Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the It Policy topic

No spam. Unsubscribe anytime.

Board reviews proposed employee separation IT-access policy; trustees ask for clarification on notification and data ownership

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Trustees reviewed a proposed IT policy that would standardize how district accounts are disabled when employees leave. Board members requested clearer language about who notifies employees of deactivation, data retention and vendor/third-party access.

The Elko County School District Board received a first reading of a proposed policy (GDB-04) that would standardize IT access and account deactivation when employees separate from district employment.

District IT staff presented the draft policy and said the proposal implements recommendations from the district's risk-management partner. Trustees raised questions about the notification timeline—specifically, how and when departing employees are told their accounts will be disabled—and about digital records and ownership of data created in district systems.

Trustee Susan Stanfill suggested adding a paragraph to the policy requiring notification to the affected employee of the date their access will end; she recommended the policy explicitly require the site administrator to notify HR/payroll and the employee so no one is surprised when deactivation occurs. At the same time trustees sought assurance that the district retains records for compliance and that immediate deactivation would be used only in specific circumstances. IT staff confirmed accounts are retained according to district retention rules and that immediate disabling is used only when directed by HR.

Trustees also asked staff to confirm whether the policy should explicitly note district ownership of student records and other materials that employees may create in district systems, and whether vendor access or third-party breaches are covered in vendor agreements. Board members requested the draft policy be revised to add: (1) an explicit employee-notification step in the deactivation timeline, (2) clarification of responsibilities (site admin, HR, IT) and (3) language on data retention and district ownership of records.

No final action was taken; staff said they would incorporate the requested clarifications and return the draft for final approval at a subsequent meeting, with the option to place the second reading on the consent agenda if trustees agree after revisions.