Utah Administrative Code (Current through November 1, 2019) |
R277. Education, Administration |
R277-487. Public School Data Confidentiality and Disclosure |
R277-487-6. Responsibilities of Chief Privacy Officer
-
(1) The Chief Privacy Officer:
(a) may recommend legislation, as approved by the Board, for additional data security protections and the regulation of use of the data;
(b) shall supervise regular privacy and security compliance audits, following initiation by the Board;
(c) shall have responsibility for identification of threats to data privacy protections;
(d) shall develop and recommend policies to the Board and model policies for LEAs for:
(i) protection of personally identifiable student data;
(ii) consistent wiping or destruction of devices when devices are discarded by public education entities; and
(iii) appropriate responses to suspected or known breaches of data security protections;
(e) shall conduct training for Board staff and LEAs on student privacy; and
(f) shall develop and maintain a metadata dictionary as required by Section 53E-9-302.