DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Privacy and Security of Student Data (Follow-Up of Audit of NY State Education Department)

Posted on October 9, 2024 by Dissent

Issued Date: September 26, 2024
Agency/Authority: State Education Department

Full Report (.pdf)

Objective

To determine the extent of implementation of the three recommendations included in our initial audit report, Privacy and Security of Student Data (Report 2021-S-29).

About the Program

The State Education Department (SED) is part of the University of the State of New York, one of the most complete, interconnected systems of educational services in the United States. SED administers school aid, regulates school operations, maintains a performance accountability system, oversees the licensing of numerous professions, certifies teachers, and administers a host of other educational programs. Its responsibilities include oversight of more than 700 school districts with 3.2 million students, 12 Regional Information Centers (RICs), and 37 Boards of Cooperative Educational Services (BOCES). The BOCES and RICs work to provide shared educational programs and services to schools throughout the State and host various schools’ student information systems and the student data reporting processes. SED is responsible for safeguarding its data and ensuring the confidentiality, integrity, and availability of its systems.

SED is charged with the general management and supervision of all public school districts and all the educational work of the State. It is also responsible for ensuring compliance with relevant laws and regulations, including Section 2-d of the Education Law (Education Law §2-d) and Part 121 of the Regulations of the Commissioner of Education (Part 121), which was adopted in January 2020.

The objectives of our initial audit, issued on May 16, 2023, were to determine whether the State Education Department consistently follows all laws and regulations regarding the safety and privacy of students’ data and is monitoring New York State school districts to ensure they are complying with the legislation and regulations that govern data privacy and security. The audit covered the period from March 2020 through November 2022. Overall, the audit found that SED did not fully comply with its policies related to information security and data privacy, including completing the data classification for all types of information that it creates, collects, processes, or stores, some of which contain students’ personally identifiable information. Additionally, SED didn’t provide sufficient oversight of school districts to ensure compliance with key requirements of Part 121, such as security policies, incident reporting, and the Parents’ Bill of Rights.

Key Findings

SED officials made significant progress in addressing the problems we identified in the initial audit report. Of the initial report’s three audit recommendations, two were implemented and one was partially implemented.

State Government Accountability Contact Information:
Audit Director
: Nadine Morrell
Phone: (518) 474-3271; Email: [email protected]
Address: Office of the State Comptroller; Division of State Government Accountability; 110 State Street, 11th Floor; Albany, NY 12236

Category: Commentaries and AnalysesEducation SectorU.S.

Post navigation

← Attorney General Tong Co-Leads $52 Million Multistate Settlement with Marriott for Data Breach of Starwood Guest Reservation Database
National Public Data files for bankruptcy, admits ‘hundreds of millions’ potentially affected →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Why Dumping Sensitive Data on Network Shares is a Liability
  • A militarily degraded Iran may turn to asymmetrical warfare – raising risk of proxy and cyber attacks
  • Pro-Russian hackers disrupt Dutch government websites ahead of NATO summit
  • Iran-Linked Threat Actors Leak Visitors and Athletes’ Data from Saudi Games
  • UK: Oxford City Council still investigating cyberattack from earlier this month
  • Steelmaker Nucor Says Hackers Stole Data in Recent Attack
  • People’s Republic of China cyber threat activity: Cyber Threat Bulletin
  • Ukrainian Web3 security auditing company Hacken suffered an attack that allowed a hacker to create 900 million HAI tokens
  • McLaren provides written notice to 743,131 patients after ransomware attack in July 2024 (2)
  • A state forensics lab was leaking its files. Getting it locked down involved a number of people.

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Sky Views Personal Data as a Potential Weapon in IPTV Piracy War
  • Florida Used a Nationwide Surveillance Camera Network 250 Times To Aid in Immigration Arrests
  • Federal Court Strikes Down HIPAA Reproductive Health Care Privacy Rule
  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.