State Student Data Privacy Laws: What They Ask of a Communications Vendor
There is no single American student data privacy law. There is FERPA, which is federal and dates from 1974, and then there are roughly forty state statutes stacked on top of it, most of them passed between 2014 and 2021, most of them modelled on one of two drafting templates, and nearly all of them written about “operators” of “online services designed and marketed for K-12 school purposes” — language that predates the way districts now buy communications software. This page is the map of what they actually have in common.
| Pattern | Binds | What it requires | What it changes in your contract |
|---|---|---|---|
| Prohibition on secondary use | The vendor, directly | No sale of student information, no targeted advertising, no building a commercial profile | Nothing, if the vendor's business model already forbids it. Everything, if the vendor monetises families. |
| Contract-content mandate | The district, reaching the vendor through the contract | Named clauses must appear in the agreement before data moves | The DPA is not optional paperwork. A missing clause is a defective contract, not a defective vendor. |
| Publication and transparency | The district, mostly | Publish the list of vendors holding student data, and often the agreements themselves | Your vendor list becomes a public document. Vendors who will not let their DPA be published are a problem. |
| Breach notification clock | The vendor, directly | Notify the district within a fixed window of discovering or determining a breach | The window belongs in the contract with a named recipient and a channel that is not one person's inbox. |
| Deletion on district request | The vendor, directly | Delete student information when the district asks, subject to stated exceptions | Needs a defined request route and a defined completion definition. “Deleted” from backups is a different promise. |
| Designated officer or plan | The district | Name a privacy or data official, adopt a written security plan, sometimes against a named framework | Your vendor questionnaire should ask which framework the vendor maps to, and what evidence exists. |
Almost every state statute in this area is some combination of these six. Once you can see which combination your state uses, the page for your state stops being forty pages of statute and becomes four or five decisions you have to make in a contract.
The distinction that decides everything: who does the statute bind?
State student data privacy laws split into two drafting families, and the difference is not academic. It decides whether a vendor can be non-compliant on its own, or only through your contract.
The SOPIPA family. California's Student Online Personal Information Protection Act was the first, and around twenty states copied its structure. These statutes bind the operator directly. The vendor is prohibited from selling student information, from targeted advertising based on it, and from building a non-educational profile, whether or not your contract says a word about it. Washington's student user privacy provisions and North Carolina's student online privacy provisions belong to this family.
The AB 1584 family. California's Education Code § 49073.1 works the other way round. It tells the local educational agency what its contract must contain. The statute reaches the vendor only because the district is forbidden to sign an agreement missing the required elements. New York's Education Law § 2-d, Connecticut's student data provisions and Illinois SOPPA all carry a strong contract-content component.
Most states have both. The practical consequence is this: a vendor telling you “we comply with your state's law” is telling you something about the first family and nothing at all about the second, because the second is a statement about your paperwork, not their code. Ask which clauses they will sign, not whether they comply.
The five questions that resolve most of a state review
A district that answers these five in writing has done most of the work, whichever state it is in.
- Is student information leaving the district at all, and which fields? A communications platform usually holds student name, grade or school, guardian name, guardian phone, guardian email, home language, and the message history linking them. That last item is the one districts forget, and it is the one that is most obviously an education record.
- Which named clauses does our state require in the agreement? Not “do we have a DPA” — which clauses. Districts on a state alliance addendum often have these already; districts on a vendor's own paper frequently do not.
- What is our breach clock, and who receives the notice? If the answer is a personal email address of someone who left in June, the clock does not work.
- What must we publish, and where? Several states require a public vendor list, some require the agreements themselves. That is a district obligation a vendor cannot discharge for you.
- What happens at the end? Deletion request route, deletion definition, export format, and how long the export right survives termination. This is where most contracts are silent and most disputes start.
The states with genuinely distinct requirements
The statutes worth reading in full, because they ask something the others do not:
- New York Education Law § 2-d — a Parents' Bill of Rights for Data Privacy and Security that must be appended to the contract, plus supplemental information published per contract, plus a data security and privacy plan.
- California SOPIPA and AB 1584 — the two drafting templates the rest of the country copied, sitting side by side in one state.
- Illinois SOPPA — the strongest transparency regime, requiring districts to publish operators and agreements, with parent inspection and correction rights routed through the school.
- Texas — the only state where the district's own cybersecurity policy, coordinator and incident reporting duty are legislated alongside the student data restrictions.
- Connecticut — the shortest breach clock in the country by a wide margin.
- Colorado — the only state we are aware of that formally distinguishes a contracted provider from an on-demand service a teacher signs up for, and regulates them differently.
- Massachusetts — not a student privacy statute at all, but a general information security regulation with a written-programme requirement that reaches your vendors.
- Ohio — a safe harbour that rewards mapping to a named cybersecurity framework, which changes what you should ask a vendor for.
- Washington — student privacy restrictions sitting next to one of the most demanding public records regimes in the country.
Every other state has, at minimum, FERPA, a general data breach notification statute that applies to public bodies, and a public records law. Those three alone are enough to shape a communications contract. If your state is not listed above, that is not a gap in your obligations; it is a gap in this page, and the honest answer is to work from the six patterns in the table and confirm the specifics with your state education agency.
What Kastr can and cannot say about this
We are a pre-launch vendor with no customers. Here is our actual position, because you are going to ask.
- We have no SOC 2 report. Not in progress, not in observation. We have not been audited. Any vendor page implying otherwise before an auditor has signed something is doing the thing this whole category does.
- We have no SSO, SAML, OIDC or MFA. Magic link is the only authentication we implement: 32 random bytes, 15-minute expiry, single use, atomically consumed so a prefetching mail scanner cannot replay it, with no account enumeration because a token is issued whether or not the address exists. That is a defensible design. It is not a substitute for an identity provider, and if your district standard requires SSO we will fail your questionnaire.
- We have no VPAT. We can describe our accessibility position honestly; we cannot hand you a conformance report we have not produced.
- Export is a contract right, not a button. Clause 7.1 of our agreement gives you your data on request in a machine-readable format. Self-serve export tooling is not built. We would rather write that sentence than let you discover it in month nine.
- What we do have is tenant isolation enforced by Postgres row-level security under a non-owner database role that fails closed, a cross-tenant leakage suite that runs in CI against real Postgres, and a per-district append-only audit log hash-chained with SHA-256 where UPDATE and DELETE are revoked at the database role. Those are the three things a state statute review actually turns on, and they are verifiable rather than asserted.
This page describes what a statute asks of a vendor. It is not legal advice, statutes are amended, and section numbering moves. Confirm the current text with your own counsel or your state education agency before you rely on any of it in a contract or a procurement file.
Questions people actually ask
Does a parent communication platform count as an operator under state student privacy laws?
Usually yes, and districts often assume otherwise because the statutes talk about “online services designed and marketed for K-12 school purposes” and people picture a learning app. A platform holding student names, guardian contact details and a message history linked to students is squarely inside that description in most states. Treat it as in scope and let your counsel tell you it is not.
Do we need a separate data privacy agreement for every state we operate in?
Districts operate in one state, so in practice you need one agreement that satisfies your state. Charter networks and regional service agencies crossing state lines are the exception, and the usual approach is a base agreement plus a state-specific addendum, which is exactly how the state alliance DPA templates are structured.
Is a signed Student Privacy Pledge enough to satisfy a state statute?
No. The Pledge is a voluntary public commitment, enforceable if at all as a consumer-protection matter rather than as compliance with your state's contract-content requirements. It tells you something about a vendor's posture. It does not put a required clause in your agreement, and no state statute we are aware of accepts it as a substitute.
Which state has the strictest student data privacy law?
It depends on the axis. New York asks for the most paperwork per contract. Illinois asks for the most public transparency. Connecticut has the tightest breach clock. California has the broadest direct prohibitions on vendor behaviour. A vendor built to satisfy New York, Illinois and Connecticut simultaneously is comfortably inside most other states, which is a reasonable way to set an internal bar.
What happens to our data privacy agreement if the vendor is acquired?
In most agreements, nothing — it assigns with the business and the acquirer inherits it, including any terms they would never have offered you. Look for an explicit change-of-control provision. Ours is clause 11.2: on an acquisition or a material change to data terms you may terminate within 90 days with export and a prorated refund and no penalty. Whatever your vendor's clause says, read it before signing rather than after the press release.
One price. Every feature. Locked for three years.
$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.