State compliance

New York Education Law § 2-d: What It Requires of a Communications Vendor

New York asks more of a per-contract paper trail than any other state we are aware of, and it asks for most of it before data moves rather than after. A vendor that has never worked with a New York district usually discovers this at the point of signature, which is the worst possible moment, because the district cannot waive any of it.

Last reviewed 2026-08-04 ยท Kastr is pre-launch; we publish dated status rather than logos.

The supplemental information a New York contract carries — and what a communications vendor has to be able to answer
ElementThe question behind itWhat a weak answer looks like
Exclusive purposesWhat may the vendor use student data for, stated narrowly“To provide and improve the Services” — “improve” is doing a lot of work there
Subcontractor oversightWho else touches the data, and how are they bound to the same termsA sub-processor list that does not match the one in the security questionnaire
Contract duration and end-of-term handlingWhen does the data go, and what does “go” mean“Deleted in accordance with our retention policy” with no policy attached
Parent challenge to accuracyHow does a parent get a wrong phone number or language of record corrected“Contact the district” where the district cannot edit the field either
Storage and protectionWhere the data sits and what protects itA region name and the word “encrypted” with no statement of at-rest versus in-transit
EncryptionEncryption of personally identifiable information in motion and at restTLS described as though it covered storage

Element names are paraphrased for readability. Use the wording in your own district's Ed Law 2-d contract rider, which your BOCES or district counsel maintains, rather than this table, when you build the actual document.

What § 2-d actually does

Education Law § 2-d, with implementing regulations at 8 NYCRR Part 121, governs how educational agencies in New York — districts, BOCES, charter schools and the State Education Department — handle personally identifiable information, and what they must require of third-party contractors who receive it.

Four obligations matter to a communications platform.

  • A Parents' Bill of Rights for Data Privacy and Security. The educational agency publishes it, and it is appended to every contract with a third-party contractor that will receive student data. It is not boilerplate a vendor supplies; it is the district's document, and the vendor signs a contract that carries it.
  • Supplemental information for each contract. The elements in the table above are published alongside the Bill of Rights for each contract. This is the part vendors underestimate: it is per-contract, it is public-facing, and it forces specificity about purposes and subcontractors that generic terms of service never contain.
  • A data security and privacy plan from the contractor. The third-party contractor must have one, and it must align with the educational agency's own policy.
  • A designated Data Protection Officer at the educational agency, and a framework anchor. Part 121 requires the agency's data security and privacy policy to align with the National Institute of Standards and Technology Cybersecurity Framework. That matters to a vendor because it sets the vocabulary your questionnaire answers should be written in.

Confirm the current text of § 2-d and Part 121 before drafting. The regulation has been amended since it was first adopted and your BOCES regional information centre will have the current rider language.

The breach clock, and why the vendor's window is the tight one

New York splits the notification duty. The third-party contractor must notify the educational agency of a breach or unauthorised release without unreasonable delay and, as we understand the regulation, no later than seven calendar days from discovery. The educational agency then has its own, longer window to notify affected parents — on our reading, no more than sixty days from discovery. Confirm both counts against the current regulation; day-counts are exactly the sort of provision that gets amended.

Two operational consequences, whichever the exact numbers are.

  • Seven days is not seven business days of investigation. It is a week from discovery, which in practice means a vendor must be able to notify while the forensic picture is still incomplete. A vendor whose incident process starts with a fortnight of legal review cannot meet it.
  • The notice has to reach a person who exists. Name the recipient by role, not by individual, give a second channel, and test it once a year. A large share of missed breach clocks are missed because the notice went to an address belonging to someone who left the district.

Ask for the incident record, not the incident policy. Every vendor has a policy document. The useful question is what their system records when something happens: who accessed what, when, from where, and whether that record can be altered afterwards. Kastr writes every send, every audience resolution and every administrative action into a per-district append-only audit log, hash-chained with SHA-256 so each entry covers the one before it, with UPDATE and DELETE revoked at the database role and row-level security policies that grant only INSERT and SELECT. That is a materially different artefact from an application log, and it is the one that is useful in the seven days after a discovery.

What this means for a communications platform specifically

Most Ed Law 2-d guidance is written about learning software. The communications case has three wrinkles.

The message history is the sensitive asset, not the roster. A record showing that a named student's guardian received an attendance notice on a date is student PII, is an education record, and is what a parent's accuracy challenge or a records request will reach. Any vendor treating message logs as operational telemetry rather than as student data has mis-scoped the contract.

Home language and consent state are PII too. The field that says a household is served in Haitian Creole, and the field that says a mobile number has not consented to SMS, are both about an identifiable family. They belong inside the same protections as the name.

Translation introduces a second processor. If message text is sent to a machine translation service, that service is a subcontractor and belongs in the supplemental information. Kastr uses DeepL. Our translation cache is keyed on a SHA-256 of the source string and holds no index of students, families or districts, so a cached row is retrievable only by someone who already has the exact source text — but it is still a sub-processor, and it should be disclosed as one rather than described as an internal feature.

Kastr's position, stated plainly

We are pre-launch. We have no New York customers, and no customers anywhere.

  • We can sign a § 2-d rider. The supplemental information elements are answerable for us: purposes are narrow, the sub-processor list is short and real, and clause 9.4 of our agreement permanently forbids marketing to district families or any family-facing subscription revenue, which removes an entire category of secondary-use argument.
  • We have no SOC 2 report and have not been audited. If your Part 121 review expects an independent attestation, we do not have one.
  • We have no SSO and no MFA. Authentication is a single-use magic link with a 15-minute lifetime, bound to the requesting device by a hashed-token cookie compared in constant time. Districts with an SSO mandate should stop here.
  • Export is a contract right at clause 7.1, not a self-serve tool. Neither the tool nor the “cryptographic deletion proof” language you will see elsewhere in this category exists in our product today. We will not put either on a procurement form.
  • Audience targeting is limited. Only “specific people” and “everyone” resolve. If your privacy design assumes you can scope a message to one school or one grade to limit exposure, we cannot do that yet, and you should weigh it.

This page describes what a statute asks of a vendor. It is not legal advice, statutes are amended, and section numbering moves. Confirm the current text with your own counsel or your state education agency before you rely on any of it in a contract or a procurement file.

Questions people actually ask

Does Education Law 2-d apply to a parent communication platform?

If the platform receives personally identifiable information from student records — names, grades, schools, guardian contact details linked to students — then it is receiving what § 2-d protects, and the district's contract obligations attach. The statute is not limited to instructional software. Have counsel confirm the classification, but assume yes when scoping.

Who writes the Parents' Bill of Rights, the district or the vendor?

The educational agency publishes it. The vendor's role is to sign a contract that carries it and to supply the supplemental information about that specific contract. A vendor offering you their own Bill of Rights to adopt has misunderstood the structure.

How quickly must a vendor tell a New York district about a breach?

The regulation sets a short outer limit measured from discovery — our understanding is seven calendar days for the contractor to notify the educational agency, with a longer window for the agency to notify parents. Confirm the current figures in 8 NYCRR Part 121, then write the shorter of the statutory window and your own requirement into the contract with a named role as recipient.

Does Ed Law 2-d require encryption?

It requires protection of personally identifiable information including encryption, and the distinction that matters in review is in transit versus at rest. Ask the vendor to state both separately, and to say which key management arrangement applies, rather than accepting the single word “encrypted”.

One price. Every feature. Locked for three years.

$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.