{"data":{"id":"us-md/md.-code-education-7-2102","jurisdiction":"us-md","citation":"Md. Code, Education § 7–2102","heading":"","body":"The Department, in consultation with the Department of Information Technology and county boards, shall develop and update best practices for county boards to:\n(1) Manage and maintain data privacy and security practices in the processing of student data and personally identifiable information across the county board’s information technology and records management systems;\n(2) Develop and implement:\n(i) A data privacy and security incident response plan;\n(ii) A breach notification plan; and\n(iii) Procedures and requirements for allowing access to student data and personally identifiable information for a legitimate research purpose; and\n(3) Publish information annually on:\n(i) Types of student data and personally identifiable information processed by the county board, the protocols for processing student data, and the rationales for selecting processing protocols;\n(ii) Contracted services that involve sharing student data between a county board and a school service contract provider; and\n(iii) Procedures and rationales for vetting and selecting Internet sites, services, and applications.","path":["Article - Education"],"source_url":"https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=ged\u0026section=7-2102","current_through":"2026-01-01","vintage":"","retrieved_at":"2026-09-14T19:57:38Z","sha256":"d76cc5f0690e909af9adea5d78696418ca897e01c3694cf4cde91165b656a6b8","source_id":"us-md","stale":false,"prev":"us-md/md.-code-education-7-2101","next":"us-md/md.-code-education-7-2103"},"notice":"GroundRules: Original legal text. Not legal advice."}
