Md. Code Ann., Educ. § 7-2102

Best Practices to Manage and Maintain Data Privacy

Effective Jul 1, 2018Added by Acts 2018, c. 381, § 1, eff. July 1, 2018.State of Maryland

The Department, in consultation with the Department of Information Technology and county boards, shall develop and update best practices for county boards to:

  1. (1) Manage and maintain data privacy and security practices in the processing of student data and personally identifiable information across the county board's information technology and records management systems;
  2. (2) Develop and implement:

    1. (i) A data privacy and security incident response plan;
    2. (ii) A breach notification plan; and
    3. (iii) Procedures and requirements for allowing access to student data and personally identifiable information for a legitimate research purpose; and
  3. (3) Publish information annually on:

    1. (i) Types of student data and personally identifiable information processed by the county board, the protocols for processing student data, and the rationales for selecting processing protocols;
    2. (ii) Contracted services that involve sharing student data between a county board and a school service contract provider; and
    3. (iii) Procedures and rationales for vetting and selecting Internet sites, services, and applications.

Added by Acts 2018, c. 381, § 1, eff. July 1, 2018.

Log InSign Up