Attendance Systems
Continuously optimise uReply Attendance, RAS, and the CU Link card sensing system to ensure simple interfaces, support for large classes, and real-time report generation. Require all teaching staff (including part-time tutors) to prioritise official tools, and provide operational training and technical support. In particular, uReply should explicitly incorporate comprehensive data privacy terms, clearly stating the scope of data collected, purposes of use, retention periods, access rights, and destruction mechanisms, so that staff and students know exactly how their data is handled. - Consider Open-Source Approaches to Developing or Improving Attendance Tools to Increase Trust and Security
Open-source software makes its source code publicly available, allowing anyone to audit its operational logic, data flows, and security vulnerabilities. This directly enhances transparency: students and staff need not blindly trust a closed-source black box, but can verify that the system truly performs only attendance functions, without secretly collecting extra data or transmitting it externally. Open source also facilitates independent security audits; the community can detect and fix issues early, thereby reducing the risk of misuse or hidden backdoors. The university could consider partially open-sourcing existing systems or collaborating with the open-source community to develop lightweight attendance tools that comply with local privacy requirements, further building trust in the system among teachers and students. - Establish Clear Guidelines on the Use of Third-Party Tools
Explicitly prohibit or strictly limit the use of non-official applications (especially those involving location or personal data) for attendance. If exceptions are needed in special circumstances, prior approval from the department and IT division should be required, along with full disclosure to students of the reasons, data-handling practices, and opt-out mechanisms. - Enhance Management and Compliance Training for Part-Time Tutors
Mandate completion of an online privacy and information security course upon onboarding; conduct regular departmental checks on attendance methods; and establish a rapid complaint and intervention mechanism allowing students to report non-compliant arrangements anonymously. At the same time, emphasise the principle of “trust first”—if doubts arise about individual students, investigate rather than imposing a one-size-fits-all mandate on the entire class. - Re-examine the Purpose of the Attendance System
Consider whether attendance genuinely serves learning objectives. Alternatives such as combining classroom interaction, group discussions, or short assignments could be used to assess participation, reducing reliance on mere “check-ins.” If attendance must be taken, verification mechanisms should be reliable (e.g., combining student card sensing with random checks) and grounded in integrity rather than surveillance. - Improve Transparency and Communication
The university should proactively publish the handling outcomes of the incident and subsequent measures, and regularly explain privacy policies and the advantages of official systems to staff and students to rebuild trust. Student representatives should also be invited to participate in reviews of related guidelines.
Although this incident was an isolated case, it highlights the challenge universities face in the digital age of balancing “administrative efficiency” with “respect for privacy.” Only by refining official systems (including the addition of clear privacy terms), considering open source to increase transparency, and truly embedding “trust and integrity” can similar controversies be avoided in the future.
Open Platform Society also responded to the CUHK WeChat check-in incident with the principles of “Privacy First, Open Source By Design“.