Student Online Personal Protection Act (SOPPA)

Beginning July 1, 2021, school districts will be required by the Student Online Personal Protection Act (SOPPA) to provide additional guarantees that student data is protected when collected by educational technology companies, and that data is used for beneficial purposes only.

District Requirements:

  • Annually post a list of all operators of online services or applications utilized by the district.
  • Annually post all data elements that the school collects, maintains, or discloses to any entity. This information must also explain how the school uses the data, and to whom and why it discloses the data.
  • Post contracts for each operator within 10 days of signing.
  • Annually post subcontractors for each operator.
  • Post the process for how parents can exercise their rights to inspect, review and correct information maintained by the school, operator, or ISBE.
  • Post data breaches within 10 days and notify parents within 30 days.
  • Create a policy for who can sign contracts with operators.
  • Designate a privacy officer to ensure compliance.
  • Maintain reasonable security procedures and practices. Agreements with vendors in which information is shared must include a provision that the vendor maintains reasonable security procedures and practices.

Although not required by law, school districts will also need to undertake the following to meet the above requirements:

  • Provide teachers with the list of online operators that are safe and approved for use.
  • Develop a process for keeping data inventory up-to-date.

Approved Technology List