Ohio Student Data Privacy and the Data Protection Act Safe Harbour
Ohio's contribution to this area is unusual and, for a procurement officer, genuinely useful. Rather than prescribing controls, the Data Protection Act offers an affirmative defence to entities whose cybersecurity programme reasonably conforms to a recognised framework. That flips the vendor question from “are you secure”, which nobody can answer, to “which framework do you map to, and what shows it”, which is answerable.
| Framework family | Typical fit | Evidence a district can actually check | Cost to the vendor |
|---|---|---|---|
| NIST Cybersecurity Framework | Most edtech, and the framework New York's Part 121 points districts to | A control mapping document with owners and dates | Low to moderate |
| NIST SP 800-171 / 800-53 | Vendors also serving federal or defence customers | A system security plan and a plan of action | High |
| CIS Critical Security Controls | Small engineering teams; implementation groups scale down honestly | Named implementation group and a per-control status list | Low |
| ISO/IEC 27000 family | Vendors with international customers | A statement of applicability, or a certificate if certified | High |
| FedRAMP-authorised infrastructure | Rare in K-12 communications | The authorisation record for the underlying service, not the vendor | Very high |
| “Industry best practices” | Not a framework | Nothing checkable | Zero, which is the tell |
The safe harbour is an affirmative defence available to covered entities in Ohio litigation; whether and how it is available to your district, and what “reasonably conforms” requires, are questions for counsel. What it usefully gives a district is a vocabulary for a vendor question that otherwise has no good form.
How to use the safe harbour as a procurement instrument
Whether or not your district ever relies on the defence, the framework question is the best-formed security question you can ask a small vendor. “Are you secure” produces marketing. “Which framework does your programme map to, at what implementation level, and what document shows the mapping” produces either a document or a silence, and both are informative.
Two follow-ups make it sharper.
- “Which controls are you not meeting, and what is the plan?” Every honest mapping has gaps. A vendor presenting a fully green mapping either has not done the work or is not telling you about it.
- “Who owns the mapping, and when was it last touched?” A named person and a date within a year is the whole answer.
Our position: Kastr maps its practices to the CIS Critical Security Controls at the implementation group appropriate to a company of our size, and we will show you the mapping including the gaps. We have not been audited against anything. There is no SOC 2 report, no ISO certificate and no third-party attestation of any kind, and we would rather say that plainly on a public page than let a procurement officer find out in week six.
Ohio student records, and what a communications vendor touches
Ohio's student records provisions in the Revised Code restrict the release of personally identifiable information from student records without consent, alongside FERPA. Ohio also has a general data breach notification statute that applies to entities holding personal information about Ohio residents, with its own definitions and timeline. Confirm the current sections and timelines with counsel — both areas have been amended.
The communications-specific consequence is the one districts consistently underestimate: a message log is student record material. It records that a named student's guardian was contacted, on a date, about a subject. Districts that classify communications platforms as “operational tools” rather than as systems holding student records end up with a retention schedule, a records process and an access policy that do not cover the largest single volume of student-linked events they generate.
The fix is administrative and cheap: put the communications platform on the same records inventory as the SIS, assign it a retention class per artefact type, and give the records officer a written description of what it holds.
What to ask, in what order, for an Ohio evaluation
- Framework and mapping, per the table above. First, because the answer colours everything else.
- Tenant isolation, described mechanically. Not “each district's data is separated” — by what mechanism, enforced where, and what happens when the tenant context is missing. Kastr's answer: Postgres row-level security, policies evaluated under a non-owner DML-only role set inside every transaction, hierarchy-aware so a district sees its own and its schools' rows and never another district's, failing closed to zero rows when no organisation context is set, with a cross-tenant leakage suite running in CI against real Postgres including an owner-bypass regression check.
- Audit record properties. What is recorded, who can alter it, how long it is kept.
- Credential handling. Ask what happens if an administrator pastes a live API key into a configuration field. Ours rejects it: connector configuration hard-rejects literal credential patterns and requires a reference pointer instead. It is a small control and it prevents a very common real incident.
- Sub-processors, named. A short accurate list beats a long aspirational one.
- The gaps. Ask directly what the vendor cannot do. Ours: no SSO, SAML, OIDC or MFA; no SOC 2; no VPAT; no self-serve export, only the clause 7.1 contract right; no automated retention purge behind the published defaults; no grade, school or route audience targeting; no auto-notice engine behind the rules interface. That list is longer than most vendors will give you, and every item on it is checkable.
This page describes what a statute asks of a vendor. It is not legal advice, statutes are amended, and section numbering moves. Confirm the current text with your own counsel or your state education agency before you rely on any of it in a contract or a procurement file.
Questions people actually ask
What is the Ohio Data Protection Act safe harbour?
Ohio's Data Protection Act, in Chapter 1354 of the Revised Code, provides an affirmative defence in certain tort actions for entities whose cybersecurity programme reasonably conforms to one of several recognised frameworks. Whether it is available to your district, and what conformance requires, are questions for counsel — but the framework vocabulary is useful in vendor evaluation regardless.
Which cybersecurity framework should we ask an edtech vendor about?
For a small vendor, the CIS Critical Security Controls or the NIST Cybersecurity Framework are the realistic answers, and NIST CSF has the advantage of being the framework several states already point districts toward. What matters more than the choice is whether a mapping document exists, who owns it, when it was last reviewed, and whether the gaps are disclosed.
Are school message logs student records in Ohio?
A log recording that a named student's guardian was contacted about a subject on a date is student-linked information held by the district, and should be treated as record material for retention and access purposes. Put the communications platform on the same records inventory as your student information system rather than treating it as an operational tool.
Does a vendor need SOC 2 to sell to an Ohio district?
No statute we are aware of requires it. Many districts require it by policy, which is a legitimate procurement choice. What a SOC 2 report proves is narrower than most buyers assume — it is an opinion about controls the vendor itself selected, over a stated period. Read the scope section and the exceptions before treating it as a pass.
One price. Every feature. Locked for three years.
$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.