Jul 21 2026
Data Analytics

Data Governance Helps K–12 Leaders Safeguard School Data

K–12 IT leaders are using formal policies and technology tools to strengthen data privacy and compliance.

A few years ago, Jenn Judkins was attending a data governance training session when the instructor posed a question: “You may say you have a good data privacy practice in place, but is it documented? If it’s not documented, does it really exist?”

That question resonated with Judkins, technology director at Wayland Public Schools in Massachusetts. She had spent years thinking about how to protect student data, working with her team to follow best practices around access, data protection and vetting software vendors. But none of it was formally written down.

The instructor, Melissa Tebbenkamp, a consultant and an experienced K–12 IT leader, told the group that documentation is foundational because policies and practices that are not written down can’t be trained on, enforced, monitored for effectiveness or improved upon.

Click the banner below to discover how CDW supports data governance in schools.

 

“It’s not enough to know in my head what the right thing is to do,” Judkins says. “It was important to articulate everything I was thinking about and that our team had discussed in a document that could be a reference for others in the school community.”

A growing number of districts are building data governance programs to improve data privacy and security; meet compliance requirements such as the Family Educational Rights and Privacy Act and Children’s Online Privacy Protection Act; and ensure data accuracy for reporting, analytics and AI.

But many still struggle. Districts often treat data governance as an IT project when it’s actually a districtwide leadership responsibility that requires buy-in across the organization, says Tebbenkamp, now the technology director for CoSN.

“Some districts are doing it really well, but generally, we’re still seeing that gap there,” she says.

Data governance and cybersecurity go hand in hand. Key practices include least-privilege access, which limits staff to only the data their roles require, and data minimization, meaning districts should only collect data they have a clear, identified purpose for, she says. Districts should also destroy data they no longer need and de-identify data used for reporting.

Technology helps enforce such policies. Identity management and identity lifecycle tools automatically activate and deactivate accounts as staff and students join or leave, preventing old accounts from becoming security vulnerabilities and ensuring everyone has the right access.

“You can’t have proper data governance without data privacy and cybersecurity,” she says. “The success of one is dependent on the strength of the other.”

41%

The percentage of districts that are improving their data governance practices

Source: CoSN, “2025 State of EdTech District Leadership,” May 2025

Governance and Technology Tools Keep Data in Line

Wayland Public Schools standardized on Google Workspace for Education Plus as its productivity and collaboration suite, and Judkins now uses the suite’s built-in tools to implement governance policies, including multifactor authentication, single sign-on and data loss prevention (DLP).

The district, which has five schools and about 2,700 students, also uses Google Vault for data retention and legal discovery. For artificial intelligence use, the district guides staff to use Google Gemini because it doesn’t train on prompts and data stays internal, she says.

When Judkins joined Wayland in 2024, Tebbenkamp’s challenge about documentation combined with the district’s impending adoption of a new student information system (SIS) led her to propose a formal data governance manual and a districtwide committee to finalize it. Leadership gave her the green light.

Judkins had previously drafted an early version of the manual as part of a course she took. She updated it and assembled a committee to discuss and finalize it. The committee — made up of district leaders, frontline staff and data stewards who are department heads accountable for specific student and staff data — determined who should see what data and why.

In the first meeting, Judkins explained why data governance matters and introduced core concepts such as least-privilege access, data classification and the data lifecycle. In two subsequent meetings, they reviewed what data the district collects, determined role-based access controls for applications and classified data by sensitivity level.

KEEP READING: Identity management makes schools less vulnerable to cybercrime.

The collaborative process resulted in a comprehensive, districtwide manual on data use and privacy, Judkins says.

“Without stakeholder buy-in, the work doesn’t take hold. Documentation and shared ownership have to work together for it to truly become part of how an organization operates,” she says.

The IT department configured role-based access inside the SIS and other applications. Principals now see only student records from their own schools and no longer have access to districtwide student data. Staff also get view-only access to data dashboards relevant to their work.

Most staffers use Google Authenticator for multifactor authentication, while Google single sign-on serves as the district’s primary identity hub, giving users access to district-approved applications through one set of credentials.

Wayland is also deploying ClassLink OneSync, an identity lifecycle management tool that automatically creates, updates and revokes access across systems based on SIS data. “We want to treat identity as a proactive security perimeter, so users have exactly what they need the moment they join, and access is revoked the moment they leave,” Judkins says.

After a third-party audit of its Google Admin Console settings, the district is expanding its use of Google’s DLP features, including the ability to tag sensitive files and apply rules that block external sharing.

“Our goal is to ensure governance happens in the background, so our teachers and students can focus on learning, knowing that the system is protecting their data automatically,” she says.

Automation is not enough, however. Before submitting reports to the state, Judkins routes them through data stewards for review. “Our philosophy is to trust but verify,” she says.

Review Data Privacy Agreements With Software Vendors

Technology leaders at two other small districts say data governance is an ongoing, yearslong effort, but they’ve made steady progress.

When the pandemic pushed classes online, many districts rushed to adopt new educational apps. In the aftermath, Littleton Public Schools Technology Systems Coordinator Natalie Croteau and other Massachusetts tech directors on a listserv got curious: “Let’s pull back a bit. Where’s all this data going?”

Without formal agreements in place, student data was not protected. She and Karen Winsper, director of instructional technology at Norton Public Schools, addressed the risk by joining The Education Cooperative (TEC), a nonprofit whose Student Data Privacy Consortium negotiated standard data privacy agreements with vendors on member districts’ behalf.

The contracts give districts ownership and control of student data, prohibit targeted advertising to students, require minimum data security requirements and breach notification, and require vendors to run criminal background checks on their employees.

The privacy agreements proved their worth when Winsper switched cloud-based SIS vendors. She leveraged a “directive for disposition of data” within the data privacy agreement, requiring the prior vendor to formally return student records and verify the destruction of remaining data.

“I don't want to rely on the vendor’s goodwill," Winsper says. "This gives us teeth to hold them accountable.”

DIVE DEEPER: Here’s what K–12 leaders need to know about third-party SaaS risk.

Beyond vendor agreements, both districts use technology to manage data access. They apply least-privilege access principles across their systems, from their SIS and other applications to security cameras. Both also use Google Admin Console to manage permissions. Winsper uses ClassLink for single sign-on.

Croteau extends least-privilege principles to students as well. Middle schoolers can only email within their schools, but high schoolers get external email access. She also requires staff to use two-factor authentication for their Google accounts.

Winsper and Croteau believe “access creep” is an ongoing risk. When employees change roles, new permissions get added, but the old ones often don’t get removed, leaving employees with access to buildings or systems they shouldn’t have. Their solution is periodic access reviews. “You have to set up guidelines for when you revisit access,” Winsper says. “Once a year, are you going in and checking?”

Both districts have data governance in place, and are in the process of writing their formal manuals. Even when that’s complete, the work to improve data governance will continue. 

“It is an evolving document that should be looked at often,” Croteau says. “Just because you wrote it a year ago doesn’t mean you’re done.”

Illustration by John Hersey
Close

New Research from CDW on Workplace Friction

Learn how IT leaders are working to build a frictionless enterprise.