RD571 - Model Data Security Plan for the Protection of School Division Student Data 2016 – 2017 – August 29, 2016
2016 – 2017 Model Data Security Plan for the Protection of School Division Student
Legislation enacted by the 2015 General Assembly, HB 2350 amended the Code of Virginia by adding in Chapter 2 of Title 22.1 a section numbered 22.1?20.2, relating to the Department of Education; student data security. The legislation directed the Virginia Department of Education to develop in collaboration with the Virginia Information Technologies Agency model data security plan for the protection of student data held by school divisions. A report shall be submitted to the chairmen of the House Committee on Appropriations and the Senate Committee on Finance on the cost of developing a model student data security plan.
2016 – 2017 plan requirements were as follows:
Develop and update no less than annually, a model data security plan for the protection of student data that includes:
• Guidelines for access to student data and student data systems.
• Privacy compliance standards.
• Privacy and security audits.
• Procedures to follow in the event of a breach of student data.
• Data retention and disposition policies.
Department of Education designated a chief data security officer to assist school divisions, upon request, with the development and implementation of their own data security plans and to develop best practice recommendations regarding the use, retention, and protection of student data.