State compliance

Illinois SOPPA: Published Agreements, Parent Rights and the Breach Clock

Illinois asks for something no other state asks for at the same strength: publication. The Student Online Personal Protection Act does not only require you to have an agreement with each operator holding covered information — it requires the district to tell the public who those operators are, and to make the agreements available. That turns a routine contract into a document that will be read by people who are not in the room when it is signed.

Last reviewed 2026-08-04 ยท Kastr is pre-launch; we publish dated status rather than logos.

Who does what under SOPPA — the duty split between operator and school district
DutyOperatorDistrictNote
Written agreement before covered information is disclosedSignsMust have it in place first“First” means before the roster import, not before go-live
Publish the list of operators holding covered informationYes, on the district websiteA live public inventory, not a filing cabinet
Publish or make available the agreementsMust be willingYesA vendor refusing publication is a procurement problem in Illinois
Parent right to inspect covered informationMust support itReceives and routes the requestRequests come to the school, not to the vendor
Parent right to request correctionMust support itRoutes and follows upTest the correction path before signing
Breach notice to the schoolYes, within the statutory windowRuns from determination that a breach occurred
Breach notice to parentsYes, within its own windowTwo clocks in series, not one
Prohibition on sale and targeted advertisingDirect statutory dutyApplies whatever the contract says

Day-counts deliberately omitted from this table. SOPPA sets outer limits on both notification steps measured from determination and from receipt respectively; confirm the current figures in 105 ILCS 85 rather than relying on a vendor's summary, and then contract for the shorter of the statutory window and what you actually need.

What publication does to a contract

Most vendor agreements are written on the assumption that only the signatories will read them. SOPPA breaks that assumption, and it has three second-order effects worth planning for.

  • Vagueness becomes visible. A use-limitation clause reading “to provide and improve the Services” looks unremarkable in a folder and looks evasive on a district website next to eleven other agreements that are specific.
  • Sub-processor lists get compared. Once agreements are public, a parent or a board member can compare what one vendor discloses with what another does. Vendors with an accurate short list benefit; vendors with a marketing-approved list do not.
  • Redaction requests surface early. Ask during evaluation whether the vendor will consent to publication of the agreement, and what if anything they would want redacted. The answer is diagnostic. Ours is that the agreement can be published in full; there is nothing in it we would not want a parent to read.

Illinois also expects the district to maintain the list as an ongoing public inventory. That is a governance job, not a one-off, and it is the one that decays. A district that runs an annual reconciliation of its published operator list against its actual data flows will find surprises in year one and fewer in year three.

Parent inspection and correction, applied to a message log

SOPPA gives parents the right to inspect covered information held by an operator and to request correction, with the request routed through the school rather than direct to the vendor. That routing is sensible and it puts the operational burden on you.

In a communications platform, the covered information a parent will actually ask about is:

  • The phone numbers and email addresses on file for the household, and which of them the district has been using.
  • The home language of record, which drives whether messages arrive in a language the family reads.
  • The relationship recorded between an adult and a student, which is the field that goes wrong in split-custody households and is the one with the most consequence when it does. See custody rules for school communications.
  • The message history: what was sent to whom, when, on what channel, and whether it was delivered.

Before you sign, ask the vendor to show you how a district administrator answers each of those four in the interface, with a timer running. If the answer is a support ticket and a CSV three days later, your SOPPA response process has a three-day floor built into it.

Illinois also has its own school student records statute sitting underneath SOPPA, with its own parent inspection timeline measured in school days. Those two regimes overlap and they are not the same; confirm both with counsel and build one internal process that satisfies the stricter of them.

The Illinois questions nobody asks a comms vendor

Biometrics. Illinois's biometric privacy statute is the most consequential in the country, and voice is within its subject matter. A voice broadcast that plays a recorded message creates no voiceprint and is not the concern. A feature that identifies a caller by voice, or that builds a voice model, would be a very different conversation. Kastr does neither: outbound voice is text-to-speech or a recorded file delivered by a carrier, and nothing in the product analyses inbound audio. Ask any vendor offering voice features to state this in writing, because “we do not do biometrics” is cheap and “we do not process or store any voice sample” is specific.

Translation as disclosure. If message text goes to a third-party translation service, covered information may be leaving with it. Kastr uses DeepL and caches results keyed on a SHA-256 hash of the source string, with no index of students, families or districts — a cached row is retrievable only by someone who already holds the exact source text. Disclose the translation provider in the agreement anyway. It is a sub-processor.

The reconciliation exercise worth doing once. Take your published SOPPA operator list. For each entry, write down which system pushed data to it, which roster field set went, and when the agreement was last reviewed. In most districts that exercise finds at least one operator receiving more fields than anyone remembers agreeing to, and at least one agreement signed by someone who has left. Neither is a scandal. Both are much cheaper to find in October than during a breach.

This page describes what a statute asks of a vendor. It is not legal advice, statutes are amended, and section numbering moves. Confirm the current text with your own counsel or your state education agency before you rely on any of it in a contract or a procurement file.

Questions people actually ask

Does SOPPA require districts to publish their vendor contracts?

Illinois requires the district to make information about operators holding covered information publicly available, including the agreements. That is stronger than the transparency duty in most states and it should shape how you negotiate: assume the document will be read by parents and board members, not only by the signatories.

Who does a parent contact to see data an operator holds under SOPPA?

The school. SOPPA routes inspection and correction requests through the district rather than to the vendor directly, which means your process, your timeline and your staff carry the burden. Test the vendor's ability to answer those requests before you sign rather than during your first one.

How long does an operator have to notify an Illinois school of a breach?

SOPPA sets an outer limit running from the operator's determination that a breach occurred, and a separate limit for the district's notification to parents running from receipt. Confirm the current day-counts in 105 ILCS 85, then contract for the shorter of the statutory window and your own operational requirement.

Does SOPPA apply to a communications platform or only to learning apps?

The statute is about operators of online services used for K-12 school purposes that hold covered information. A platform holding student names, guardian contact details and student-linked message history is holding covered information. Assume it is in scope and have counsel tell you otherwise.

Does Illinois's biometric privacy law affect school voice calls?

Playing a recorded or synthesised message to a phone does not create a biometric identifier. Anything that analyses, matches or stores a voice sample is a different matter entirely. Ask a voice-capable vendor to state in writing that no voice sample is processed or retained, rather than accepting a general assurance that they do not do biometrics.

One price. Every feature. Locked for three years.

$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.