Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

Board rejects data-protection resolution after debate over cost and vendor risk

New Hanover County Board of Education · August 5, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Board member David Perry moved a resolution to tighten district data architecture and reduce reliance on multi-tenant cloud vendors after recent statewide breaches; staff described existing vendor audits and insurance, and the motion failed on a roll-call vote, 1–6.

David Perry, a board member who introduced the resolution, argued the district should phase in measures to isolate student data from multi-tenant cloud architectures and not rely solely on vendor attestations after recent statewide breaches.

"PowerSchool... Millions of students, including our own, had their personally identifiable information stolen," Perry said, citing recent incidents and urging the district to consider architecture changes and a delayed effective date if needed. Perry moved to adopt the data-confidentiality and security agreement and asked that it be implemented on a timetable that would allow technical and budget planning.

District IT staff and board members pushed back on cost and practicality. The district's IT representative (identified in the meeting as Lance) explained that many applications pass only directory fields (first name, last name, email and grade) while Infinite Campus contains more sensitive records and carries stricter vendor requirements, and that the district already requires SOC 2 (Type 2) or similar certifications for vendors that access sensitive data. Dr. Tim Merrick and others noted the limits of certifications after a vendor breach, but staff said the district also maintains cybersecurity insurance.

Board members debated trade-offs between added cybersecurity equipment and staffing versus classroom resources. One board member framed it this way: spending for deep infrastructure changes could mean fewer teachers in classrooms. After discussion, the motion to adopt the resolution failed 1–6 on roll-call.

The board did not adopt the proposed architectural restrictions and directed no formal new procurement restrictions that night; staff said they would continue oversight of vendor certifications and insurance coverage and maintain existing cybersecurity protocols.