New York State Education Department Logo

DPO NEWSLETTER

NYSED Privacy Office

October 2025

Happy Cybersecurity Awareness Month!

 

NYSED Information Security Office Data Security Reviews:


Thank you for your continued partnership in reviewing your security posture; our goal is to support you not just during the reviews but moving forward with any questions.

 

To date, our overall review of all LEAs statewide are:

  • 76 completed in 2024, 117 completed in 2025
  • 911 School Districts + Charter Schools left to go
  • 6.9% of schools were completed at the end of 2024; as of now, it is 10.6%

Cybersecurity Incident Reports

Recently enacted General Municipal Law Article 19-c requires all New York State public school districts to report to the New York State Division of Homeland Security and Emergency Services:


  1.  Any cybersecurity incident and/or any demand for ransom within 72 hours after reasonably identifying a cybersecurity incident has occurred.
  2.  A ransom payment within 24 hours of payment.
  3.  A ransom payment explanation within 30 days of payment. 



For more information about this new requirement, visit the DHSES website on Cybersecurity Incident and Ransom Payment Reporting

 

Educational agencies must continue to report data incidents pursuant to Education Law § 2-d. Data incident reporting to NYSED remains unchanged.

The New York State and Local Cybersecurity Grant Program (SLCGP)

The New York State and Local Cybersecurity Grant Program (SLCGP) is a grant opportunity for school districts related to the procurement of multi-factor authentication tokens. The deadline for this grant is on October 22, 2025.

 

For more information, please see the following:



 

Questions about this program should be directed to the Division of Homeland Security and Emergency Services at Grant.Info@dhses.ny.gov.



SDPC Resource Registry Updates and Reminder


A data privacy agreement (DPA) is a contract between two parties that states the rights and obligations of each party concerning the protection of sensitive data. In accordance with Education Law § 2-d, education agencies in New York State enter into DPAs with vendors and third-party contractors to support the protection of student data and certain staff data (such as protected APPR data). 

 

One tool to alleviate the burden of entering DPAs with vendors is the SDPC Resource Registry. The Registry streamlines the DPA process. 

 

There are currently 12 RICS, 37 BOCES, and 615 School District actively represented within the registry which allows 1,400 users access to NYS Standardized DPAs.

 

There are currently 1,260 Vendors representing over 2,084 DPAs that are available to NYS educational entities.

 

If your school district would like to learn more about the Resource Registry, please contact your local RIC. Charter schools can contact RICDPAsupport@ricone.org.  

Save the Date


RIC One Data Privacy and Security Service (DPSS) 5th Annual Statewide Conference


March 24 & 25, 2026


Turning Stone Resort Casino


Verona, NY

Directory Information Policy Resources


The Privacy Office published new resources regarding FERPA’s directory information exception, which are available at the bottom of this page on the Data Privacy website.


Questions?

You can contact us at privacy@nysed.gov.

NYSED Privacy Office

Whitney Braunlin, Chief Privacy Officer