Who Can See Your Students' Data Right Now? Six Governance Moves Every District Can Make This Year
- Aug 25
- 5 min read
Your district holds attendance records, grades, behavior logs, IEPs, and health files. Every new EdTech tool you adopt adds another door into all of it.
Most districts have a data privacy policy. Far fewer have the practices that make the policy real.
A recent piece in EdTech Magazine by Wylie Wong lays out six of them — and none require a new platform, a budget line, or a board vote.
The problem isn't policy. It's practice.
Data governance in K–12 tends to get treated as a document. Someone writes it, the board approves it, it lives in a binder.
But the exposure districts actually face doesn't come from a missing policy. It comes from the gap between what the policy says and what's configured in the systems: accounts that were never closed, permissions that were never reviewed, information that was collected years ago and never deleted.
Every one of those is a liability that sits with the district — not with the vendor.
Practice 1: Start locked down, not opened up
Grant the narrowest access that lets someone do their job, then loosen it only when there's a real, justified need.
The order matters more than it sounds. Districts that start permissive and try to tighten later run into resistance, because taking something away reads as an accusation.
"Once you've given them access, it becomes difficult to justify why you're pulling that back. You can't put the toothpaste back in the tube."
— Jenn Judkins, Technology Director, Wayland Public Schools (MA)
Least privilege is cheap on day one and expensive to retrofit.
Practice 2: You can't lose what you never collected
The most reliable way to protect a piece of student data is to not have it.
Districts accumulate information without deciding to — enrollment packets, residency documentation, utility bills submitted as proof of address. It arrives, it gets stored, and nobody ever revisits whether it's still needed.
Melissa Tebbenkamp, Technology Director for CoSN, points to collection without a clear purpose as the root of the problem. Social Security numbers are the sharpest example: unless a specific requirement demands one, don't ask for it.
"You don't have to protect what you don't collect."
— Jenn Judkins
The corollary is deletion. Data that's served its purpose should come off your systems, not sit indefinitely as a breach waiting for an occasion.
Practice 3: Two accounts for anyone with admin rights
Staff who hold administrative privileges should work from two separate accounts — one for administrative functions, one for everyday email, browsing, and classroom work.
The reason is blunt. Daily-use accounts are the ones that get phished. If that account is also the one with system-wide privileges, a single bad click hands over the whole environment. Splitting them means a compromised daily account is a contained problem instead of a district-wide one.
Tebbenkamp frames it as limiting attack surface. It's one of the few controls that meaningfully changes the outcome of an incident that's already begun.
Practice 4: Temporary access should expire on its own
Some access genuinely needs to be temporary. A teacher helping build student schedules for six weeks needs the scheduling system for six weeks — not permanently.
Judkins's approach is unglamorous and effective: grant the access for the window the work requires, and set a calendar reminder to revoke it when that window closes. Without the reminder, nobody remembers, and the access quietly becomes permanent.
This applies well beyond temp employees — student teachers, consultants, summer program staff, vendor support reps troubleshooting a problem.
Practice 5: Have a human who knows the data check it before the state does
Districts submit substantial reporting to their state. IT usually runs the extract, but IT isn't always positioned to notice when a number is wrong.
The fix is naming data stewards — subject-matter experts who review their own domain's data before submission. An English learner program director knows what their enrollment should roughly look like. A technology director doesn't.
"They're the ones that would have the ability, more than we would, to say, 'Wait a minute, that can't be right.'"
— Jenn Judkins
Errors caught before submission are corrections. Errors caught after are findings.
Practice 6: Audit for access creep once a year
People change roles. Their permissions rarely change with them.
A teacher becomes an instructional coach, then a building administrator, and at each step picks up new access without shedding the old. After a decade, that person can see nearly everything — not because anyone decided they should, but because nobody ever subtracted.
Karen Winsper of Norton Public Schools reduces the whole practice to one question:
"Once a year, are you going in and checking?"
An annual access review is the audit that catches what the other five practices miss.
What this looks like on the ground
In Wayland, Massachusetts, that means calendar reminders tied to the scheduling window and a technology director who treats access grants as loans rather than gifts.
In Norton, it means an annual pass through the roster asking whether each person's permissions still match their current job.
At CoSN, the guidance is about the intake side: stop pulling in data — Social Security numbers above all — that no requirement obligates you to hold.
None of it is a product. All of it is a decision somebody made and then repeated.
What leaders should actually do
Ordered by how quickly you can act on them:
Put the annual access review on next year's calendar today. Not a project — a recurring date with an owner's name on it. This is the single highest-return item on the list.
Split admin accounts from daily-use accounts for everyone holding elevated privileges. It's a configuration change, and it changes what a successful phish costs you.
Audit what you're collecting at enrollment. Walk the packet field by field and ask what requirement each one satisfies. Anything that can't answer comes off the form, and the historical copies get a deletion timeline.
Make every temporary grant carry an end date — with a calendar reminder attached at the moment access is issued, not later.
Name data stewards for state reporting and build their review into the submission process before the next cycle.
The through-line: governance isn't something you buy. It's a handful of decisions somebody has to own before an audit or an incident makes them for you.
Get this in your inbox every week
The YOSS Advantage is our weekly newsletter for K–12 leaders — AI, EdTech, and the policy shifts that land on your desk, cut down to what actually affects your district. No filler, no vendor pitch, just the week's most useful reading with the "so what" already worked out.
Subscribe here: https://subscribe.learnyoss.com/
Source & Credit
This post summarizes and builds on "6 Data Governance Best Practices for K–12" by Wylie Wong, published in EdTech Magazine on August 13, 2026.
All six practices, the reporting, and every quoted expert — Jenn Judkins, Technology Director at Wayland Public Schools; Melissa Tebbenkamp, Technology Director for CoSN; and Karen Winsper of Norton Public Schools — come from Wong's original article. The "what leaders should actually do" section is YOSS's own framing built on top of that reporting. Our thanks to Wylie Wong and EdTech Magazine for the work.



