
NYC Public Schools Lack Central Inventory to Track Third-Party Vendors, Exposing Students and Staff to Privacy Risks
An audit conducted by the New York State Comptroller's Office between 2020 and 2025 identified significant gaps in the New York City Public Schools (NYCPS) system, leaving students and employees vulnerable to privacy and data security breaches. The audit found that NYCPS lacks a central inventory to track third-party vendors used by individual schools, increasing risks of unauthorized data access or exposure. The New York State Auditor also criticized the NYC Education Department for delayed cooperation in providing requested information during the audit. No specific technical vulnerabilities, CVE IDs, or breach incidents were detailed in the findings. The report highlights systemic weaknesses in vendor management and compliance oversight within the education sector.