Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Vendor Controls topic

No spam. Unsubscribe anytime.

Board presses district on where vendors store student data and breach remedies

School District (SDOC) Board Workshop · July 29, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Trustees pressed staff about vendor server locations, FERPA constraints and contractual remedies after breaches; staff said contracts require U.S. cloud regions, 72‑hour breach notification and indemnification clauses.

Board members asked how the district decides whether to do business with vendors based on where their data is stored and what contractual remedies exist if an outside partner suffers a breach. Peter Thorn said the district seeks vendors that store data in U.S. cloud regions to satisfy FERPA and related requirements, and staff confirmed previous contracts were altered or dropped when storage or security assurances were insufficient.

A staff member explained standard contract terms: vendors are responsible for breach notification (typically within 72 hours) and for costs tied to remediation and notification; many contracts include indemnification. Thorn added that the district asks software vendors about AI capabilities and data flows as part of the software intake process and reviews renewals to confirm compliance.

Board members also asked whether the district's training data could be used by vendors to train their own models. Staff said negotiation language can and has protected the district's intellectual property, and in some cases the contract gives the district a claim to proceeds if vendor use of district data creates a new product.