Educational Agencies: Report a Data Incident
Educational agencies must report unauthorized disclosures and/or access to data protected by state and federal law to 快猫成版视频鈥檚 Chief Privacy Officer. Upon completion of the form, an email confirmation will be sent to the submitter.
To assist you in preparing to complete the Data Incident Reporting Form, please see the master list of questions. Note that you will not be required to answer all of these questions. The questions that you will be prompted to answer vary depending on the nature of the incident being reported.
Where applicable, educational agencies may also be required to complete an Incident Recovery form to demonstrate that a cybersecurity incident has been addressed and agency systems have been cleaned. This is important to protect SED鈥檚 systems.
Please read the Q&A below for additional information. For questions, please email us at privacy@nysed.gov. Thank you.
Q: What is a breach?
A: Part 121 (Education Law 搂2-d鈥檚 regulation) defines a breach as the unauthorized accessibility, acquisition, access, use, or disclosure of student data and/or teacher or principal APPR data by or to a person not authorized to acquire, access, use, or receive such data.
Q: What sorts of incidents/breaches should be reported?
A: Any cases of unauthorized acquisition, access, use, or disclosure of student data and/or teacher or principal APPR data by or to a person not authorized to acquire, access, use, or receive it.
Q: Do we need to report an incident where data systems are accessible or accessed but no actual data is taken?
A: Yes, pursuant to Part 121, a breach occurs when either student data or teacher/principal APPR data is accessible, accessed or otherwise disclosed to a person who is not the student, the student鈥檚 parent, or does not have an educational need to know the information.
Q: How should educational agencies report data incidents/breaches?
础:听To streamline reporting, in January 2026 the Privacy Office introduced a single form that can be filled out electronically to report all data incidents, as that term is defined by Education Law 搂 2-d.听Use this form for all data incident reporting to the 快猫成版视频 Chief Privacy Officer.
Q:听Am I required to report this incident to the Division of Homeland Security and Emergency Services (DHSES)?
础:听For information about reporting cybersecurity incidents and ransom payments, please visit the . Questions regarding this type of reporting can be directed to DHSES.
Q: What if my educational agency has data reporting obligations that are impacted by a cybersecurity incident? Is there a process for submitting reports and data to Level 2 and the 快猫成版视频 Business Application Portal?
A: 快猫成版视频 has established procedures with our Board of Cooperative Educational Services (BOCES) District Superintendents and Regional Information Center (RIC) Directors to assist with required reporting for the Student Information Repository System (SIRS) and the NYS Business Application Portal (IRSP). The arrangement will provide temporary secure access to designated/approved users of Impacted districts at a RIC or BOCES location using equipment that has not been infected with malware. SED will also assist with any special reporting requirements of our P-12 program offices.
To use this alternative reporting arrangement:
- The superintendent of each impacted district must call their local RIC and provide a limited list of no more than 4 designated district personnel who currently have IRSP access and are responsible for submitting data via the IRSP.
- Designated personnel must travel to the local RIC at a time agreed upon by the district and RIC to access the IRSP and applications to submit data. Additional dates can be scheduled as needed through the district鈥檚 recovery process.
- The RIC and 快猫成版视频 will coordinate granting temporary access to the IRSP Business Portal for data submission(s) for designated personnel at the scheduled time.听
For additional information about this alternate reporting arrangement, please contact 快猫成版视频鈥檚 Information Reporting Service office.听

