New York’s 2014 Student Data Privacy Law

The New York State Data Privacy Act of 2014 established important rules for protecting student information held by schools and outside technology providers. The law is commonly associated with Education Law §2-d, which governs the privacy and security of personally identifiable information in student records.

For parents, the central issue is control. Schools increasingly rely on learning platforms, assessment vendors, data dashboards, and cloud services. The law requires education officials to explain how these providers may use student information and to take reasonable steps to prevent unauthorized access, disclosure, or misuse.

Understanding the law can help families evaluate school policies, ask informed questions, and participate in broader debates about standardized testing, education technology, and local control.

What The Law Covers

Education Law §2-d applies to school districts, charter schools, BOCES, and other educational agencies covered by New York education law. It addresses personally identifiable information, which may include a student’s name, identification number, academic records, disciplinary history, disability status, biometric information, or other data that can identify a child.

The law also governs third-party contractors that receive student information from an educational agency. A company operating a testing platform or online classroom tool cannot treat school data as ordinary commercial information. Its contract must describe permitted uses, security requirements, and limits on redisclosure.

Limits On Commercial Use

A provider generally may use student information only to perform the educational service described in its agreement. The data cannot be sold or used for targeted advertising based on a student’s records. Contractors must also restrict access to authorized personnel and follow procedures for handling, retaining, and destroying information.

These requirements matter because schools often adopt digital services quickly, while families may have little opportunity to review complex vendor agreements. Parents can ask whether a platform creates individual profiles, shares information with subcontractors, retains records after a contract ends, or transfers data outside the school’s direct control.

Rights Parents Should Know

Parents and eligible students have rights to inspect and review student data maintained by an educational agency, subject to applicable education-record rules. Families can request information about the categories of data collected, the purpose for collecting it, and the types of contractors with access.

Each educational agency must publish a data security and privacy policy. The policy should explain safeguards, breach procedures, complaint channels, and the responsibilities of school officials and vendors. Parents who believe a provider or school has violated privacy requirements may use the agency’s complaint process and may also review guidance from the New York State Education Department.

New York’s privacy framework developed alongside federal protections such as FERPA and COPPA. Those laws may apply in different circumstances, so a school’s responsibilities can depend on the student’s age, the type of record, and the technology service involved.

What Schools And Vendors Must Do

The law requires educational agencies to designate a data protection officer or comparable official and to maintain a public-facing privacy policy. Contracts with outside providers must include security and privacy provisions, including restrictions on data use, breach response, and access by subcontractors.

A provider must notify the educational agency of a breach or unauthorized release according to the applicable legal requirements. The school or district then has responsibilities for responding, documenting the incident, and notifying affected parties when required. Families should ask who will contact them and what information will be provided if their child’s records are exposed.

Area What Parents Should Look For
Data collection Clear explanation of what information is gathered and why
Vendor access Names or categories of outside companies receiving records
Permitted use Limits on advertising, sale, profiling, and redisclosure
Security Encryption, access controls, staff training, and monitoring
Retention Procedures for returning or deleting information
Breach response Timelines, responsible officials, and family notification

Questions Worth Asking The District

A school district should be able to explain which digital tools collect student information and which vendors operate them. Parents can request the district’s data privacy policy, review its inventory of data elements, and ask whether the district has conducted a privacy or security assessment before adopting a service.

It is also reasonable to ask whether families may decline a particular program, whether an alternative exists, and how long records remain available. These questions are especially relevant when online assessments, behavioral monitoring tools, or centralized student databases are connected to broader testing systems.

Concerns about technology should also be viewed within the larger policy debate. Families examining the influence of private organizations and technology interests in public education may find this discussion of outside education influence useful when considering who shapes data and testing policies.

Practical Steps For Families

Parents can protect their children’s privacy by creating a written record of requests and responses. A calm, specific inquiry is often more effective than a general objection. Ask for the name of the vendor, the contract or privacy notice, the data elements involved, and the procedure for correcting inaccurate information.

Useful actions include:

Data privacy is a continuing local responsibility, not a one-time compliance exercise. Parents, teachers, and community members can attend board meetings, monitor proposed contracts, and support policies that give families meaningful notice and control. Contact local education officials and New Yorkers United for Kids to stay informed and take part in advocacy for transparent, accountable student data practices.