Data Privacy and Security
New York State Education Law Section 2-d
New York State Education Law Section 2-d and the Family Educational Rights and Privacy Act provide clear protections for student data, and NYSED is committed to complying with all applicable laws. The New York State Department of Education has committed to promoting the least intrusive data collection policies practicable that advance the goals of improving academic achievement, empowering parents with information and advancing efficient and effective school operations while minimizing the collection and transmission of personally identifiable information, and will work to ensure that this is reflected in the practices of every educational agency in New York State by developing policies and standards that will provide clear guidance to the field.
Regulatory changes to increase information security measures to safeguard the Personally Identifiable Information (PII) of students and certain school personnel. Part 121 regulations outline requirements for educational agencies and their third-party contractors to ensure the security and privacy of such protected information and were developed in consultation with stakeholders and the public.
Policy 8635 Information and Data Privacy, Security, Breach and Notification Policy 8635-E.2 Parents Bill of Rights for Data Privacy and Security of DataParent Bills of Rights Supplemental InformationDistrict Inventory (Bill of Rights Supplemental Information)Unauthorized Disclosure of Personally Identifiable Information Complaint Form
COPPA Parent/Guardian Letter and Form
Policy #'s 1130-E, 5500-E.1, and 5500-E.2
Policy# 1130-E -- Click here to print form to fill out only if you do not wish your child to be included in school related photos or media coverage.
Family Educational Rights and Privacy Act (FERPA) – The foundational federal law on the privacy of students’ educational records, FERPA safeguards student privacy by limiting who may access student records, specifying for what purpose they may access those records, and detailing what rules they have to follow when accessing the data.