Texas Student Data Privacy: What Binds the Vendor and What Binds the District
Texas is the state where the district's own security programme is legislated alongside the vendor restrictions, which changes the shape of an evaluation. In most states a comms procurement is a privacy review. In Texas it is a privacy review plus a cybersecurity-programme question plus an incident-reporting question, and the three are owned by different people in most districts.
| Instrument | Binds | Core obligation | What it changes in a comms evaluation |
|---|---|---|---|
| Education Code ch. 32, subch. D (student data privacy) | The operator | No sale of covered information, no targeted advertising, no non-educational profiling; reasonable security; deletion at district request | A vendor-conduct check. Ask about the business model, not the policy page. |
| Education Code § 11.175 (district cybersecurity) | The district | Adopt a cybersecurity policy, designate a cybersecurity coordinator as TEA liaison, report qualifying incidents, notify affected parents and staff | Your coordinator becomes a named party in the contract's incident path, not a bystander. |
| The SCOPE Act (Bus. & Com. Code ch. 509, from HB 18, 2023) | Digital service providers, with litigation history | Duties toward known minors; parts of it have been the subject of federal injunction proceedings | Applicability to a district-contracted platform is a counsel question, not a vendor claim. |
We are deliberately not stating which SCOPE Act provisions are currently enforceable. That has moved through federal litigation since enactment and any figure we printed would risk being stale. Ask your counsel for the current position rather than any vendor, including us.
What the Education Code asks of the vendor
Texas's student data privacy provisions in the Education Code follow the SOPIPA drafting family. They define an operator, and they prohibit the familiar set: selling covered information, engaging in targeted advertising based on it, and building a profile of a student for non-educational purposes. They require reasonable security practices, and deletion of covered information at the district's request.
For a communications platform this is a business-model interrogation more than a technical one. There are exactly two ways a comms vendor makes money from families: a paid family tier, or advertising. Ask whether either exists, whether either is planned, and whether the answer is written into the contract or merely stated on a web page. A statement on a web page survives an acquisition by nobody.
Our own answer: clause 9.4 forbids marketing or selling to district families and forbids family-facing subscription revenue, permanently, and clause 11.2 gives you a 90-day exit with export and a prorated refund if the company changes hands or materially changes its data terms. Those two clauses together are the only durable answer to this question that we know of.
Section 11.175, and why it lands in your procurement file
Texas requires each school district to adopt a cybersecurity policy, to designate a cybersecurity coordinator who acts as the district's liaison to the Texas Education Agency, and to report qualifying incidents. The district must also notify affected parents and employees where a breach involves their sensitive or confidential information. Confirm the current thresholds and reporting mechanics with TEA — the reporting route and the definition of a qualifying incident are the parts that have been refined since enactment.
Three practical consequences for a communications contract:
- The coordinator has to be in the incident path. Name the role in the contract as a notice recipient, alongside whoever handles procurement. A vendor notifying your business office and nobody else has technically notified you and practically has not.
- You will be asked what the vendor's incident record looks like. Not their policy — their record. Ask what the system captures, whether the capture is tamper-evident, and how quickly you can be given the relevant extract. Kastr's audit log is per-district, append-only at two independent layers, and hash-chained with SHA-256; that is the artefact we would hand you, and it is designed to be readable by someone who is not an engineer.
- Your own notification duty is not delegable. A vendor can supply facts. It cannot notify your families on your behalf and leave you compliant, and no contract clause makes that true.
The SCOPE Act, handled carefully
HB 18 of the 2023 session created the Securing Children Online through Parental Empowerment Act, in the Business and Commerce Code. It imposes duties on digital service providers with respect to known minors. It has been the subject of federal constitutional litigation, and portions of it have been enjoined.
We are not going to tell you which provisions currently bind whom. Two reasons. First, the litigation posture has moved and could move again, and a vendor page asserting a current legal status is the exact failure mode this cluster exists to avoid. Second, whether a platform a district contracts for — where the district, not the child, is the customer, and where the data flows under an education-records framework — falls inside the Act's definitions and exemptions is genuinely arguable and is a question for a Texas lawyer.
What we would suggest asking in a procurement is narrower and answerable: does the platform have any direct-to-minor surface at all? Does a student hold an account? Can a student receive a message that a school employee did not send? For Kastr the answers are that student-facing accounts exist within the district's own identity model, no family-facing commercial surface exists, and no advertising or recommendation system exists anywhere in the product. That is a factual answer a vendor can give. The legal conclusion is yours.
Records requests, and the thing districts forget
Texas has a strong public information regime, and a district's records are generally subject to it with the education-record exceptions applying. That has a specific consequence for messaging: a message a district sends about school business is a district record regardless of which device it left from, and staff texting families from personal phones is the most common way a district discovers this the hard way.
The operational fix is not a policy memo. It is giving staff a school-controlled channel that is easier to use than their own phone, so that the record exists in one retrievable place by default. That is worth more to a records officer than any retention setting. See whether school text messages are public records for the general shape of the problem.
Two honest limits on our side. Kastr resolves only two audience types — specific people, and everyone in the district. There is no school-level, grade-level or bus-route targeting, so a Texas district that wants to scope a message to one campus to limit both exposure and records volume cannot do it in our product today. And auto-notice rules can be configured but nothing fires them; there is no engine. Both are roadmap, and neither belongs on a procurement form as a capability.
This page describes what a statute asks of a vendor. It is not legal advice, statutes are amended, and section numbering moves. Confirm the current text with your own counsel or your state education agency before you rely on any of it in a contract or a procurement file.
Questions people actually ask
Does Texas have a student data privacy law for edtech vendors?
Yes. The Education Code contains student data privacy provisions in the SOPIPA drafting family that bind operators directly — prohibiting sale of covered information, targeted advertising and non-educational profiling, and requiring reasonable security and deletion at district request. Confirm the current section numbering with counsel before citing it in a contract.
What does Texas require a district to do about cybersecurity?
Education Code § 11.175 requires each district to adopt a cybersecurity policy, designate a cybersecurity coordinator who serves as the liaison to the Texas Education Agency, and report qualifying incidents, with notification duties to affected parents and employees. Confirm reporting mechanics and thresholds directly with TEA.
Does the SCOPE Act apply to a school communications platform?
That is a real legal question with a genuinely contested answer, and parts of the Act have been through federal injunction proceedings. Ask your district's counsel for the current position. Any vendor giving you a confident yes or no about their own product's status under contested legislation is telling you something about the vendor.
Are staff text messages to parents public records in Texas?
Records about district business are generally district records regardless of the device used, with education-record and other exceptions applying. The practical risk is not the statute, it is that a message sent from a personal phone may exist nowhere the district can retrieve it. Give staff a channel that logs by default and the problem mostly disappears.
One price. Every feature. Locked for three years.
$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.