A Data Manager is an individual designated by a Local Education Agency (LEA) to fulfill the duties described in the Utah State Legislature's Title 53E-09-308: Sharing student data. Prohibition. Requirements for student data manager. Authorized student data sharing. Namely, they authorize and manage the sharing of student data, act as a local point of contact with the state, and fulfill other duties as defined in their local data governance plan
The following table describes what data managers need to complete and send to the Utah State Board of Education by October 1 of each year.
Rechecking evidence that received a Pass last year. Since there were no substantive changes in requirements for the notices and policies, LEAs that received a Pass on last year’s check will only be asked to resubmit the URL where the evidence can be found on the LEA website. If substantive changes were made to the document, the LEA may request a recheck. LEAs that did not receive a Pass on an element will be checked for content.
No Metadata Dictionary check. The metadata dictionary will not be checked during the 2020-2021 school year to allow the Utah State Board of Education and schools time to adjust to changes in R277-487 related to allowable methods to meet the requirement.
Inclusion of two Center for Internet Security (CIS) controls. R277-487-3(1)(g) requires LEAs to share evidence that they have implemented a cybersecurity framework. For this year, we are requesting that LEAs will describe to what degree they have adopted CIS subcontrol 13.1 (classification of sensitive information) and CIS subcontrol 14.4 (encryption of sensitive information in transit). We will be reviewing these to understand the baseline of adoption; therefore, if you have not completed these yet, you may indicate as such without penalty.
Evidence collection. Evidence will again be collected via Qualtrics survey. The link to this survey will be included in the Student Data Privacy Newsletter and sent directly to data managers via email.
Subscribe to the Student Data Privacy Newsletter
1. Name and Contact Information of the LEAs Data Manager(s)
Not Applicable
Title 53E-9-303(2): Local Student Data Protection Governance
Utah State Legislature
2. Name and Contact Information of the LEAs Information Security Officer
Not Applicable
Rule R277-487: Public School Data Confidentiality and Disclosure
Utah Office of Administrative Rules
3. Copy Internet Link of your Annual Notification of Family Education Rights and Privacy Act (FERPA) Rights
FERPA Model Notification of Rights for Elementary and Secondary Schools
United States Department of Education
34 CFR 99.7: What Must an Educational Agency or Institution Include in its Annual Notification?
Cornell Law School Legal Information Institute (LII)
4. Copy Internet Link of your Directory Information Notice
Model Notice for Directory Information
United States Department of Education
34 CFR 99.37: What Conditions Apply to Disclosing Directory Information?
Cornell Law School Legal Information Institute (LII)
5. Copy Internet Link to your Student Data Collection Notice
6. Copy Internet Link to your Data Governance Plan
Title 53E-9-301(6): Definitions.
Utah State Legislature
7. Copy Internet Link Showing that your Metadata Dictionary is Available on your LEA Website
Title 53E-9-303(3)(b): Local Student Data Protection Governance
Utah State Legislature
8. Respond to Questions Regarding Adoption of Center for Internet Security (CIS) Controls
CIS Controls
Center for Internet Security (CIS)
SP 800-45 Version 2: Guidelines on Electronic Mail Security
National Institute for Standards and Technology (NIST)
SP 800-60 Volume 1 Revision 1 Guide for Mapping Types of Information and Information Systems to Security Categories
National Institute for Standards and Technology (NIST)
Secure Data Classifications and Approved Data Sharing Technologies Template
Rule R277-487: Public School Data Confidentiality and Disclosure
Utah Office of Administrative Rules
Consent to Disclose Student Data with a Website/Application
Data Manager Course Modules
Canvas
Family Educational Rights and Privacy Act (FERPA) Model Notice for Directory Information
FERPA Model Notification of Rights for Elementary and Secondary Schools
United States Department of Education