SOPIPA
SOPIPA — California's Student Online Personal Information Protection Act, enacted in 2014 and in force since 2016 — regulates operators of online services designed and marketed for K-12 use. Its distinguishing feature is that it binds the vendor directly, without a district contract in between.
| Prohibition | A concrete example of a violation |
|---|---|
| No targeted advertising based on covered information | Showing a tutoring advert to families whose child's record shows a low reading score |
| No amassing a profile except for K-12 school purposes | Retaining an engagement profile after the district's contract ends, to market a consumer tier |
| No sale of covered information | Passing guardian mobile numbers to a data broker, or transferring them in an asset sale outside a permitted succession |
| No disclosure of covered information | Handing a student list to a partner vendor for a joint promotion, absent a permitted purpose |
| Affirmative duty: reasonable security | Storing guardian contact data with no access control between districts |
| Affirmative duty: delete on school request | Refusing a district's deletion request because deletion is not a supported feature |
Why direct application matters
FERPA reaches a vendor only through the district's contract. SOPIPA reaches the vendor because the vendor operates a service designed and marketed for K-12 use, regardless of what any contract says and regardless of whether the district negotiated well.
Practically, that changes the failure mode. Under FERPA, a district with a weak contract has a weak position. Under SOPIPA the prohibited conduct is prohibited whether or not the district noticed, and enforcement runs through the state attorney general rather than through the district.
California separately requires contract terms between local educational agencies and third parties handling pupil records — the provisions commonly cited as AB 1584 — including that pupil records continue to belong to and be under the control of the district. The two work together: one sets a floor on vendor conduct, the other sets requirements for the paperwork.
Note also what SOPIPA does not do. It does not ban advertising in a school product outright; it bans advertising targeted using covered information. It does not create a private right of action. And it does not, on its own, require a specific breach-notification timeline — several state clones added that later.
How other states diverged
More than twenty states passed SOPIPA-derived statutes, and they did not copy it cleanly. Grouping them by what they added is more useful than listing them:
- Contract mandates. Several states require specific clauses in every vendor agreement rather than relying on the prohibitions alone. New York's Education Law 2-d is the most demanding example, adding a parents' bill of rights and a designated data protection officer.
- Breach notification timelines. Illinois' SOPPA amendments are the widely cited case, adding fixed notification windows and a duty on districts to publish their vendor contracts.
- Deletion and access rights running to parents directly, rather than only to the district.
- Registries and reporting, requiring districts to maintain a public inventory of the operators holding student data.
The consequence for a multi-state vendor is that "we comply with SOPIPA" is a floor, not an answer. The right question is which state's requirements the vendor has actually implemented, and whether it can name them.
What to require in the agreement
SOPIPA gives a district a set of obligations it does not have to negotiate for. A data privacy agreement is where they become enforceable by the district itself rather than only by the attorney general. The clauses worth insisting on map one-to-one:
- No advertising of any kind in the family experience, targeted or not — stricter than the statute, and easy for an honest vendor to accept.
- No secondary use, including product improvement and model training, without written district authorisation.
- Deletion on request and on termination, with a stated timeline and a stated exception list.
- Named sub-processors, with notice before the list changes.
- A termination right if the vendor is acquired or materially changes its data terms.
Kastr's version. Clause 9.4 prohibits marketing or selling to district families and prohibits family-facing subscription revenue for the life of the agreement. Clause 11.2 gives a 90-day termination right with export and a prorated refund if we are acquired or materially change our data terms. Clause 7.1 is an export right. We publish retention defaults per record class; the automated purge job behind them is not built yet, and we would rather you knew that before signing than after.
This entry describes what the rule says. Whether and how it applies to your district is a question for your own counsel, not for a vendor.
Questions people actually ask
Does SOPIPA apply to vendors outside California?
It applies to operators of services designed and marketed for K-12 use whose activities reach California students, not only to companies located there. In practice most national vendors treat it as a baseline. Other states have their own statutes with additional requirements.
What is the difference between SOPIPA and FERPA?
FERPA binds the educational agency and reaches vendors through contract; its sanction is a funding remedy against the district. SOPIPA binds the operator directly, prohibits specific conduct outright, and is enforced by the state attorney general.
Does SOPIPA ban all advertising in a school app?
No. It bans advertising targeted using covered student information, and bans building profiles for non-educational purposes. Generic advertising is not prohibited by the statute itself, though several districts prohibit it by contract and several state clones go further.
Which states have SOPIPA-style laws?
More than twenty, with meaningful variation. Some add breach-notification windows, some add mandatory contract clauses, some add parent-facing access and deletion rights. Ask a vendor which specific state requirements it has implemented rather than whether it is SOPIPA compliant.
One price. Every feature. Locked for three years.
$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.