California SOPIPA and AB 1584: The Two Halves of a Communications Contract
California wrote both of the drafting templates the rest of the country copied, and it kept both. SOPIPA regulates what an operator may do with student information whether or not you have a contract. Education Code § 49073.1, the statute everyone still calls AB 1584, regulates what your contract must contain before the data moves. A vendor can satisfy one and fail the other, and most districts only check one.
| Question | SOPIPA (Bus. & Prof. Code § 22584) | AB 1584 (Ed. Code § 49073.1) |
|---|---|---|
| Who is bound | The operator, directly | The local educational agency, through its contract |
| Applies without a contract? | Yes | No — it is a contract-content rule |
| Targeted advertising | Prohibited | Reached via the use-limitation clause |
| Selling student information | Prohibited | Reached via the use-limitation clause |
| Who owns the records | Silent | Must state that pupil records remain the property of and under the control of the LEA |
| Parent review and correction | Silent | The contract must describe how it happens |
| Breach notification to families | Silent | The contract must describe the procedure |
| End of contract | Deletion on LEA request | Certification that records are not available to the vendor after the contract ends, and how that is enforced |
| Security standard | Reasonable security procedures and practices | The contract must describe how confidentiality is ensured |
| Failure mode | The vendor is unlawful | Your contract is defective, and offending provisions are void |
The last row is the point. An AB 1584 failure is a district paperwork failure that a vendor cannot fix for you, and it is the one an audit finds.
SOPIPA, in the terms a communications vendor has to answer
SOPIPA reaches operators of online services designed and marketed for K-12 school purposes, where the operator has actual knowledge that the service is used primarily for those purposes. A district communications platform is comfortably inside that description.
What it prohibits is short and unusually clear for a privacy statute: no targeted advertising based on covered information; no amassing a profile of a student except in furtherance of K-12 school purposes; no selling or renting student information; and no disclosure of covered information outside the enumerated circumstances. What it requires is reasonable security procedures and practices appropriate to the nature of the information, and deletion of a student's covered information when the school or district asks.
The test worth applying is a business-model test rather than a policy test. Any vendor whose revenue can flow from families rather than from the district has a permanent incentive that the statute is fighting. Ask directly: does the company have, or plan, any family-facing paid tier, any advertising, any data-derived product? A vendor that answers “not currently” has answered no.
Kastr's answer is contractual rather than aspirational. Clause 9.4 of our agreement forbids marketing or selling to district families and forbids any family-facing subscription revenue, permanently. It is a term you can enforce, not a value we describe.
AB 1584, clause by clause
Education Code § 49073.1 tells a local educational agency what a contract with a third party for the digital storage, management or retrieval of pupil records must contain. The elements, paraphrased:
- A statement that pupil records continue to be the property of and under the control of the LEA.
- A description of how pupils may retain possession and control of their own pupil-generated content.
- A description of how the third party will ensure the security and confidentiality of pupil records.
- A description of the procedures for notifying affected parents, guardians or pupils in the event of an unauthorised disclosure.
- A certification that pupil records will not be available to the third party once the contract ends, and a description of how that is enforced.
- A description of how parents, guardians or pupils may review and correct personally identifiable information in pupil records.
- A prohibition on using personally identifiable information from pupil records for any purpose other than those required or specifically permitted by the contract.
- A description of how the LEA and the third party will jointly ensure compliance with FERPA.
Provisions of a contract that conflict with the statute are void. Read the current text before drafting — this list is a working summary, not a substitute for it.
The clause that catches communications vendors is the sixth. Parents must be able to review and correct personally identifiable information. In a messaging platform the fields parents most want corrected are the phone number of record, the email of record and the home language, and a surprising number of platforms have no route for a parent to change any of them without a front office staff member retyping it. Ask the vendor to demonstrate the correction path with a real click-through, not a screenshot.
The California-specific traps
Directory information is not a licence. California pupil records law sits underneath both statutes, and a district's directory information designation under Education Code § 49073 does not convert a message log into something disclosable. See directory information opt-outs for how an opt-out should propagate into a communications platform, which is usually the place it fails.
The teacher-signup problem. AB 1584 governs contracts. A teacher creating a free classroom account, agreeing to consumer terms of service and typing in twenty-eight student names has created a data flow with no contract behind it and therefore no required clauses. That is a widespread pattern in this category, and it is a district governance problem rather than a vendor problem. Colorado is the only state we are aware of that legislates the distinction directly — see Colorado's contract provider versus on-demand provider split.
Consumer privacy law is a separate question. Whether and how California's general consumer privacy regime touches a vendor serving a public school district, given the education-records carve-outs and the service-provider construct, is a real question with a real answer that we are not the right party to give you. Ask counsel; do not accept a vendor's summary of it, including ours.
The claim to interrogate hardest. Almost every vendor in this category will tell you their platform deletes data on request. Ask what deletion means: the row, the backups, the message text held for delivery reporting, the translation cache, the telephony carrier's own logs. Kastr publishes retention defaults per record class, and we will tell you the uncomfortable part — there is no automated purge job behind those defaults today, so treat them as a stated policy and a contractual commitment rather than as an enforced mechanism. Any vendor that will not answer this question at that level of detail is answering it.
This page describes what a statute asks of a vendor. It is not legal advice, statutes are amended, and section numbering moves. Confirm the current text with your own counsel or your state education agency before you rely on any of it in a contract or a procurement file.
Questions people actually ask
Is a parent messaging app covered by SOPIPA?
If it is designed and marketed for K-12 school purposes and the operator knows it is used primarily that way, yes. The prohibitions — no sale, no targeted advertising, no non-educational profiling — apply directly to the vendor regardless of what your contract says.
What is the difference between SOPIPA and AB 1584?
SOPIPA regulates the vendor's conduct directly. AB 1584, at Education Code § 49073.1, regulates what your contract must contain. A vendor can be fully SOPIPA-compliant while your agreement with them is defective under AB 1584, and the second failure is yours rather than theirs.
Does AB 1584 apply to a free tool a teacher signs up for?
It is written about contracts entered into by the local educational agency. A teacher accepting consumer terms of service has generally not created one, which is precisely why that route is a governance risk rather than a compliance solution. Set a district policy about who may enter agreements involving pupil records, and audit against it.
Can a California district require deletion of student data mid-contract?
SOPIPA requires an operator to delete a student's covered information under its control at the request of the school or district. Whether that request is operationally simple is a separate matter — get the request route, the acknowledgement, and the definition of completion written into the agreement rather than relying on the statute alone.
Does California require the district to publish its vendor contracts?
California's student data statutes do not impose the kind of blanket publication duty Illinois does, though contracts of a public agency are generally subject to public records law. If publication matters to your process, look at Illinois SOPPA for the strictest model and set your own practice against it.
One price. Every feature. Locked for three years.
$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.