700,000+

Students Protected

157 districts and charters+

Districts & Charters

5,406

Vendor Agreements

β€”

Days Left

SB 267 Enforcement: July 1, 2026

Utah LEAs must evaluate edtech products for addictive design, data practices, and academic effectiveness before adoption. Districts with expired DPAs face immediate compliance gaps.

πŸ‘₯ Key Roles

Data Manager

Utah Code 53E-9-303

Required

Responsibilities:

  • β€’ Serving as the primary contact for USBE's student data privacy team
  • β€’ Completing annual compliance checks, including the Privacy Practices Benchmark
  • β€’ Overseeing privacy practices in your LEA (policies, DPAs, data sharing)
  • β€’ Collaborating with the information security officer
  • +1 more...

First Steps:

  • 1. Sign up for the Student Data Privacy newsletter
  • 2. Schedule one-hour onboarding meeting with USBE specialist
  • 3. Complete Data Manager Course on Canvas

Information Security Officer (ISO)

Recommended

Responsibilities:

  • β€’ Serving as the primary cybersecurity contact for USBE's Student Data Privacy Team
  • β€’ Completing annual compliance checks, including cybersecurity components of Privacy Practices Benchmark
  • β€’ Overseeing implementation of a cybersecurity framework (per Board Rule R277-487)
  • β€’ Collaborating with data manager to respond to data incidents and breaches
  • +1 more...

First Steps:

  • 1. Sign up for Student Data Privacy newsletter
  • 2. Familiarize with cybersecurity framework your LEA has adopted
  • 3. Attend conferences and professional learning opportunities

Appointed Records Officer (ARO)

Required

Responsibilities:

  • β€’ Establish and enforce protocols for controlling access to student records
  • β€’ Manage and maintain data retention policies
  • β€’ Provide guidance and training to LEA staff on record management
  • β€’ Act as liaison between LEAs, parents, and state authorities
  • +1 more...

First Steps:

  • 1. Complete Records Officer Certification Course
  • 2. Review Educational Retention Schedule
  • 3. Familiarize with Quick Disposition Guide

πŸ“ž Key Contacts

Nicole Sanchez

Student Data Privacy Specialist

privacy@schools.utah.gov

Jeremy Zabriskie

Data Privacy and Security Specialist

privacy@schools.utah.gov

Maren Peterson

Local/State Agency RIM Specialist, Utah State Archives

marenpeterson@utah.gov(801) 531-3866

πŸ“š Resources

πŸ“„ DPA Templates

  • National Data Privacy Agreement (NDPA) v2.2

    Current standard template (released November 2025) with all exhibits. Used by SDPC member states nationwide.

  • National Research Student Data Privacy Agreement (NRDPA)

    Template for research partnerships

  • Early Interactive Software Provider NDPA (EISP-NDPA)

    Specialized template for early education software

  • A Vendor's Guide to Utah DPAs

    Comprehensive guide explaining Utah requirements for vendors

πŸ“– Guides

  • Data Manager Onboarding Slides

    Presentation for new data managers

  • Privacy Principles One-pager

    Quick reference for core privacy principles

  • Cyber Threats vs. Digital Threats One-pager

    Understanding the difference between threat types

  • Data Breach Reporting and Notification Requirements

    Step-by-step guide for breach response

  • 2024 H.B. 182 Guidance for LEA Leaders on Student Surveys

    Legislative guidance on survey compliance

πŸŽ“ Training

  • Data Privacy Basics

    Foundation course for all staff

  • Handling Employee Data

    Privacy training for HR and administrative staff

  • Office Staff Training

    Privacy training for front office personnel

  • Sharing Data with Law Enforcement

    Guidelines for legal data disclosure requests

  • 2025 Annual Privacy Practices Benchmark Webinar

    Annual compliance training

πŸ”§ Tools

  • Utah Vendor Agreement Registry

    Searchable database of 1,200+ vendor and product agreementsβ€”DPAs, NDPA exhibits, and statewide contracts

    Access β†’
  • IAMSAFE Framework

    7-step edtech evaluation: Inventory, Appraise, Map, Score, Act, File, Evaluate. Designed for SB 267 compliance.

    Access β†’
  • Academic Effectiveness Rubric

    6-dimension, 5-star scoring system aligned to ESSA evidence tiers. Evaluates pedagogy, engagement, accessibility, data practices, addictive design, and equity.

    Access β†’
  • USPA Application Menu

    Google Sheet tracking approved apps statewide

  • Utah DPA Negotiation Tracker Form

    Submit new DPA negotiations

  • Utah DPA Negotiation Tracker Sheet

    Dashboard of all ongoing negotiations

  • USBE Data Breach Reporting Form

    Official form for reporting breaches to USBE

πŸ”„ Workflows

Vendor Approval Workflow

Process for approving new educational technology vendors

1Request Received
β†’
2Check Registry
β†’
3Evaluate Status
β†’
4Vendor Signs
β†’
5Upload to Registry
β†’
6Approve

Data Breach Response Workflow

Process for responding to data security incidents

1Incident Discovered
β†’
2ISO Notifies
β†’
3Assess Impact
β†’
4Report to USBE
β†’
5Report to Cyber Center
β†’
6Notify Affected
β†’
7Document & Remediate
β†’
8Follow-up Review

Annual Compliance Workflow

Annual Privacy Practices Benchmark submission process

1Announcement
β†’
2Data Manager Survey
β†’
3ISO Components
β†’
4Submit
β†’
5Address Gaps
β†’
6Document

GRAMA Request Workflow

Process for handling public records requests

1Request Received
β†’
2ARO Review
β†’
3Classify Records
β†’
4Legal Consult
β†’
5Prepare Records
β†’
6Redact
β†’
7Respond
β†’
8Document

βœ… Compliance Requirements

● Mandatory Designations

  • βœ“ Data Manager (Utah Code 53E-9-303) - REQUIRED
  • βœ“ Information Security Officer - REQUESTED
  • βœ“ Appointed Records Officer - REQUIRED (Annual certification)

● Annual Requirements

  • βœ“ Privacy Practices Benchmark submission
  • βœ“ Cybersecurity framework compliance review
  • βœ“ Records Officer recertification
  • βœ“ Privacy policy updates
  • βœ“ Staff training completion

● Ongoing Requirements

  • βœ“ DPA management with all vendors accessing student data
  • βœ“ SB 267 edtech product evaluations (effective July 1, 2026)
  • βœ“ Data breach reporting (within required timelines)
  • βœ“ GRAMA request responses
  • βœ“ Participation in USPA
  • βœ“ Newsletter subscription and monitoring

Ready to validate your knowledge?

Take the ABYA Privacy & AI Governance Certification to demonstrate your district's compliance readiness.

Start certification β†’