§ 53E-9-301 Definitions
§ 53E-9-302 State student data protection governance
§ 53E-9-302 v2 State student data protection governance
§ 53E-9-303 Local student data protection governance
§ 53E-9-304 Student data ownership and access — Notification in case of significant data breach
§ 53E-9-305 Collecting student data — Prohibition — Student data collection notice — Written consent
§ 53E-9-306 Using and expunging student data — Rulemaking — Disciplinary records
§ 53E-9-307 Securing and cataloguing student data
§ 53E-9-308 Sharing student data — Prohibition — Requirements for student data manager — Authorized student data sharing
§ 53E-9-308 v2 Sharing student data — Prohibition — Requirements for student data manager — Authorized student data sharing
§ 53E-9-309 Third-party contractors
§ 53E-9-310 Penalties

Terms Used In Utah Code > Title 53E > Chapter 9 > Part 3 - Student Data Protection

  • Adult student: means a student who:
    (a) is at least 18 years old;
    (b) is an emancipated student; or
    (c) qualifies under the McKinney-Vento Homeless Education Assistance Improvements Act of 2001, 42 U. See Utah Code 53E-9-301
  • Biometric identifier: means a:
    (i) retina or iris scan;
    (ii) fingerprint;
    (iii) human biological sample used for valid scientific testing or screening; or
    (iv) scan of hand or face geometry. See Utah Code 53E-9-301
  • Biometric information: means information, regardless of how the information is collected, converted, stored, or shared:
    (a) based on an individual's biometric identifier; and
    (b) used to identify the individual. See Utah Code 53E-9-301
  • Contract: A legal written agreement that becomes binding when signed.
  • Damages: Money paid by defendants to successful plaintiffs in civil cases to compensate the plaintiffs for their injuries.
  • Data breach: means an unauthorized release of or unauthorized access to personally identifiable student data that is maintained by an education entity. See Utah Code 53E-9-301
  • Data governance plan: means an education entity's comprehensive plan for managing education data that:
    (a) incorporates reasonable data industry best practices to maintain and protect student data and other education-related data;
    (b) describes the role, responsibility, and authority of an education entity data governance staff member;
    (c) provides for necessary technical assistance, training, support, and auditing;
    (d) describes the process for sharing student data between an education entity and another person;
    (e) describes the education entity's data expungement process, including how to respond to requests for expungement;
    (f) describes the data breach response process; and
    (g) is published annually and available on the education entity's website. See Utah Code 53E-9-301
  • Education entity: means :
    (a) the state board;
    (b) a local school board;
    (c) a charter school governing board;
    (d) a school district;
    (e) a charter school; or
    (f) the Utah Schools for the Deaf and the Blind. See Utah Code 53E-9-301
  • Expunge: means to seal or permanently delete data, as described in state board rule made in accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act, under Section 53E-9-306. See Utah Code 53E-9-301
  • General audience application: means an Internet website, online service, online application, mobile application, or software program that:
    (a) is not specifically intended for use by an audience member that attends kindergarten or a grade from 1 to 12, although an audience member may attend kindergarten or a grade from 1 to 12; and
    (b) is not subject to a contract between an education entity and a third-party contractor. See Utah Code 53E-9-301
  • Guardian: A person legally empowered and charged with the duty of taking care of and managing the property of another person who because of age, intellect, or health, is incapable of managing his (her) own affairs.
  • Guardian: includes a person who:Utah Code 68-3-12.5
  • IEP: means a written statement for a student with a disability that is developed, reviewed, and revised in accordance with the Individuals with Disabilities Education Act, 20 U. See Utah Code 53E-1-102
  • Jurisdiction: (1) The legal authority of a court to hear and decide a case. Concurrent jurisdiction exists when two courts have simultaneous responsibility for the same case. (2) The geographic area over which the court has authority to decide cases.
  • LEA: means :
    (a) a school district;
    (b) a charter school; or
    (c) the Utah Schools for the Deaf and the Blind. See Utah Code 53E-9-301
  • Local school board: means a board elected under 2. See Utah Code 53E-1-102
  • Metadata dictionary: means a record that:
    (a) defines and discloses all personally identifiable student data collected and shared by the education entity;
    (b) comprehensively lists all recipients with whom the education entity has shared personally identifiable student data, including:
    (i) the purpose for sharing the data with the recipient;
    (ii) the justification for sharing the data, including whether sharing the data was required by federal law, state law, or a local directive; and
    (iii) how sharing the data is permitted under federal or state law; and
    (c) without disclosing personally identifiable student data, is displayed on the education entity's website. See Utah Code 53E-9-301
  • Necessary student data: means data required by state statute or federal law to conduct the regular activities of an education entity, including:
    (a) name;
    (b) date of birth;
    (c) sex;
    (d) parent contact information;
    (e) custodial parent information;
    (f) contact information;
    (g) a student identification number;
    (h) local, state, and national assessment results or an exception from taking a local, state, or national assessment;
    (i) courses taken and completed, credits earned, and other transcript information;
    (j) course grades and grade point average;
    (k) grade level and expected graduation date or graduation cohort;
    (l) degree, diploma, credential attainment, and other school exit information;
    (m) attendance and mobility;
    (n) drop-out data;
    (o) immunization record or an exception from an immunization record;
    (p) race;
    (q) ethnicity;
    (r) tribal affiliation;
    (s) remediation efforts;
    (t) an exception from a vision screening required under Section 53G-9-404 or information collected from a vision screening described in Section 53G-9-404;
    (u) information related to the Utah Registry of Autism and Developmental Disabilities, described in Section 26B-7-115;
    (v) student injury information;
    (w) a disciplinary record created and maintained as described in Section 53E-9-306;
    (x) juvenile delinquency records;
    (y) English language learner status; and
    (z) child find and special education evaluation data related to initiation of an IEP. See Utah Code 53E-9-301
  • Optional student data: includes :
    (i) information that is:
    (A) related to an IEP or needed to provide special needs services; and
    (B) not necessary student data;
    (ii) biometric information; and
    (iii) information that is not necessary student data and that is required for a student to participate in a federal or other program. See Utah Code 53E-9-301
  • Parent: means :
    (a) a student's parent;
    (b) a student's legal guardian; or
    (c) an individual who has written authorization from a student's parent or legal guardian to act as a parent or legal guardian on behalf of the student. See Utah Code 53E-9-301
  • Person: means :Utah Code 68-3-12.5
  • Personally identifiable student data: includes :
    (i) a student's first and last name;
    (ii) the first and last name of a student's family member;
    (iii) a student's or a student's family's home or physical address;
    (iv) a student's email address or other online contact information;
    (v) a student's telephone number;
    (vi) a student's social security number;
    (vii) a student's biometric identifier;
    (viii) a student's health or disability data;
    (ix) a student's education entity student identification number;
    (x) a student's social media user name and password or alias;
    (xi) if associated with personally identifiable student data, the student's persistent identifier, including:
    (A) a customer number held in a cookie; or
    (B) a processor serial number;
    (xii) a combination of a student's last name or photograph with other information that together permits a person to contact the student online;
    (xiii) information about a student or a student's family that a person collects online and combines with other personally identifiable student data to identify the student; and
    (xiv) information that, alone or in combination, is linked or linkable to a specific student that would allow a reasonable person in the school community, who does not have personal knowledge of the relevant circumstances, to identify the student with reasonable certainty. See Utah Code 53E-9-301
  • Process: means a writ or summons issued in the course of a judicial proceeding. See Utah Code 68-3-12.5
  • School official: means an employee or agent of an education entity, if the education entity has authorized the employee or agent to request or receive student data on behalf of the education entity. See Utah Code 53E-9-301
  • Signature: includes a name, mark, or sign written with the intent to authenticate an instrument or writing. See Utah Code 68-3-12.5
  • State: when applied to the different parts of the United States, includes a state, district, or territory of the United States. See Utah Code 68-3-12.5
  • State board: means the State Board of Education. See Utah Code 53E-1-102
  • Statute: A law passed by a legislature.
  • Student data: means information about a student at the individual student level. See Utah Code 53E-9-301
  • Student data manager: means :
    (a) the state student data officer; or
    (b) an individual designated as a student data manager by an education entity under Section 53E-9-303, who fulfills the duties described in Section 53E-9-308. See Utah Code 53E-9-301
  • Subpoena: A command to a witness to appear and give testimony.
  • Targeted advertising: means presenting advertisements to a student where the advertisement is selected based on information obtained or inferred over time from that student's online behavior, usage of applications, or student data. See Utah Code 53E-9-301
  • Third-party contractor: means a person who:
    (a) is not an education entity; and
    (b) pursuant to a contract with an education entity, collects or receives student data in order to provide a product or service, as described in the contract, if the product or service is not related to school photography, yearbooks, graduation announcements, or a similar product or service. See Utah Code 53E-9-301
  • Transcript: A written, word-for-word record of what was said, either in a proceeding such as a trial or during some other conversation, as in a transcript of a hearing or oral deposition.
  • Writing: includes :Utah Code 68-3-12.5
  • Written consent: means written authorization to collect or share a student's student data, from:
    (a) the student's parent, if the student is not an adult student; or
    (b) the student, if the student is an adult student. See Utah Code 53E-9-301