Facebook
Twitter
LinkedIn

New York Is Already Doing This. Here’s What K-12 IT Directors Can Learn From It.

We recently had the opportunity to sit down with Michelle Krieger, keynote speaker at the TETA Summer Institute 2026 and Data Protection Officer for Lake Shore Central School District in New York.

If you’re in Alabama, Mississippi, Georgia, Florida, or Tennessee, you may not think much about Data Protection Officers yet. But after talking with Michelle, it’s clear this isn’t just a New York conversation anymore. States are beginning to look more closely at student data privacy, AI governance, and cybersecurity, and Tennessee already appears to be moving in that direction.

The interesting part is that Michelle didn’t spend much time talking about laws. She spent most of the conversation talking about leadership and practical steps districts can take today.

Start treating data privacy as a district responsibility

One point came up over and over during the interview. Student data isn’t just the technology department’s responsibility.

Technology teams still manage the systems, but curriculum, finance, HR, principals, and district leadership all make decisions that affect how student information is collected, shared, and protected.

Rather than trying to own every piece yourself, Michelle recommends creating a governance team that brings those departments together. If your district already has a Safety Committee, that’s often the easiest place to start.

AI policies matter more than AI tools

Michelle asks school leaders three questions whenever she speaks:

  • Do you allow AI?
  • Do you have an AI policy?
  • Do you have a framework for how staff should use it?

Most districts can answer the first question. Far fewer have clear guidance for the second and third.

Her recommendation wasn’t to stop using AI. It was to decide where AI makes sense, where extra caution is needed, and what information should never be entered into public AI platforms.

She also pointed out that many products districts already use have quietly added AI features, making vendor reviews an ongoing process instead of a one-time approval.

Training is still your best defense

One of the biggest risks isn’t your firewall.

It’s someone clicking a phishing email.

Michelle spends a significant part of her job training employees across the district, not just technology staff. Everyone with a district email address plays a role in protecting student data, and regular, practical training does more good than trying to catch employees making mistakes.

Take inventory of the data you’re keeping

One idea that stood out during our conversation was Michelle’s view that “minimalism is a security strategy.”

Many districts keep files simply because they’ve always kept them. Periodically reviewing what information you actually need, who has access to it, and whether it still serves a purpose can reduce both risk and complexity.

Don’t evaluate yourself in a vacuum

Michelle also encouraged districts to seek outside assessments when possible. Organizations like CISA, state agencies, cyber insurance providers, and trusted partners can often identify blind spots that are easy to miss when you’re looking at your own environment every day.

Even a basic assessment gives you a starting point and helps prioritize what should be addressed first.

The biggest takeaway

One thing became clear by the end of our conversation.

The job of the K-12 IT Director continues to expand.

Today’s technology leaders aren’t just responsible for networks, devices, phones, and Wi-Fi. They’re helping shape AI policies, guide cybersecurity planning, review vendors, educate staff, and protect student information.

Whether your state creates a formal Data Protection Officer role or not, those responsibilities are already arriving.

Preparing for them now is a lot easier than waiting until they’re required.


Michelle Krieger is the Data Protection Officer for Lake Shore Central School District and co-author of From Chalk Dust to Digital Trust: A Guide in Data Privacy and Security for K-12 Leaders. We interviewed Michelle following her keynote presentation at the TETA Summer Institute 2026 for an episode of The IT Director’s Playbook podcast.

Facebook
Twitter
LinkedIn