Parents Bill of Rights for Data Privacy and Security
Pursuant to Education Law section 2-d, BOCES and school districts are now required to publish, on their websites, a parents bill of rights for data privacy and security and to include such information with every contract entered into with a third party contractor where the third party contractor receives student data or teacher or principal data. The following is the New York Mills Union Free School District’s bill of rights for data privacy and security:
A student’s personally identifiable information (PII) cannot be sold or released by the New York Mills Union Free School for any commercial or marketing purposes.
Parents have the right to inspect and review the complete contents of their child's education record including any student data stored or maintained by the New York Mills Union Free School. This right of inspection is consistent with the requirements of the Family Educational Rights and Privacy Act (FERPA). In addition to the right of inspection of the educational record, Education Law §2-d provides a specific right for parents to inspect or receive copies of any data in the student’s educational record. The New York State Department of Education (NYSED) will develop policies and procedures pertaining to this right.
State and federal laws protect the confidentiality of PII, and safeguards associated with industry standards and best practices, including, but not limited to, encryption, firewalls, and password protection, must be in place when data is stored or transferred.
A complete list of all student data elements collected by the State is available for public review at http://www.p12.nysed.gov/irs/sirs/documentation/NYSEDstudentData.xlsx, or you may obtain a copy of this list by writing to the Office of Information & Reporting Services, New York State Education Department, Room 863 EBA, 89 Washington Avenue, Albany, NY 12234.
Parents have the right to file complaints with the New York Mills Union Free School about possible privacy breaches of student data by the New York Mills Union Free School’s third party contractors or their employees, officers, or assignees, or with NYSED. Complaints regarding student data breaches should be directed to Kathy Houghton, Superintendent, New York Mills Union Free School, 1 Marauder Blvd., New York Mills NY 13417. Phone: (315) 768-8127. Email: firstname.lastname@example.org. Complaints to NYSED should be directed in writing to the Chief Privacy Officer, New York State Education Department, 89 Washington Avenue, Albany NY 12234, email to CPO@mail.nysed.gov. The complaint process is under development and will be established through regulations to be proposed by NYSED’s Chief Privacy Officer, who has not yet been appointed.
For purposes of further ensuring confidentiality and security of student data — as well as the security of personally-identifiable teacher or principal data — the Parents’ Bill of Rights (above) and the following supplemental information must be included in each contract that a school district or BOCES enters into with a third-party contractor with access to this information:
the exclusive purposes for which the student data, or teacher or principal data, will be used;
how the third party contractor will ensure that the subcontractors, persons or entities that the third party contractor will share the student data or teacher or principal data with, if any, will abide by data protection and security requirements;
when the agreement with the third party contractor expires and what happens to the student data or teacher or principal data upon expiration of the agreement;
if and how a parent, student, eligible student, teacher or principal may challenge the accuracy of the student data or teacher or principal data that is collected; and
where the student data or teacher or principal data will be stored (described in such a manner as to protect data security), and the security protections taken to ensure such data will be protected, including whether such data will be encrypted.
In addition, the Chief Privacy Officer (when appointed), with input from parents and other education and expert stakeholders, is required to develop additional elements of the Parents’ Bill of Rights to be prescribed in the Regulations of the Commissioner. Accordingly, this Bill of Rights will be revised from time to time in accordance with further guidance received from the Chief Privacy Officer, the Commissioner of Education and NYSED.