Skip to content
Council Discourse

NYC Council meetings, chaptered and linked by time.

Created by Uzair Qadir

Inspired by Vikram Oberoi's City Meetings

Q&A

Avilés questions DOE on state comptroller audit findings

New York City Council · Jun 24, 2026 · starts 1:16:45 · 5 min 54 sec

Councilmember Avilés cites the May 2026 state comptroller audit finding DOE lacks written data classification policies, risk assessment, and backup/recovery procedures required by the NIST framework under EdLaw 2D. Dennis Doyle responds that DOE complies with privacy laws, accepted audit recommendations, and is implementing improvements including a formal data classification policy.

Alexa Avilés

Yeah, thank you.

Alexa Avilés

Thank you so much, Chairs, for this important hearing.

Alexa Avilés

I guess I'd like to ask the administration around issues of privacy.

Alexa Avilés

I certainly was one of those council members who is deeply concerned about, you know, kind of this...

Alexa Avilés

What we don't know what's happening in our schools related to AI and student use, direct usage of AI.

Alexa Avilés

So I'm deeply concerned about privacy.

Alexa Avilés

As you all know, on May 4th, the state comptroller's office released a really scathing audit, finding that the New York City Public Schools maintains no written policies for data classification, risk assessment.

Alexa Avilés

Or backup and recovery as required by the NIST data security framework specified by EdLaw 2D.

Alexa Avilés

So given that that law was passed in 2014, why has the DOE failed to develop these policies that's making, obviously, these data breaches, which are profoundly concerning, more likely and harder to respond to?

Danielle Junta

Thank you for that question and I just want to let you know we have our chief data privacy officer with us today who's going to respond.

Dennis Doyle

Yeah, thank you.

Dennis Doyle

Thank you for the question.

Dennis Doyle

I just want to start out by saying obviously student privacy is of the utmost importance to New York City Public Schools.

Dennis Doyle

And we did work with the New York State Comptroller on this audit over the last few years.

Dennis Doyle

We submitted a formal response to that audit that sort of explains that we comply with all federal, state, and local privacy laws.

Dennis Doyle

In some cases, we go beyond what the law requires.

Dennis Doyle

But that we're always working continuously to try to improve our data privacy practices.

Dennis Doyle

And while we disagree with some of the findings in the New York State Comptroller's audit report, we did accept and agree the recommendations that were made in that report.

Dennis Doyle

To some extent, we assert that we already comply with the recommendations in that report.

Dennis Doyle

And one example is actually, as you're referring to, is the requirement that we align with the NIST cybersecurity framework.

Dennis Doyle

This is something that we...

Dennis Doyle

We use, as you've noted,

Dennis Doyle

Were required by New York State Education Law Section 2D to align with the NIST Cybersecurity Framework.

Dennis Doyle

And just a point on that, the NIST Cybersecurity Framework is not necessarily a checklist of requirements for organizations to follow.

Dennis Doyle

It's a framework for assessing an organization's cybersecurity posture and to continuously evaluate it and to try to continuously improve it.

Dennis Doyle

And so we have been implementing the NIST cybersecurity framework.

Dennis Doyle

With that said, we recognize that there are improvements that we plan on making.

Dennis Doyle

One is to update our data privacy and security policies page, which we will be doing in the coming months.

Dennis Doyle

We will also be issuing a formal written data classification policy.

Dennis Doyle

We do have a data classification policy.

Dennis Doyle

It's documented in a few different places, but we want to make sure that we have a very clear, formal data classification policy for that.

Dennis Doyle

We're also, as has been mentioned earlier in this hearing, working with the schools to make sure we have a better understanding of the tools that they're using to make sure that it's in compliance with their data privacy and security policies.

Dennis Doyle

Another thing noted in the audit report was the timeliness of notifications.

Dennis Doyle

We're also improving on that front.

Dennis Doyle

I think if you read the report itself, in 2020,

Dennis Doyle

24 and 2025, there were five, the state controller found that there were only five of 102 reported data breaches that were not made in accordance with the timeline requirements.

Dennis Doyle

But with that said,

Dennis Doyle

We are striving to improve that.

Dennis Doyle

Part of the difficulty with notification timeliness is making sure that we're having our staff be fully aware of what their obligations are and that they're reporting it up to us in a timely fashion.

Dennis Doyle

We also can encounter difficulties with working with third-party vendors and trying to get the pertinent information from them in time in order to issue these notifications.

Dennis Doyle

We also will have translation requirements when it comes to sending out notifications.

Dennis Doyle

So there are a lot of hurdles when it comes to issuing these notifications in a timely way.

Dennis Doyle

But with that said, we're still working to improve that.

Dennis Doyle

And also on the training point, we've also improved in terms of staff completion rate for our training.

Dennis Doyle

In 2023-24, it was 117,000 staff members completed our data privacy and security training.

Dennis Doyle

In 25-26, that number went up to 138,000 of approximately 150,000 or 160,000 staff.

Dennis Doyle

And this is also an area where we actually exceed the law, where education law 2D only requires training for those who have access to student data.

Dennis Doyle

We require it for all of our employees, which we think is a good policy.

Dennis Doyle

Unfortunately, that also creates separate challenges in sort of ensuring that everyone actually is completing the training that has access to data so that we're complying with the law.

Dennis Doyle

So in short,

Dennis Doyle

You know, we are working continuously to improve our data privacy and compliance policies and practices.

Dennis Doyle

We've accepted the recommendations of the controller, and we look forward to, you know, issuing these new improvements in the coming months.