Data privacy agreement
A data privacy agreement is the contract between a district and a vendor that governs what happens to student and family data: what is collected, what it may be used for, who else sees it, how long it is kept, and what happens to it when the relationship ends.
| Clause | Strong version | Weak version you will actually be sent |
|---|---|---|
| Data elements | An itemised schedule of every field exchanged | "Student directory and contact information as required" |
| Purpose limitation | Named purposes only; anything else needs written authorisation | "To provide and improve the Services" |
| Sub-processors | Named list, advance notice of changes, right to object | "Vendor may engage subcontractors" |
| Breach notification | A fixed clock in hours or days, starting at discovery, with content requirements | "Without undue delay" |
| Deletion on termination | Stated window, stated exceptions, written confirmation | "Data will be deleted in accordance with Vendor's retention policy" |
| Export | Machine-readable, on request, during the term and at exit | Silence, or "available for an additional fee" |
| Change of control | District may terminate on acquisition or material data-terms change | "Assignable to a successor in interest" |
| Ownership | Records remain the property and under the control of the district | "Vendor owns aggregated and de-identified data" |
Where the standard templates come from
Most US districts do not draft from scratch. The Student Data Privacy Consortium, a project of the Access 4 Learning Community, maintains the National Data Privacy Agreement, and many states run their own alliance with a state-specific version and a shared registry of signed agreements.
The NDPA's structure is worth knowing even if your state uses something else. There is a core agreement, and then exhibits: a description of the services, a schedule of the data elements exchanged, a set of definitions, a form for requesting deletion or inspection, and — the one that saves the most work — a general offer page, in which a vendor offers the same signed terms to any other district in the state. One district negotiates; every other district in the alliance countersigns.
That mechanism is the privacy-side equivalent of a piggyback contract, and it has the same prerequisite: someone has to have done the negotiation properly the first time, because everyone downstream inherits it.
The amendments vendors ask for
Districts see the same requested edits repeatedly. Each is defensible in isolation and each gives something away:
- "Improve the Services" added to purpose limitation. Reads as harmless maintenance. Covers analytics, product research and, increasingly, model training.
- "Aggregated and de-identified data" carved out of every restriction. Reasonable in principle; the question is who decides what counts as de-identified, and whether the standard is written down.
- Breach notification softened from a fixed clock to "without undue delay", or the trigger moved from discovery to confirmation, which can add weeks.
- Deletion made subject to the vendor's own retention policy — a document the vendor can change unilaterally.
- Sub-processor list replaced with a URL that the vendor maintains, with no notice obligation.
- Liability capped at fees paid, which for a $17,000 annual contract is not a deterrent to anything.
- Assignment permitted to any successor, which is how a district ends up a customer of a company it did not evaluate.
None of these are dishonest requests. But a district signing without reading them has, in substance, agreed to terms it never discussed.
What Kastr can and cannot sign up to
Stating our own position, because a page about DPAs written by a vendor is worthless otherwise.
- Clause 7.1 is an export right. It obliges us to produce your data in a machine-readable form on request. It is a contractual commitment, not a button in the console — there is no self-serve export feature today, and we would rather write that here than let you find out at renewal.
- Clause 9.4 forbids family monetisation, permanently. No marketing to your families, no selling to them, no family-facing subscription revenue.
- Clause 11.2 is a change-of-control exit. If we are acquired or materially change our data terms, you may terminate within 90 days with export and a prorated refund.
- Retention defaults are published per record class. The automated purge job that would enforce them is not built. Today the schedule is a commitment we honour manually, and describing it as enforced would be a lie you could catch.
- We are not SOC 2 audited. We are pre-launch. If your DPA requires a current Type II report as a condition of signature, we cannot meet it this year.
One question worth asking every vendor. "If your export feature breaks, does the contract still oblige you to produce our data?" A product feature can be deprecated in a release note. A clause cannot.
This entry describes what the rule says. Whether and how it applies to your district is a question for your own counsel, not for a vendor.
Questions people actually ask
What is the difference between a DPA and a master services agreement?
The MSA governs the commercial relationship: price, term, service levels, liability. The DPA governs the data: what may be collected, what it may be used for, who else touches it, and what happens at the end. They are often signed together and are frequently inconsistent with each other, which is worth checking before signature.
What is the NDPA and who maintains it?
The National Data Privacy Agreement is a standard template maintained by the Student Data Privacy Consortium, part of the Access 4 Learning Community. Many states run an alliance with a state-specific version and a shared registry, so a vendor's signed agreement can be adopted by other districts in the state.
How long should a vendor have to notify a district of a breach?
Fix a number rather than accepting a standard. Districts commonly require notification within 24 to 72 hours of discovery, with a defined content list. Several states set their own statutory windows for education data, which override whatever the contract says.
What happens to student data when a contract ends?
Whatever the agreement says, which is why the deletion and export clauses matter more than any feature comparison. Look for a stated deletion window, a stated list of exceptions, written confirmation of completion, and an export obligation that survives termination rather than expiring with your login.
One price. Every feature. Locked for three years.
$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.