Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Committee updates data‑privacy policy to follow NIST framework and add breach reporting
Summary
Policy revisions will align district data‑privacy and breach‑notification procedures with the NIST Framework 2.0 and recent state mandates, adding ransomware reporting and clarifying vendor obligations; the committee forwarded the changes for first reading.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Committee staff described a substantive revision to the district's information and data‑privacy policy to align with the NIST cybersecurity framework and new state reporting rules.
“When there is a breach of personally identifiable information, what are the provisions that we must do in terms of notifying the parents, notifying the state,” the staff member said while outlining expanded definitions and incident‑reporting requirements. The revisions add explicit steps for ransomware incidents and clarify responsibilities when third‑party vendors hold student data. The committee agreed the district's existing policy contains most elements but that the new regulatory reporting requirements make this update necessary.
The Policy Committee agreed to forward the revised data‑privacy policy to the full board for first reading; staff will return with any minor edits identified by counsel before board consideration.

