1 | 1 | | By: Parker S.B. No. 928 |
---|
2 | 2 | | |
---|
3 | 3 | | |
---|
4 | 4 | | A BILL TO BE ENTITLED |
---|
5 | 5 | | AN ACT |
---|
6 | 6 | | relating to the protection of personally identifiable student |
---|
7 | 7 | | information and the use of covered information by an operator or |
---|
8 | 8 | | educational entity; authorizing a civil and administrative |
---|
9 | 9 | | penalty. |
---|
10 | 10 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
11 | 11 | | SECTION 1. Section 32.151, Education Code, is amended by |
---|
12 | 12 | | amending Subdivision (1) and adding Subdivisions (1-a), (1-b), |
---|
13 | 13 | | (1-c), (1-d), (1-e), (1-f), and (5-a) to read as follows: |
---|
14 | 14 | | (1) "Aggregate student information" means student |
---|
15 | 15 | | information collected by an educational entity that: |
---|
16 | 16 | | (A) is totaled and reported at the group, cohort, |
---|
17 | 17 | | school, school district, region, or state level, as determined by |
---|
18 | 18 | | the educational entity; |
---|
19 | 19 | | (B) does not reveal personally identifiable |
---|
20 | 20 | | student information; and |
---|
21 | 21 | | (C) cannot reasonably be used to identify, |
---|
22 | 22 | | contact, single out, or infer information about a student or a |
---|
23 | 23 | | device used by a student. |
---|
24 | 24 | | (1-a) "Biometric identifier" means any measurement of |
---|
25 | 25 | | the human body or its movement that is used to attempt to uniquely |
---|
26 | 26 | | identify or authenticate the identity of an individual, including a |
---|
27 | 27 | | blood sample, hair sample, skin sample, body scan, retina or iris |
---|
28 | 28 | | scan, fingerprint, voiceprint, or record of hand or face geometry. |
---|
29 | 29 | | (1-b) "Coordinating board" means the Texas Higher |
---|
30 | 30 | | Education Coordinating Board. |
---|
31 | 31 | | (1-c) "Covered information" means personally |
---|
32 | 32 | | identifiable information or information that is linked to |
---|
33 | 33 | | personally identifiable information, in any media or format, that |
---|
34 | 34 | | is not publicly available and is: |
---|
35 | 35 | | (A) created by or provided to an operator or |
---|
36 | 36 | | educational entity by a student or the student's parent in the |
---|
37 | 37 | | course of the student's or parent's use of the operator's or |
---|
38 | 38 | | entity's website, online service, online application, or mobile |
---|
39 | 39 | | application for a school purpose; |
---|
40 | 40 | | (B) created by or provided to an operator or |
---|
41 | 41 | | educational entity by an employee of a school district or school |
---|
42 | 42 | | campus for a school purpose; or |
---|
43 | 43 | | (C) gathered by an operator or educational entity |
---|
44 | 44 | | through the operation of the operator's or entity's website, online |
---|
45 | 45 | | service, online application, or mobile application for a school |
---|
46 | 46 | | purpose and personally identifies a student, including the |
---|
47 | 47 | | student's educational record, electronic mail, first and last name, |
---|
48 | 48 | | home address, telephone number, electronic mail address, |
---|
49 | 49 | | information that allows physical or online contact, discipline |
---|
50 | 50 | | records, test results, special education data, juvenile |
---|
51 | 51 | | delinquency records, grades, evaluations, criminal records, |
---|
52 | 52 | | medical records, health records, social security number, biometric |
---|
53 | 53 | | identifier information, disabilities, socioeconomic information, |
---|
54 | 54 | | food purchases, political affiliations, religious information, |
---|
55 | 55 | | text messages, student identifiers, search activity, photograph, |
---|
56 | 56 | | voice recordings, or geolocation information. |
---|
57 | 57 | | (1-d) "Data breach" means an incident in which student |
---|
58 | 58 | | information that is sensitive, protected, or confidential, as |
---|
59 | 59 | | provided by state or federal law, is stolen or is copied, |
---|
60 | 60 | | transmitted, viewed, or used by a person unauthorized to engage in |
---|
61 | 61 | | that action. |
---|
62 | 62 | | (1-e) "Educational entity" includes school districts, |
---|
63 | 63 | | open-enrollment charter schools, regional education service |
---|
64 | 64 | | centers, institutions of higher education, and other local |
---|
65 | 65 | | education agencies. |
---|
66 | 66 | | (1-f) "Information privacy officer" means the |
---|
67 | 67 | | information privacy officer designated by the commissioner under |
---|
68 | 68 | | Section 32.1512. |
---|
69 | 69 | | (5-a) "Student" means a person who is enrolled at a |
---|
70 | 70 | | public primary or secondary school. |
---|
71 | 71 | | SECTION 2. Subchapter D, Chapter 32, Education Code, is |
---|
72 | 72 | | amended by adding Sections 32.1511, 32.1512, 32.1513, 32.1514, |
---|
73 | 73 | | 32.1515, 32.1516, 32.1517, 32.1518, 32.1521, 32.1531, 32.1551, |
---|
74 | 74 | | 32.1552, 32.1561, 32.1562, 32.1563, 32.158, 32.159, and 32.160 to |
---|
75 | 75 | | read as follows: |
---|
76 | 76 | | Sec. 32.1511. OWNERSHIP OF COVERED INFORMATION AND WORK |
---|
77 | 77 | | PRODUCT. (a) A student retains ownership over the student's own: |
---|
78 | 78 | | (1) covered information; and |
---|
79 | 79 | | (2) work or intellectual product, regardless of |
---|
80 | 80 | | whether the product was created for academic credit. |
---|
81 | 81 | | (b) A student may download, export, transfer, or otherwise |
---|
82 | 82 | | save or maintain any document, covered information, or other data |
---|
83 | 83 | | created by the student that is held or maintained by an educational |
---|
84 | 84 | | entity. |
---|
85 | 85 | | Sec. 32.1512. INFORMATION PRIVACY OFFICER; DUTIES. (a) |
---|
86 | 86 | | The commissioner shall designate an agency employee to serve as an |
---|
87 | 87 | | information privacy officer to oversee privacy and security |
---|
88 | 88 | | policies regarding student information. |
---|
89 | 89 | | (b) The information privacy officer shall: |
---|
90 | 90 | | (1) ensure that the agency handles covered information |
---|
91 | 91 | | maintained by the agency in a manner that complies with this |
---|
92 | 92 | | subchapter, the Family Educational Rights and Privacy Act of 1974 |
---|
93 | 93 | | (20 U.S.C. Section 1232g), and any other federal or state |
---|
94 | 94 | | information privacy or security law; |
---|
95 | 95 | | (2) establish and publish in a form that is easily |
---|
96 | 96 | | accessible policies necessary to ensure that the use of technology |
---|
97 | 97 | | sustains, enhances, and does not erode privacy protections related |
---|
98 | 98 | | to the use, collection, and disclosure of covered information; |
---|
99 | 99 | | (3) develop and provide to each educational entity a |
---|
100 | 100 | | model student information privacy and security plan; |
---|
101 | 101 | | (4) evaluate legislative and regulatory proposals |
---|
102 | 102 | | involving the use, collection, and disclosure of covered |
---|
103 | 103 | | information by educational entities; |
---|
104 | 104 | | (5) conduct privacy impact assessments, including an |
---|
105 | 105 | | assessment of the type of covered information collected and the |
---|
106 | 106 | | number of students affected, for: |
---|
107 | 107 | | (A) legislative proposals affecting educational |
---|
108 | 108 | | entities; and |
---|
109 | 109 | | (B) agency and coordinating board rules and |
---|
110 | 110 | | program initiatives; |
---|
111 | 111 | | (6) consult and coordinate with representatives of the |
---|
112 | 112 | | state, agency, and coordinating board and other appropriate persons |
---|
113 | 113 | | regarding the use of covered information and the implementation of |
---|
114 | 114 | | this subchapter; |
---|
115 | 115 | | (7) establish and operate a privacy incident response |
---|
116 | 116 | | program to ensure that each incident related to covered information |
---|
117 | 117 | | involving the agency is properly reported, investigated, and |
---|
118 | 118 | | mitigated; |
---|
119 | 119 | | (8) establish a model process and policy for a student |
---|
120 | 120 | | or the student's parent to file a complaint regarding: |
---|
121 | 121 | | (A) a violation of student information privacy; |
---|
122 | 122 | | or |
---|
123 | 123 | | (B) an inability to access, review, or correct |
---|
124 | 124 | | information contained in the student's educational record; and |
---|
125 | 125 | | (9) provide training, guidance, technical assistance, |
---|
126 | 126 | | and outreach to build a culture of student information protection |
---|
127 | 127 | | and student data security among educational entities and third |
---|
128 | 128 | | parties who contract with those entities. |
---|
129 | 129 | | (c) Not later than February 1 of each year, the information |
---|
130 | 130 | | privacy officer shall prepare and submit a written report to the |
---|
131 | 131 | | standing committees of each house of the legislature with primary |
---|
132 | 132 | | jurisdiction over primary, secondary, and higher education |
---|
133 | 133 | | regarding actions taken by the agency related to student |
---|
134 | 134 | | information privacy, including complaints regarding privacy |
---|
135 | 135 | | violations, internal controls, and other related matters. |
---|
136 | 136 | | Sec. 32.1513. GENERAL INVESTIGATIVE POWER OF INFORMATION |
---|
137 | 137 | | PRIVACY OFFICER. (a) The information privacy officer may |
---|
138 | 138 | | investigate an operator or educational entity as necessary to |
---|
139 | 139 | | enforce this subchapter and protect covered information gathered |
---|
140 | 140 | | from students in this state. |
---|
141 | 141 | | (b) On request of the information privacy officer, an |
---|
142 | 142 | | operator, educational entity, or a third party who contracts with |
---|
143 | 143 | | an operator or educational entity shall make all applicable records |
---|
144 | 144 | | and materials available to the officer as necessary to enable the |
---|
145 | 145 | | officer to determine compliance with this subchapter. |
---|
146 | 146 | | (c) The information privacy officer shall: |
---|
147 | 147 | | (1) limit the scope of the investigation and any |
---|
148 | 148 | | accompanying report to those matters that are necessary to the |
---|
149 | 149 | | administration of this subchapter; and |
---|
150 | 150 | | (2) in matters related to compliance with federal law, |
---|
151 | 151 | | refer the matter to the appropriate federal agency and cooperate |
---|
152 | 152 | | with an investigation by the federal agency. |
---|
153 | 153 | | Sec. 32.1514. AGENCY COMPREHENSIVE STUDENT INFORMATION |
---|
154 | 154 | | INVENTORY. The agency shall, to the maximum extent possible, |
---|
155 | 155 | | develop, maintain, and post on the agency's Internet website a |
---|
156 | 156 | | comprehensive student information inventory that accounts for all |
---|
157 | 157 | | covered information assets created by, collected by, under the |
---|
158 | 158 | | control or direction of, or maintained by the agency, including |
---|
159 | 159 | | student information that: |
---|
160 | 160 | | (1) is required to be reported by law; |
---|
161 | 161 | | (2) has been proposed for inclusion in the agency's |
---|
162 | 162 | | student information system with a statement regarding the reason |
---|
163 | 163 | | for the proposed inclusion; and |
---|
164 | 164 | | (3) is collected or maintained by the agency for no |
---|
165 | 165 | | current purpose or reason. |
---|
166 | 166 | | Sec. 32.1515. INFORMATION SECURITY POLICIES AND |
---|
167 | 167 | | PROCEDURES. (a) Subject to the approval of the information privacy |
---|
168 | 168 | | officer, each educational entity shall adopt and implement |
---|
169 | 169 | | reasonable information security policies and procedures in |
---|
170 | 170 | | accordance with this subchapter to protect students' educational |
---|
171 | 171 | | records and covered information from unauthorized access, |
---|
172 | 172 | | destruction, use, modification, or disclosure. |
---|
173 | 173 | | (b) An educational entity must take into account the |
---|
174 | 174 | | entity's specific needs and priorities in adopting policies and |
---|
175 | 175 | | procedures under Subsection (a). |
---|
176 | 176 | | Sec. 32.1516. STUDENT INFORMATION MANAGER. (a) Each |
---|
177 | 177 | | educational entity shall designate an individual to act as a |
---|
178 | 178 | | student information manager. The student information manager |
---|
179 | 179 | | shall: |
---|
180 | 180 | | (1) create, maintain, and submit to the information |
---|
181 | 181 | | privacy officer an information governance plan addressing the |
---|
182 | 182 | | protection of existing and future student information and records; |
---|
183 | 183 | | and |
---|
184 | 184 | | (2) establish a review process for all covered |
---|
185 | 185 | | information requests for the purpose of external research or |
---|
186 | 186 | | evaluation. |
---|
187 | 187 | | (b) Not later than December 1 of each year, the student |
---|
188 | 188 | | information manager shall submit a report to the agency's |
---|
189 | 189 | | information privacy officer. The report must include: |
---|
190 | 190 | | (1) proposed changes to the educational entity's |
---|
191 | 191 | | information security policies and procedures adopted under Section |
---|
192 | 192 | | 32.1515; and |
---|
193 | 193 | | (2) any data breaches or attempted data breaches |
---|
194 | 194 | | detected by the educational entity. |
---|
195 | 195 | | Sec. 32.1517. CONTRACT PROVISIONS. A contract between an |
---|
196 | 196 | | educational entity and an operator must include the following |
---|
197 | 197 | | provisions: |
---|
198 | 198 | | (1) requirements and restrictions related to the |
---|
199 | 199 | | collection, use, storage, and sharing of covered information by the |
---|
200 | 200 | | operator that are necessary for the educational entity to ensure |
---|
201 | 201 | | the operator's compliance with this subchapter and other law; |
---|
202 | 202 | | (2) a description of the person or type of person, |
---|
203 | 203 | | including an affiliate or subcontractor of the operator, with whom |
---|
204 | 204 | | the operator may share covered information; |
---|
205 | 205 | | (3) when and how to delete covered information |
---|
206 | 206 | | received by the operator; |
---|
207 | 207 | | (4) a prohibition on the secondary use of covered |
---|
208 | 208 | | information by the operator, except when used for a legitimate |
---|
209 | 209 | | school or research purpose or as described by Sections 32.153 and |
---|
210 | 210 | | 32.154; |
---|
211 | 211 | | (5) an agreement by the operator that the educational |
---|
212 | 212 | | entity or the educational entity's designee may audit the operator |
---|
213 | 213 | | to verify compliance with the contract; |
---|
214 | 214 | | (6) requirements for the operator or a subcontractor |
---|
215 | 215 | | of the operator to establish security measures to prevent, detect, |
---|
216 | 216 | | or mitigate a data breach; and |
---|
217 | 217 | | (7) requirements for the operator or a subcontractor |
---|
218 | 218 | | of the operator to notify the educational entity of a suspected data |
---|
219 | 219 | | breach. |
---|
220 | 220 | | Sec. 32.1518. NOTICE OF INFORMATION DISCLOSURE. (a) Not |
---|
221 | 221 | | less than annually, an educational entity that collects covered |
---|
222 | 222 | | information shall provide to each parent of a student whose covered |
---|
223 | 223 | | information is collected a notice of information disclosure form |
---|
224 | 224 | | stating in plain language the conditions under which the student's |
---|
225 | 225 | | covered information may be disclosed. The educational entity shall |
---|
226 | 226 | | provide the form as a stand-alone document. |
---|
227 | 227 | | (b) The notice of information disclosure form must: |
---|
228 | 228 | | (1) list the covered information that the educational |
---|
229 | 229 | | entity collects and the rationale for collecting the information, |
---|
230 | 230 | | including whether the information is required by law to be |
---|
231 | 231 | | collected; |
---|
232 | 232 | | (2) state that a student's covered information |
---|
233 | 233 | | collected by the educational entity may not be shared without the |
---|
234 | 234 | | written consent of the student's parent; |
---|
235 | 235 | | (3) list each operator or other third party with |
---|
236 | 236 | | access to or control of covered information maintained by the |
---|
237 | 237 | | educational entity; |
---|
238 | 238 | | (4) outline the rights and responsibilities of the |
---|
239 | 239 | | educational entity under this subchapter; and |
---|
240 | 240 | | (5) contain an acknowledgment section that: |
---|
241 | 241 | | (A) states that the intended recipient of the |
---|
242 | 242 | | notice actually received the notice and understands its contents; |
---|
243 | 243 | | (B) allows for the recipient to record the |
---|
244 | 244 | | recipient's objection to the collection of any covered information |
---|
245 | 245 | | relating to the parent's student that is not required by law to be |
---|
246 | 246 | | collected; and |
---|
247 | 247 | | (C) includes a signature line. |
---|
248 | 248 | | (c) Each parent who receives a notice of information |
---|
249 | 249 | | disclosure form under Subsection (a) shall sign the acknowledgement |
---|
250 | 250 | | section described by Subsection (b)(5) and return the form to the |
---|
251 | 251 | | educational entity as soon as possible. |
---|
252 | 252 | | (d) An educational entity shall: |
---|
253 | 253 | | (1) annually update its notice of information |
---|
254 | 254 | | disclosure form; and |
---|
255 | 255 | | (2) maintain a written or electronic record of each |
---|
256 | 256 | | signed acknowledgment form received under this section. |
---|
257 | 257 | | Sec. 32.1521. PROHIBITED USE OF COVERED INFORMATION AND |
---|
258 | 258 | | COLLECTION OF BIOMETRIC IDENTIFIER INFORMATION BY EDUCATIONAL |
---|
259 | 259 | | ENTITY. (a) Except as otherwise provided by this subchapter, an |
---|
260 | 260 | | educational entity may not release or otherwise disclose a |
---|
261 | 261 | | student's covered information in exchange for a good, product, |
---|
262 | 262 | | application, service, or any other thing of measurable value. |
---|
263 | 263 | | (b) An educational entity may not use or release covered |
---|
264 | 264 | | information for the purpose of targeted advertising unless the |
---|
265 | 265 | | release of the data is essential for a school purpose, including the |
---|
266 | 266 | | use of adaptive educational software or other strictly tailored |
---|
267 | 267 | | educational endeavor with the sole purpose of providing a tailored |
---|
268 | 268 | | educational experience to the student. |
---|
269 | 269 | | (c) An educational entity may not collect a student's |
---|
270 | 270 | | biometric identifier information unless required by law. |
---|
271 | 271 | | Sec. 32.1531. ALLOWED DISCLOSURE OF COVERED INFORMATION BY |
---|
272 | 272 | | EDUCATIONAL ENTITY. (a) An educational entity may disclose |
---|
273 | 273 | | covered information if the disclosure is: |
---|
274 | 274 | | (1) authorized in writing by the student's parent; |
---|
275 | 275 | | (2) determined by the entity to be necessary because |
---|
276 | 276 | | of an imminent health or safety emergency; |
---|
277 | 277 | | (3) ordered by a court of competent jurisdiction; or |
---|
278 | 278 | | (4) authorized or required by a provision of federal |
---|
279 | 279 | | or state law. |
---|
280 | 280 | | (b) The educational entity must comply with the |
---|
281 | 281 | | requirements of federal and state law to protect any student |
---|
282 | 282 | | information disclosed under this section. |
---|
283 | 283 | | (c) This subchapter may not be construed to prohibit or |
---|
284 | 284 | | otherwise limit the ability of an educational entity to report or |
---|
285 | 285 | | make available aggregate student information or other collective |
---|
286 | 286 | | information for reasonable use. |
---|
287 | 287 | | Sec. 32.1551. NOTIFICATION OF DATA BREACH AFFECTING |
---|
288 | 288 | | OPERATOR. (a) Not later than 24 hours after an operator becomes |
---|
289 | 289 | | aware of a data breach, the operator shall notify the applicable |
---|
290 | 290 | | educational entity with whom the operator has contracted of the |
---|
291 | 291 | | breach and take action to determine the scope of student |
---|
292 | 292 | | information affected by the breach. |
---|
293 | 293 | | (b) The operator shall update the educational entity as soon |
---|
294 | 294 | | as the full scope of the data breach is assessed and take all |
---|
295 | 295 | | reasonable steps to notify all persons affected by the breach. |
---|
296 | 296 | | Sec. 32.1552. NOTIFICATION OF DATA BREACH AFFECTING |
---|
297 | 297 | | EDUCATIONAL ENTITY. (a) Not later than 24 hours after an |
---|
298 | 298 | | educational entity becomes aware of a data breach, the educational |
---|
299 | 299 | | entity shall notify the information privacy officer of the |
---|
300 | 300 | | suspected or confirmed breach. |
---|
301 | 301 | | (b) Not later than the third business day after the date a |
---|
302 | 302 | | data breach is verified, an educational entity shall notify the |
---|
303 | 303 | | parent of each student affected by the breach. |
---|
304 | 304 | | Sec. 32.1561. INSPECTION OF INFORMATION CONTAINED IN |
---|
305 | 305 | | STUDENT'S EDUCATIONAL RECORD. (a) On request of a student's |
---|
306 | 306 | | parent, an educational entity or operator shall allow the student's |
---|
307 | 307 | | parent to inspect the covered information and other information |
---|
308 | 308 | | contained in the student's educational record maintained by the |
---|
309 | 309 | | entity or operator. |
---|
310 | 310 | | (b) The educational entity or operator shall provide the |
---|
311 | 311 | | information requested under Subsection (a) in a timely manner and, |
---|
312 | 312 | | if possible, in an electronic format. |
---|
313 | 313 | | (c) An educational entity or operator is not required to |
---|
314 | 314 | | provide information requested under Subsection (a) if: |
---|
315 | 315 | | (1) the information cannot reasonably be made |
---|
316 | 316 | | available to the requesting individual; or |
---|
317 | 317 | | (2) the reproduction of the requested information |
---|
318 | 318 | | would be unduly burdensome. |
---|
319 | 319 | | Sec. 32.1562. CORRECTION OF INFORMATION CONTAINED IN |
---|
320 | 320 | | STUDENT'S EDUCATIONAL RECORD. (a) After reviewing information |
---|
321 | 321 | | requested under Section 32.1561, a student's parent may request |
---|
322 | 322 | | that the educational entity or operator make corrections to address |
---|
323 | 323 | | inaccurate or incomplete data in the student's educational record |
---|
324 | 324 | | maintained by the entity or operator. |
---|
325 | 325 | | (b) On request by a student's parent, an educational entity |
---|
326 | 326 | | or operator shall expunge from the student's educational record |
---|
327 | 327 | | covered information related to: |
---|
328 | 328 | | (1) an unsubstantiated accusation made against the |
---|
329 | 329 | | student; or |
---|
330 | 330 | | (2) alleged conduct committed by the student if: |
---|
331 | 331 | | (A) prosecution of the student's case was refused |
---|
332 | 332 | | for lack of prosecutorial merit or insufficient evidence and no |
---|
333 | 333 | | formal proceedings, deferred adjudication, or deferred prosecution |
---|
334 | 334 | | were initiated; or |
---|
335 | 335 | | (B) the court or jury found the student not |
---|
336 | 336 | | guilty or made a finding the student did not engage in delinquent |
---|
337 | 337 | | conduct or conduct indicating a need for supervision and the case |
---|
338 | 338 | | was dismissed with prejudice. |
---|
339 | 339 | | (c) Not later than the 90th day after the date an |
---|
340 | 340 | | educational entity or operator receives a request under Subsection |
---|
341 | 341 | | (a) or (b), the educational entity or operator shall make changes to |
---|
342 | 342 | | the student's educational record as necessary and confirm the |
---|
343 | 343 | | changes with the student's parent. |
---|
344 | 344 | | Sec. 32.1563. RULES; FORMS. (a) The commissioner shall |
---|
345 | 345 | | adopt rules as necessary to implement this subchapter. |
---|
346 | 346 | | (b) The commissioner shall develop forms as necessary to |
---|
347 | 347 | | implement this subchapter, including model forms for: |
---|
348 | 348 | | (1) providing the notice of information disclosure |
---|
349 | 349 | | required by Section 32.1518; and |
---|
350 | 350 | | (2) obtaining written parental consent for the |
---|
351 | 351 | | disclosure of covered information as required by Section 32.1531. |
---|
352 | 352 | | Sec. 32.158. CIVIL PENALTY. (a) An operator that violates |
---|
353 | 353 | | this subchapter or a rule adopted under this subchapter is liable |
---|
354 | 354 | | for a civil penalty if the violation resulted in a negligent data |
---|
355 | 355 | | breach. |
---|
356 | 356 | | (b) In determining the amount of a civil penalty to impose |
---|
357 | 357 | | under this section, the court shall include: |
---|
358 | 358 | | (1) the cost of identity protection for each person |
---|
359 | 359 | | affected by the data breach or compromise; |
---|
360 | 360 | | (2) legal fees and costs incurred by each person |
---|
361 | 361 | | affected by the data breach or compromise; and |
---|
362 | 362 | | (3) any other penalty that the court deems reasonable |
---|
363 | 363 | | or appropriate. |
---|
364 | 364 | | Sec. 32.159. ADMINISTRATIVE PENALTY. (a) The commissioner |
---|
365 | 365 | | may assess an administrative penalty for a violation of this |
---|
366 | 366 | | subchapter in an amount of not less than $1,000 or more than $5,000. |
---|
367 | 367 | | (b) The aggregate amount of penalties that the commissioner |
---|
368 | 368 | | may assess against a person under this section during a calendar |
---|
369 | 369 | | year may not exceed $1,000,000. |
---|
370 | 370 | | Sec. 32.160. CRIMINAL LIABILITY NOT AFFECTED. This |
---|
371 | 371 | | subchapter may not be construed to limit or otherwise affect a |
---|
372 | 372 | | person's criminal liability under other law. |
---|
373 | 373 | | SECTION 3. The heading to Section 32.152, Education Code, |
---|
374 | 374 | | is amended to read as follows: |
---|
375 | 375 | | Sec. 32.152. PROHIBITED USE OF COVERED INFORMATION AND |
---|
376 | 376 | | COLLECTION OF BIOMETRIC IDENTIFIER INFORMATION BY OPERATOR. |
---|
377 | 377 | | SECTION 4. Section 32.152, Education Code, is amended by |
---|
378 | 378 | | amending Subsection (a) to read as follows: |
---|
379 | 379 | | (a) An operator may not knowingly: |
---|
380 | 380 | | (1) engage in targeted advertising on any website, |
---|
381 | 381 | | online service, online application, or mobile application if the |
---|
382 | 382 | | target of the advertising is based on any information, including |
---|
383 | 383 | | covered information and persistent unique identifiers, that the |
---|
384 | 384 | | operator has acquired through the use of the operator's website, |
---|
385 | 385 | | online service, online application, or mobile application for a |
---|
386 | 386 | | school purpose; |
---|
387 | 387 | | (2) use information, including persistent unique |
---|
388 | 388 | | identifiers, created or gathered by the operator's website, online |
---|
389 | 389 | | service, online application, or mobile application, to create a |
---|
390 | 390 | | profile about a student unless the profile is created for a school |
---|
391 | 391 | | purpose; [or] |
---|
392 | 392 | | (3) except as provided by Subsection (c), sell or rent |
---|
393 | 393 | | any student's covered information; |
---|
394 | 394 | | (4) exchange a student's covered information for any |
---|
395 | 395 | | good, service, or application; |
---|
396 | 396 | | (5) disclose covered information except as provided |
---|
397 | 397 | | under this subchapter; or |
---|
398 | 398 | | (6) unless required by law, collect a student's |
---|
399 | 399 | | biometric identifier information. |
---|
400 | 400 | | SECTION 5. The heading to Section 32.153, Education Code, |
---|
401 | 401 | | is amended to read as follows: |
---|
402 | 402 | | Sec. 32.153. ALLOWED DISCLOSURE OF COVERED INFORMATION BY |
---|
403 | 403 | | OPERATOR. |
---|
404 | 404 | | SECTION 6. Section 32.153, Education Code, is amended by |
---|
405 | 405 | | amending Subsection (a) and adding Subsection (f) to read as |
---|
406 | 406 | | follows: |
---|
407 | 407 | | (a) An operator may use or disclose covered information |
---|
408 | 408 | | under the following circumstances: |
---|
409 | 409 | | (1) to further a school purpose of the website, online |
---|
410 | 410 | | service, online application, or mobile application and the |
---|
411 | 411 | | recipient of the covered information disclosed under this |
---|
412 | 412 | | subsection does not further disclose the information unless the |
---|
413 | 413 | | disclosure is to allow or improve operability and functionality of |
---|
414 | 414 | | the operator's website, online service, online application, or |
---|
415 | 415 | | mobile application; |
---|
416 | 416 | | (2) to ensure legal and regulatory compliance; |
---|
417 | 417 | | (3) to protect against liability; |
---|
418 | 418 | | (4) to respond to or participate in the judicial |
---|
419 | 419 | | process, including to comply with an investigation by law |
---|
420 | 420 | | enforcement as authorized by law or a court order; |
---|
421 | 421 | | (5) to protect: |
---|
422 | 422 | | (A) the safety or integrity of users of the |
---|
423 | 423 | | website, online service, online application, or mobile |
---|
424 | 424 | | application; or |
---|
425 | 425 | | (B) the security of the website, online service, |
---|
426 | 426 | | online application, or mobile application; |
---|
427 | 427 | | (6) for a school, education, or employment purpose |
---|
428 | 428 | | requested by the student or the student's parent and the |
---|
429 | 429 | | information is not used or disclosed for any other purpose; |
---|
430 | 430 | | (7) to use the covered information for: |
---|
431 | 431 | | (A) a legitimate research purpose; or |
---|
432 | 432 | | (B) a school purpose or postsecondary |
---|
433 | 433 | | educational purpose; [or] |
---|
434 | 434 | | (8) for a request by the agency or the school district |
---|
435 | 435 | | for a school purpose; |
---|
436 | 436 | | (9) to market an educational application or product to |
---|
437 | 437 | | a student's parent, if the operator did not use covered information |
---|
438 | 438 | | shared or collected by or on behalf of an educational entity to |
---|
439 | 439 | | develop the application or product; |
---|
440 | 440 | | (10) to allow a recommendation engine on the |
---|
441 | 441 | | operator's website, online service, online application, or mobile |
---|
442 | 442 | | application to recommend to a student's parent content or services |
---|
443 | 443 | | related to learning or employment, if the recommendation is not |
---|
444 | 444 | | motivated by payment or other consideration from another party; or |
---|
445 | 445 | | (11) to respond to the request of a student's parent |
---|
446 | 446 | | for information or feedback, if the content of the response is not |
---|
447 | 447 | | motivated by payment or other consideration from another party. |
---|
448 | 448 | | (f) Notwithstanding any other law, an operator shall use a |
---|
449 | 449 | | student's covered information received under a contract with an |
---|
450 | 450 | | educational entity strictly for the purpose provided under the |
---|
451 | 451 | | contract unless the student's parent affirmatively chooses to |
---|
452 | 452 | | disclose the student's information for a secondary purpose. |
---|
453 | 453 | | SECTION 7. The heading to Section 32.154, Education Code, |
---|
454 | 454 | | is amended to read as follows: |
---|
455 | 455 | | Sec. 32.154. ALLOWED USE OF COVERED INFORMATION BY |
---|
456 | 456 | | OPERATOR. |
---|
457 | 457 | | SECTION 8. The heading to Section 32.155, Education Code, |
---|
458 | 458 | | is amended to read as follows: |
---|
459 | 459 | | Sec. 32.155. PROTECTION OF COVERED INFORMATION BY OPERATOR. |
---|
460 | 460 | | SECTION 9. Sections 32.155(c), (d), and (e), Education |
---|
461 | 461 | | Code, are amended to read as follows: |
---|
462 | 462 | | (c) In addition to including the unique identifier in |
---|
463 | 463 | | releasing information as provided by Subsection (b), an operator |
---|
464 | 464 | | may include any other data field identified by the agency or by an |
---|
465 | 465 | | educational entity [a school district, open-enrollment charter |
---|
466 | 466 | | school, regional education service center, or other local education |
---|
467 | 467 | | agency] as necessary for the information being released to be |
---|
468 | 468 | | useful. |
---|
469 | 469 | | (d) An educational entity [A school district, |
---|
470 | 470 | | open-enrollment charter school, regional education service center, |
---|
471 | 471 | | or other local education agency] may include additional data fields |
---|
472 | 472 | | in an agreement with an operator or the amendment of an agreement |
---|
473 | 473 | | with an operator under this section. An operator may agree to |
---|
474 | 474 | | include the additional data fields requested by an educational |
---|
475 | 475 | | entity [a school district, open-enrollment charter school, |
---|
476 | 476 | | regional education service center, or other local education agency] |
---|
477 | 477 | | but may not require that additional data fields be included. |
---|
478 | 478 | | (e) An educational entity [A school district, |
---|
479 | 479 | | open-enrollment charter school, regional education service center, |
---|
480 | 480 | | or other local education agency] may require an operator that |
---|
481 | 481 | | contracts directly with the entity to adhere to a state-required |
---|
482 | 482 | | student data sharing agreement that includes the use of an |
---|
483 | 483 | | established unique identifier standard for all operators as |
---|
484 | 484 | | prescribed by the agency. |
---|
485 | 485 | | SECTION 10. The heading to Section 32.156, Education Code, |
---|
486 | 486 | | is amended to read as follows: |
---|
487 | 487 | | Sec. 32.156. DELETION OF COVERED INFORMATION BY OPERATOR. |
---|
488 | 488 | | SECTION 11. This Act takes effect September 1, 2023. |
---|