Vendor Privacy Training
Privacy matters more than ever in K–12 education, and your company needs the right tools to stay compliant and protect sensitive data. The A4L Community’s Vendor Privacy Training is designed to help you meet legal requirements and strengthen your team’s privacy expertise with industry-specific guidance.
The training modules are available for all Vendors – no A4L Community membership required!
(A 20% discount is applied for A4L Community Members)
Privacy and security are two separate disciplines with some overlap. The focus of our privacy training is on legal compliance with the patchwork of federal and state student privacy laws and managing risks associated with parent and student expectations of fair and reasonable uses of data. These modules will compliment (instead of repeating) information from trainings you may already be using to cover security topics like phishing attacks and strong passwords.
Laws like New York’s Ed Law 2-D specify that, minimally, all staff who access student or teacher data must take a training on federal and state laws. Content may also be relevant to other staff, even if they do not have direct access to student data, including those in leadership roles, operations, sales, and security.
The current training ‘bundle’ has three modules, which cover the following content areas:
Privacy Fundamentals:
This opening module explains why privacy is important and the differences between privacy and security. This training also covers how to comply with all of the major federal privacy laws that edtech companies need to know (COPPA, Section 5 of the FTC Act, FERPA, PPRA), lessons from how all of those laws are enforced, and a high-level overview of major themes from state student privacy laws.
National Data Privacy Agreement (NDPA):
This module will explain the challenges with negotiating privacy terms directly with schools and walk through how the Student Data Privacy Consortium’s National Data Privacy Agreement (NDPA) solves these problems. Learners will also become familiar with the many requirements of this standardized agreement, including how to handle parent requests, place proper restrictions on advertising, respond to a data breach, de-identify and dispose of data, and negotiate vendor-specific terms.
New York State Student Privacy Law:
This module will provide an overview of the different entities that play a role in public education, including BOCES and RICs, and walk through the requirements of Ed Law 2-D, including those related specifically to contracts, limitations on commercialization of student data, security standards, and data breach response. The training will explain how the law is enforced and also provide examples of lessons learned from state enforcement actions. There is also an overview of other state laws which may be relevant, including the Child Data Protection Act and State Technology Law 106-B.
1-10 employees / seats
$300 per employee / seat
11-50 employees / seats
$3,000 plus $150 per employee/seat over 10
51-100 employees / seats
$9,000 plus $75 per employee/seat over 50
101-199 employees / seats
$12,750 plus $50 per employee/seat over 100
200+ employees / seats
$17,750 plus $25 per employee/seat over 199
Got any questions? Please Contact Us.
Copyright © Access 4 Learning Community
To help us improve our website, we use cookies and Google Analytics to track basic visitor numbers and see which pages are viewed most and how you found us. Consenting allows us to collect this anonymous browsing data.
The SDPC model Data Privacy Agreements (DPAs) have had a huge impact on the K12 EdTech ecosystem by establishing common expectations and streamlining the DPA execution process for both districts and providers.
Since 2016, over 222,000 standard DPAs have been executed and subscribed to.
By applying an average legal fee of $250 per hour, and minimal negotiation time of 1hr for each district and vendor per DPA, these standard DPAs have saved participating districts and vendors over $111 million.
