Data Privacy and Security Compliance Process

Federal and state laws and regulations impose requirements on the DOE and certain outside parties to ensure students' personally identifiable information (PII) and certain staff PII (specifically, identifiable annual professional performance review data of principals, assistant principals and teachers) remain confidential and secure. The DOE has a standardized compliance review process for vetting any outside parties (contracted and non-contracted) who receive or access data from the DOE. This compliance process helps ensure that outside parties safeguard any and all protected information pursuant to federal, state, and local regulations.

Effective July 1, 2023, all vendors of third-party software will be required to complete the DOE's compliance process and OTI's cloud review process before conducting business with the DOE. DOE staff may not use software that access or receives student or staff PII if the software vendor has not completed the compliance process. That also means schools cannot use products while they are in the process of completing the compliance process.

This process applies to contracted and non-contracted vendors, as well as outside parties that offer products and services for free.

Requirements for Outside Parties

Outside parties who receive student and certain types of staff PII (together, referred to as “covered PII” on this page) must agree to comply with various requirements under FERPA, New York State Education Law 2-d, and Chancellor's Regulation A-820, in a written agreement (such as a nondisclosure agreement or data processing agreement).

Outside parties must agree to keep covered PII confidential, only collect and use covered PII for legitimate educational purposes, to inform the DOE if the covered PII is breached or disclosed without authorization, and plan for its return and disposal one no longer needed. Outside parties also must agree to have the appropriate safeguards, policies, and practices in place to protect the data, and must submit to a compliance process. These safeguards promote transparency and provide additional protections for the benefit of our families.

More specifically, outside parties must agree to the following: