Skip to content
Council Discourse

NYC Council meetings, chaptered and linked by time.

Created by Uzair Qadir

Inspired by Vikram Oberoi's City Meetings

Q&A

De La Rosa questions data breach reporting failures

New York City Council · Jun 24, 2026 · starts 2:57:13 · 3 min 46 sec

De La Rosa cites the comptroller's finding that DOE reported 67 of 141 breaches late, nearly half. Doyle explains difficulties with vendor reporting timeliness, staff awareness, and forensic investigation delays. De La Rosa asks what steps beyond training have been taken to fix lapses in notifying families within the required 60-day timeframe.

Carmen N. De La Rosa

I want to end with just more about the state controller's report.

Carmen N. De La Rosa

About data breaches.

Carmen N. De La Rosa

I think very concerning to all of us, correct?

Member of the Public

Yes, absolutely.

Carmen N. De La Rosa

Good answer.

Carmen N. De La Rosa

Oh, we're nodding again.

Carmen N. De La Rosa

Okay, yeah.

Carmen N. De La Rosa

That's called saying yes out loud.

Carmen N. De La Rosa

It's called implementing feedback.

Carmen N. De La Rosa

We love to see that.

Carmen N. De La Rosa

And, of course, the DOE thinks it's important to report data breaches in a timely manner when they occur.

Carmen N. De La Rosa

Reporting the breaches is required by Part 121 of the State Education Department's regulations.

Carmen N. De La Rosa

It requires the DOE to notify the State Education Department's Chief Privacy Officer within 10 calendar days of discovering a breach.

Carmen N. De La Rosa

The Comptroller's audit reviewed 141 breaches and found that the DOE reported 67 of those breaches, which is almost half of them, late.

Carmen N. De La Rosa

Explain why the DOE failed to comply with the law in almost half of the instances that the Comptroller examined.

Member of the Public - Dennis

Yeah, thank you for the question.

Member of the Public - Dennis

I think as far as reporting to the state goes, when we have a breach,

Member of the Public - Dennis

I alluded to this before in another answer, but part of our difficulty is that we rely on either our vendors to come to us and report this information to us in a timely fashion, which unfortunately does not always happen, or

Member of the Public - Dennis

we rely on our staff to come to us and report the breach or unauthorized disclosure to us as soon as possible.

Member of the Public - Dennis

And I think one of the ways that we've improved on that front, and I think the figures in the controller's audit show that at least we're trending in the right direction, is by improving our awareness campaigns, improving our training.

Member of the Public - Dennis

I understand that we are not at 100% completion for the training, but even that number is improving.

Member of the Public - Dennis

We're finding that we're getting more.

Member of the Public - Dennis

More staff that are aware of their privacy obligations.

Member of the Public - Dennis

They're in contact with our office more and reporting more to us.

Member of the Public - Dennis

So I think we're improving on that front.

Member of the Public - Dennis

And it's a tight timeline, I think 10 days to report to the state.

Member of the Public - Dennis

So those are some of the factors that go into it.

Member of the Public - Dennis

But, yeah, we're moving in the right direction on that front.

Carmen N. De La Rosa

So you've spoken about how you ensure or are attempting to ensure that professionals get the training so that they report.

Carmen N. De La Rosa

But what about the vendors?

Member of the Public - Dennis

Our vendors are required under our data processing agreements to notify us as soon as they have confirmed an unauthorized.

Member of the Public - Dennis

authorized disclosure or a data breach.

Member of the Public - Dennis

There are sometimes difficulties with getting that information from vendors in a timely fashion, notwithstanding what they're required to do under the DPA.

Member of the Public - Dennis

Sometimes vendors don't contact us at the right point of contact.

Member of the Public - Dennis

They will, for example, contact a school and not contact the student privacy office so we can affect the notification right away.

Carmen N. De La Rosa

But that's not, I'm sorry, but that's not in their contract that in the instance of a data breach, contact.

Member of the Public - Dennis

It is.

Member of the Public - Dennis

It is, but we still have difficulty with vendors, you know, complying with that part of the contract, and we're looking into, you know.

Member of the Public - Dennis

Different ways that we can strengthen our DPAs to make sure that vendors are going to be held accountable to this to make sure that they're reporting it in a timely fashion.

Carmen N. De La Rosa

So you drop them as a vendor?

Member of the Public - Dennis

Say that again?

Carmen N. De La Rosa

You drop them as a vendor if they don't comply?

Member of the Public - Dennis

I didn't, no, I didn't say that.

Carmen N. De La Rosa

I know, I'm asking.

Member of the Public - Dennis

Would we?

Member of the Public - Dennis

I mean, we have...

Carmen N. De La Rosa

No, have you?