20-2-663. Designation and role of chief privacy officer.
The only printed version. Current through: Including Acts of the 2025 Regular Session of the General Assembly.
(a) The State School Superintendent shall designate a senior department employee to serve as the chief privacy officer of the department to assume primary responsibility for data privacy and security policy, including:
(1) Establishing department-wide policies necessary to assure that the use of technologies sustains, enhances, and does not erode privacy protections relating to the use, collection, and disclosure of student data;
(2) Ensuring that student data contained in the state data system is handled in full compliance with this article, the federal Family Educational Rights and Privacy Act, and other state and federal data privacy and security laws;
(3) Evaluating legislative and regulatory proposals involving use, collection, and disclosure of student data by the department;
(4) Conducting a privacy impact assessment on legislative proposals, regulations, and program initiatives of the department, including the type of personal information collected and the number of students affected;
(5) Coordinating with the Attorney General’s office and other legal entities as necessary to ensure that state programs, policies, and procedures involving civil rights, civil liberties, and privacy considerations are addressed in an integrated and comprehensive manner;
(6) Preparing an annual report to the General Assembly on activities of the department that affect privacy, including complaints of privacy violations, internal controls, and other matters;
(7) Working with the department general counsel and other officials in engaging with stakeholders about the quality, usefulness, openness, and privacy of data;
(8) Establishing and operating a department-wide Privacy Incident Response Program to ensure that incidents involving department data are properly reported, investigated, and mitigated, as appropriate;
(9) Establishing a model process and policy for any parent to file complaints of privacy violations or inability to access his or her child’s education records against the responsible local board of education pursuant to Code Section 20-2-667; and
(10) Providing training, guidance, technical assistance, and outreach to build a culture of privacy protection, data security, and data practice transparency to students, parents, and the public among all state and local governmental education entities that collect, maintain, use, or share student data.
(b) The chief privacy officer may investigate issues of compliance with this article and with other state data privacy and security laws by the department and local boards of education and may:
(1) Have access to all records, reports, audits, reviews, documents, papers, recommendations, and other materials available to the department that relate to programs and operations with respect to the responsibilities of the chief privacy officer under this Code section;
(2) Make such investigations and reports relating to the administration of the programs and operations of the department as are necessary or desirable; and
(3) In matters relating to compliance with federal laws, refer the matter to the appropriate federal agency and cooperate with any investigations by such federal agency.
(c)(1) In consultation with the Attorney General’s office, the chief privacy officer shall promulgate for all regional educational service agencies, all local education agencies, all elementary and secondary schools in this state, the Department of Juvenile Justice (DJJ) school system, the Department of Human Services (DHS), the Division of Family and Children Services (DFCS), and the Department of Defense Education Activity (DoDEA) a guidance document that shall address, but shall not be limited to, the following topics:
(A) The current state and federal laws applicable to local education agencies and elementary and secondary schools in this state, DJJ, DHS, DFCS, and DoDEA intended to protect the privacy of student education records, student health records, student data, and the personally identifiable information of students and their families;
(B) The application of the federal Family Educational Rights and Privacy Act (FERPA) to local education agencies and elementary and secondary schools in this state, DJJ, DHS, DFCS, and DoDEA, including what information is and is not covered under FERPA;
(C) What student education records and student health records can be shared with other educators, other schools, DJJ, DHS, DFCS, and DoDEA;
(D) What information about a student a local education agency, an elementary or secondary school, DJJ, DHS, DFCS, and DoDEA is permitted or required to share with a law enforcement officer, a law enforcement agency, a judge or court personnel, or another state or local agency or officer with a legal interest in such student; and
(E) What information about a student a law enforcement officer, a law enforcement agency, a judge or court personnel, or another state or local agency with a legal interest in such student is permitted or required to share with a local education agency, an elementary or secondary school, DJJ, DHS, DFCS, or DoDEA.
(2)(A) The guidance document required by paragraph (1) of this subsection shall be issued by December 31, 2025, and shall be reviewed and updated by July 1 each year and at any other time as necessary to ensure the information included in such guidance document is accurate.
(B) Each time the guidance document required by paragraph (1) of this subsection is issued or updated, it shall be posted on the department’s public website along with responses to common or frequently asked questions relevant to the topics included in such guidance document.
(3) The chief privacy officer shall consult with experts and authorities as appropriate to meet the requirements of this subsection.