First comes privacy. Then comes innovation.

Classcraft is committed to working with districts to help them comply with New York State’s latest privacy standards.

We work with districts to help them comply with New York State privacy standards.

Classcraft’s NYS privacy fact sheet

Our commitment to privacy

Classcraft is a signatory to the Student Privacy Pledge and has standardized data security agreements in place under the Student Data Privacy Consortium, which has alliances in more than 20 US states.

If you have questions regarding Classcraft’s data security, please contact us at [email protected].

Overview: New York State Education Law Section 2-d

NYS Education Law Section 2-d calls for regulations that address a number of issues, such as:

§121.2
Education Agency Data Collection Transparency and Restrictions

§121.3
Parents Bill of Rights

§121.4
Handling Complaints of Breach or Unauthorized Release of Personally Identifiable Information (PII)

§121.5 and §121.6
Data Security and Privacy

§121.7
Training for Educational Agency Employees

§121.8
Educational Agency Data Protection Officer

§121.9
Third Party Contractors

§121.10
Reports and Notifications of Breach and Unauthorized Release

§121.11
Third Party Contractor Civil Penalties

§121.12
Right of Parents to Inspect and Review Student Education Records

Most of the regulations address obligations of the educational agencies to ensure their collection and use of PII is transparent and conforms to the standards outlined by Ed law 2-d.

Among other things, educational agencies are mandated to comply with the following:

  • Not sell PII or use it for marketing or commercial purposes — or allow others to do so
  • Minimize data collection and transmission
  • Ensure that third party contractors have data sharing agreements that require the confidentiality of the data and that data must be maintained in accordance with federal and state laws — as well as the educational agency’s own data security and privacy policy
  • Develop and publish their own Parent Bill of Rights for Data Privacy and Security
  • Include the Parent Bill of Rights in each contract with third parties who receive PII
  • Ensure that contracts with third parties include supplemental information on how the third party contractor will ensure compliance with applicable state and federal laws
  • Establish and communicate procedures for data breaches
  • Adopt the NIST Cybersecurity Framework for improving data security

Classcraft works with districts to achieve legislative compliance

Classcraft partners with educators to comply with state privacy standards and itself adheres to the following privacy policies:

  • Classcraft does not use PII for marketing or commercial purposes and does not allow any third parties to use PII for marketing or commercial purposes.
  • Classcraft does not collect Teacher or Principal Data as defined by Education Law Section 2-d Part 121.1.
  • Classcraft only collects information that is required to deliver the Classcraft product. The collected data is fully explained in the Classcraft Privacy Policy.
  • Classcraft educates all employees who may have access to PII on the confidential nature of the data and has each employee sign a Personal Data Security Agreement.
  • Classcraft restricts access to those employees who need access in order to provide the contracted services. Employees do not normally interact directly with students but instead work with teachers and administrators who use Classcraft.
  • Classcraft does not use the PII for any purpose that is not explicitly covered in its contract with the educational agency.
  • Classcraft deletes all PII upon instruction from the educational agency; failing specific instructions, data is deleted according to the Classcraft Privacy Policy.
  • COPPA compliance: Classcraft can be used with students under the age of 13. As students can only use Classcraft if they are invited by their teacher, Classcraft relies on the educational agency and its staff to ensure that the correct parental approvals have been obtained. Often this is done using a blanket software approval form. However, should a Classcraft-specific form be required, we are able to provide sample forms.
  • FERPA Compliance: Under the contracts with educational agencies, Classcraft is designated as a school official and has a legitimate educational interest in student data. Classcraft has a procedure in place to allow parents and students over the age of 18 to review and request changes to their data collected by the Classcraft platform, and works with educational agencies to accomodate all such requests. This procedure can be found under the heading “Changes to and Access to Personal Information” in the Classcraft Privacy Policy - https://www.hmhclasscraft.com/privacy-policy/.
  • In the event of a data breach, Classcraft will work closely with the education agency to remedy and inform affected users according to the procedures outlined in the Classcraft Privacy Policy and the contract with the education agency.

Responsibilities of NYS educational agencies regarding third-party contractors

Educational agencies maintain the obligation to ensure their contract with the contractor includes the contractor’s data security and privacy plan and that this is accepted by the educational agency. Furthermore, the plan must outline how the contractor will:

  • Implement security regulations in a manner consistent with the educational agency’s own policies
  • Specify the security measures in place
  • Demonstrate that the contract describes the policies for data deletion, parent access to data, and security measures that will be in place

Key questions the third party contractor should answer in a Data Sharing and Confidentiality Agreement include:

  1. What will the contractor do to ensure compliance with state, federal and local data security and privacy requirements?
  2. What administrative, technical, and other safeguards does the contractor have in place to protect the security and confidentiality of the data?
  3. What training will the contractor provide for its officers, employees and subcontractors regarding the laws governing the confidentiality of the data prior to receiving access to it?

Classcraft data sharing and confidentiality policies

Compliance with state, federal and local data security and privacy requirements

Classcraft management, specifically the Data Protection Officer and the Chief Financial Officer, perform reviews of the relevant state, federal and local requirements onan annual basis, minimum, to ensure they are aware of changes in these requirements. Data security policies are adjusted to meet any changes in these requirements within a reasonable delay. Classcraft adopts technologies, safeguards and practices that are in alignment with the NIST Cybersecurity Framework. Classcraft has clearly outlined what data is collected and how it will be used in the Classcraft Privacy Policy.

Safeguards to protect data security and confidentiality

Classcraft has taken the following safeguards and practices to safeguard protected data:

  1. Assign a Data Protection Officer to ensure compliance with Classcraft security policies
  2. Maintain an inventory of authorized devices
  3. Maintain an inventory of authorized software
  4. Maintain secure configurations for hardware and software on all mobile devices, workstations and servers, including encryption of data both in transit and at rest
  5. Perform periodic vulnerability assessments
  6. Maintain a control system for use of administrative privileges
  7. Maintain audit logs
  8. Maintain email and web browser protections
  9. Install malware defences
  10. Limit and control network ports, protocols and services
  11. Maintain a data recovery protocol
  12. Control access to data based on a need-to-know basis
  13. Maintain wireless access controls
  14. Maintain account monitoring and control
  15. Utilize application security software
  16. Maintain an incident response plan

Data confidentiality training

Upon hiring, all Classcraft officers and employees are explained the nature of the data that Classcraft collects and the importance of data security, particularly as it relates to Personally Identifiable Information. Employees are required to acknowledge having read and understood the Classcraft Privacy Policy and must also sign a Confidentiality Agreement upon hiring.

How Classcraft works with NYS education agencies

Each agency in NYS is required to have a written contract with third party contractors. Part of this contract includes the agency’s own Parents’ Bill of Rights for Data Security and Privacy. Classcraft undertakes to adhere to the contracts it signs with each agency, including agreeing to the specific agency’s requirements for handling data breaches, and for the return, deletion and destruction of protected data.