Annual Privacy Compliance Review
Annual Privacy Compliance Review
Each year, school districts and charter schools are required to submit evidence to the Student Data Privacy Team at USBE to demonstrate compliance with federal and state privacy regulations. This process is known as the annual privacy compliance review.
Webinar
In September 2024, a comprehensive webinar will be conducted to explain the requirements for the 2024-2025 Privacy Compliance Review. The webinar covers various aspects, including the metadata dictionary. You will be able to access the recorded video on our YouTube Channel. Links to an external site.
Responsibility for Submitting Privacy Compliance Review
For the 2024-2025 school year, your Local Education Agency (LEA) will need to complete four surveys as part of the privacy compliance review. Two of these surveys will be completed by the designated data manager(s) and the other two by the designated information security officer(s).
Data Manager Surveys (Responsibilities)
- Data Manager Contact Information Survey
- 2024-25 Privacy Compliance Review Survey
Information Security Officer Surveys (Responsibilities)
- Information Security Officer Contact Information Survey
- 2024-25 Cybersecurity Framework Survey
What, When, and How to Submit
Each LEA will complete these four surveys in the 2024-2025 school year. Here's a breakdown of each survey:
Data Manager Contact Information Survey
- Responsibility: Designated data manager(s)
- Link Distribution: In September 2024, a survey link will be emailed to all designated data managers.
- Survey Content: The survey will ask you to confirm your role, contact information, job title, job description, supervisor contact information, and additional optional questions to better understand your role in the LEA.
- Due Date: No specific due date, but we encourage prompt submission.
Information Security Officer Contact Information Survey
- Responsibility: Designated information security officer(s)
- Link Distribution: In September 2024, a survey link will be emailed to all designated information security officers.
- Survey Content: The survey will confirm your role, contact information, job title, job description, supervisor contact information, and may include optional questions to understand your role better.
- Due Date: No specific due date, but prompt submission is encouraged.
2024-25 Cybersecurity Framework Survey
- Responsibility: Primary designated information security officer (ISO)
- Link Distribution: In October 2024, a survey link will be emailed to primary information security officers.
- Due Date: The survey must be submitted by November 15, 2024. Contact John Lyman or Nicole Sanchez for extensions.
- Survey Content: The survey assesses your LEA's implementation of a cybersecurity framework and asks questions about cybersecurity training, among other non-technical aspects.
2024-25 Privacy Compliance Review Survey
- Responsibility: Primary designated data manager
- Link Distribution: In October 2024 a survey link will be emailed to primary data managers.
- Due Date: The survey must be submitted by November 15, 2024. Contact John Lyman or Nicole Sanchez for extensions.
- Survey Content: This survey requires evidence of compliance with federal and state privacy laws. Depending on your LEA's status, you may need to submit your metadata dictionary, Annual Notice of FERPA Rights, Directory Information Notice, Student Data Collection Notice, or Data Governance Plan.
Checking Previous Year's Performance
To check your LEA's performance in the previous year's privacy compliance review, look for a compliance report titled "Student Data Privacy Compliance Report 2023-2024" that was emailed to your data manager on January 10, 2024. Keep in mind that if you resubmitted, you likely have a newer report. If needed, contact John Lyman or Nicole Sanchez for a new copy of your Privacy Compliance Report.
Review Process
The Student Data Privacy Auditor at USBE will review the evidence submitted by your LEA. After the review, a report will be emailed to you to show the results of the compliance review.
Contact for Assistance
If you require assistance with preparing for or submitting your privacy compliance review, please contact John Lyman, Nicole Sanchez, or the USBE Student Data Privacy Team at privacy@schools.utah.gov.