Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Security topic

No spam. Unsubscribe anytime.

FCPS policy committee reviews draft merging student data privacy into broader data security policy; asks staff for further regulatory detail

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The policy committee discussed merging Policy 442 (student data privacy) into Policy 208 (data security), aligning the draft with Maryland cybersecurity laws and adding implementation rules for third‑party applications; staff will return with a more developed regulation draft, likely in March.

At its Jan. 22, 2025, policy committee meeting, Frederick County Public Schools staff presented an intermediate draft to merge Policy 442 (student data privacy) into Policy 208 (data security) and asked the committee for direction on next steps. Mr. Gardner, identified as the committee’s IT subject matter expert, joined the table for the discussion.

Staff said the draft updates would add student-data language to Policy 208, relocate the written information security program (WISP) to the implementation section, and expand definitions (for example, confidential information and personally identifying information). The recommendation from staff was to continue work on regulations that implement the policy — directing the superintendent to draft rules that incorporate requirements from the Local Cybersecurity Act and relevant Maryland Department of Information Technology standards — and to bring a more complete proposal back to the committee, likely in March.

The committee and staff discussed the school system’s application‑approval workflow for third‑party, student‑facing software. Mr. Gardner described the multi-step review: teachers submit a request; curriculum/instruction reviews instructional appropriateness and accessibility; student‑data staff (SASSA) reviews privacy impacts; IT performs cybersecurity review; and, if the district purchases software, the contract routing process requires Department of Technology and Innovation (DTI) approval. Mr. Gardner said, “we do have an application approval process, particularly for student facing applications that fall subject to things like accessibility standards,” and outlined that approved applications are placed on a district list for use only after each office signs off.

Committee members also raised the risk of unauthorized uploads and user behavior. Mr. Gardner recommended education and procedural controls, describing the goal as buying users “half a second” to pause before they upload sensitive data: “what I'm asking for is half a second for people before they click on the link, before they upload data.” Staff noted existing acceptable‑use and employee‑code‑of‑conduct provisions that address misuse and said those will be cross‑referenced in the revised policy and regulations.

Staff returned repeatedly to the need for more definitions and for regulations that translate policy aims into operational standards and vendor contract language. No formal vote was taken; the committee asked staff to continue work on the regulation and to return with a more developed draft in March.

The committee also noted the district’s recent partner breach as a contextual reason to prioritize the work and urged staff to consult MSDE and DTI guidance while drafting regulatory language.