Data Governance Objectives
- ongoing and transparent communication with parents and the community regarding data privacy practices.
- Establish a centralized data governance framework or enterprise architecture that all departments and stakeholders must adhere to, ensuring the confidentiality, integrity, and availability of district data.
- Develop and implement standardized policies to prevent the misuse of personal information related to students and employees.
- Regularly propose, develop, review, and update data security and privacy standards, procedures, and related documentation.
- Ensure district compliance with all applicable state and federal data privacy laws and regulations.
Student Data Collection and Security Fact Sheet
Employee Data Privacy Handbook
Data Governance Guidelines
Software FAQ
* Handbooks, procedures and guidelines are reviewed at least annually to provide updates that align with changes in laws/regulations and the constantly changing technology landscape.
Sharing Data with Vendors/Third-Parties
Goose Creek CISD takes the privacy of both student and staff data very seriously. Before procuring services or contracting with a third-party, a security risk assessment is performed. Much like a credit score is used in the lending process, a security risk score can reveal risks that a company would present and the likelihood they would suffer a data breach or other security incident. Goose Creek continuously monitors these third-parties in order to manage any risk that may occur and take appropriate proactive measures to keep district data secure. Secondly, if data will be shared with a vendor/third-party, a signed Data Privacy Agreement MUST be in place before a contract is signed. The current Data Privacy Agreement in use is the TX_NDPA_v1r6.
Records Management Compliance Training
- This required training describes and mandates that every staff member, elected official, or anyone serving the district is responsible for school district records.
- Records include any type of record about a student including paper or electronic forms is a legal requirement.
- It is a shared responsibility and is every person’s responsibility.
- All new hires are required to complete district-provided FERPA training.
- All staff complete mandatory trainings yearly that include trainings on FERPA, CIPPA, COPA, and other laws.
- The training is updated annually and regularly when new information is needed.
Records Management Board Policies
CPC (LEGAL) - OFFICE MANAGEMENT: RECORDS MANAGEMENT
CPC (LOCAL) - OFFICE MANAGEMENT: RECORDS MANAGEMENT
FL (LEGAL) - STUDENT RECORDS
FL (LOCAL) - STUDENT RECORDS
The Texas Local Government Records Act, Chapter 201
*Board Policy is reviewed regularly to ensure that they align with all current laws and regulations.
** Note: Local government records retention schedules are available on the TSLAC website.