De La Rosa pushes for contractual penalties for vendor data breaches
De La Rosa asks if DOE has included penalties in vendor contracts for data breach reporting failures. Doyle says DOE is looking into strengthening data processing agreements to include penalties for not notifying in a timely fashion. De La Rosa calls penalties 'incredibly appropriate' given the scale of student data involved with AI.
At minimum, by the way, at minimum, I feel like there should be a penalty, but...
We do get reimbursed for it, but that's sort of another area where we try to go beyond what's required by Ed Law 2D to make sure that once we do send those notifications that they have these resources.
So in a...
In addition to the increased training or trying to get that number up to 100%, which is the requirement slash the goal, what is the DOE doing to fix the lapses?
So you've mentioned the training.
What other steps have they taken?
I think we're relying on timely reporting from all of our offices and all of our schools so that we can get this information out as soon as possible.
And there's no, so you're saying there's no issue between once you get the data or information, there is no hurdle, no speed bump, no hiccup for the DOE to then report it to the state?
Well, reporting to the state is one thing.
I think we're talking about reporting.
And to families, yes.
If we're talking about notifying families, that's a little bit more complicated because we have to get the impacted data.
We have to understand who is impacted.
We have to then get, if it's a vendor that's involved, we have to get the data from the vendor, then match it against our own records so we have contact information, translate the notices.
60 days.
You have a 60-day time frame, right?
I'm simply asking if there are any additional steps based on the finding of the audit that you were doing to improve this to ensure that you are notifying families in the 60-day time frame.
Yeah, and I think one of the things that we're looking into is, and we're always looking into, is ways to strengthen our data processing agreements if we're talking about a data breach that's associated with a vendor to make sure that they are held accountable, that there could be...
Penalties, for example, for not notifying us in a timely fashion.
Well, is that going to be in your contracts then?
Because I think the penalties are completely appropriate for a company.
Besides reimbursing you for paying for families'data monitoring,
Is that going to be included in your contracts, that there will be a penalty when there are data breaches?
It's something that we are looking into for including into our data processing agreements, yeah.
Okay, I mean, I think that's incredibly appropriate given the scale that we're talking about and the amount of, especially with AI, the amount of student data that we're talking about.
Because we're not just talking about personally identifying information that you guys carry.
We're talking about all the stuff that they're inputting into whatever chatbots or systems that they're using, which goes a lot deeper.
Knowing that, especially since kids use, I hope you're teaching them, they shouldn't, but using these chatbots as mental health counselors and using them as friends and as buddies.
Yeah, and one other thing that I should point out too is when we're talking about data breaches and when the controllers report first at data breaches, we're not only talking about data breaches that are derived from third-party vendors.
Under Ed Law 2D, a data breach is any unauthorized disclosure.
So if we have a DUE staff member that's sending an email to the wrong recipient and includes one student's personally identifiable information in that, technically that's going to be considered a data breach.
It's going to trigger all the same obligations.
under Ed Law 2D.
And I think a lot of the delays that we see are sometimes, again, the staff not reporting that to us in a timely fashion so that we can get the notifications out.
Okay, thank you.
I'm going to turn it back over to Chair Dena Rosas.