A. The Department of Education shall develop, in collaboration with the Virginia Information Technologies Agency, and update regularly but in no case less than annually, a model data security plan for the protection of student data held by school divisions. Such model plan shall include (i) guidelines for access to student data and student data systems, including guidelines for authentication of authorized access; (ii) privacy compliance standards; (iii) privacy and security audits; (iv) procedures to follow in the event of a breach of student data; and (v) data retention and disposition policies. The model plan and any updates shall be made available to every school division.
B. The Department of Education shall designate a chief data security officer, with such state funds as made available, to assist school divisions, upon request, with the development and implementation of their own data security plans and to develop best practice recommendations regarding the use, retention, and protection of student data.
2015, c. 561.
Structure Code of Virginia
Chapter 2 - Board of Education
§ 22.1-8. General supervision vested in Board
§ 22.1-9. Appointment, terms, and vacancies
§ 22.1-9.1. Student Advisory Board established
§ 22.1-16. Bylaws and regulations generally
§ 22.1-16.1. Board to establish regulations regarding human research
§ 22.1-16.4. Nutrition and physical activity best practices database
§ 22.1-16.5. Training materials on human trafficking
§ 22.1-16.6. Guidelines for alternatives to suspension
§ 22.1-16.7. Regulations regarding endorsement to teach military science
§ 22.1-16.8. Instructional material; sexually explicit content; parental notification
§ 22.1-17. Statements concerning regulations
§ 22.1-17.01. Definition of "intervener."
§ 22.1-17.02. Definition of "student with limited or interrupted formal education"
§ 22.1-17.1. Regulations for reenrollment
§ 22.1-17.2. Nursing education programs
§ 22.1-17.3. Identification of student internship programs
§ 22.1-17.4. Certain honorary diplomas to be issued under specific circumstances
§ 22.1-17.5. Public notice and comment regarding certain resource guides
§ 22.1-17.7. Social-emotional learning guidance standards
§ 22.1-18.01. Biennial review of the standards of quality required; budget estimates
§ 22.1-19.1. Action for violations related to secure mandatory tests
§ 22.1-20. Retention of pupil personnel records
§ 22.1-20.2. Student data security
§ 22.1-20.3. Granting easements across lands of certain schools and institutions
§ 22.1-20.4. Alternative assessments for students who are English language learners