Classcraft is committed to working with districts to help them comply with New York State’s latest privacy standards.
We work with districts to help them comply with New York State privacy standards.
Classcraft is a signatory to the Student Privacy Pledge and has standardized data security agreements in place under the Student Data Privacy Consortium, which has alliances in more than 20 US states.
If you have questions regarding Classcraft’s data security, please contact us at [email protected].
NYS Education Law Section 2-d calls for regulations that address a number of issues, such as:
§121.2
Education Agency Data Collection Transparency and Restrictions
§121.3
Parents Bill of Rights
§121.4
Handling Complaints of Breach or Unauthorized Release of Personally Identifiable Information (PII)
§121.5 and §121.6
Data Security and Privacy
§121.7
Training for Educational Agency Employees
§121.8
Educational Agency Data Protection Officer
§121.9
Third Party Contractors
§121.10
Reports and Notifications of Breach and Unauthorized Release
§121.11
Third Party Contractor Civil Penalties
§121.12
Right of Parents to Inspect and Review Student Education Records
Most of the regulations address obligations of the educational agencies to ensure their collection and use of PII is transparent and conforms to the standards outlined by Ed law 2-d.
Among other things, educational agencies are mandated to comply with the following:
Classcraft partners with educators to comply with state privacy standards and itself adheres to the following privacy policies:
Educational agencies maintain the obligation to ensure their contract with the contractor includes the contractor’s data security and privacy plan and that this is accepted by the educational agency. Furthermore, the plan must outline how the contractor will:
Key questions the third party contractor should answer in a Data Sharing and Confidentiality Agreement include:
Compliance with state, federal and local data security and privacy requirements
Classcraft management, specifically the Data Protection Officer and the Chief Financial Officer, perform reviews of the relevant state, federal and local requirements onan annual basis, minimum, to ensure they are aware of changes in these requirements. Data security policies are adjusted to meet any changes in these requirements within a reasonable delay. Classcraft adopts technologies, safeguards and practices that are in alignment with the NIST Cybersecurity Framework. Classcraft has clearly outlined what data is collected and how it will be used in the Classcraft Privacy Policy.
Safeguards to protect data security and confidentiality
Classcraft has taken the following safeguards and practices to safeguard protected data:
Data confidentiality training
Upon hiring, all Classcraft officers and employees are explained the nature of the data that Classcraft collects and the importance of data security, particularly as it relates to Personally Identifiable Information. Employees are required to acknowledge having read and understood the Classcraft Privacy Policy and must also sign a Confidentiality Agreement upon hiring.
How Classcraft works with NYS education agencies
Each agency in NYS is required to have a written contract with third party contractors. Part of this contract includes the agency’s own Parents’ Bill of Rights for Data Security and Privacy. Classcraft undertakes to adhere to the contracts it signs with each agency, including agreeing to the specific agency’s requirements for handling data breaches, and for the return, deletion and destruction of protected data.