Vendor 101
There are many areas of consideration under the various laws on how educational entities and marketplace providers access, manage and move learner data. Here is a snapshot of the critical ones.
CIPA: Children’s Internet Privacy Act
Internet filters for K–12 schools and libraries to protect children from harmful online content as a condition for federal funding.
PPRA: Protection of Pupils Rights Amendment
Requires parental consent for any surveys that contain political, sexual, mental state, relationships, religious information
COPPA: Children’s’ Online Privacy & Protection Act
Requires operators of websites or online services for children under 13 that they are collecting personal information
HIPAA: Health Insurance Portability & Accountability Act
Usually HIPAA does not apply because information by definition is part of “education records” under FERPA and, therefore, is not subject to the HIPAA
FERPA: Family Educational Rights & Privacy Act (1974)
Schools must have written permission to release any information but allows schools to disclose under certain conditions
State: Legislation as well as Local Statutes and Regulations
40 states have passed 125 student privacy laws since 2013 laws
Family Educational Rights & Privacy Act (1974)
Generally, schools must have written permission from the parent or eligible student in order to release any information from a student’s education record. However, FERPA allows schools to disclose those records, without consent, to the following parties or under the following conditions (34 CFR § 99.31).
Education Agencies must adhere to the 1974 FERPA Law. It outlines how entities must protect student data, ownership and even data exchange rules – way before digital tools were in use!
But like many laws, there are “FERPA exceptions”. The major exception schools use to contract software services (because most cannot develop their own) is the Schools Official Exemption – meaning vendors.
Actually, the wording is: Performs an institutional service or function for which the school or district would otherwise use its own employees;
Other schools to which a student is transferring;
Specified officials for audit or evaluation purposes;
Organizations conducting certain studies for or on behalf of the school;
Accrediting organizations;
State and local authorities, within a juvenile justice system, pursuant to specific State law.
Appropriate officials in cases of health and safety emergencies;
School officials with legitimate educational interest;
School officials with legitimate educational interest should enter into Data Privacy Agreements (DPA) which should cover;
Schools, and not vendors, are held accountable under FERPA so they must obtain Data Privacy Agreements with Vendors covering what can and cannot be done with the data.
Now that you know why schools need a Data Privacy Agreement (DPA) as part of their Terms of Service (TOS) conversations – Why is it so hard?
Do The Math!
…with limited resources on all sides…
Copyright © Access 4 Learning Community
To help us improve our website, we use cookies and Google Analytics to track basic visitor numbers and see which pages are viewed most and how you found us. Consenting allows us to collect this anonymous browsing data.
The SDPC model Data Privacy Agreements (DPAs) have had a huge impact on the K12 EdTech ecosystem by establishing common expectations and streamlining the DPA execution process for both districts and providers.
Since 2016, over 222,000 standard DPAs have been executed and subscribed to.
By applying an average legal fee of $250 per hour, and minimal negotiation time of 1hr for each district and vendor per DPA, these standard DPAs have saved participating districts and vendors over $111 million.
