PRINTER'S NO.    2522
                     THE GENERAL ASSEMBLY OF PENNSYLVANIA
                         HOUSE BILL
                         No. 1987
                                               Session of
                                                 2024
     INTRODUCED BY RYNCAVAGE, N. NELSON, KENYATTA AND DALEY,
        JANUARY 31, 2024
     REFERRED TO COMMITTEE ON EDUCATION, JANUARY 31, 2024
                                    AN ACT
 1   Amending the act of March 10, 1949 (P.L.30, No.14), entitled "An
 2      act relating to the public school system, including certain
 3      provisions applicable as well to private and parochial
 4      schools; amending, revising, consolidating and changing the
 5      laws relating thereto," in preliminary provisions, providing
 6      for student data security.
 7      The General Assembly of the Commonwealth of Pennsylvania
 8   hereby enacts as follows:
 9      Section 1.    The act of March 10, 1949 (P.L.30, No.14), known
10   as the Public School Code of 1949, is amended by adding a
11   section to read:
12      Section 130.    Student Data Security.--(a)   The department
13   shall develop, in consultation with the Office of Information
14   Technology, and update regularly, but no less than annually, a
15   model data security plan for the protection of student data held
16   by a school entity.
17      (b)    The model student data security plan shall include:
18      (1)    Guidelines for access to student data and student data
19   systems, including guidelines for authentication of authorized
20   access.
 1      (2)   Privacy compliance standards.
 2      (3)   Privacy and security audits.
 3      (4)   Procedures to follow in the event of a breach of student
 4   data.
 5      (5)   Data retention and disposition policies.
 6      (c)   The model plan and any updates shall be made available
 7   to all school entities.
 8      (d)   The department shall designate a chief data security
 9   officer, with any State money as made available, to assist a
10   school entity, upon request, with the development and
11   implementation of a student data security plan and to develop
12   best practice recommendations regarding the use, retention and
13   protection of student data.
14      (e)   The department shall convene a working group to assist
15   with the development of initial instructions, procedures,
16   services, security assessments, best practices and security
17   measures required by this section for the development of a model
18   student data security plan. The working group shall include the
19   Secretary of Education, the chief information officer,
20   representatives from school entities across this Commonwealth
21   and other parties deemed necessary by the department.
22      (f)   The working group shall compile a report on or before
23   December 1, 2025, on the cost of developing and implementing a
24   model student data security plan. The working group shall submit
25   the report to the chair and minority chair of the Appropriations
26   Committee of the Senate, the chair and minority chair of the
27   Appropriations Committee of the House of Representatives, the
28   chair and minority chair of the Education Committee of the
29   Senate and the chair and minority chair of the Education
30   Committee of the House of Representatives.
20240HB1987PN2522                  - 2 -
 1      (g)     As used in this section, the following words and phrases
 2   shall have the meanings given to them in this subsection unless
 3   the context clearly indicates otherwise:
 4      "Department."     The Department of Education of the
 5   Commonwealth.
 6      "Personally identifiable information."     The term includes,
 7   but is not limited to:
 8      (1)     The student's name.
 9      (2)     The name of the student's parent or other family
10   members.
11      (3)     The address of the student or student's family.
12      (4)     A personal identifier, such as the student's Social
13   Security number, student number or biometric record.
14      (5)     Other indirect identifiers, such as the student's date
15   of birth, place of birth and mother's maiden name.
16      (6)     Other information that, alone or in combination, is
17   linked or linkable to a specific student that would allow a
18   reasonable person in the school community, who does not have
19   personal knowledge of the relevant circumstances, to identify
20   the student with reasonable certainty.
21      (7)     Information requested by a person who the educational
22   agency or institution reasonably believes knows the identity of
23   the student to whom the education record relates.
24      "School entity."     A school district, intermediate unit, area
25   career and technical school, charter school, cyber charter
26   school or regional charter school.
27      "Student data."     Personally identifiable information from
28   student records of a school entity.
29      Section 2.     This act shall take effect in 60 days.
20240HB1987PN2522                     - 3 -
Statutes/Laws affected: Printer's No. 2522: P.L.30, No.14