Kansas Student Data Privacy Legislation Overview

undefined
 
Kansas Student Data
Privacy
 
Current Privacy Legislation
KSDE Policy and Practice
April 17, 2015
 
Kansas Data Privacy Legislation
 
KS Student Data Privacy Act
In effect as of July 1, 2014
 
SDPA Legislation Highlights:
Provides restrictions for disclosing student data
o
Applies to education entities (both school districts and
KSDE)
o
Applies to all student data collected by KSDE
 
 
 
Kansas Data Privacy Legislation
 
Disclosure of student data is allowed
o
to the student and the student’s parents.
o
to anyone when an adult student / parent consents in writing.
o
to authorized personnel of school districts, KSDE, and KBOR
as required to perform assigned duties.
o
to authorized personnel of any state agency or to service
providers (contractors) working for state agencies or school
districts (
REQUIRES Data Sharing Agreements
) specifically
for 
instruction, assessment, or longitudinal reporting.
o
Comply with subpoena or court order and to public health
officials in compliance with health statutes.
o
To enhancement vendors providing photography services, class
ring services, yearbook publishing services, memorabilia
services, or similar services.
 
 
 
 
 
 
Kansas Data Privacy Legislation
 
o
Grants enforcement authority to the KS Attorney
 
General or any District Attorney.
 
o
Requires notification to affected party of unauthorized
disclosure.
 
o
Requires Kansas education boards to adopt a policy in
accordance with SDPA in addition to applicable federal
laws and regulations.
 
o
Note: Disclosure and management of student data must
follow both FERPA and SDPA guidelines.
 
 
 
 
 
Kansas Data Privacy Legislation
 
KSDE shall annually publish on its website the categories of student data that are submitted to
and maintained in any statewide longitudinal student data system. Publications required by this
section shall be published with an easily identifiable link located on the department's website
homepage.
 
Annual report to governor and legislature. On or before May 15, 2015, and each year thereafter,
the state board shall submit to the governor and the legislature a written report. The report shall
include, but not be limited to the following information:
 
o
(a) Any categories of student data collected for the statewide longitudinal student
data system that are not otherwise described as student data under K.S.A. 2014
Supp. 72-6216, and amendments thereto;
 
o
(b) any changes to existing data collections, which includes changes to federal
reporting requirements by the secretary of the United States department of education;
 
o
(c) an explanation of any exceptions provided by the state board in the preceding
calendar year regarding the release or transfer of student data; and
 
o
(d) the scope and nature of any privacy or security audits completed in the preceding
calendar year.
 
KSDE Data Privacy Compliance
1)
Transparency
2)
Security Policies
3)
Technical Architecture
4)
Data Governance
5)
Training
6)
Resources
 
 
 
 
 
KSDE Data Policy and Practice
 
1)
Transparency
KSDE publishes data collection information publicly
Reasons for collection include:
o
Public, State and federal reporting
o
Calculations for state funding
o
Administering state assessments
o
School accountability
o
Early childhood school readiness
o
To monitor and to improve programs and inform instruction
Program Participation
o
Free/Reduced Lunch, Virtual Education, Child of Military Family
o
Special Ed: Primary Disability / Gifted / accommodations
o
English for Speakers of Other Languages (ESOL)
Course Outcomes
o
Course Identifier, Completion status /Educator ID
o
Letter/Percent/Pass-Fail
 
 
 
KSDE Data Policy and Practice
 
2.) Security Policies
State of Kansas IT Security Policies
o
Information Technology Executive Counsel 7230A
Family Educational Rights and Privacy Act 
(FERPA)
Data Sharing agreements
o
Ex: KS Board of Regents, Department of Children and
Families, Department of Health and Environment
o
Department of Agriculture, National Student Clearinghouse
KSDE Security Policies
o
Incorporates State and Federal requirements
 
 
 
 
 
 
KSDE Data Policy and Practice
 
3.) Technical Architecture
Security based network design
Enterprise Class Technologies
Industry Recognized Best Practices
Device and Student Data Encryption
AAA (Authentication, Authorization and Accounting)
(COOP) Continuity of Operations Planning
External Auditing
 
 
 
 
 
 
 
 
 
KSDE Data Policy and Practice
 
4.) Data Governance
KSDE has a mature Data Governance program, began in 2008
Model data governance program for the National Education
Community
 
Data Governance Program Overview:
o
Formal structure for decision making and authority for data related matters
o
Establishes roles and responsibilities concerning data
o
Ensures compliance, security and ethical standards for data use
Data Compliance Officer
o
KSDE recently reallocated an existing FTE to create this position
 
 
 
 
 
 
 
 
KSDE Data Policy and Practice
 
5.) Training
KSDE Data Quality Certification Program
o
School District focused instruction on general data quality practices, including an
overview of the Student Data Privacy Act and FERPA, as well as intensive role-
based training with the KSDE web-based applications, including the Kansas
Individual Data on Students (KIDS) system.
KSDE Security Awareness Metric (SAM)
o
KSDE employees and contractors are required to complete the Security
Awareness Metric (SAM) within the first two days of employment.
o
Results reviewed and tracked by agency IT Security staff.
Security Awareness and Data Security Training
o
All KSDE staff are required to attend these updated sessions annually.
o
These requirements are reported and tracked by agency IT Security
staff.
 
 
 
KSDE Data Policy and Practice
 
6.) Resources and awareness
KSDE Public Website 
www.ksde.org
o
Information on data collection and
security
o
Applicable laws and regulations
o
State of Kansas Specific Policies
o
Student Data Privacy Resources
o
Training information
 
 
KSDE Data Policy and Practice
 
 
Contact
Lane Wiley
KSDE Director of Information Technology
785-296-7931
 
Questions?
Slide Note
Embed
Share

Kansas Student Data Privacy legislation, including the KS Student Data Privacy Act, emphasizes restrictions on disclosing student data and outlines permissible disclosures, enforcement measures, and reporting requirements. KSDE plays a key role in overseeing data management practices to ensure compliance with privacy guidelines. The legislation mandates annual publication of student data categories and submission of reports to the governor and legislature regarding data collection, changes, exceptions, audits, and more.

  • Kansas
  • Student Data Privacy
  • Legislation
  • KSDE
  • Education

Uploaded on Sep 17, 2024 | 1 Views


Download Presentation

Please find below an Image/Link to download the presentation.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.

You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.

E N D

Presentation Transcript


  1. Kansas Student Data Privacy Current Privacy Legislation KSDE Policy and Practice April 17, 2015

  2. Kansas Data Privacy Legislation KS Student Data Privacy Act In effect as of July 1, 2014 SDPA Legislation Highlights: Provides restrictions for disclosing student data o Applies to education entities (both school districts and KSDE) o Applies to all student data collected by KSDE Kansas State Department of Education www.ksde.org

  3. Kansas Data Privacy Legislation Disclosure of student data is allowed o to the student and the student s parents. o to anyone when an adult student / parent consents in writing. o to authorized personnel of school districts, KSDE, and KBOR as required to perform assigned duties. o to authorized personnel of any state agency or to service providers (contractors) working for state agencies or school districts (REQUIRES Data Sharing Agreements) specifically for instruction, assessment, or longitudinal reporting. o Comply with subpoena or court order and to public health officials in compliance with health statutes. o To enhancement vendors providing photography services, class ring services, yearbook publishing services, memorabilia services, or similar services. Kansas State Department of Education www.ksde.org

  4. Kansas Data Privacy Legislation o Grants enforcement authority to the KS Attorney General or any District Attorney. o Requires notification to affected party of unauthorized disclosure. o Requires Kansas education boards to adopt a policy in accordance with SDPA in addition to applicable federal laws and regulations. o Note: Disclosure and management of student data must follow both FERPA and SDPA guidelines. Kansas State Department of Education www.ksde.org

  5. Kansas Data Privacy Legislation KSDE shall annually publish on its website the categories of student data that are submitted to and maintained in any statewide longitudinal student data system. Publications required by this section shall be published with an easily identifiable link located on the department's website homepage. Annual report to governor and legislature. On or before May 15, 2015, and each year thereafter, the state board shall submit to the governor and the legislature a written report. The report shall include, but not be limited to the following information: o (a) Any categories of student data collected for the statewide longitudinal student data system that are not otherwise described as student data under K.S.A. 2014 Supp. 72-6216, and amendments thereto; o (b) any changes to existing data collections, which includes changes to federal reporting requirements by the secretary of the United States department of education; o (c) an explanation of any exceptions provided by the state board in the preceding calendar year regarding the release or transfer of student data; and o (d) the scope and nature of any privacy or security audits completed in the preceding calendar year. Kansas State Department of Education www.ksde.org

  6. KSDE Data Policy and Practice KSDE Data Privacy Compliance 1) Transparency 2) Security Policies 3) Technical Architecture 4) Data Governance 5) Training 6) Resources Kansas State Department of Education www.ksde.org

  7. KSDE Data Policy and Practice 1) KSDE publishes data collection information publicly Reasons for collection include: o Public, State and federal reporting o Calculations for state funding o Administering state assessments o School accountability o Early childhood school readiness o To monitor and to improve programs and inform instruction Program Participation o Free/Reduced Lunch, Virtual Education, Child of Military Family o Special Ed: Primary Disability / Gifted / accommodations o English for Speakers of Other Languages (ESOL) Course Outcomes o Course Identifier, Completion status /Educator ID o Letter/Percent/Pass-Fail Transparency Kansas State Department of Education www.ksde.org

  8. KSDE Data Policy and Practice 2.) Security Policies State of Kansas IT Security Policies o Information Technology Executive Counsel 7230A Family Educational Rights and Privacy Act (FERPA) Data Sharing agreements o Ex: KS Board of Regents, Department of Children and Families, Department of Health and Environment o Department of Agriculture, National Student Clearinghouse KSDE Security Policies o Incorporates State and Federal requirements Kansas State Department of Education www.ksde.org

  9. KSDE Data Policy and Practice 3.) Technical Architecture Security based network design Enterprise Class Technologies Industry Recognized Best Practices Device and Student Data Encryption AAA (Authentication, Authorization and Accounting) (COOP) Continuity of Operations Planning External Auditing Kansas State Department of Education www.ksde.org

  10. KSDE Data Policy and Practice 4.) Data Governance KSDE has a mature Data Governance program, began in 2008 Model data governance program for the National Education Community Data Governance Program Overview: o Formal structure for decision making and authority for data related matters o Establishes roles and responsibilities concerning data o Ensures compliance, security and ethical standards for data use Data Compliance Officer o KSDE recently reallocated an existing FTE to create this position Kansas State Department of Education www.ksde.org

  11. KSDE Data Policy and Practice 5.) Training KSDE Data Quality Certification Program o School District focused instruction on general data quality practices, including an overview of the Student Data Privacy Act and FERPA, as well as intensive role- based training with the KSDE web-based applications, including the Kansas Individual Data on Students (KIDS) system. KSDE Security Awareness Metric (SAM) o KSDE employees and contractors are required to complete the Security Awareness Metric (SAM) within the first two days of employment. o Results reviewed and tracked by agency IT Security staff. Security Awareness and Data Security Training o All KSDE staff are required to attend these updated sessions annually. o These requirements are reported and tracked by agency IT Security staff. Kansas State Department of Education www.ksde.org

  12. KSDE Data Policy and Practice 6.) Resources and awareness KSDE Public Website www.ksde.org oInformation on data collection and security oApplicable laws and regulations oState of Kansas Specific Policies oStudent Data Privacy Resources oTraining information Kansas State Department of Education www.ksde.org

  13. Questions? Contact Lane Wiley KSDE Director of Information Technology 785-296-7931 Kansas State Department of Education www.ksde.org

More Related Content

giItT1WQy@!-/#giItT1WQy@!-/#giItT1WQy@!-/#giItT1WQy@!-/#giItT1WQy@!-/#