ED Law 2D
The New York State Education Law 2-D pertains to the unauthorized release of personally identifiable information. To read the full legislation, please visit the New York State Senate website.
In January 2020, the Board of Regents adopted Part 121 of the Regulations of the Commissioner of Education, which provides guidance to educational agencies and their third-party contractors on ways to strengthen data privacy and security to protect student data and annual professional performance review data.
Data Privacy and Security Policies and Resources
- Parents' Bill of Rights
- Information and Data Privacy, Security, Breach and Notification
- Computer Use in Instruction/Acceptable Use Policy
- Computer Resources and Data Management
- Internet Safety Policy
- Military Recruiters' Access to Secondary School Students and Information on Students
- District Approved Software List
- Federal Laws that Protect Students
- Student Privacy
- Parent Resources
- District Approved Third Party Contractors
- Annual Data Privacy & Security Training
Parents' Bill of Rights
Parents' Bill of Rights for Data Privacy and Security
The Kingston City School District is committed to protecting the privacy and security of each student's personally identifiable information in educational records from unauthorized parties in accordance with State and Federal law. Parents should be aware of the following rights they have concerning their child's data:
- A student's personally identifiable information cannot be sold or released for any commercial purposes.
- Parents have the right to inspect and review the complete contents of their child's education record.
- The confidentiality of a student's personally identifiable information is protected by existing state and federal laws, and safeguards such as encryption, firewalls, and password protection, must be in place when data is stored or transferred. Third party contractors are required to employ technology, safeguards and practices that align with the National Institute of Standards and Technology Cybersecurity Framework.
- A complete list of all student data elements collected by the State Education Department is available for public review at: Student Data Inventory | New York State Education Department (nysed.gov) or by writing to the Office of Information & Reporting Services, New York State Education Department, Room 863 EBA, 89 Washington Avenue, Albany, NY 12234.
- Parents have the right to file complaints about possible breaches of student data. Parents may submit a complaint regarding a potential breach by the District Data Protection Officer: Dr. Alissa Oliveto, 845.943.3018, Email: aoliveto, 21 Wynkoop Place, Kingston, NY 12401. The School District shall promptly acknowledge any complaints received and commence an investigation into the complaint, while taking the necessary precautions to protect personally identifiable information. The School District shall provide a response detailing its findings from the investigation no more than sixty (60) days after receipt of the complaint. Complaints pertaining to the State Education Department or one of its third-party vendors should be directed in writing to the Chief Privacy Officer, New York State Education Department, 89 Washington Avenue, Albany, NY 12234, or email to privacy@nysed.gov.
- In the event of a data breach or unauthorized disclosure of students' personally identifiable information, third party contractors are required by law to notify the School District within seven (7) days of discovery of the breach or unauthorized disclosure.
- If the District enters into a contract with a third party in which student, teacher, or principal data is shared with a third party, supplemental information for each such contract will be appended to this Parents' Bill of Rights.
- Parents may access the State Education Department's Parents' Bill of Rights at: EDUCATION LAW §2-D BILL OF RIGHTS FOR DATA PRIVACY AND SECURITY (nysed.gov)
Information and Data Privacy, Security, Breach and Notification
The Board of Education acknowledges the heightened concern regarding the rise in identity theft and the need for secure networks and prompt notification when security breaches occur. The Board adopts the National Institute for Standards and Technology Cybersecurity Framework Version 1.1 (NIST CSF) for data security and protection. The Data Protection Officer is responsible for ensuring the District's systems follow NIST CSF and adopting technologies, safeguards, and practices which align with it. This will include an assessment of the District's current cybersecurity state, their target future cybersecurity state, opportunities for improvement, progress toward the target state, and communication about cyber security risk.
The Board will designate a Data Protection Officer to be responsible for the implementation of the policies and procedures required in Education Law §2-d and its accompanying regulations, and to serve as the point of contact for data security and privacy in the District. This appointment will be made at the annual organizational meeting.
See the full BOE policy for Information and Data Privacy, Security, Breach and Notification (8635)
Computer Use in Instruction/Acceptable Use Policy
The Board of Education is committed to optimizing student learning and teaching. The Board considers student access to a computer network, including the Internet, to be a powerful and valuable educational and research tool, and encourages the use of computers and computer-related technology solely for the purpose of advancing and promoting learning and teaching.
The computer network can provide a forum for learning through the use of district approved software applications and online databases, bulletin boards and electronic mail, can significantly enhance educational experiences and provide statewide, national and global communication opportunities for staff and students.
All users of the district's computer network and the Internet must understand that use is a privilege, not a right, and that use entails responsibility.
The Superintendent of Schools will establish regulations governing the use and security of the district's computer network. All users of the district's computer network and equipment will comply with this policy and those regulations. Failure to comply may result in disciplinary action as well as suspension and/or revocation of computer access privileges.
The Superintendent or their designee, working in conjunction with appropriate district staff, will be responsible for the purchase and distribution of computer software and hardware throughout district schools. They will prepare and submit for the Board's approval a comprehensive multi-year technology plan which shall be revised as necessary to reflect changing technology and/or district needs.
Adoption of Updated Policy: December 16, 2025
See the full BOE policy for Computer Use in Instruction/Acceptable Use (4526)
Computer Resources and Data Management
The Board of Education recognizes that computers are a powerful and valuable education and research tool and as such are an important part of the instructional program. In addition, the district depends upon computers as an integral part of administering and managing the schools' resources, including the compilation of data and record keeping for personnel, students, finances, supplies and materials. This policy outlines the Board's expectations in regard to these different aspects of the district's computer resources.
General Provisions
The Superintendent will be responsible for designating a computer network coordinator who will oversee the use of district computer resources. District staff will be appointed to oversee the development of a curriculum map that infuses technology into the curriculum, prepare in-service programs for the training and development of other district staff in computer skills, appropriate use of computers and the incorporation of computer use in subject areas.
The Superintendent, or their designee, working in conjunction with appropriate district staff will be responsible for the purchase and distribution of computer software and hardware throughout the schools. They will prepare and submit for the Board's approval a comprehensive multi-year technology plan which will be revised as necessary to reflect changing technology and/or district needs.
The Superintendent, or their designee, will establish regulations governing the use and security of the district's computer resources. The security and integrity of the district computer network and data is a serious concern to the Board, and the district will make every reasonable effort to maintain the security of the system. All users of the district's computer resources will comply with this policy and regulation, as well as the district's policy on internet safety. Failure to comply may result in disciplinary action, as well as suspension and/or revocation of computer access privileges.
All users of the district's computer resources must understand that use is a privilege, not a right, and that use entails responsibility. Users of the district's computer network must not expect, nor does the district guarantee, privacy for electronic mail (e-mail) or any use of the district's computer network. The district reserves the right to access and view any material stored on district equipment or any material used in conjunction with the district's computer network.
Use of the district's computer network and digital resources is a privilege—not a right—for students. All student users must follow this policy, its accompanying regulations, general network etiquette, and the district's Acceptable Use Policy.
Responsible use of technology is an important part of being a member of the school community. Violations of this policy may result in disciplinary action, including temporary or permanent loss of computer access privileges, as well as other consequences as outlined in the student code of conduct.
Access to the district's computer systems, network, and digital resources is a required component of employment and professional responsibilities. All staff members are expected to use these systems in accordance with the district's Acceptable Use Policy, related regulations, and established standards of conduct.
Misuse or failure to comply with these policies may result in disciplinary action, up to and including termination of employment, depending on the severity and nature of the violation.
Management of Computer Records
The Board recognizes that since district data is maintained in computer systems, it is critical to exercise appropriate control over computer records, including financial, personnel and student information. The Superintendent, working with the Coordinator of Network & Technology and other appropriate staff, will establish procedures governing management of computer records. The procedures will address:
- Passwords
- System administration
- Separation of duties
- Remote access
- Data back-up (including archiving of e-mail)
- Record retention
- Disaster recovery plans
Review and Dissemination
Since computer technology is a rapidly changing area, it is important that this policy be reviewed periodically by the Board and the district's external auditor. The regulation governing appropriate computer use will be distributed annually to staff and students and will be included in both employee and student handbooks.
Adoption of Updated Policy: December 16, 2025
See the full BOE policy for Computer Resources and Data Management (8630)
Internet Safety Policy
The Board of Education is committed to undertaking efforts that serve to make safe for children the use of district computers for access to the Internet and World Wide Web. To this end, although unable to guarantee that any selected filtering and blocking technology will work perfectly, the Board directs the Superintendent of Schools to procure and implement the use of technology protection measures that block or filter Internet access by:
- adults to visual depictions that are obscene or child pornography, and
- minors to visual depictions that are obscene, child pornography, or harmful to minors, as defined in the Children's Internet Protection Act.
Subject to staff supervision, however, any such measures may be disabled or relaxed for adults conducting bona fide research or other lawful purposes, in accordance with criteria established by the Superintendent or his or her designee.
The Superintendent or their designee also will develop and implement procedures that provide for the safety and security of students using electronic mail, chat rooms, and other forms of direct electronic communications; monitoring the online activities of students using district computers; and restricting student access to materials that are harmful to minors.
In addition, the Board prohibits the unauthorized disclosure, use and dissemination of personal information regarding students; unauthorized online access by students, including hacking and other unlawful activities; and access by students to inappropriate matter on the Internet and World Wide Web. The Superintendent or their designee will establish and implement procedures that enforce these restrictions.
The Coordinator of Network & Technology (Coordinator), designated under the district's Computer Use in Instruction/Acceptable Use Policy, will monitor and examine all district computer network activities to ensure compliance with this policy and accompanying regulation. In addition, the Coordinator and Assistant Superintendent for Human Resources and Public Relations will be responsible for ensuring that staff and students receive training on their requirements.
All users of the district's computer network must understand that use is a privilege, not a right, and that any such use entails responsibility. They must comply with the requirements of this policy and accompanying regulation, in addition to generally accepted rules of network etiquette, and the district's Computer Use in Instruction/Acceptable Use Policy. Failure to comply may result in disciplinary action including, but not limited to, the revocation of computer access privileges.
Adoption of Updated Policy: December 16, 2025
See the full BOE policy for Internet Safety Policy (4526.1)
Military Recruiters' Access to Secondary School Students and Information on Students
In compliance with the Elementary and Secondary Education Act of 1965, as amended by the No Child Left Behind Act of 2001 (NCLB); and the National Defense Authorization Act, and in accordance with the Family Educational Rights and Privacy Act (FERPA), the School District shall comply with a request by a military recruiter for secondary students' names, addresses, and telephone listings, unless the student or his/her parent/guardian has "opted out" of providing such information.
Further, in compliance with the NCLB, the District shall give military recruiters the same access and no additional access to secondary school students as they provide to postsecondary institutions or to prospective employers. The Superintendent will develop regulations which define access, and monitor the frequency of access, by military recruiters, postsecondary institutions, and prospective employers.
Under FERPA, the School District must provide notice to parents and students of the types of student information that it releases publicly. This type of information, commonly referred to as "directory information," which is released by the District includes — but is not limited to — such items as students' names, addresses, and telephone listings. The notice must include an explanation of parent and student rights to request that the information not be disclosed without prior written consent; and further requires that parents and students be notified that the School District routinely discloses students' names, addresses, and telephone listings to military recruiters upon request, subject to a parent or student request not to disclose such information without written consent.
A single notice provided through a mailing, student handbook, or other method that is reasonably calculated to inform parents and students of the above information is sufficient to satisfy the notification requirements of both FERPA and the NCLB. The notification shall advise the parent and student of how to opt out of the public, nonconsensual disclosure of directory information and the method and timeline within which to do so.
If a parent or student opts out of providing directory information (or any subset of such information) to third parties, the opt-out request must apply to military recruiters as well. For example, if the opt-out states that telephone numbers will not be disclosed to the public, the District may not disclose telephone numbers to military recruiters.
The Superintendent/designee shall ensure that appropriate notification is provided to parents and students informing them of their right to opt-out of the release of designated directory information without prior written consent.
- Elementary and Secondary Education Act of 1965, Section 9528
- 20 United States Code (USC) Section 7908, as amended by the No Child Left Behind Act of 2001
- National Defense Authorization Act Section 544
- 10 United States Code (USC) Section 503
- Family Educational Rights and Privacy Act of 1974
- 20 United States Code (USC) Section 1232(g)
- 34 Code of Federal Regulations (CFR) Section 300.571
- Education Law Section 2-a
- 8 New York Code of Rules and Regulations (NYCRR) Section 3.33
District Approved Software List
District Approved Software List
Report an Improper Disclosure
If a parent/guardian, eligible student, classroom teacher, building principal or other District employee believes or has evidence that student or classroom teacher/building principal PII has been breached or released without authorization, they must submit a complaint in writing to the District.
Complaints shall generally be received by the Data Protection Officer, Dr. Alissa Oliveto, 845.943.3018, Email: aoliveto. If a complaint is received by another District employee, such employee must immediately notify the Data Protection Officer.
This complaint process will be communicated to parents, eligible students, classroom teachers, building principals, and other District employees. The District will promptly acknowledge receipt of written complaints, commence an investigation, and take the necessary precautions to protect PII. Following its investigation of the complaint, the District will provide the complainant with its findings within a reasonable period of time, generally no more than 60 calendar days from the date of receipt of the complaint. If the District requires additional time, or if the response may compromise security or impede a law enforcement investigation, the District will provide the individual who filed a complaint with a written explanation that includes the approximate date when the District will respond to the complaint.
The District will maintain a record of all complaints of breaches or unauthorized releases of student data and their disposition in accordance with applicable data retention policies, including the Retention and Disposition Schedule for New York Local Government Records (LGS-1). More details can be found in Policy 8635.
Federal Laws that Protect Students
Laws such as FERPA, PPRA, and COPPA were created to protect student data. Learn more.
Student Privacy
More information on Student Privacy
The Board recognizes its responsibility under the federal Protection of Pupil Privacy Rights Act (PPRA) to enact policies that protect student privacy, in accordance with law. This is particularly relevant in the context of the administration of surveys that collect personal information, the disclosure of personal information for marketing purposes and in conducting physical exams.
I. Student Surveys
The Board of Education recognizes that student surveys are a valuable tool in determining student needs for educational services. In accordance with law and Board policy, consent of person in parental relation is required before requiring minors to take part in surveys which gather any of the following information:
- political affiliations or beliefs of the student or the student's person in parental relation;
- mental or psychological problems of the student or the student's family;
- sex behavior or attitudes;
- illegal, anti-social, self-incriminating or demeaning behavior;
- critical appraisals of other individuals with whom respondents have close family relationships;
- legally recognized privileged or analogous relationships, such as those of lawyers, physicians and ministers;
- religious practices, affiliations or beliefs of the student or the student's family; or
- income (other than that required by law to determine eligibility for participation in a program or for receiving financial assistance under such program).
In the event that the district plans to survey students to gather information included in the list above, the district will obtain written consent from the parent/guardian in advance of administering the survey. The notification/consent form will also apprise the person in parental relation of their right to inspect the survey prior to their child's participation. In addition, the district will notify parents/guardians that they may inspect any survey created by a third party before the survey is administered or distributed to students. Prior written consent and the right to inspect surveys transfers to students once they turn 18 years old or are emancipated.
U.S. Department of Education Funded Surveys. The district will make instructional materials available for inspection by person(s) in parental relation(s) if the materials will be used in connection with a U.S. Department of Education funded survey, analysis or evaluation in which their children participate and it addresses one or more of the above items. In addition, the district will obtain prior written person(s) in parental relation(s) consent before minor students are required to participate in any such survey, analysis or evaluation.
Surveys Funded by Other Sources. The person(s) in parental relation(s) has a right to inspect, upon request, a survey created by a third party (other than the U.S. Department of Education) which addresses one or more of the above items before the survey is administered or distributed by the school to the student. Such request must be submitted by the person(s) in parental relation(s) to the Building Principal at least 10 days prior to the administration or distribution of any survey.
The district will limit access to information collected by any survey that contains the items listed above to those school officials who have a legitimate educational interest. The terms "school official" and "legitimate educational interest" are defined in district policy 5500, Student Records.
All disclosure or use of student personal information will be protected by the district pursuant to the requirements of the Family Educational Rights and Privacy Act (FERPA), Individuals with Disabilities Education Act (IDEA), Protection of Pupil Rights Amendment (PPRA), the National School Lunch Act, Children's Online Privacy Protection Act (COPPA), and NY Education Law §2-d [For guidance regarding the disclosure of student information, see policies 5500, Student Records, and 8635, Information and Data Privacy, Security, Breach and Notification].
II. Instructional Materials
Person(s) in parental relation(s) will be granted, upon request, reasonable access and the right to inspect instructional materials used as part of the educational curriculum for the student within a reasonable period of time after such request is received by the district. Requests will be submitted by the person(s) in parental relation(s), in writing, to the Building Principal. "Instructional material" is defined as: "instructional content that is provided to a student, regardless of format including printed or representational materials, audio-visual materials, and materials in electronic or digital formats (such as materials accessible through the Internet). It does not include academic tests or academic assessments." The right to inspect instructional materials transfers to students once they turn 18 years old or are emancipated.
III. Physical Examinations or Screenings
Prior to the administration of any non-emergency, invasive physical examination or screening that is required as a condition of attendance, administered by the school and scheduled by the school in advance, which are not necessary to protect the immediate health or safety of the student or other students, a student's person in parental relation will be notified and given an opportunity to opt their child out of the exam.
IV. Collection, Disclosure or Use of Personal Information
Unless required or authorized by federal or state law and/or regulation, it is the policy of the Board to not permit the collection, disclosure or use of personal information collected from students for the purpose of marketing or selling that information or otherwise providing that information for that purpose, unless otherwise exempted pursuant to law. "Personal Information" is defined as information that would allow a reasonable person in the school or community, who does not have personal knowledge of the relevant circumstances, to identify the student with reasonable certainty. Such data might include social security number, student's name or identification number, parents' name and/or address, a biometric record, etc.
This provision will not apply to the collection, disclosure, or use of personal information collected from students for the exclusive purpose of developing, evaluating or providing educational products or services for, or to, students or educational institutions, such as:
- College or other postsecondary education recruitment, or military recruitment;
- Book clubs, magazines and programs providing access to low-cost literary products;
- Curriculum and instructional materials used in schools;
- Tests and assessments used to provide cognitive, evaluative, diagnostic, clinical, aptitude, or achievement information for students or to generate other statistically useful data for the purpose of securing such tests and assessments, and the subsequent analysis and public release of the aggregate data from such tests and assessments;
- The sale by students of products or services to raise funds for school-related activities;
- Student recognition programs.
V. Notification to Parents
The district will notify parents/guardians and students who are at least 18 years old or who are emancipated at least annually, at the beginning of the school year, and when enrolling students for the first time in district schools, of their rights under this policy. The school district will also notify parents/guardians within a reasonable period of time after any substantive change to this policy.
Adoption: June 18, 2024
See the full BOE policy for Student Privacy (5550)
Parent Resources
Strengthening Student Data Privacy
Personally Identifiable Information (PII) is information that can be used to identify an individual whether directly (e.g. student's name; names of parents or family members; address of the student or student's family; personal identifiers like social security numbers) or indirectly when linked with other information.
Common Sense
Common Sense is a trusted resource for millions of families in the digital age—at home, in schools, and beyond. They draw on original research, industry expertise, and community support to advocate for legislation and policies that help all kids thrive.
NYSED Parent and Student Resources
This page provides a parent fact sheet, frequently asked questions, information about complaints of breaches, and the Bill of Rights for Data Privacy and Security.
National Cybersecurity Alliance Resources
National Cybersecurity Alliance makes it easy for everyone to learn more about cybersecurity and staying safe online. They have collected helpful, easy-to-follow resources and guides.
District Approved Third Party Contractors
The District will ensure that contracts with third-party contractors reflect that confidentiality of any student and/or classroom teacher or building principal PII be maintained in accordance with federal and state law and regulations, and this policy.
Third-party_vendor_contract_information.pdf
Link to information about Third-Party Contractors
"Third-Party Contractor" means any person or entity, other than an educational agency (i.e., a school, school District, BOCES or State Education Department), that receives student or classroom teacher/building principal PII from the educational agency pursuant to a contract or other written agreement for purposes of providing services to such educational agency, including but not limited to data management or storage services, conducting studies for or on behalf of the educational agency, or audit or evaluation of publicly funded programs. This includes an educational partnership organization that receives PII from a school District to carry out its responsibilities pursuant to Education Law §211-e (for persistently lowest-achieving schools or schools under registration review) and is not an educational agency. This also includes a not-for-profit corporation or other nonprofit organization, other than an educational agency.
For a complete list of statutory and regulatory definitions, please see Education Law §2-d(1)(a)-(k) and the Part 121 Commissioner's Regulations at §121.1.
Each third-party contractor that will receive student data or classroom teacher or building principal data must:
- Adopt technologies, safeguards and practices that align with the NIST CSF;
- Comply with the District's data security and privacy policy and applicable laws impacting the District;
- Limit internal access to PII to only those employees or subcontractors that need access to provide the contracted services;
- Not use the PII for any purpose not explicitly authorized in its contract;
- Not disclose any PII to any other party without the prior written consent of the parent or eligible student (i.e., students who are eighteen years old or older):
- except for authorized representatives of the third-party contractor to the extent they are carrying out the contract; or
- unless required by statute or court order and the third party contractor provides notice of disclosure to the District, unless expressly prohibited.
- Maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of PII in its custody;
- Use encryption to protect PII in its custody while in motion or at rest; and
- Not sell, use, or disclose PII for any marketing or commercial purpose, facilitate its use or disclosure by others for marketing or commercial purpose, or permit another party to do so. Third party contractors may release PII to subcontractors engaged to perform the contractor's obligations, but such subcontractors must abide by data protection obligations of state and federal law and regulations, and the contract with the District.
If a third-party contractor has a breach or unauthorized release of PII, it will promptly notify the District in the most expedient way possible without unreasonable delay, but no more than seven calendar days after the breach's discovery.
Third-Party Contractors' Data Security and Privacy Plan
The District will ensure that contracts with all third-party contractors include the third-party contractor's data security and privacy plan. This plan must be accepted by the District.
At a minimum, each third party contractor's data security and privacy plan will:
- Outline how all state, federal, and local data security and privacy contract requirements over the life of the contract will be met, consistent with this policy;
- Specify the safeguards and practices it has in place to protect PII;
- Demonstrate that it complies with the requirements of Section 121.3(c) of the Commissioner's Regulations concerning the supplement to the Bill of Rights;
- Specify how those who have access to student and/or classroom teacher or building principal data receive or will receive training on the federal and state laws governing confidentiality of such data prior to receiving access;
- Specify if the third-party contractor will utilize subcontractors and how it will manage those relationships and contracts to ensure personally identifiable information is protected;
- Specify how the third-party contractor will manage data security and privacy incidents that implicate personally identifiable information including specifying any plans to identify breaches and unauthorized disclosures, and to promptly notify the District;
- Describe if, how and when data will be returned to the District, transitioned to a successor contractor, at the District's direction, deleted or destroyed by the third-party contractor when the contract is terminated or expires.
See the full BOE policy for Information and Data Privacy, Security, Breach and Notification (8635)
Cooperative Educational Services through a BOCES
The District may not be required to enter into a separate contract or data sharing and confidentiality agreement with a third-party contractor that will receive student data or teacher or principal data from the District under all circumstances. For example, the District may not need its own contract or agreement where:
- it has entered into a cooperative educational service agreement (CoSer) with a BOCES that includes use of a third-party contractor's product or service; and
- when BOCES has entered into a contract or data sharing and confidentiality agreement with the third-party contractor, pursuant to Education Law Section 2-d and its implementing regulations, that is applicable to the District's use of the product or service under that CoSer.
To meet its obligations whenever student data or teacher or principal data from the District is received by a third-party contractor pursuant to a CoSer the District will consult with the BOCES to, among other things:
- ensure there is a contract or data sharing and confidentiality agreement pursuant to Education Law Section 2-d and its implementing regulations in place that would specifically govern the District's use of a third-party contractor's product or service under a particular CoSer;
- determine procedures for including supplemental information about any applicable contracts or data sharing and confidentiality agreements that a BOCES has entered into with a third-party contractor in its Parents' Bill of Rights for Data Privacy and Security;
- ensure appropriate notification is provided to affected parents, eligible students, teachers, and/or principals about any breach or unauthorized release of PII that a third-party contractor has received from the District pursuant to a BOCES contract; and
- coordinate reporting to the Chief Privacy Officer to avoid duplication in the event the District receives information directly from a third-party contractor about a breach or unauthorized release of PII that the third-party contractor received from the District pursuant to a BOCES contract.
Click-Wrap Agreements
Periodically District staff may wish to use software, applications, or other technologies in which the user must "click" a button or box to agree to certain online terms of service prior to using the software, application, or other technology. These are known as "click-wrap agreements" and are considered legally binding "contracts or other written agreements" under Education Law Section 2-d and its implementing regulations.
District staff are prohibited from using software, applications, or other technologies pursuant to a click wrap agreement in which the third-party contractor receives student data or teacher or principal data from the District unless they have received prior approval from the District's Data Privacy Officer or designee.
The District will develop and implement procedures requiring prior review and approval for staff use of any software, applications, or other technologies pursuant to click-wrap agreements.
Annual Data Privacy & Security Training
The District will annually provide data privacy and security awareness training to its officers and staff with access to PII. This training will include, but not be limited to, training on the applicable laws and regulations that protect PII and how staff can comply with these laws and regulations. The District may deliver this training using online training tools. Additionally, this training may be included as part of the training that the District already offers to its workforce.
The District will publish this policy on its website and provide notice of the policy to all its officers and staff.
