New York State has ordered Instream, a file-scanning service, to pay a $125,000 penalty after a 2024 breach exposed 6,253 records connected to 25 educational agencies. The New York State Education Department announcement identified two failures: unauthorized access to education records and delayed notification of the incident.

Commissioner Betty A. Rosa said the case demonstrates that "New York State will hold service providers accountable." In addition to paying the penalty, Instream must complete a third-party risk assessment, implement multi-factor authentication, verify the sources of network connections, and create an incident response plan that includes timely notifications.

The responsibility begins with the district

Under Education Law 2-d and its implementing regulations, the legal responsibility for reviewing education technology vendors belongs to the school district or educational agency. Teachers still make many of the day-to-day decisions that determine whether student information enters an unapproved system.

The safest approach is to treat classroom technology as a procurement and privacy decision, not simply as an instructional choice. Before creating an account or uploading a roster, check your district’s website, identify the person responsible for data privacy, and confirm that the vendor has been approved. If the district has not reviewed the tool, do not enter student names, grades, special education information, behavior notes, or other personally identifiable information.

Check the district’s required vendor information

Part 121 of the Commissioner’s Regulations requires districts to publish supplemental information for contracts with third parties that handle student data. The information must be available on the district website. It is not enough for the district to keep the material in an internal file that families and employees cannot access.

The published information should identify the vendor, explain the specific purposes for which data may be used, describe where the information is stored, state how long it will be retained, and explain how it will be deleted or otherwise disposed of. It must also address whether data is encrypted while being transmitted and while stored.

Before signing up for a digital tool, search the district website for the vendor’s name. If no record appears, contact the district’s privacy office or technology department. The absence of a listing may mean the district has failed to publish required information, or it may mean the vendor has not been reviewed. Neither situation supports uploading student data without further confirmation.

Districts must also designate a Data Protection Officer. Find that person’s name and contact information before the school year begins. A district data protection officer can confirm whether a product has been approved, explain what information may be shared, and direct questions to the right administrator. Written confirmation creates a clear record and shifts the decision from an individual classroom employee to the institution responsible for compliance.

Why free classroom apps require extra caution

Paid software typically moves through a purchasing process that includes contracts, legal review, and technology approval. Free software often begins with a sign-up form. That convenience can remove the safeguards that normally identify how student information will be collected, used, stored, and deleted.

New York’s privacy rules do not generally exempt free products. They also prohibit the sale of student information and restrict the use of that information for marketing. A company that does not charge schools may still generate revenue through advertising, data analysis, upgrades, or other business arrangements. Teachers should therefore examine the vendor’s privacy terms rather than assume that “free” means low risk.

Click-through terms create another concern. When a teacher accepts a terms-of-service agreement for an entire class, the teacher may be making a decision about other people’s children without authority to bind the district. A classroom app approval process may be slow or inconsistently documented, but it remains the appropriate route.

The practical rule is simple: submit a new tool for approval before entering student information. If approval is pending, use a demonstration account, fictional data, or a lesson that does not require personally identifiable information. That allows instruction to continue without creating an avoidable privacy risk.

New York teachers still need clear AI guidance

Artificial intelligence presents a more difficult problem because statewide direction remains limited. NYSED presented an artificial intelligence framework to the Board of Regents in March 2024. Based on the available guidance, districts have continued to develop their own policies, leaving educators with different rules depending on where they work.

New York City published a preliminary AI policy in March 2026 that offers a useful reference point. It bars the use of AI for grading, special education and 504 plans, discipline, counseling and crisis response, and academic placement decisions. The policy also states that “student information can never be entered into unapproved AI tools.”

That standard is a sensible baseline for districts without more specific rules. When using AI tools in New York classrooms, do not enter student names, identification numbers, grades, individualized education program details, accommodation information, health information, or behavior records into an unapproved chatbot or other AI service. Assume that text entered into an online tool may be stored, reviewed, used to improve the service, or retained longer than expected unless the district has confirmed otherwise in writing.

Teachers should also ask whether an AI product uses student prompts for training, permits human review, offers deletion controls, and provides an administrative account that allows the district to manage access. If the vendor cannot clearly answer those questions, the tool is not ready for student data.

The Instream case shows why vendor risk matters. The breach did not have to begin inside a school building. A service provider positioned between educational agencies and their files was enough to expose records. District approval must therefore cover the full vendor chain, not just the software visible to a teacher.

Education Law 2-d also protects employee information

Coverage of New York student data privacy often focuses on children, but Education Law 2-d also addresses certain employee records. Teacher and principal information drawn from annual professional performance reviews is confidential and protected from unauthorized release.

That protection is particularly important as districts update evaluation systems and purchase software to administer them. If a vendor will handle APPR records, ask how the system limits access, encrypts information, retains records, and responds to a suspected breach. Teacher APPR data protection is a legitimate faculty and union concern, not merely a technical question. Our guide to the STEPS evaluation rewrite explains the broader changes affecting these systems.

Employees who access personally identifiable information must also receive annual data privacy and security awareness training. If you have not received the required training, make a written request to your principal, district privacy officer, or human resources department. A documented request is more likely to produce a response than an informal hallway conversation and gives the district a record of the issue.

Parents, students, and staff members may file complaints about possible breaches. The regulations require findings to be provided within 60 days. Employees should report suspected exposure promptly, preserve relevant emails or screenshots, and avoid forwarding sensitive records unnecessarily while an investigation is underway.

Understand the breach notification deadlines

The school data breach notification timeline establishes specific deadlines. A vendor must notify the educational agency within seven calendar days after discovering a breach. The agency then has 10 calendar days to notify the state’s Chief Privacy Officer. Affected individuals must receive notice within 60 days.

These deadlines make immediate reporting important. A teacher who suspects that a roster, gradebook, email account, or shared drive has been exposed should contact the district’s designated privacy or security official at once. Do not wait to determine whether the incident is serious enough to report. The district, not the individual teacher, must assess the incident and manage the required notices.

Instream was penalized in part for missing the initial notification window. The breach occurred in July 2024, while the state’s public announcement came in August 2026. The timing illustrates how a delayed response can extend the consequences of an incident long after the original exposure.

The regulations calculate a notification penalty as the greater of $5,000 or $10 per affected person. For 6,253 records, the per-person calculation would be approximately $62,530. The state collected $125,000 from Instream and described the payment as a settlement. The published determination did not include the settlement agreement, leaving questions about how the final amount was calculated.

That uncertainty is relevant to districts negotiating contracts now. Procurement officials should ask vendors to identify their notification obligations, response deadlines, insurance coverage, audit rights, subcontractors, and responsibility for investigation costs before an incident occurs.

A practical privacy checklist for the start of school

Before students return, set aside time to review every digital service you plan to use, including platforms that have been part of your classroom for years. Then take the following steps:

  1. List each app, website, learning platform, assessment system, and AI service you expect to use.
  2. Search the district website for the vendor’s name and review the published Part 121 supplemental information.
  3. Contact the Data Protection Officer about any tool that is missing from the district’s records.
  4. Ask in writing whether the district has a current contract and what categories of information the tool may receive.
  5. Remove student information from unapproved systems and use fictional or de-identified data for demonstrations.
  6. Confirm when annual privacy and security training will be provided.
  7. Save the district’s breach-reporting contact information in an easily accessible location.
  8. Review whether AI tools retain prompts, use them for training, or allow vendor personnel to access them.

Do not assume that an app is safe because another teacher uses it, because it appears in a common marketplace, or because it is free. Approval, contract terms, data minimization, and clear reporting procedures are stronger indicators of responsible use.

Other policy changes educators should watch

NYSED is accepting public comments through 11:59 p.m. on September 28 on proposed amendments to sections 100.19 and 100.21 of the Commissioner’s Regulations. The changes would reorganize the accountability and receivership system into four tiers. Educators working in schools under state oversight may want to review the proposal and submit comments before the deadline.

Comments can be sent to [email protected]. For a plain-language explanation of what vendors mean when they promise encryption “in motion and at rest,” see our network’s explainer on modern hosting and compliance standards.

The Instream enforcement action is a reminder that student privacy failures can occur through ordinary classroom software, not only through a direct attack on a school’s network. Teachers cannot negotiate every vendor contract, but they can check approval records, limit the information they share, and report concerns quickly. Those steps reduce risk while giving districts the information they need to meet their legal obligations.

More information about data privacy, including instructions for students and parents to file a privacy complaint, is available on the Department’s Privacy Office website.