Aug 13 2026
Security

6 Data Governance Best Practices for K–12

Protecting student data requires not only policy but smart and practical steps to reduce potential exposure.

K–12 districts are entrusted with a wide range of student data. Attendance records, grades, behavior logs, Individualized Education Programs and health records are gathered and stored in school systems, often for years after children move on to other districts or graduate. And as schools adopt more ed tech tools, they’re responsible for even more data. With that responsibility comes risk: A single mismanaged account can lead to an exposure that puts students’ information at risk.

Strong data governance requires building smart policy; it also requires putting into place deliberate practices that reduce exposure risk and district liability.

Click the banner below to discover how your district can build a strong data foundation.

 

1. Grant Least-Privilege Access

Start with the most restrictive permissions. Loosen them only when there is a clear need. “Once you’ve given them access, it becomes difficult to justify why you’re pulling that back. You can’t put the toothpaste back in the tube,” says Jenn Judkins, technology director at Wayland Public Schools in Massachusetts. 

2. Limit The Data You Collect

Collect only the data you need and delete it when you’re done. Don’t collect data that has no clear purpose, says Melissa Tebbenkamp, technology director for CoSN. Start with enrollment, where unnecessary data accumulates. Delete residency documents such as bills once they are no longer required. Don’t collect Social Security numbers unless there’s a specific need. “You don’t have to protect what you don’t collect,” Judkins says. 

3. Separate Administrative Accounts From Daily-Use Accounts

Staffers who have administrative access should have two accounts: one for administrative needs and one for daily use. That way, if a daily-use account is compromised, the attack surface is limited, Tebbenkamp says. 

4. Don’t Give Unlimited Access, Especially for Temporary Employees

Grant access only for as long as it’s needed. If employees need system access for a limited time, such as a teacher who assists with student scheduling for six weeks each year, grant it for that time frame only, and set a calendar reminder to revoke access when the work is done, Judkins says. 

5. Review Data Before It Goes to the State

Have data stewards review state reports before submission. The director of the English learner program will catch errors that IT never would. "They’re the ones that would have the ability, more than we would, to say, ‘Wait a minute, that can’t be right,’” Judkins says.

6. Check for Access Creep

When staffers change roles, old permissions often don’t get removed. Review access at least annually to ensure employees aren’t carrying permissions from previous positions. “Once a year, are you going in and checking?” says Karen Winsper of Norton Public Schools.

skynesher/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.