Data Confidentiality

R277-487, 34 CFR 99, 53E

1. Governing Principles

LEA takes its responsibility toward student data seriously. This governance plan incorporates the following Generally Accepted Information Principles (GAIP):

  1. Risk: There is risk associated with data and content. The risk must be formally recognized, either as a liability or through incurring costs to manage and reduce the inherent risk.

  2. Due Diligence: If a risk is known, it must be reported. If a risk is possible, it must be confirmed.

  3. Audit: The accuracy of data and content is subject to periodic audit by an independent body.

  4. Accountability: An organization must identify parties which are ultimately responsible for data and content assets.

  5. Liability: The risks in information means there is a financial liability inherent in all data or content that is based on regulatory and ethical misuse or mismanagement.

2. Data Maintenance and Protection Policy

The LEA recognizes that there is risk and liability in maintaining student data and other education-related data and will incorporate reasonable data industry best practices to mitigate this risk. 

2.1 Process

In accordance with R277-487, the LEA shall do the following:

  1. Designate an individual as an Information Security Officer

  2. Adopt the CIS Controls or comparable

  3. Report to the USBE by October 1 each year regarding the status of the adoption of the CIS controls or comparable and future plans for improvement.

3. Roles and Responsibilities Policy

The LEA acknowledges the need to identify parties who are ultimately responsible and accountable for data and content assets. These individuals and their responsibilities are as follows:

3.1 Data Manager roles and responsibilities

  1. authorize and manage the sharing, outside of the student data manager's education entity, of personally identifiable student data for the education entity as described in this section

  2. provide for necessary technical assistance, training, and support

  3. act as the primary local point of contact for the state student data officer

  4. ensure that the following notices are available to parents: 

    1. annual FERPA notice (see 34 CFR 99.7), 

    2. directory information policy (see 34 CFR 99.37),

    3. survey policy and notice (see 20 USC 1232h and 53E-9-203), 

    4. data collection notice (see 53E-9-305)

3.2 Information Security Officer

  1. Oversee adoption of the CIS controls

  2. Provide for necessary technical assistance, training, and support as it relates to IT security

4. Training and Support Policy

The LEA recognizes that training and supporting educators and staff regarding federal and state data privacy laws is a necessary control to ensure legal compliance. 

4.1 Procedure

  1. The data manager will ensure that educators who have access to student records will receive an annual training on confidentiality of student data to all employees with access to student data. The content of this training will be based on the Data Sharing Policy. 

  2. By October 1 each year, the data manager will report to USBE the completion status of the annual confidentiality training and provide a copy of the training materials used.

  3. The data manager shall keep a list of all employees who are authorized to access student education records after having completed a training that meets the requirements of 53E-9-204.

5. Audit Policy

In accordance with the risk management priorities of the LEA, the LEA will conduct an audit of: 

  1. The effectiveness of the controls used to follow this data governance plan; and

  2. Third-party contractors, as permitted by the contract described in 53E-9-309(2). 

6. Data Sharing Policy

There is a risk of redisclosure whenever student data is shared. The LEA shall follow appropriate controls to mitigate the risk of redisclosure and to ensure compliance with federal and state law.

6.1 Procedure

  1. The data manager shall approve all data sharing or designate other individuals who have been trained on compliance requirements with FERPA.

  2. For external research, the data manager shall ensure that the study follows the requirements of FERPA’s study exception described in 34 CFR 99.31(a)(6).

  3. After sharing from student records, the data manager shall ensure that an entry is made in the LEA Metadata Dictionary to record that the exchange happened.

  4. After sharing from student records, the data manager shall make a note in the student record of the exchange in accordance with 34 CFR 99.32.

7. Expungement Request Policy

The LEA recognizes the risk associated with data following a student year after year that could be used to mistreat the student. The LEA shall review all requests for records expungement from parents and make a determination based on the following procedure.

7.1 Procedure

The following records may not be expunged: grades, transcripts, a record of the student’s enrollment, assessment information.

The procedure for expungement shall match the record amendment procedure found in 34 CFR 99, Subpart C of FERPA.

  1. If a parent believes that a record is misleading, inaccurate, or in violation of the student’s privacy, they may request that the record be expunged.

  2. The LEA shall decide whether to expunge the data within a reasonable time after the request.

  3. If the LEA decides not to expunge the record, they will inform the parent of their decision as well as the right to an appeal hearing.

  4. The LEA shall hold the hearing within a reasonable time after receiving the request for a hearing.

  5. The LEA shall provide the parent notice of the date, time, and place in advance of the hearing.

  6. The hearing shall be conducted by any individual that does not have a direct interest in the outcome of the hearing.

  7. The LEA shall give the parent a full and fair opportunity to present relevant evidence. At the parents’ expense and choice, they may be represented by an individual of their choice, including an attorney.

  8. The LEA shall make its decision in writing within a reasonable time following the hearing.

  9. The decision must be based exclusively on evidence presented at the hearing and include a summary of the evidence and reasons for the decision.

  10. If the decision is to expunge the record, the LEA will seal it or make it otherwise unavailable to other staff and educators.

8. Data Breach Response Policy

The LEA shall follow industry best practices to protect information and data. In the event of a data breach or inadvertent disclosure of personally identifiable information, the LEA staff shall follow industry best practices for responding to the breach.

8.1 Procedures 

  1. The Director will work with the information security officer to designate individuals to be members of the cyber incident response team (CIRT)

  2. At the beginning of an investigation, the information security officer will begin tracking the incident and log all information and evidence related to the investigation.

  3. The information security officer will call the CIRT into action once there is reasonable evidence that an incident or breach has occurred.

  4. The information security officer will coordinate with other IT staff to determine the root cause of the breach and close the breach.

  5. The CIRT will coordinate with legal counsel to determine if the incident meets the legal definition of a significant breach as defined in R277-487 and determine which entities and individuals need to be notified. 

  6. If law enforcement is notified and begins an investigation, the CIRT will consult with them before notifying parents or the public so as to not interfere with the law enforcement investigation.

 

9. Publication Policy

The LEA recognizes the importance of transparency and will post this policy on the LEA website.

Canyon Grove Academy SMS Text Messaging Policy & Terms of Service

Last Updated: [Date]

Canyon Grove Academy uses SMS text messaging to communicate important information, emergencies, and routine updates to parents, guardians, and staff. This page outlines our SMS Terms of Service and Privacy Policy to ensure compliance with the Telephone Consumer Protection Act (TCPA), the Family Educational Rights and Privacy Act (FERPA), the Utah Student Data Protection Act (USDPA), and mobile carrier 10DLC regulations.

By opting in to receive SMS messages from [School Name], you agree to the following terms and our data privacy practices.

SMS Terms of Service

1. Types of Messages

Canyon Grove Academy utilizes text messaging to deliver two categories of communications:

  • Emergency & Safety Alerts: Time-sensitive notifications regarding weather closures (e.g., snow days), lockdowns, safety threats, or immediate health emergencies.

  • Routine Educational Updates: Reminders regarding parent-teacher conferences, attendance (unexcused absences/tardies), grade reports, lunch balances, and general school events.

2. Opting In (Consent)

Consent to receive automated routine messages is obtained during student registration or by texting a designated keyword SCHOOL to our shortcode/phone number. Opting in to SMS messages is not a condition of enrollment or receiving educational services from Canyon Grove Academy.

Note: In accordance with FCC regulations, providing your phone number to [School Name] for emergency contact purposes grants us the right to send Emergency & Safety Alerts without explicit prior opt-in.

3. Message Frequency and Costs

Message frequency will vary based on the school calendar, individual teacher updates, and unforeseen events. Standard message and data rates may apply depending on your mobile carrier plan. [School Name] is not responsible for any fees charged by your cellular provider for receiving these messages.

4. Opting Out (Revoking Consent)

You may opt out of receiving routine SMS messages at any time.

  • To stop receiving texts: Reply STOP, QUIT, CANCEL, OPT-OUT, or UNSUBSCRIBE to any message you receive from us.

  • After texting STOP, you will receive one final confirmation message stating that you have been unsubscribed.

Please note: Opting out of routine updates may not automatically opt you out of critical Emergency & Safety Alerts. To remove your number entirely from all school systems, please contact the main office.

5. Getting Help

If you are experiencing issues with the messaging program or need assistance, reply HELP to any message you receive, or contact our administration office at 801 785 9300. 

SMS Privacy Policy

[School Name] is committed to protecting the privacy of our students, parents, and staff. This section dictates how we handle the mobile data collected for SMS communications.

1. Information We Collect

When you opt in to our SMS program, we collect and store:

  • Your mobile phone number.

  • Your explicit consent data (the time, date, and method of your opt-in).

  • Your association with a student(s) enrolled at Canyon Grove Academy.

2. Use of Information

Your mobile phone number and consent data will be used solely for the purpose of sending authorized school communications as described in the Terms of Service above.

3. Strict Non-Sharing Policy (10DLC Compliance)

To comply with strict mobile carrier regulations (A2P 10DLC) and Utah student data laws, we maintain a strict non-sharing policy:

No mobile information, phone numbers, or SMS consent data will be shared with, sold to, or distributed to any third parties or affiliates for marketing or promotional purposes.

The only exception to this rule is sharing your data with our contracted, FERPA-compliant software service providers (e.g., our Student Information System or secure messaging vendor) strictly for the purpose of delivering the messages on behalf of Canyon Grove Academy. These vendors are bound by Data Privacy Agreements (DPAs) with the State of Utah and are legally prohibited from utilizing your data for any other purpose.

4. Educational Privacy (FERPA)

Because SMS text messaging is not an encrypted or perfectly secure medium, Canyon Grove Academy staff will not transmit highly sensitive educational records via text message. Specific grades, behavioral incidents, Special Education/IEP data, or sensitive health information will be communicated via secure email, phone call, or our encrypted parent portal.

5. Data Security

We implement reasonable security measures and access controls to protect your phone number and consent data from unauthorized access or disclosure, in accordance with the Utah Student Data Protection Act.

6. Changes to This Policy

Canyon Grove Academy reserves the right to modify these Terms of Service or Privacy Policy at any time. Any changes will be posted on this page with an updated effective date.

Contact Us:

If you have questions about this policy or our data practices, please contact:

it@canyongrove.com