DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Privacy and Security of Student Data (Follow-Up of Audit of NY State Education Department)

Posted on October 9, 2024 by Dissent

Issued Date: September 26, 2024
Agency/Authority: State Education Department

Full Report (.pdf)

Objective

To determine the extent of implementation of the three recommendations included in our initial audit report, Privacy and Security of Student Data (Report 2021-S-29).

About the Program

The State Education Department (SED) is part of the University of the State of New York, one of the most complete, interconnected systems of educational services in the United States. SED administers school aid, regulates school operations, maintains a performance accountability system, oversees the licensing of numerous professions, certifies teachers, and administers a host of other educational programs. Its responsibilities include oversight of more than 700 school districts with 3.2 million students, 12 Regional Information Centers (RICs), and 37 Boards of Cooperative Educational Services (BOCES). The BOCES and RICs work to provide shared educational programs and services to schools throughout the State and host various schools’ student information systems and the student data reporting processes. SED is responsible for safeguarding its data and ensuring the confidentiality, integrity, and availability of its systems.

SED is charged with the general management and supervision of all public school districts and all the educational work of the State. It is also responsible for ensuring compliance with relevant laws and regulations, including Section 2-d of the Education Law (Education Law §2-d) and Part 121 of the Regulations of the Commissioner of Education (Part 121), which was adopted in January 2020.

The objectives of our initial audit, issued on May 16, 2023, were to determine whether the State Education Department consistently follows all laws and regulations regarding the safety and privacy of students’ data and is monitoring New York State school districts to ensure they are complying with the legislation and regulations that govern data privacy and security. The audit covered the period from March 2020 through November 2022. Overall, the audit found that SED did not fully comply with its policies related to information security and data privacy, including completing the data classification for all types of information that it creates, collects, processes, or stores, some of which contain students’ personally identifiable information. Additionally, SED didn’t provide sufficient oversight of school districts to ensure compliance with key requirements of Part 121, such as security policies, incident reporting, and the Parents’ Bill of Rights.

Key Findings

SED officials made significant progress in addressing the problems we identified in the initial audit report. Of the initial report’s three audit recommendations, two were implemented and one was partially implemented.

State Government Accountability Contact Information:
Audit Director
: Nadine Morrell
Phone: (518) 474-3271; Email: [email protected]
Address: Office of the State Comptroller; Division of State Government Accountability; 110 State Street, 11th Floor; Albany, NY 12236

Category: Commentaries and AnalysesEducation SectorU.S.

Post navigation

← Attorney General Tong Co-Leads $52 Million Multistate Settlement with Marriott for Data Breach of Starwood Guest Reservation Database
National Public Data files for bankruptcy, admits ‘hundreds of millions’ potentially affected →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • When ransomware listings create confusion as to who the victim was
  • Rajkot civic body’s GIS website hit by cyber attack, over 400 GB data feared stolen
  • Taiwan’s BitoPro hit by NT$345 million cryptocurrency hack
  • Texas gastroenterology and surgical practice victim of ransomware attack
  • Romanian Citizen Pleads Guilty to ‘Swatting’ Numerous Members of Congress, Churches, and Former U.S. President
  • North Dakota Enacts Financial Data Security and Data Breach Notification Requirements
  • Pro-Ukraine hacker group Black Owl poses ‘major threat’ to Russia, Kaspersky says
  • Vanta bug exposed customers’ data to other customers
  • Lyrix Ransomware Targets Windows Users with Advanced Evasion Techniques
  • Central Maine Healthcare tackles suspected cybersecurity issue; hospitals remain open

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Florida ban on kids using social media likely unconstitutional, judge rules
  • State Data Minimization Laws Spark Compliance Uncertainty
  • Supreme Court Agrees to Clarify Emergency Situations Where Police Don’t Need Warrant
  • Stewart Baker vs. Orin Kerr on “The Digital Fourth Amendment”
  • Fears Grow Over ICE’s Reach Into Schools
  • Resource: HoganLovells Asia-Pacific Data, Privacy and Cybersecurity Guide 2025
  • She Got an Abortion. So A Texas Cop Used 83,000 Cameras to Track Her Down.

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.