for EdTech vendors
Student data protection for the operators who actually ship the product.
FERPA, COPPA, state student-privacy law, district procurement questionnaires, AI-feature disclosures — every one of them is a compliance surface your engineering team is not staffed to run alone. vCISO Lite runs them for you, in the language districts actually use.
The seven-item September action lists for both frameworks: read the FERPA back-to-school refresh and the COPPA back-to-school refresh. Both updated for the 2026-27 school year.
Why now
Back-to-school is the highest-risk window.
The 2026-27 school year is onboarding students right now. Anything that was still in draft over summer — DPAs, parental consent workflows, AI-feature governance, incident-response coverage — becomes a district-compliance-officer phone call in October.
- 2022Illuminate Education breach — 10M students exposed
- 2024PowerSchool breach — 62M students, single largest ever
- 2025DoE mandated state-agency FERPA certification (April 30)
- 2026Ohio HB 96 — first state to require every K-12 district to adopt an AI policy (July 1)
- 2026-27AI-in-classroom features drive net-new FTC and DPA scrutiny; other states drafting to match Ohio
- 01
Summer signings are now onboarding students
Every district that signed with you in May-July is provisioning student accounts against your platform this week. If a DPA is still “in legal review,” or a parental-consent flow was aspirational in the RFP response, you have exposure the moment the first student record lands.
- 02
Parents notice new tools in the first six weeks
September is prime complaint season. A single well-documented response to a district’s records officer this month is worth more than a dozen marketing pages next spring. A missing response — or a delayed one — becomes an FTC referral.
- 03
The RFPs you answered in the spring get audited in the fall
Every “we do X” answer in a spring RFP is an item a district compliance officer can circle back on. Districts are running post-award audits on more contracts than they used to; vendors that hedged in the spring answer for it in the fall.
- 04
AI features touched student data over summer
Every AI-powered tutor, personalization engine, or content-generation feature that shipped over summer routes student data through a model. Under-13 users need parental consent for it. Districts want a written AI-governance answer before onboarding. This is the highest-frequency new complaint pattern in the current FTC docket.
students exposed in the 2024 PowerSchool breach — the largest EdTech breach ever recorded.
Class-action filings · TechCrunch reporting, 2024-25
of apps used in schools share student data with third parties, most without district visibility.
Consortium for School Networking, 2024
FTC penalty against Amazon Alexa for misrepresenting deletion of children’s voice recordings + geolocation. Order also blocks reuse of deleted data for model improvement. The precedent that changed vendor behavior.
FTC v. Amazon.com, Inc., 2023
state student-privacy statutes now in effect. California SDPC, Texas SB 820, New York Ed Law 2-d lead the pack.
Student Data Privacy Consortium, 2025
What changed
District procurement in 2026 is not the district procurement you knew.
The security review that used to be a checkbox is now a substantive review with follow-up. The DPA that used to be a template is now a live contract with annual re-attestation. Every “we do X” answer is a promise you get audited against six months later.
What districts actually want
Six things that show up in every district review.
None of these are theoretical — they are the six items that appear in state consortium questionnaires (California SDPC, Texas SB 820, New York Ed Law 2-d) and in the standard SDPC National DPA. Preparing against them once is faster than answering the same questions differently for every district.
Student-data gap analysis
FERPA, COPPA, and state-specific gap identification against your current architecture. The output is a prioritized roadmap the district reviewer can also read.
Policy generation for student data
Directory-information handling, parental-consent workflows, data-minimization posture, sub-processor list — generated from your architecture and reviewed by a real practitioner, not a template.
Evidence-gathering across the stack
Cloud providers, LMS and SIS integrations, identity provider, AI subprocessors. Continuous evidence collection so the RFP response is generated from live data, not reconstructed the night before.
District questionnaire response, in hours
SDPC National DPA v2.2 (the actual contractual layer for K-12 vendor onboarding in most states), state-specific NDPA variants (CA, TX, IL, NY), district-authored security questionnaires. AI-drafted responses with evidence auto-attached, exported in the format the district asked for.
Audit packs for procurement and post-award
One-click evidence packages mapped to FERPA + COPPA + state certifications. Pre-organized so the district's compliance officer sees the answer to their next question without asking.
Year-over-year refresh discipline
Every artifact carries a review date. Every DPA carries a renewal reminder. Every AI feature triggers a consent-posture recheck. The RFP you win in 2026-27 stays defensible through 2029-30.
How it works
Assess the gap. Answer the district. Prove it year over year.
- 01 · onboarding
Two-hour gap assessment
Point us at your architecture and current evidence — cloud providers, LMS integrations, identity provider, AI subprocessors. We produce a prioritized readiness view against FERPA, COPPA, and state privacy law, with an itemized remediation plan.
- 02 · every RFP
Questionnaire response in hours, not weeks
When a district sends the SDPC National DPA (v2.2 or the state-consortium variant they use) or their own security questionnaire, the platform drafts responses from your live evidence, attaches the supporting artifacts, and exports in the format the district asked for. Your team reviews and sends.
- 03 · every year
Refresh discipline that survives audit
Every artifact has a review date. Every DPA has a renewal reminder. Every new AI feature triggers a consent-posture recheck. When a district audits your 2026-27 RFP responses in 2028, the answer is on the shelf.
The compounding output
Your next SDPC National DPA response is already assembled.
Most US school districts — 30,000+ across every state — run vendor privacy reviews through the Student Data Privacy Consortium’s National Data Privacy Agreement (SDPC National DPA), or a district-authored variant of it. Every DPA response, sub-processor record, consent-posture answer, and AI-feature attestation lives on the same evidence graph so when a district sends the DPA, the platform assembles the response — shaped for what SDPC and state-consortium reviewers actually check in 2026-27.
sections addressed
(incl. 3 AI vendors)
vs. 2-3 weeks manually
(post-award audit ready)
- Anthropic (Claude curriculum assistant): currently school-authorization only. Direct-parental consent flow committed for 2026-Q4. Flagged as WATCH in the response so the district reviewer sees the roadmap before asking.
- OpenAI (GPT-4o writing coach): Enterprise API tier with attached training-data attestation. 90-day review cadence documented. Notification-window commitment is 24h per feature-DPA §7.
Where the market moved
Every new AI feature is a new consent conversation.
The AI-tutor rollouts, generative-content features, and personalization engines that shipped over summer all route student data through a model — often a third-party one. Under FTC 2025-26 enforcement posture, that is a COPPA disclosure event before it is a product feature. Districts want the written answer before onboarding, not after a parent complaint.
- Which AI vendor receives student data, and under what DPA?
- For under-13 users, do you have direct parental consent or are you claiming school-authorization?
- Is the AI vendor using student data to train models?
- What is your incident-response plan for an AI-output incident?
Named AI subprocessors with executed DPAs and their data-flow scopes, exportable in the district’s expected format.
Consent-basis inventory per AI feature: direct parental consent, school-authorization, or classroom-use-only carveout. Documented once, referenced across every district ask.
Written attestation from each named AI vendor that student data is not used for model training, or the narrow exception under which it is. This is the ask that surprises most edtech vendors.
Named IR retainer with an AI-incident scenario in the playbook. Not a generic cyber IR. The AI-specific one (hallucinated PII in a response, model-output routed to wrong district, etc.) needs its own workflow.
On the record
What tracked AI-subprocessor posture actually looks like.
Three model vendors, six attestation dimensions each. When a district-questionnaire responder needs the answer, they pull from the row — not from the engineering lead’s memory at midnight. Amber chip means “watch item” (surface it to the district before they ask), not a gap.
The full six-dimension framework: the register above is the operational view. The AI-in-the-classroom vendor responsibility framework walks each dimension with the district-side reasoning behind it.
Pricing
Priced for the EdTech founder, not for the district CIO office.
Public pricing, month-to-month. Sized for the pre-Series-B EdTech vendor with 10-500 district customers. No implementation fee, no per-seat surprises. The compliance posture done once, defensible across every RFP.
Questions we hear
Frequently asked.
How is FERPA different from COPPA?
FERPA protects student education records and applies to schools receiving federal funding — and by extension, their vendors. COPPA protects children under 13 online and requires verifiable parental consent. EdTech companies often need to comply with both, plus state student privacy laws. vCISO Lite maps controls across all of them.
How does the platform handle AI features that touch student data?
Every AI feature that routes student data to a third-party model is a COPPA disclosure event under Rule 312.5 and a DPA amendment under most district agreements. The platform tracks which of your AI vendors have student-data access, maps each to the consent posture required (school authorization vs. direct parental consent), and produces the district-facing documentation on demand.
What if a district security review identifies gaps?
Gaps are observations that need attention — they are addressable. vCISO Lite helps you track gaps, prioritize fixes, and document remediation. Our gap analysis typically identifies issues before district reviews do, helping you win more RFPs.
How do we handle different state requirements?
We track student privacy requirements across all 50 states plus DC. When you are pursuing districts in California, Texas, or New York (the most stringent states), we show you exactly what additional requirements apply and help you document compliance.
Where do the FERPA and COPPA guides sit relative to the platform?
The FERPA guide and COPPA guide are the reference material for the founder who wants to understand the underlying frameworks. The AI-in-the-classroom vendor responsibility framework is the reference for the AI-feature governance layer that sits on top of both. The platform is what runs all three in production — the DPAs, the vendor tracking (including AI subprocessors), the district-questionnaire responses. All three refresh every school year.
Win the district. Keep the district.
The 2026-27 school year is already onboarding students. The RFP season for 2027-28 starts in April. Get the compliance posture done once so it holds up across both.