POLICY MANUAL

School Service Providers' Use of Student Personal Information - Policy JRCA

Definitions
For the purposes of this policy:

"Elementary and secondary school purposes" means purposes that (i) customarily take place at the direction of an elementary or secondary school, elementary or secondary school teacher, or school division; (ii) aid in the administration of school activities, including instruction in the classroom or at home; administrative activities; and collaboration between students, school personnel or parents; or (iii) are otherwise for the use and benefit of an elementary or secondary school.

"Personal profile" does not include account information that is collected and retained by a school service provider and remains under control of a student, parent or elementary or secondary school.

"School-affiliated entity" means any private entity that provides support to the school division or a public elementary or secondary school. "School-affiliated entity" includes alumni associations, booster clubs, parent-teacher associations, parent-teacher-student associations, parent-teacher organizations, public education foundations, public education funds and scholarship organizations.

"School service" means a website, mobile application or online service that (i) is designed and marketed solely for use in elementary or secondary schools; (ii) is used (a) at the direction of teachers or other employees at elementary or secondary schools or (b) by any school-affiliated entity; and (iii) collects and maintains, uses or shares student personal information. "School service" does not include a website, mobile application or online service that is (a) used for the purposes of college and career readiness assessment or (b) designed and marketed for use by individuals or entities generally, even if it is also marketed for use in elementary or secondary schools.

"School service provider" means an entity that operates a school service pursuant to a contract with the school division.

"Student personal information" means information collected through a school service that identifies a currently or formerly enrolled individual student or is linked to information that identifies a currently or formerly enrolled individual student.

"Targeted advertising" means advertising that is presented to a student and selected on the basis of information obtained or inferred over time from such student's online behavior, use of applications, or sharing of student personal information. "Targeted advertising" does not include advertising (i) that is presented to a student at an online location (a) on the basis of such student's online behavior, use of applications or sharing of student personal information during his current visit to that online location or (b) in response to that student's request for information or feedback and (ii) for which a student's online activities or requests are not retained over time for the purpose of subsequent advertising.

Required Contract Terms
The contract between a school service provider and the School Board shall require the school service provider

  • to provide clear and easy-to-understand information about the types of student personal information it collects through any school service and how it maintains, uses or shares such student personal information;
  • to maintain a policy for the privacy of student personal information for each school service and provide prominent notice before making material changes to its policy for the privacy of student personal information for the relevant school service;
  • to maintain a comprehensive information security program that is reasonably designed to protect the security, privacy, confidentiality and integrity of student personal information and makes use of appropriate administrative, technological and physical safeguards;
  • to facilitate access to and correction of student personal information by each student whose student personal information has been collected, maintained, used or shared by the school service provider, or by such student's parent, either directly or through the student's school or teacher;
  • to collect, maintain, use and share student personal information only with the consent of the student or, if the student is less than 18 years of age, his parent or for the purposes authorized in the contract between the School Board and the school service provider;
  • when it collects student personal information directly from the student, to obtain the consent of the student or, if the student is less than 18 years of age, his parent before using student personal information in a manner that is inconsistent with its policy for the privacy of student personal information for the relevant school service, and when it collects student personal information from an individual or entity other than the student, to obtain the consent of the school division before using student personal information in a manner that is inconsistent with its policy for the privacy of student personal information for the relevant school service;
  • to require any successor entity or third party with whom it contracts to abide by its policy for the privacy of student personal information and comprehensive information security program before accessing student personal information; and
  • to require that, upon the request of the school or School Board, the school service provider will delete student personal information within a reasonable period of time after such request unless the student or, if the student is less than 18 years of age, his parent consents to the maintenance of the student personal information by the school service provider.

The contract will also prohibit the school service provider from knowingly

  • using or sharing any student personal information for the purpose of targeted advertising to students;
  • using or sharing any student personal information to create a personal profile of a student other than for elementary and secondary school purposes authorized by the school division, with the consent of the student or, if the student is less than 18 years of age, his parent, or as otherwise authorized in the contract between the school division and the school service provider; or
  • selling student personal information except to the extent that such student personal information is sold to or acquired by a successor entity that purchases, merges with or otherwise acquires the school service provider.

Nothing in this policy shall be construed to prohibit school service providers from

  • using student personal information for purposes of adaptive learning, personalized learning or customized education;
  • using student personal information for maintaining, developing, supporting, improving or diagnosing the school service;
  • providing recommendations for employment, school, educational or other learning purposes within a school service when such recommendation is not determined in whole or in part by payment or other consideration from a third party;
  • disclosing student personal information to (i) ensure legal or regulatory compliance, (ii) protect against liability or (iii) protect the security or integrity of its school service; or
  • disclosing student personal information pursuant to a contract with a service provider, provided that the school service provider (i) contractually prohibits the service provider from using any student personal information for any purpose other than providing the contracted service to or on behalf of the school service provider, (ii) contractually prohibits the service provider from disclosing any student personal information provided by the school service provider to any third party unless such disclosure is permitted by Va. Code § 22.1-289.01(B)(7) and (iii) requires the service provider to comply with the requirements set forth Va. Code § 22.1-289.01(B) and the prohibitions set forth in Va. Code § 22.1-289.01(C).

Nothing in this policy shall be construed to:

  • impose a duty upon a provider of an electronic store, gateway, marketplace, forum or means for purchasing or downloading software or applications to review or enforce compliance with this policy with regard to any school service provider whose school service is available for purchase or download on such electronic store, gateway, marketplace, forum or means;
  • impose liability on an interactive computer service, as that term is defined in 47 U.S.C. § 230(f), for content provided by another individual; or
  • prohibit any student from downloading, exporting, transferring, saving or maintaining his personal information, data or documents.

Adopted: July 12, 2016

Legal Refs.:

Code of Virginia, 1950, as amended, § 22.1-289.01.

Cross Ref.:

ET Educational Technology Foundation and Public School Foundations

JO Student Records

KMA Relations with Parent Organizations

 

Download JRCA pdf