Davis School District has outlined its formal protocols for maintaining student and employee data privacy, emphasizing compliance with state and federal laws through strict procurement and privacy policies. The district's framework focuses on ensuring compatibility with existing systems and maintaining transparency regarding how third-party entities may access or share student information.
Core Privacy Principles
The district's approach to data security is built upon several core pillars, including compliance through privacy and procurement law, compatibility with district systems, and the careful management of student data. According to district documentation, these measures are designed to connect directly with district instructional practices while ensuring cost controls follow state procurement laws.
To maintain transparency, the district has committed to communicating any third-party data sharing with the community. This communication strategy is supported by a variety of public-facing documents and portals, including an Approved Tools Public Portal and an Approved Tools Employee Portal, which allow staff and the public to verify the legitimacy of digital tools used within the district.
Regulatory and Legal Frameworks
The regulatory landscape governing the district includes a complex hierarchy of federal and state mandates. The district's policies are designed to respond to various statutes, including the Student Data Protection Act (SDPA) and the Student Data Privacy Consortium (SDPC). These frameworks ensure that all digital interactions and data collections adhere to established legal standards.
In addition to student-specific protections, the district manages various notices and policies regarding biometric data collection and website privacy. These include specific disclosures such as the DSD Student Data Collection Notice and the DSD Website Data Privacy Notice. The district also maintains a Government Data Protection Act (GDPA) framework and adheres to the Utah Office of Administrative Rules.
Stakeholder Responsibilities and Communication
The district provides specific guidance and documentation for different stakeholders to ensure accountability across all levels of administration. This includes specialized training and specific responsibilities assigned to teachers, administrators, the Student Data Privacy Manager, and the Information Data Manager.
For parents and guardians, the district provides several resources to navigate media and communication permissions. These include a Media Permission Letter, which serves as a memo to parents regarding student interviews, photographs, or video recordings. The district also manages SMS Terms of Service for various school programs to ensure that text messaging remains within established privacy parameters.
Governance and Security Protocols
Data governance within the district is supported by a structured set of procedures and documentation. This includes a Data Governance Plan, a Data Retention policy, and a Metadata Dictionary to ensure information is organized and handled correctly. The district also maintains a specific IT Security Plan to protect the integrity of its digital infrastructure.
Furthermore, the district addresses specific privacy needs through the FERPA Annual Notice and Directory Information Notice, ensuring that educational rights are clearly communicated. This comprehensive approach to data management is supported by various internal and external documents, ranging from the DSD Board Privacy Policy to specific employee data privacy notices.
Commitment to Data Security
By integrating legal compliance with instructional practice, the district aims to create a secure environment for both student and staff data. Through the use of approved tools, rigorous training for administrators and teachers, and clear communication regarding data disclosure, the district seeks to meet the evolving requirements of state and federal privacy statutes.