Skip to content

Parents' Bill of Rights for Data Privacy and Security

New York Education Law § 2-d and 8 NYCRR Part 121 · Version 1.0 · 6 August 2026 · Contact: privacy@canoanumis.org

New York school districts must publish a Parents' Bill of Rights and attach supplemental information for each contract that involves student data. This page is Canoa // edu's contribution to that packet: the rights themselves, as the statute states them, and then the supplemental information a district needs from us. It is written to be attached to a district's own bill of rights without editing.

The rights

  1. A student's personally identifiable information cannot be sold or released for any commercial purpose.
  2. Parents have the right to inspect and review the complete contents of their child's education record.
  3. State and federal laws protect the confidentiality of personally identifiable information, and safeguards such as encryption, firewalls, and password protection must be in place when data is stored or transferred.
  4. A complete list of all student data elements collected by the State is available for public review at the NYSED website, or by writing to the Office of Information and Reporting Services, New York State Education Department, 89 Washington Avenue, Albany, NY 12234.
  5. Parents have the right to have complaints about possible breaches of student data addressed. Complaints should be directed in writing to the district's designated privacy official, or to the NYSED Chief Privacy Officer at CPO@mail.nysed.gov.

Supplemental information for the Canoa // edu contract

Supplemental information required by Education Law 2-d
Required disclosureCanoa // edu
Exclusive purposes for which student data will be used To present an assignment to the correct student, record and check their answers, return a score to the district's gradebook, and let the teacher review the work. Nothing else.
How we ensure subcontractors abide by confidentiality and security obligations Written agreements with data-protection obligations no weaker than our own; annual review; the complete list is published at subprocessors, with 30 days' notice to district contacts before any change.
Contract expiration and what happens to data On expiration or termination, student submissions are deleted and deletion is confirmed in writing; see the data deletion procedure. Automatic deletion also runs continuously at school year + 90 days.
How a parent may challenge the accuracy of data Through the district. We hold no name, so we cannot locate a specific child's record; the district can, and can correct or delete it through us at any time.
Where data will be stored, and security protections On managed infrastructure operated by REG.RU (Moscow, Russian Federation). TLS 1.2+ in transit, encryption at rest, per-deployment isolation, cryptographically validated LTI launches with no passwords in existence, limited and logged staff access, backups rotating out within 35 days.
Encryption of data in motion and at rest Yes, both, using industry-standard mechanisms.

What "student data" means in our case

It is worth stating plainly for New York reviewers: Canoa // edu never receives a student's name, email address, photograph, date of birth, address, or any other direct identifier. The only student-linked values in our system are an opaque identifier minted by the district's own LMS, the course context id, the answers, and the scores. Whether that constitutes personally identifiable information is a question the district's counsel should answer under its own analysis — we treat it as if it does, and apply every protection above accordingly.

Data Security and Privacy Plan

Part 121 requires a signed Data Security and Privacy Plan aligned to the district's policy and the NIST Cybersecurity Framework. We provide one on request, mapped to the district's own template, within two business days: privacy@canoanumis.org. Related documents: Student Privacy Policy · NDPA · Data Deletion Procedure · Accessibility Conformance Report.

Breach notification

If we learn of a breach or unauthorized release of student data, we notify the district without unreasonable delay and no later than seven calendar days from discovery, as required by Education Law § 2-d, and we cooperate fully with the district's own notification obligations to parents and to the NYSED Chief Privacy Officer.