<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

A Practicing DPO's Guide to NY Ed Law 2-d: The Compliance Cheatsheet and Beyond

Ed Law 2-d is explicit: student PII has to be protected at rest, not just in transit. Learn what that actually requires, what it looks like to operationalize in a real district, and where even the most prepared DPOs still have gaps.

JOIN US

October 8, 2026 | 12:00 PM ET

Virtual

Most people responsible for Ed Law 2-d compliance aren't full-time DPOs. They're directors of technology with the DPO role added to an already full plate — and the ground has shifted underneath them.

Third-party incidents went from 4% to 32% of all K-12 breaches in just two years. The human element shows up in 62% of breaches overall, where a wrong attachment, a forwarded email, a staff member who didn't think twice inadvertently spilled data. And if something goes wrong, the 10-day breach notification clock starts whether your district is ready to run that play or not.

This year's Cybersecurity Awareness Month theme is "Securing the Next 250." For school districts, that framing is personal. The data we're talking about protecting belongs to kids.


WHAT YOU'LL TAKE AWAY

  • What Ed Law 2-d actually says about encryption — and the biggest gap between the law and what most districts think they're doing
  • The things DPOs are most likely getting wrong simply because the role sits on top of another full-time job
  • What to ask vendors before you sign, now that third-party incidents are a third of all K-12 breaches
  • What the 10-day breach notification clock really demands of a district operationally
  • How to build protection that assumes people will make mistakes, instead of depending on staff to remember
  • Where records retention and LGS-1 fit into the DPO's compliance picture going forward
  • Why TLS alone is compliance theater if the protection stops working the moment the email lands

WHO SHOULD ATTEND

  • Data Protection Officers
  • Directors of technology functioning as their district's DPO
  • District leaders who would own a breach response if one happened tomorrow
  • Anyone trying to get their arms around Ed Law 2-d encryption requirements without a dedicated compliance team

Register Now!

See You Soon