for EdTech vendors

Student data protection for the operators who actually ship the product.

FERPA, COPPA, state student-privacy law, district procurement questionnaires, AI-feature disclosures — every one of them is a compliance surface your engineering team is not staffed to run alone. vCISO Lite runs them for you, in the language districts actually use.

The seven-item September action lists for both frameworks: read the FERPA back-to-school refresh and the COPPA back-to-school refresh. Both updated for the 2026-27 school year.

Why now

Back-to-school is the highest-risk window.

The 2026-27 school year is onboarding students right now. Anything that was still in draft over summer — DPAs, parental consent workflows, AI-feature governance, incident-response coverage — becomes a district-compliance-officer phone call in October.

  1. 2022Illuminate Education breach — 10M students exposed
  2. 2024PowerSchool breach — 62M students, single largest ever
  3. 2025DoE mandated state-agency FERPA certification (April 30)
  4. 2026Ohio HB 96 — first state to require every K-12 district to adopt an AI policy (July 1)
  5. 2026-27AI-in-classroom features drive net-new FTC and DPA scrutiny; other states drafting to match Ohio
  1. 01

    Summer signings are now onboarding students

    Every district that signed with you in May-July is provisioning student accounts against your platform this week. If a DPA is still “in legal review,” or a parental-consent flow was aspirational in the RFP response, you have exposure the moment the first student record lands.

  2. 02

    Parents notice new tools in the first six weeks

    September is prime complaint season. A single well-documented response to a district’s records officer this month is worth more than a dozen marketing pages next spring. A missing response — or a delayed one — becomes an FTC referral.

  3. 03

    The RFPs you answered in the spring get audited in the fall

    Every “we do X” answer in a spring RFP is an item a district compliance officer can circle back on. Districts are running post-award audits on more contracts than they used to; vendors that hedged in the spring answer for it in the fall.

  4. 04

    AI features touched student data over summer

    Every AI-powered tutor, personalization engine, or content-generation feature that shipped over summer routes student data through a model. Under-13 users need parental consent for it. Districts want a written AI-governance answer before onboarding. This is the highest-frequency new complaint pattern in the current FTC docket.

62M

students exposed in the 2024 PowerSchool breach — the largest EdTech breach ever recorded.

Class-action filings · TechCrunch reporting, 2024-25

96%

of apps used in schools share student data with third parties, most without district visibility.

Consortium for School Networking, 2024

$25M

FTC penalty against Amazon Alexa for misrepresenting deletion of children’s voice recordings + geolocation. Order also blocks reuse of deleted data for model improvement. The precedent that changed vendor behavior.

FTC v. Amazon.com, Inc., 2023

90+

state student-privacy statutes now in effect. California SDPC, Texas SB 820, New York Ed Law 2-d lead the pack.

Student Data Privacy Consortium, 2025

What changed

District procurement in 2026 is not the district procurement you knew.

The security review that used to be a checkbox is now a substantive review with follow-up. The DPA that used to be a template is now a live contract with annual re-attestation. Every “we do X” answer is a promise you get audited against six months later.

Pre-2024 procurement
2026-27 procurement
Security review
checkbox on a spreadsheet
substantive review with follow-up questions
DPA
template attached to the MSA
annual re-attestation + live sub-processor register
AI features
not on the questionnaire
six-dimension response required before onboarding
Post-award audit
vanishingly rare
routine on any contract > $50K
Parent complaint
handled by the district PR team
routed to records officer, then to FTC if unresolved
Incident response
generic cyber IR
AI-specific playbook + notification-window commitment
What most vendors are still running.
What vCISO Lite was built for.

What districts actually want

Six things that show up in every district review.

None of these are theoretical — they are the six items that appear in state consortium questionnaires (California SDPC, Texas SB 820, New York Ed Law 2-d) and in the standard SDPC National DPA. Preparing against them once is faster than answering the same questions differently for every district.

Assess

Student-data gap analysis

FERPA, COPPA, and state-specific gap identification against your current architecture. The output is a prioritized roadmap the district reviewer can also read.

Draft

Policy generation for student data

Directory-information handling, parental-consent workflows, data-minimization posture, sub-processor list — generated from your architecture and reviewed by a real practitioner, not a template.

Collect

Evidence-gathering across the stack

Cloud providers, LMS and SIS integrations, identity provider, AI subprocessors. Continuous evidence collection so the RFP response is generated from live data, not reconstructed the night before.

Answer

District questionnaire response, in hours

SDPC National DPA v2.2 (the actual contractual layer for K-12 vendor onboarding in most states), state-specific NDPA variants (CA, TX, IL, NY), district-authored security questionnaires. AI-drafted responses with evidence auto-attached, exported in the format the district asked for.

Prove

Audit packs for procurement and post-award

One-click evidence packages mapped to FERPA + COPPA + state certifications. Pre-organized so the district's compliance officer sees the answer to their next question without asking.

Renew

Year-over-year refresh discipline

Every artifact carries a review date. Every DPA carries a renewal reminder. Every AI feature triggers a consent-posture recheck. The RFP you win in 2026-27 stays defensible through 2029-30.

How it works

Assess the gap. Answer the district. Prove it year over year.

  1. 01 · onboarding

    Two-hour gap assessment

    Point us at your architecture and current evidence — cloud providers, LMS integrations, identity provider, AI subprocessors. We produce a prioritized readiness view against FERPA, COPPA, and state privacy law, with an itemized remediation plan.

    Time
    2 hours elapsed
    Output
    Ranked gap list · roadmap · district-facing summary
  2. 03 · every year

    Refresh discipline that survives audit

    Every artifact has a review date. Every DPA has a renewal reminder. Every new AI feature triggers a consent-posture recheck. When a district audits your 2026-27 RFP responses in 2028, the answer is on the shelf.

    Cadence
    Auto-triggered on change or annually
    Format
    Auditor-ready evidence pack

The compounding output

Your next SDPC National DPA response is already assembled.

Most US school districts — 30,000+ across every state — run vendor privacy reviews through the Student Data Privacy Consortium’s National Data Privacy Agreement (SDPC National DPA), or a district-authored variant of it. Every DPA response, sub-processor record, consent-posture answer, and AI-feature attestation lives on the same evidence graph so when a district sends the DPA, the platform assembles the response — shaped for what SDPC and state-consortium reviewers actually check in 2026-27.

2026-27 · SDPC National DPA Response
Prepared for Roosevelt Unified School District · Data Privacy & Security Review
100%
SDPC National DPA
sections addressed
12
Sub-processors listed
(incl. 3 AI vendors)
4h
Elapsed to generate
vs. 2-3 weeks manually
2028
Auto-refresh due
(post-award audit ready)
Sub-processorCategoryConsent postureIR window
AWS (us-east-1)InfrastructureSchool-auth72h
Auth0IdentityContract72h
OpenAI (GPT-4o writing)AI subprocessorSchool-auth + parental (tutor)24h
Anthropic (Claude curric.)AI subprocessorSchool-auth only · WATCH24h
Google Cloud (Chirp)AI subprocessorExpress parental (under-13)72h
DatadogObservabilityNo PII path72h
SendGridTransactionalDirectory-info only72h
  • Anthropic (Claude curriculum assistant): currently school-authorization only. Direct-parental consent flow committed for 2026-Q4. Flagged as WATCH in the response so the district reviewer sees the roadmap before asking.
  • OpenAI (GPT-4o writing coach): Enterprise API tier with attached training-data attestation. 90-day review cadence documented. Notification-window commitment is 24h per feature-DPA §7.
sample output · district + vendor data illustrative only · template alignment: SDPC National DPA v2.0

Where the market moved

Every new AI feature is a new consent conversation.

The AI-tutor rollouts, generative-content features, and personalization engines that shipped over summer all route student data through a model — often a third-party one. Under FTC 2025-26 enforcement posture, that is a COPPA disclosure event before it is a product feature. Districts want the written answer before onboarding, not after a parent complaint.

vciso-lite · ai-feature-vetting · edtech
the four questions districts ask
The pattern
Any student-facing AI feature
FERPACOPPAState privacy laws
// the district compliance officer asks4
  • Which AI vendor receives student data, and under what DPA?
  • For under-13 users, do you have direct parental consent or are you claiming school-authorization?
  • Is the AI vendor using student data to train models?
  • What is your incident-response plan for an AI-output incident?
// what the vendor pack answers4
A1 · DPA extract

Named AI subprocessors with executed DPAs and their data-flow scopes, exportable in the district’s expected format.

A2 · consent posture

Consent-basis inventory per AI feature: direct parental consent, school-authorization, or classroom-use-only carveout. Documented once, referenced across every district ask.

A3 · training-data attestation

Written attestation from each named AI vendor that student data is not used for model training, or the narrow exception under which it is. This is the ask that surprises most edtech vendors.

A4 · AI incident-response

Named IR retainer with an AI-incident scenario in the playbook. Not a generic cyber IR. The AI-specific one (hallucinated PII in a response, model-output routed to wrong district, etc.) needs its own workflow.

On the record

What tracked AI-subprocessor posture actually looks like.

Three model vendors, six attestation dimensions each. When a district-questionnaire responder needs the answer, they pull from the row — not from the engineering lead’s memory at midnight. Amber chip means “watch item” (surface it to the district before they ask), not a gap.

AI subprocessor
Data flows
Consent basis
Training-data
Human authority
Auditability
Incident-resp.
OAI
OpenAI
Writing coach · GPT-4o
Documented
Essay text + user_id · 30d retention · feature-DPA §3.2
Covered
School-auth (COPPA §312.5(c)(6)) + direct parental for tutor mode
Attested
Enterprise API — no training. Attestation attached · 90d review
Advisory
Suggestion only, teacher decides publication. Per-feature record.
Logged
Feature logs 1yr, PII redacted. Sampled quarterly.
24h notify
security@openai · per DPA §7
ANT
Anthropic
Curriculum assistant · Claude Sonnet
Documented
Standards text + user_id · 30d retention · feature-DPA §3.4
Partial
School-auth only. No parental-consent flow yet for tutor mode.
Attested
Enterprise tier — no training. Attestation attached · 90d review
Advisory
Draft only, teacher publishes. Per-feature record.
Logged
Feature logs 1yr, PII redacted. Sampled quarterly.
24h notify
security@anthropic · per DPA §7
GC
Google Cloud
Speech-to-text · Chirp
Documented
Audio + transcript · 90d retention · IEP accommodation flag
Covered
Under-13 audio = express parental consent required
In review
GCP DPA — training clause under legal review by district counsel
Assistive
Not authoritative. Teacher reviews transcript.
Logged
Feature logs 6mo, sampled by accommodation type
72h notify
cloud-security@google · per DPA §6
Illustrative — every AI-vendor record follows this shape.Amber = watch item, surfaced pre-emptively. Row exportable to SIG/CAIQ/DPA response.

The full six-dimension framework: the register above is the operational view. The AI-in-the-classroom vendor responsibility framework walks each dimension with the district-side reasoning behind it.

Pricing

Priced for the EdTech founder, not for the district CIO office.

Public pricing, month-to-month from Starter through Business. Sized for the pre-Series-B EdTech vendor with 10-500 district customers. No implementation fee, no per-seat surprises. The compliance posture done once, defensible across every RFP.

Gap assessment against FERPA + COPPA + all 50 states, live
SDPC National DPA responder + district-specific questionnaire drafts
AI-subprocessor register with per-feature consent-posture tracking

Questions we hear

Frequently asked.

  • How is FERPA different from COPPA?

    FERPA protects student education records and applies to schools receiving federal funding — and by extension, their vendors. COPPA protects children under 13 online and requires verifiable parental consent. EdTech companies often need to comply with both, plus state student privacy laws. vCISO Lite maps controls across all of them.

  • How does the platform handle AI features that touch student data?

    Every AI feature that routes student data to a third-party model is a COPPA disclosure event under Rule 312.5 and a DPA amendment under most district agreements. The platform tracks which of your AI vendors have student-data access, maps each to the consent posture required (school authorization vs. direct parental consent), and produces the district-facing documentation on demand.

  • What if a district security review identifies gaps?

    Gaps are observations that need attention — they are addressable. vCISO Lite helps you track gaps, prioritize fixes, and document remediation. Our gap analysis typically identifies issues before district reviews do, helping you win more RFPs.

  • How do we handle different state requirements?

    We track student privacy requirements across all 50 states plus DC. When you are pursuing districts in California, Texas, or New York (the most stringent states), we show you exactly what additional requirements apply and help you document compliance.

  • Where do the FERPA and COPPA guides sit relative to the platform?

    The FERPA guide and COPPA guide are the reference material for the founder who wants to understand the underlying frameworks. The AI-in-the-classroom vendor responsibility framework is the reference for the AI-feature governance layer that sits on top of both. The platform is what runs all three in production — the DPAs, the vendor tracking (including AI subprocessors), the district-questionnaire responses. All three refresh every school year.

Win the district. Keep the district.

The 2026-27 school year is already onboarding students. The RFP season for 2027-28 starts in April. Get the compliance posture done once so it holds up across both.