Protecting Student Data Privacy in the State of Maryland
March 23, 2022 | 3 minutes read
Maryland’s Student Data Privacy Act of 2015 is a data privacy law that was passed for the purpose of protecting the personal information of students within the U.S. state of Maryland. Under the Student Data Privacy Act of 2015, online operators that collect student information in the context of educational pursuits are responsible for ensuring that this information remains secure and protected at all times. To this point, the law establishes various provisions that online operators within the state of Maryland must adhere to as it concerns the protection of student information, ranging from the development and implementation of security measures for the purposes of protecting said information, to prohibiting the use of student information for purposes other than the advancement of education.
How is an online operator defined under the law?
Under Maryland’s Student Data Privacy Act of 2015, an online operator is defined as “a person who is operating in accordance with a contract or an agreement with a public school or local school system in the State to provide an Internet website, an online service, an online application, or a mobile application that: Is used primarily for a PreK–12 school purpose; Is issued at the direction of a public school, a teacher, or any other employee of a public school, local school system, or the Department; and Was designed and marketed primarily for a PreK–12 school purpose.”
What categories of student data are covered under the law?
Under Maryland’s Student Data Privacy Act of 2015, various categories of personal information that could be used to identify students within the state are protected under the provisions set forth in the law. These data elements include but are not limited to:
- First and last names.
- Educational and disciplinary records.
- Telephone numbers.
- Electronic address.
- Any other information that would permit physical or online contact.
- Grades, student evaluations, and test results.
- Criminal records.
- Special education records.
- Social security numbers.
- Medical and health records.
- Socioeconomic information.
- Photos and voice recordings.
- Biometric information and identifiers.
What are the obligations of online operators under the law?
Under the provisions of Maryland’s Student Data Privacy Act of 2015, online operators that serve students within the state are mandated to fulfill a number of requirements as it relates to the protection of the personal data and privacy of said students. Most notably, online operators are prohibited from selling the personal information of students for the purposes of targeted marketing. Moreover, online operators are also responsible for implementing and maintaining security protocols that will ensure that the personal information of students within the state of Maryland is protected from unauthorized access, use, or disclosure. To this end, online operators must also delete the personal information of Maryland students within a reasonable amount of time, or at the request of a particular school district.
Conversely, the law does outline certain circumstances under which online operators are permitted to disclose the personal information of students within Maryland. Such circumstances include:
- To take precautions against liability.
- To ensure regulatory or legal compliance.
- To participate or respond to the judicial process.
- To a state or local educational institution or agency within Maryland.
- If the disclosure is mandated by other state or federal legislation, and the online operator complies with the requirements that are set forth in such legislation as it concerns the disclosure of personal information.
In response to the increasing role that internet technology and communications have come to play in the advancement of American education, many states around the country have turned to passing data privacy laws geared toward protecting the personal information of K-12 students. As such, the state of Maryland passed the Student Data Privacy Act of 2015 to ensure that the personal information of students within the state is protected at all times, in accordance with the growing threat of data breaches and cyber criminality in online spaces. With this being said, the law provides both students and their parents with the assurance that the information they share with online operators in the course of their educational endeavors is protected at every level of their journey.