Data Security in a Digital World

Slides:



Advertisements
Similar presentations
National Forum on Education Statistics sponsored by the National Cooperative Education Statistics System and the National Center for Education Statistics.
Advertisements

Family Educational Rights and Privacy Act What you should know about FERPA.
FERPA - Sharing Student Information
Protect Our Students Protect Ourselves
FERPA: UPDATE ON THE FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT Presented by Brenda V. S. Selman University Registrar-MU University of Missouri-Columbia.
FERPA (Oops, can I say that?) Online Tutoring Training Workshop The Learning Center The University of Louisiana-Lafayette.
Safeguarding Data to Ensure Effective Data Use Paige Kowalski |Director| State Policy & Advocacy July 2014.
FERPA for Students What Every MSU Student Should Know Prepared by the Office of the Registrar.
FERPA Family Educational Rights and Privacy Act September 20, 2012Presented by: David Stocker General Counsel ACT, Inc.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
LOSFA’s Vision is to be Louisiana’s First Choice for College Access Louisiana Office of Student Financial Assistance (LOSFA) LASFAA 2014 Financial Aid.
FERPA What You Need to Know as a Wayne State Student Prepared by the Office of the Registrar.
FERPA: WHAT YOU SHOULD KNOW ILASFAA April 18, 2008 Amy Perrin Director of Financial Aid Elgin Community College.
RVCC FACULTY FERPA WORKSHOP OCTOBER 2011 DAN PALUBNIAK REGISTRAR
Family Educational Rights and Privacy Act What you need to know...
1 The University of Texas at Tyler Protecting the Confidentiality of Social Security Numbers UTS165 Information Resources Use and Security Policy.
School Based Research: The Family Education Rights and Privacy Act (FERPA) & The Protection of Pupil Rights Amendment (PPRA) IRB C Member Presentation.
FERPA and IRB: Implications for Testing Centers Judith W. Grant, Ph.D.,CIP NCTA Conference San Antonio, Texas August 6, 2009.
FERPA The Family Educational Rights and Privacy Act (The Buckley Amendment)
2/16/2010 The Family Educational Records and Privacy Act.
FERPA 2008 New regulations enact updates from over a decade of interpretations.
The Family Educational Rights and Privacy Act (FERPA) The Importance of Protecting Student Records This session will help you better understand the law.
Data Privacy: Third Parties, Vendors, & Nonprofits Baron Rodriguez (PTAC), Michael Hawes (DoED), & Mike Tassey (PTAC)
FERPA 101 Student Records: Institutional Responsibility and Student Rights What Every University Employee Should Know Prepared by the Office of the Registrar.
8/28/2015 The Family Educational Rights and Privacy Act (FERPA)  Also known as the Buckley Amendment.  Statute: 20 U.S.C. 1232g; Regulations: 34 CFR.
THE FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT (FERPA) AND STATE LONGITUDINAL DATA SYSTEMS Steven Y. Winnick Montana Office of Holland & Knight LLP Public.
Family Educational Rights and Privacy Act (FERPA) Statute: 20 U. S. C
The 411 on IEPs and Section 504s Claudia Otto, Ph.D. Oklahoma Department of Career & Technology Education March 10, 2015.
Confidentiality and Public Information Act LISD Special Education Department Training SY
FERPA Questions and Answers Lenawee Data Camps June and August, 2009.
Family Educational Rights and Privacy Act. From the moment a child enters the school system, sensitive information is collected about the child (and even.
FERPA: What you Need to Know The Family Educational Rights and Privacy Act & SEI.
Family Educational Rights and Privacy Act (FERPA) UNION COLLEGE.
FERPA Basics Kim Barber. FERPA defined FERPA: Federal Educational Rights and Privacy Act of 1974 Law that protects and guards against release of student.
FERPA Basics From the University of Northern Iowa and Office of the Registrar.
FAMIS CONFERENCE Mari M. Presley, Assistant General Counsel Florida Department of Education June 12, 2012.
1 CONFIDENTIALITY. 2 Requirement Under IDEA 34 CFR Sec (c) All staff collecting or using personally identifiable information in public education.
Special Education 101 Elementary Dept. Chair 1/27/2009 Confidentiality.
FERPA Guidelines for Cooperating Teacher and University Supervisors.
SPECIAL EDUCATION A REVIEW OF:  CHILD FIND/ SPED PROCESS  FERPA AND CONFIDENTIALITY  LENGTH OF SCHOOL DAY.
Privacy Compliance in Schools Darrebin A/P’s Network 7 May 2009.
FERPA for the Financial Aid Office NCASFAA Fall Conference November 2012.
FERPA: An introduction to the Family Educational Rights and Privacy Act Presented by: Kristy Giacomelli Assistant Registrar
The Georgia Open Records Act and ferpa
FERPA Family Educational Rights and Privacy Act of 1974 (also known as the Buckley Amendment)
Laws and Regulations. Family Educational Rights and Privacy Act Children’s Online Privacy Protection Act Protection of Pupil Rights Amendment Health Insurance.
Welcome to Workforce 3 One U.S. Department of Labor Employment and Training Administration Webinar Date: Thursday, October 23, 2014 Presented by: Division.
FERPA Family Educational Rights and Privacy Act
Student Data Privacy and Security
Student Data Privacy and Security
Privacy & Confidentiality
FERPA (Oops, can I say that?)
SPECIAL EDUCATION A REVIEW OF: CHILD FIND/ SPED PROCESS
FERPA Family Educational Rights and Privacy Act of 1974
Family Educational Rights and Privacy Act (FERPA) Online Training
FERPA (Oops, can I say that?)
What is FERPA? Family Educational Rights and Privacy Act (FERPA) “is a federal law that protects the privacy of student education records. The law applies.
FERPA HEA Privacy Act: Protecting Students Data
READ Act Data Collection Spring 2018
Darrin Rooker, MS NYSFAAA President
Family Education Rights and Privacy Act
SPECIAL EDUCATION REQUIRED TRAINING
FERPA for Colleges & Universities
Protecting Student Data/ Financial Aid Data Sharing
Prepared by the Office of the Registrar
What does that have to do with me?
Student Data Privacy: National Trends and Wyoming’s Role
Protecting Student Data
Confidentiality Training 2014
Family Educational Rights and Privacy Act of 1974
Presentation transcript:

Data Security in a Digital World Louisiana and PII Security

Personally Identifiable Information (PII) Information that can be used to distinguish an individual Indirect PII Information that can be combined with other information to identify a specific individual Direct PII Information that relates specifically to an individual (SSN, Name, Date of Birth)

Timeline * Modified by Act 228 (2015) Data Sharing Agreements Posted (1/1/15) Release of Secure ID (6/1/15)* No release of PII to outside parties (6/1/15)* Act 228 (2015) No release of PII moved to 8/1/15 Release of Secure ID moved to 8/1/15 * Modified by Act 228 (2015)

2014 Legislative Session Act 837 Prohibits LEAs from requiring the collection of non-academic data about students such as political affiliation, religious practices, or information. Restricts LEAs from sharing personally identifiable information (PII) about students with external entities, including LDE, starting June 1, 2015. The law provides limited exceptions: LEAs may share students’ personally identifiable information with LDE if: The parent has given written consent to share that information. The state requires it for auditing, including enrollment counts. LEAs may share PII with a private entity if they sign a data sharing agreement. Requires that all data sharing agreements be publicly posted. Defines PII as any two pieces of identifiable information. As such, first and last name are considered two pieces of identifiable information. Creation and release of Louisiana Secure ID for all students by June 1, 2015. All data sharing agreement with external vendors must be in place by June 1, 2015. Provides for up to $10,000 fine and/or 3 years in prison for illegal release of each identity.

2014 Legislative Session Act 677 Requires public posting of : All PII data transfer agreements by Jan. 1, 2015 All new agreements must be posted within 10 days of signing Profiles of each data recipient List of all data transferred Data Security Coordinator contact information Process for filing a complaint

Act 837 Benefits Disadvantages Codifies what is and isn’t PII Mandates data and identity security Provided for a unified identifier for students Very narrow window to comply with all aspects of the law Definition of PII very broad and amorphous Was subject to broadly differing interpretations by districts Made schools and districts inoperable due to restrictions Disadvantage: By definition, districts could not include students in year book or school programs without a release, post pictures in the hallway, or even put student names on tests

Act 677 Benefits Disadvantages Provided for transparency in data transfers and agreements surrounding them Extremely short time frame to comply Required districts to renegotiate with vendors regarding data transfers Required extensive legal counsel and time to negotiate with some recalcitrant vendors

2015 Legislative Session 2015 Legislative Session Act 228 Clarifies language and narrows the definition of release of PII under Acts 837 & 677. Changes date for end of data sharing without data transfer agreement from June 1, 2015 to August 1, 2015 Changes date of release of Louisiana Secure ID from June 1, 2015 to August 1, 2015

Act 228 Benefits Disadvantages Redefined, narrowed, and clarified definition of PII and the restrictions on it Moved dates for posting of data transfer agreements and issuance of Louisiana Secure ID to August 1, 2015 None

Securing Data Physical Security Data Sharing Secure ID Consent Data linkage Consent

Physical Security No access for unauthorized individuals All data is secured in via encryption or physical barriers No “shoulder surfing” Workers only allowed to access data on department owned devices and no sharing of devices Destruction of data All data destroyed after use All storage devices destroyed at end-of-life Secure transmittal No fax transmittal sFTP transfer only

Data Sharing All vendors must sign and adhere to updated data sharing agreements Data sharing agreements must comply with both federal and state laws Data sharing agreements must publicly posted

Secure ID All students issued a new state-wide Secure ID Number No connection to any direct or indirect PII Generated by state and issued to student at enrollment in public and non-public schools Secure ID follows student throughout educational career, regardless of where they are enrolled

Data Linkage In order for student records to be secure, Secure ID is not linked to state student records and PII is not linked to local student records In order to link PII and Secure ID data, third party must do ID matchup Prevents any one entity from having all of the pieces

Data Linkage Third Party Performs Data Linkage State Submits PII School District Submits Secure ID

Consent All voluntary data sharing must be consented to by parent (or student of majority age) Includes: Transcripts to post-secondary institutions, scholarship, and financial aid programs All public news or publication entities including yearbook, school paper, graduation programs, etc. Data includes: Student name Photos Grade information Racial information Classification information

More Information http://www.louisianabelieves.com/resources/library/data- center/protecting-student-privacy

Questions