Skip To Main Content

Information and Data Privacy, Security, Breach and Notification

The Board of Education acknowledges the heightened concern regarding the rise in identity theft and the need for secure networks and prompt notification when security breaches occur.  The Board adopts the National Institute for Standards and Technology Cybersecurity Framework Version 1.1 (NIST CSF) for data security and protection. The Data Protection Officer is responsible for ensuring the District’s systems follow NIST CSF and adopting technologies, safeguards, and practices which align with it. This will include an assessment of the District’s current cybersecurity state, their target future cybersecurity state, opportunities for improvement, progress toward the target state, and communication about cyber security risk. 

The Board will designate a Data Protection Officer to be responsible for the implementation of the policies and procedures required in Education Law §2-d and its accompanying regulations, and to serve as the point of contact for data security and privacy in the District. This appointment will be made at the annual organizational meeting. 

I. Student and Classroom Teacher/Building Principal “Personally Identifiable Information”

II. “Private Information” under State Technology Law §208