Data Privacy, Security, and Safety

Security and Safety in Technology at Westhill

The technology department works very hard to keep the physical network secure. Students and Staff can help by being aware of phishing scams and visiting inappropriate or sketchy websites.

State and Federal Laws for Students

Westhill CSD adheres to the following federal and state laws:

  • CIPA - Child Internet Protection Act (FederaL)

  • COPPA - Children's Online Privacy Protection Act (Federal)

  • FERPA - Family Education Rights and Privacy Act (US Dep of Ed)

  • HIPPA - Health Information Privacy Protection Act (US Dep of Health)

  • NYS Ed Law 2d and Regulations 121 - Student data privacy protection law

Parents Bill of Rights for Data Privacy and Security

The NYS Education Department’s Education Law §2-d

Bill of Rights for Data Privacy and Security


Parents and eligible students can expect the following:

  1. A student’s personally identifiable information (PII) cannot be sold or released for any commercial purpose

  2. The right to inspect and review the complete contents of the student’s education record stored or maintained by an educational agency.

  3. State and federal laws, such as NYS Education Law §2-d and the Family Educational Rights and Privacy Act, that protect the confidentiality of a student’s PII, and safeguards associated with industry standards and best practices, including but not limited to, encryption, firewalls, and password protection, must be in place when data is stored or transferred.

  4. A complete list of all student data elements collected by NYSED is available for public review at www.nysed.gov/data-privacy-security, and by writing to: Chief Privacy Officer, New York State Education Department, 89 Washington Avenue, Albany, NY 12234.

  5. The right to have complaints about possible breaches and unauthorized disclosures of student data addressed. Complaints may be submitted to NYSED online at www.nysed.gov/data-privacy-security, by mail to: Chief Privacy Officer, New York State Education Department, 89 Washington Avenue, Albany, NY 12234, by email to privacy@nysed.gov, or by telephone at 518-474-0937.

  6. To be notified in accordance with applicable laws and regulations if a breach or unauthorized release of their student’s PII occurs.

  7. Educational agency workers that handle PII will receive training on applicable state and federal laws, the educational agency’s policies, and safeguards associated with industry standards and best practices that protect PII.

  8. Educational agency contracts with vendors that receive PII will address statutory and regulatory data privacy and security requirements.

"Parent" means a parent, legal guardian, or person in parental relation to a student. These rights may not apply to parents of eligible students defined as a student eighteen years or older. "Eligible Student" means a student 18 years and older.

"Personally identifiable information," as applied to student data, means personally identifiable information as defined in section 99.3 of title thirty-four of the code of federal regulations implementing the family educational rights and privacy act, section twelve hundred thirty-two-g of title twenty of the United States code, and, as applied to teacher or principal data, means "personally identifying information" as such term is used in subdivision ten of section three thousand twelve-c of this chapter.

Information about other state and federal laws that protect student data such as the Children's Online Privacy Protection Act, the Protection of Pupil Rights Amendment, and NY’s Personal Privacy Protection Law can be found at http://www.nysed.gov/student-data-privacy/federal-laws-protect-student-data.


For a list of third party apps that have a signed contract agreement with Westhill to keep student and teacher data safe, please visit this document. To see individual contracts click here.

Network Security, Compliance, and Disaster Recovery at Westhill

Here is how we do our best to keep the network and data safe at Westhill:

  1. Utilize the most up to date firewall system (maintained by BOCES).

  2. Installed one of the industry leaders in antivirus and anti malware software called Crowdstrike on all district computers.

  3. We do not allow anyone to download and install software without IT.

  4. Internet traffic is filtered (CIPA) for staff and students for inappropriate material.

  5. Student Chromebooks are filtered with GoGuardian at home and at school for inappropriate material (CIPA).

  6. When signed into Chrome on other devices, safe search is enforced in Google.

  7. Our servers are maintained regularly and security patches are applied when needed.

  8. Our servers are backed up both virtually and on a physical tape off network.

  9. Depending on a student's age, they cannot receive email from outside the district to keep them safe from phishing scams and unsolicited outside communication.

  10. We do not allow the use of online sites unless the vendor adheres to EdLaw2d by signing an agreement with Westhill or BOCES that they will not share student information outside the company. (See state and federal law section)

Staff Training

All staff with access to email are being trained in security awareness and data privacy laws once a year.