top of page
Search

Data Governance in K-12: How to Protect Student Data Before Something Goes Wrong

  • Aug 11
  • 6 min read

Every district collects more student data than it can name off the top of its head.

Grades, IEPs, health records, discipline files, bus routes, cafeteria balances, login histories — spread across a student information system, a dozen instructional apps, and whatever a teacher signed up for last spring.

Here's the number that should get your attention: only 41% of districts say they're actively improving their data governance practices, according to CoSN's 2025 State of EdTech District Leadership report. That leaves a majority operating on informal habits and institutional memory.

This post summarizes and builds on Wylie Wong's reporting for EdTech: Focus on K–12, which followed three Massachusetts districts through the work of formalizing data governance. Full credit at the bottom.

If it isn't written down, it doesn't exist

The single most important idea in the reporting comes from Melissa Tebbenkamp, a consultant and longtime K–12 technology leader who works with CoSN. Her framing: policies and practices that are not written down can't be trained on, enforced, monitored for effectiveness, or improved upon.

That's the whole case for documentation in one sentence. A superintendent who "knows" who should have access to what has no policy. They have a preference — one that disappears the moment they change jobs.

Tebbenkamp also draws the line connecting the three functions districts tend to treat separately: you can't have proper data governance without data privacy and cybersecurity. They aren't three initiatives competing for budget. They're one program.

The mistake most districts make: calling it an IT project

Data governance gets handed to the technology department because it sounds technical. It isn't — or at least, not only.

Deciding which staff should see student mental-health records is not a networking question. Deciding how long to keep discipline data is not a networking question. Those are policy calls that belong to district leadership, principals, and the people who actually own the data.

Tebbenkamp's point is that without organization-wide buy-in, the work doesn't take hold. Documentation and shared ownership have to operate together before governance becomes part of how a district runs.

What it looks like on the ground

Wayland Public Schools — building the manual from scratch

Jenn Judkins, technology director for Wayland (five schools, roughly 2,700 students), had been doing the right things informally for years. She wrote them down anyway.

"It's not enough to know in my head what the right thing is to do. It was important to articulate everything."

She assembled a cross-functional committee — district leaders, frontline staff, and data stewards, department heads made formally accountable for specific categories of student and staff data. Across three meetings, the group:

  • Learned the core concepts: least-privilege access, data classification, data lifecycle management

  • Inventoried what the district actually collects

  • Set role-based access controls application by application

  • Classified data by sensitivity level

The output was a districtwide manual on data use and privacy.

On the technology side, Wayland runs Google Workspace for Education Plus, using Google Vault for retention and legal discovery and the Google Admin Console for permissions, multifactor authentication, and single sign-on. Data loss prevention rules tag sensitive files and block external sharing automatically. ClassLink OneSync handles identity lifecycle management — creating, updating, and revoking access automatically based on what the student information system says about a person's role. Most staff authenticate through Google Authenticator.

The access rules are specific: principals see student records for their own school only, not districtwide. Staff get view-only access to the dashboards relevant to their jobs. Before state reports go out the door, data stewards review them. Wayland also brought in a third-party auditor to review its Google Admin Console settings, and runs annual access reviews so employees don't quietly retain permissions from a previous role.

On AI, Wayland steers staff toward Google Gemini specifically because it doesn't train on user prompts and keeps district data internal.

Judkins's two operating principles are worth stealing outright:

"Our goal is to ensure governance happens in the background, so teachers and students can focus on learning."
"Our philosophy is to trust but verify."

Littleton Public Schools — least privilege, all the way down to students

Natalie Croteau, technology systems coordinator, is still writing Littleton's formal manual. In the meantime she applied least-privilege access across the SIS, instructional applications, and even the security cameras.

Littleton extends the principle to students themselves: middle schoolers can email only within their school, while high schoolers get external email access. Staff are required to use two-factor authentication on their Google accounts. Access reviews happen periodically, and Croteau's advice is to set the cadence deliberately rather than leaving it to chance — establish guidelines for when you revisit access.

She also named the failure mode every district shares: access creep. People change roles, gain new permissions, and never lose the old ones. Ten years in, a handful of long-tenured employees can see nearly everything.

Her framing on the manual itself:

"It is an evolving document that should be looked at often. Just because you wrote it a year ago doesn't mean you're done."

For vendor contracts, Littleton joined The Education Cooperative (TEC), a nonprofit whose Student Data Privacy Consortium negotiates standard data privacy agreements on behalf of member districts — leverage a single district of Littleton's size would never have alone.

Norton Public Schools — the clause that had teeth

Karen Winsper, director of instructional technology, also went through TEC, and her district provides the clearest proof that paperwork matters.

When Norton switched cloud-based SIS vendors, Winsper invoked the "directive for disposition of data" clause in the privacy agreement. The outgoing vendor had to formally return the district's student records and verify that remaining copies were destroyed.

"I don't want to rely on the vendor's goodwill. This gives us teeth to hold them accountable."

That is the entire argument for detailed vendor agreements, compressed into one transition. Without the clause, Norton would have been sending polite emails and hoping. Norton runs least-privilege access districtwide, uses the Google Admin Console for permissions and ClassLink for single sign-on, and Winsper pushes for a genuine annual cycle: once a year, are you actually going in and checking?

What belongs in every vendor agreement

The TEC standard contracts give you a ready-made checklist. Whether you join a consortium or negotiate solo, your data privacy agreements should specify:

  • The district owns and controls student data — not the vendor

  • No targeted advertising to students, period

  • Minimum data security requirements the vendor must meet

  • Breach notification requirements, with defined timelines

  • Criminal background checks for vendor employees who touch student data

  • A directive for disposition of data — formal return of records and verified destruction when the contract ends

That last one is the clause most districts skip and the one Norton actually needed.

What leaders should actually do

Ordered by how fast you can move on them.

1. Run an access review this quarter. You don't need a finished manual to find access creep. Pull the permission lists for your SIS and your top five applications, compare them against current job roles, and revoke what doesn't match. Then commit to doing it annually.

2. Start restrictive and loosen deliberately. Default new permissions to the maximum restriction and open them up only when someone demonstrates a clear need. Reversing a too-open default is much harder than granting an exception.

3. Separate administrative accounts from daily-use accounts. Anyone with admin rights should be doing email and everyday work from a different login. This is a same-week change with an outsized security payoff.

4. Name your data stewards. Assign department heads formal accountability for specific data categories, and route state reports through them for review before submission. This turns governance into shared ownership instead of an IT mandate — and catches reporting errors before the state does.

5. Audit your vendor agreements for the exit clause. Go contract by contract and check whether you can compel data return and verified destruction when you leave. Where you can't, add it at renewal. If negotiating alone is unrealistic at your size, look for a regional consortium like TEC.

6. Collect less, delete more. Gather only what serves an identified purpose and set retention limits with real deletion dates. Data you no longer hold cannot be breached, subpoenaed, or mishandled.

Underneath all of it: document everything. FERPA, COPPA, and state reporting obligations all assume you can explain who has access to what and why. Undocumented practice doesn't survive a breach investigation, a public records request, or a leadership change.

Get this in your inbox every week

The YOSS Advantage is our weekly newsletter for K–12 leaders — a plain-language read on AI, EdTech, and the policy shifts that land on your desk before they land on your agenda. No hype, no vendor pitch. Just what changed this week and what it means for your district, your budget, and your staff.

Source & credit

This post summarizes and builds on "Data Governance Helps K–12 Leaders Safeguard School Data" by Wylie Wong, writing for EdTech: Focus on K–12, published July 21, 2026.

All reporting, interviews, and district case studies here — Wayland, Littleton, and Norton Public Schools, and the quotes from Jenn Judkins, Melissa Tebbenkamp, Natalie Croteau, and Karen Winsper — come from Wong's original article. The 41% data governance figure originates with CoSN's 2025 State of EdTech District Leadership report (May 2025), cited in that piece. The recommendations in "What leaders should actually do" are our framing of the practices his sources described.

Thank you to Wylie Wong and the EdTech: Focus on K–12 team for the reporting.

 
 
bottom of page