Avilés questions DOE on state comptroller audit findings
Councilmember Avilés cites the May 2026 state comptroller audit finding DOE lacks written data classification policies, risk assessment, and backup/recovery procedures required by the NIST framework under EdLaw 2D. Dennis Doyle responds that DOE complies with privacy laws, accepted audit recommendations, and is implementing improvements including a formal data classification policy.
Yeah, thank you.
Thank you so much, Chairs, for this important hearing.
I guess I'd like to ask the administration around issues of privacy.
I certainly was one of those council members who is deeply concerned about, you know, kind of this...
What we don't know what's happening in our schools related to AI and student use, direct usage of AI.
So I'm deeply concerned about privacy.
As you all know, on May 4th, the state comptroller's office released a really scathing audit, finding that the New York City Public Schools maintains no written policies for data classification, risk assessment.
Or backup and recovery as required by the NIST data security framework specified by EdLaw 2D.
So given that that law was passed in 2014, why has the DOE failed to develop these policies that's making, obviously, these data breaches, which are profoundly concerning, more likely and harder to respond to?
Thank you for that question and I just want to let you know we have our chief data privacy officer with us today who's going to respond.
Yeah, thank you.
Thank you for the question.
I just want to start out by saying obviously student privacy is of the utmost importance to New York City Public Schools.
And we did work with the New York State Comptroller on this audit over the last few years.
We submitted a formal response to that audit that sort of explains that we comply with all federal, state, and local privacy laws.
In some cases, we go beyond what the law requires.
But that we're always working continuously to try to improve our data privacy practices.
And while we disagree with some of the findings in the New York State Comptroller's audit report, we did accept and agree the recommendations that were made in that report.
To some extent, we assert that we already comply with the recommendations in that report.
And one example is actually, as you're referring to, is the requirement that we align with the NIST cybersecurity framework.
This is something that we...
We use, as you've noted,
Were required by New York State Education Law Section 2D to align with the NIST Cybersecurity Framework.
And just a point on that, the NIST Cybersecurity Framework is not necessarily a checklist of requirements for organizations to follow.
It's a framework for assessing an organization's cybersecurity posture and to continuously evaluate it and to try to continuously improve it.
And so we have been implementing the NIST cybersecurity framework.
With that said, we recognize that there are improvements that we plan on making.
One is to update our data privacy and security policies page, which we will be doing in the coming months.
We will also be issuing a formal written data classification policy.
We do have a data classification policy.
It's documented in a few different places, but we want to make sure that we have a very clear, formal data classification policy for that.
We're also, as has been mentioned earlier in this hearing, working with the schools to make sure we have a better understanding of the tools that they're using to make sure that it's in compliance with their data privacy and security policies.
Another thing noted in the audit report was the timeliness of notifications.
We're also improving on that front.
I think if you read the report itself, in 2020,
24 and 2025, there were five, the state controller found that there were only five of 102 reported data breaches that were not made in accordance with the timeline requirements.
But with that said,
We are striving to improve that.
Part of the difficulty with notification timeliness is making sure that we're having our staff be fully aware of what their obligations are and that they're reporting it up to us in a timely fashion.
We also can encounter difficulties with working with third-party vendors and trying to get the pertinent information from them in time in order to issue these notifications.
We also will have translation requirements when it comes to sending out notifications.
So there are a lot of hurdles when it comes to issuing these notifications in a timely way.
But with that said, we're still working to improve that.
And also on the training point, we've also improved in terms of staff completion rate for our training.
In 2023-24, it was 117,000 staff members completed our data privacy and security training.
In 25-26, that number went up to 138,000 of approximately 150,000 or 160,000 staff.
And this is also an area where we actually exceed the law, where education law 2D only requires training for those who have access to student data.
We require it for all of our employees, which we think is a good policy.
Unfortunately, that also creates separate challenges in sort of ensuring that everyone actually is completing the training that has access to data so that we're complying with the law.
So in short,
You know, we are working continuously to improve our data privacy and compliance policies and practices.
We've accepted the recommendations of the controller, and we look forward to, you know, issuing these new improvements in the coming months.