State · Federal · International

One district agreement.
Your state's exhibit included.

The agreement your district signs includes your state's exhibit, and the portal shows which standards it covers. Below is a plain-language map of the laws we support and how.

The SDPC framework, in one paragraph

The Student Data Privacy Consortium's National DPA v2.0 is the de-facto standard contract for K–12 vendor relationships in the United States. We sign the National DPA as our base agreement, with the SDPC state exhibit for your state as part of what the district signs. For non-U.S. districts, our own regional addendum applies (EU GDPR Art. 8 / UK AADC).

The agreement records the district as consenting on parents' behalf for educational use (COPPA), names INCLUXA as a school official with legitimate educational interest (FERPA), and binds us to the operator obligations of the state law that applies to the district.

United States

U.S. state student-data laws

State laws we see most often in K–12 contracts. The portal recognizes California, Colorado, Illinois, New York and Texas; the state exhibit is part of the agreement your district signs.

California CA Cal. Bus. & Prof. Code § 22584

Student Online Personal Information Protection Act (SOPIPA)

Scope. Operators of websites or services designed and marketed for K–12 school purposes.

What the law requires of operators

  • •No targeted advertising based on student data
  • •No selling of student information
  • •No creating commercial profiles for non-educational purposes
  • •Reasonable security and breach notification
  • •Delete student data on request from the school district

How INCLUXA covers it

No advertising of any kind. No data sale. No commercial profiling. IEP data can be deleted in the portal; other student data is removed by the district's retention setting or on request via privacy@incluxa.com.

Illinois IL 105 ILCS 85/

Student Online Personal Protection Act (SOPPA)

Scope. Strictest U.S. state law. Operators serving Illinois K–12 schools.

What the law requires of operators

  • •Annual breach notification to schools (within 30 days of discovery)
  • •Public-facing list of subprocessors
  • •Written contract with each school district
  • •Public list of operators on each district website
  • •Parents have a direct right of access to data held by operators

How INCLUXA covers it

SDPC v2.0 + Illinois SOPPA exhibit signed before processing. Subprocessor list published at /dpa#sub-processors. Breach notice to schools within 24 hours under our incident-response procedure.

New York NY N.Y. Educ. Law § 2-d

Education Law § 2-d + Part 121 Regulations

Scope. Third-party contractors receiving Personally Identifiable Information (PII) from NY education agencies.

What the law requires of operators

  • •Adopt the NY State Education Department Parents' Bill of Rights
  • •Sign a Data Privacy Agreement with each contracting agency
  • •Designate a Data Protection Officer
  • •NIST Cybersecurity Framework alignment
  • •Annual privacy and security training for staff

How INCLUXA covers it

NYSED Parents' Bill of Rights bundled into the SDPC + NY exhibit. Privacy contact: privacy@incluxa.com. NIST CSF 2.0 aligned — self-attested.

Texas TX Texas Education Code

Texas school cybersecurity and student-data law

Scope. School districts and their service providers handling student data.

What the law requires of operators

  • •Cybersecurity policy aligned with TEA-adopted framework
  • •Designation of a cybersecurity coordinator
  • •Breach notification to TEA and affected parents
  • •Annual cybersecurity risk assessment

How INCLUXA covers it

Breach notice to schools within 24 hours under our incident-response procedure. Annual internal risk assessment (NIST CSF 2.0 aligned).

Florida FL Florida Statutes

Florida student online personal information protection

Scope. Operators of websites/services targeted at PreK–12 students or used for school purposes.

What the law requires of operators

  • •No targeted advertising based on student data
  • •No selling, leasing, or trading student information
  • •No use of student data to amass profiles for non-school purposes
  • •Reasonable security procedures and practices
  • •Delete student data on school request

How INCLUXA covers it

The same commitments as for California SOPIPA apply: no advertising, no data sale, no commercial profiling. Florida exhibit available on request.

Need an exhibit for a state not listed? Email sales@incluxa.com — other states on request under the SDPC framework.

International

International children's data law

For districts outside the U.S., the operator obligations come from data-protection law. We map the same architectural posture to GDPR and the UK Children's Code.

European Union EU Regulation (EU) 2016/679 Art. 8

GDPR Article 8 — Conditions for child's consent

Scope. Information society services offered directly to children. Member states set the digital age of consent (13–16).

What the law requires of operators

  • •Obtain parental consent for direct services to children below the local age of consent
  • •Make reasonable efforts to verify parental consent
  • •Provide privacy information in clear, age-appropriate language
  • •Apply data minimization, purpose limitation, and storage limitation strictly

How INCLUXA covers it

School-authorized agent posture mirrors COPPA: districts (the data controller for school operations) consent on behalf of parents. All data is stored and processed in the United States; the region setting selects the regional addendum. EU/UK transfers rely on SCCs / UK IDTA.

United Kingdom UK ICO Code of Practice under Data Protection Act 2018

Age Appropriate Design Code (AADC) — "Children's Code"

Scope. Online services likely to be accessed by children in the UK.

What the law requires of operators

  • •Best interests of the child as a primary design consideration
  • •High-privacy default settings
  • •Data minimization and no nudge techniques
  • •Detrimental use of children's data prohibited (advertising profiling, geolocation)
  • •Data Protection Impact Assessment (DPIA) required for relevant services

How INCLUXA covers it

No advertising profiling. No student logins or public profiles. All data is stored and processed in the United States; the region setting selects the regional addendum. EU/UK transfers rely on SCCs / UK IDTA.

What the agreement records

When you sign the district agreement in Settings → Schools, you supply these fields.

State code

Two-letter state code (e.g. CA, CO, IL, NY, TX) identifies the state exhibit that is part of your agreement; the portal shows which standards it covers.

Data region

US, EU, or UK. All data is stored and processed in the United States; the region setting selects the regional addendum. EU/UK transfers rely on SCCs / UK IDTA. (e.g. GDPR Art. 8 for EU, AADC for UK).

Agreement gate

Until the agreement is signed, IEP automation, the teacher dashboard and LMS connections stay locked.