One district agreement.
Your state’s exhibit included.
The agreement your district signs includes your state’s exhibit, and the portal shows which standards it covers. Below is a plain-language map of the laws we support and how.
The SDPC framework, in one paragraph
The Student Data Privacy Consortium’s National DPA v2.0 is the de-facto standard contract for K–12 vendor relationships in the United States. We sign the National DPA as our base agreement, with the SDPC state exhibit for your state as part of what the district signs. For non-U.S. districts, our own regional addendum applies (EU GDPR Art. 8 / UK AADC).
The agreement records the district as consenting on parents’ behalf for educational use (COPPA), names INCLUXA as a school official with legitimate educational interest (FERPA), and binds us to the operator obligations of the state law that applies to the district.
U.S. state student-data laws
State laws we see most often in K–12 contracts. The portal recognizes California, Colorado, Illinois, New York and Texas; the state exhibit is part of the agreement your district signs.
Student Online Personal Information Protection Act (SOPIPA)
Scope. Operators of websites or services designed and marketed for K–12 school purposes.
What the law requires of operators
- •No targeted advertising based on student data
- •No selling of student information
- •No creating commercial profiles for non-educational purposes
- •Reasonable security and breach notification
- •Delete student data on request from the school district
How INCLUXA covers it
No advertising of any kind. No data sale. No commercial profiling. IEP data can be deleted in the portal; other student data is removed by the district’s retention setting or on request via privacy@incluxa.com.
Student Online Personal Protection Act (SOPPA)
Scope. Strictest U.S. state law. Operators serving Illinois K–12 schools.
What the law requires of operators
- •Annual breach notification to schools (within 30 days of discovery)
- •Public-facing list of subprocessors
- •Written contract with each school district
- •Public list of operators on each district website
- •Parents have a direct right of access to data held by operators
How INCLUXA covers it
SDPC v2.0 + Illinois SOPPA exhibit signed before processing. Subprocessor list published at /dpa#sub-processors. Breach notice to schools within 24 hours under our incident-response procedure.
Education Law § 2-d + Part 121 Regulations
Scope. Third-party contractors receiving Personally Identifiable Information (PII) from NY education agencies.
What the law requires of operators
- •Adopt the NY State Education Department Parents’ Bill of Rights
- •Sign a Data Privacy Agreement with each contracting agency
- •Designate a Data Protection Officer
- •NIST Cybersecurity Framework alignment
- •Annual privacy and security training for staff
How INCLUXA covers it
NYSED Parents’ Bill of Rights bundled into the SDPC + NY exhibit. Privacy contact: privacy@incluxa.com. NIST CSF 2.0 aligned — self-attested.
Texas school cybersecurity and student-data law
Scope. School districts and their service providers handling student data.
What the law requires of operators
- •Cybersecurity policy aligned with TEA-adopted framework
- •Designation of a cybersecurity coordinator
- •Breach notification to TEA and affected parents
- •Annual cybersecurity risk assessment
How INCLUXA covers it
Breach notice to schools within 24 hours under our incident-response procedure. Annual internal risk assessment (NIST CSF 2.0 aligned).
Florida student online personal information protection
Scope. Operators of websites/services targeted at PreK–12 students or used for school purposes.
What the law requires of operators
- •No targeted advertising based on student data
- •No selling, leasing, or trading student information
- •No use of student data to amass profiles for non-school purposes
- •Reasonable security procedures and practices
- •Delete student data on school request
How INCLUXA covers it
The same commitments as for California SOPIPA apply: no advertising, no data sale, no commercial profiling. Florida exhibit available on request.
Need an exhibit for a state not listed? Email sales@incluxa.com — other states on request under the SDPC framework.
International children’s data law
For districts outside the U.S., the operator obligations come from data-protection law. We map the same architectural posture to GDPR and the UK Children’s Code.
GDPR Article 8 — Conditions for child’s consent
Scope. Information society services offered directly to children. Member states set the digital age of consent (13–16).
What the law requires of operators
- •Obtain parental consent for direct services to children below the local age of consent
- •Make reasonable efforts to verify parental consent
- •Provide privacy information in clear, age-appropriate language
- •Apply data minimization, purpose limitation, and storage limitation strictly
How INCLUXA covers it
School-authorized agent posture mirrors COPPA: districts (the data controller for school operations) consent on behalf of parents. All data is stored and processed in the United States; the region setting selects the regional addendum. EU/UK transfers rely on SCCs / UK IDTA.
Age Appropriate Design Code (AADC) — “Children’s Code”
Scope. Online services likely to be accessed by children in the UK.
What the law requires of operators
- •Best interests of the child as a primary design consideration
- •High-privacy default settings
- •Data minimization and no nudge techniques
- •Detrimental use of children’s data prohibited (advertising profiling, geolocation)
- •Data Protection Impact Assessment (DPIA) required for relevant services
How INCLUXA covers it
No advertising profiling. No student logins or public profiles. All data is stored and processed in the United States; the region setting selects the regional addendum. EU/UK transfers rely on SCCs / UK IDTA.
What the agreement records
When you sign the district agreement in Settings → Schools, you supply these fields.
State code
Two-letter state code (e.g. CA, CO, IL, NY, TX) identifies the state exhibit that is part of your agreement; the portal shows which standards it covers.
Data region
US, EU, or UK. All data is stored and processed in the United States; the region setting selects the regional addendum. EU/UK transfers rely on SCCs / UK IDTA. (e.g. GDPR Art. 8 for EU, AADC for UK).
Agreement gate
Until the agreement is signed, IEP automation, the teacher dashboard and LMS connections stay locked.
Want the full DPA package?
We’ll send your IT director the SDPC v2.0 base, the relevant state exhibit, and the regional exhibit (if applicable) for review before signing.