October 1, 2026 · Manage1to1

NY Ed Law 2-d: What to Require From a Device Management Vendor

What Education Law 2-d and Part 121 actually oblige a vendor to do, the six things to get in writing before you sign, and how to tell a real answer from a brochure answer.

NY Ed Law 2-d: What to Require From a Device Management Vendor

If you run technology for a New York district, Education Law 2-d is probably not new to you. What is new, every time, is the part where a purchase you already decided on stops moving because someone in business or legal asks whether the vendor is 2-d compliant, and nobody can produce a straight answer.

That question has a real answer. It is not a badge and it is not a line in a brochure. It is a short list of specific things a vendor either does or does not do, and every one of them is checkable before you sign.

Here is the list, written so you can use it against any vendor, including us.

This is a practical summary for IT and procurement teams, not legal advice. Your district's counsel and Data Protection Officer own the final call on any contract.

What the law actually asks for

Education Law 2-d and its implementing regulation, Part 121, split the obligation in two. Most of the weight sits on your district. A meaningful share sits on anyone you hand student data to.

Your district has to adopt a published data security and privacy policy aligned to the NIST Cybersecurity Framework version 1.1, publish a Parents Bill of Rights for Data Privacy and Security, designate a Data Protection Officer, and publish a supplement to that Bill of Rights for every contract under which a vendor receives personally identifiable information.

A vendor that receives student data has to align its own safeguards to NIST CSF v1.1, comply with your district's policy rather than its own, limit internal access to staff who actually need it, use the data only for what the contract explicitly authorizes, and notify you of a breach or unauthorized release without unreasonable delay and in no case later than seven calendar days after discovering it.

That last number is the one worth memorizing. Seven calendar days is a contractual commitment, not an aspiration, and civil penalties escalate from $1,000 to $5,000 to $10,000 for repeat violations.

The six things to get in writing

1. A data security and privacy plan, specific to your contract

Part 121 requires the contract itself to include a plan describing how the vendor will implement the state, federal, and local data security requirements for the life of that agreement. A generic security whitepaper is not this. The plan has to reference your district's policy.

Ask for it as an attachment before signing, not after. We publish ours at Data Security and Privacy Plan so procurement can read it at the evaluation stage rather than during contracting.

2. NIST CSF v1.1 alignment, stated plainly

The framework is named in the regulation, so "we take security seriously" is not a response to this question. You want to hear the framework named, and you want to know whether the claim is self-attested or independently audited. Both are legitimate; they are just different, and a vendor that blurs them is telling you something.

We align our controls to NIST CSF v1.1 and the CIS Critical Security Controls, and we say plainly on our security page that this alignment is self-attested. Our hosting carries SOC 2+, PCI Merchant, CSA Star Level 1, and ISO/IEC 27001:2022 certification. Those are two different claims and we do not let them blur into one.

3. The Parents Bill of Rights, and the supplement

The Bill of Rights has to accompany every contract, and your district has to publish a supplement for each vendor agreement describing what data is collected, how it is used, who else touches it, and when it is destroyed.

The practical question is whether the vendor will help you draft that supplement or leave your team to reverse-engineer it from a privacy policy. Ours is published at Parents Bill of Rights.

4. A seven-day breach notification clause

Get the number in the contract. Not "prompt notification", not "in accordance with applicable law". The regulation says seven calendar days from discovery, and a vendor unwilling to write a number down is asking you to absorb their ambiguity.

Ask the follow-up too: notify whom? A named contact at your district, or a support queue?

5. Named subprocessors, and what happens at contract end

Anyone the vendor passes student data to inherits the same obligations. Ask for the list, and ask what happens to your data when the contract ends. Returned, destroyed, on what timeline, confirmed how.

This is where integrations matter more than districts expect. A device management platform reads from your SIS and your MDM, so the answer has to cover what flows where. Our live connections are listed openly on our integrations page, which is the fastest way to check whether the data map you are being shown is the real one.

6. Willingness to sign your paperwork

The honest tell. Some vendors will only sign their own agreement. A district operating under 2-d frequently cannot accept that, because the regulation binds the vendor to your policy.

We sign customer-side SaaS agreements and Data Processing Agreements as a matter of course, including the standard SDPC Alliance DPA, and we are listed in the SDPC Resource Registry. If a vendor treats signing your DPA as an exception requiring escalation, that is worth knowing in week one rather than week nine.

How to tell a real answer from a brochure answer

A brochure answer names a certification and stops. A real answer tells you which standard, who verified it, where the document lives, and what the vendor will commit to in writing.

Three questions that separate them quickly:

  • "Is that certification yours, or your hosting provider's?" Both matter. They are not the same claim, and plenty of listings quietly merge them.
  • "Will you sign our DPA, unmodified?" The answer arrives fast when it is yes.
  • "Who at your company gets the breach call, and how fast?" A vendor that has thought about 2-d has an answer ready. A vendor that has not will offer to follow up.

Why this ends up being an IT problem

Student data privacy law is written for lawyers and enforced against districts, but it lands on the technology office, because you are the one who knows what data actually moves and where. When procurement asks whether a platform is 2-d compliant, they are really asking you to vouch for a data flow you did not design.

The way out is boring and effective: make the vendor put the six items above in the contract, at evaluation time, before anyone has a renewal date to defend.

We publish our privacy plan, our Parents Bill of Rights, our framework alignment, and our integration list openly, precisely so a district can answer the compliance question without booking a call with us first. If it is easier to have the conversation live, book a 30-minute demo and bring your business office. We would rather answer the hard questions during evaluation than during contracting.


Back to Learn