Student Data Privacy Agreement
National Data Privacy Agreement (NDPA) Template — ThinkKits LLC
Data Privacy Agreement
Between the Local Education Agency and ThinkKits LLC
[District Street Address]
[City, State, ZIP]
7930 Jones Branch Drive, Suite 400
McLean, VA 22102
Effective Date: [Effective Date — MM/DD/YYYY]
Recitals and Purpose
This Data Privacy Agreement ("Agreement" or "DPA") is entered into as of the Effective Date by and between [District Legal Name] (the "LEA" or "District"), a local education agency organized under the laws of the State of [State], and ThinkKits LLC, a Virginia limited liability company ("Provider").
WHEREAS, the LEA desires to obtain certain education technology services from the Provider as described in the associated Order Form or Service Agreement ("Services Agreement"); and
WHEREAS, in the course of providing those services, the Provider may receive, access, or process Student Data (as defined herein) on behalf of the LEA; and
WHEREAS, the LEA and Provider desire to set forth the terms governing the collection, use, protection, and deletion of Student Data in compliance with applicable federal and state law;
NOW, THEREFORE, in consideration of the mutual covenants and promises set forth herein and for other good and valuable consideration, the parties agree as follows.
Definitions
As used in this Agreement, the following terms have the meanings set forth below. Capitalized terms not defined herein have the meanings ascribed in the Services Agreement.
Description of Student Data
The categories of Student Data that the Provider may receive or process under this Agreement are limited to those set forth in Exhibit A attached hereto and incorporated by reference. The LEA represents that it has the authority to provide such data to the Provider under FERPA and applicable state law.
3.1 Scope of Data
Provider shall collect and process only the minimum Student Data necessary to perform the Services. The parties agree that Exhibit A accurately describes the full scope of Student Data to be shared. Any expansion of data scope requires a written amendment signed by both parties.
3.2 LEA Responsibility
The LEA is responsible for ensuring that Student Data transmitted to Provider is accurate, complete, and transmitted through secure means. The LEA shall notify Provider promptly of any known inaccuracies in Student Data.
3.3 No Sale of Data
Provider shall not sell Student Data. "Sale" means the exchange of Student Data for monetary or other valuable consideration, as defined under applicable state law including but not limited to the California Student Privacy Act and state equivalents in the LEA's jurisdiction.
Data Use Restrictions
4.1 Permitted Uses
Provider may use Student Data solely for the following purposes:
- Providing, maintaining, and improving the Services as described in the Services Agreement;
- Responding to technical support requests initiated by the LEA or its authorized users;
- Complying with applicable legal requirements or valid legal process;
- Enforcing Provider's rights under this Agreement or the Services Agreement;
- Such other uses as are expressly authorized in writing by the LEA.
4.2 Prohibited Uses
Provider shall NOT use Student Data for any of the following purposes:
- Targeted advertising to students, parents, or guardians;
- Creating advertising profiles of students;
- Selling, renting, leasing, or trading Student Data to any third party;
- Disclosing Student Data for purposes unrelated to the Services without prior written consent of the LEA;
- Informing, influencing, or enabling product or service offerings directed at students based on Student Data from the Services;
- Combining Student Data with data from other sources in a manner that could identify individual students, except as necessary to provide the Services.
4.3 De-Identified Data
Provider may use De-Identified Data for product development, research, and improvement of educational services, provided that: (a) the data has been de-identified in accordance with FERPA standards; (b) Provider does not attempt to re-identify the data; and (c) Provider contractually prohibits any recipient of such data from attempting re-identification.
4.4 Research and Evaluation
Provider may use Student Data to conduct research only if such research is: (i) for the improvement of educational products and services; (ii) conducted on behalf of and with the written authorization of the LEA; and (iii) compliant with all applicable legal requirements including IRB review where applicable.
Data Security Obligations
5.1 Security Program
Provider shall maintain a comprehensive written information security program ("WISP") that includes administrative, technical, and physical safeguards reasonably designed to protect Student Data against unauthorized access, use, modification, disclosure, or destruction. Such safeguards shall be no less protective than those Provider applies to its own confidential information and shall meet or exceed industry-standard practices for educational technology providers.
5.2 Minimum Security Standards
Provider's security program shall include, at a minimum:
- Encryption of Student Data in transit using TLS 1.2 or higher;
- Encryption of Student Data at rest using AES-256 or equivalent;
- Role-based access controls limiting Student Data access to personnel with a legitimate need;
- Multi-factor authentication for administrative access to systems processing Student Data;
- Periodic security assessments and vulnerability scanning;
- Documented incident response and data breach notification procedures;
- Employee security training at hire and at least annually thereafter;
- Secure software development lifecycle (SDLC) practices.
5.3 Access Controls
Provider shall ensure that only authorized employees, contractors, and Subprocessors with a documented need have access to Student Data. Provider shall maintain access logs and shall make such logs available to LEA upon request.
5.4 Security Assessments
Provider shall conduct or obtain a third-party security assessment at least annually and shall provide a summary of findings and remediation status to the LEA upon written request. Provider shall remediate any high or critical vulnerabilities within 30 days of discovery.
5.5 LEA Audit Rights
Upon reasonable written notice (no less than 10 business days), the LEA may audit Provider's data security practices, or designate a qualified third party to do so, no more than once per calendar year. Provider shall cooperate fully with any such audit.
Data Breach Notification
6.1 Initial Notification
Provider shall notify the LEA's designated Privacy Officer or Authorized Representative of any confirmed or reasonably suspected Breach of Student Data within 24 hours of Provider's discovery of such Breach, regardless of whether Provider has completed its investigation. Notification shall be made via the contact information in Section 13 and confirmed in writing by email.
6.2 Full Written Report
Within 48 hours of the initial notification, Provider shall deliver a written incident report to the LEA that includes, to the extent then known:
- A description of the nature of the Breach;
- The categories and approximate number of students and Student Data records affected;
- The likely consequences of the Breach;
- The measures taken or proposed to address the Breach and mitigate its effects;
- The name and contact information of the Provider's data protection contact person.
Provider shall supplement this report as additional information becomes available and shall provide updates to the LEA at least every 48 hours until the Breach is fully contained and remediated.
6.3 Cooperation and Remediation
Provider shall promptly take all reasonable steps to contain the Breach, investigate its scope and cause, and remediate the underlying vulnerability. Provider shall cooperate fully with the LEA's investigation and any regulatory inquiries. Provider shall bear all reasonable costs of investigation, notification, and remediation attributable to Provider's failure to maintain required security standards.
6.4 Parent and Student Notification
The LEA retains the authority and responsibility for notifying affected students and parents/guardians of any Breach as required by applicable law. Provider shall provide all reasonable assistance to the LEA in preparing and delivering such notifications, including providing affected student lists and supporting documentation.
6.5 Law Enforcement Delay
In the event a law enforcement agency requests that notification be delayed, Provider shall notify the LEA of such request immediately and shall delay notification only for the period expressly requested by law enforcement. Provider shall notify the LEA when the law enforcement delay has been lifted.
Data Deletion and Return Upon Termination
7.1 Deletion or Return Election
Upon expiration or termination of the Services Agreement, or upon written request by the LEA at any time, Provider shall, at the LEA's election within 30 days of such termination or request:
- Return: Provide the LEA with a complete export of all Student Data in a standard machine-readable format (CSV, JSON, or equivalent); or
- Delete: Securely destroy all Student Data in Provider's possession, including data held by Subprocessors, using NIST SP 800-88 Guidelines for Media Sanitization or equivalent standard.
7.2 Certification of Deletion
Within 10 business days of completing deletion, Provider shall deliver to the LEA a written certification confirming that all Student Data has been deleted or destroyed, identifying the deletion method used and the systems from which data was removed.
7.3 Legal Hold Exception
Notwithstanding the foregoing, Provider may retain Student Data for the minimum period required by applicable federal or state law, or pursuant to a valid legal hold, provided that Provider: (a) notifies the LEA in writing of such retention and its legal basis; (b) limits access to retained data to personnel required for legal compliance purposes; and (c) deletes such data immediately upon expiration of the required retention period.
7.4 Backup Media
Provider shall delete Student Data from backup media within the normal backup rotation schedule, not to exceed 90 days after the date of the return or deletion election, unless otherwise prohibited by law.
7.5 Continued Data Use Prohibition
After termination of the Services Agreement, Provider shall have no right to use, access, or process Student Data for any purpose, including product development or research, unless expressly authorized in a separate written agreement executed after termination.
Subprocessor Consent and Management
8.1 Current Subprocessors
Provider's current Subprocessors who may process Student Data are listed in Exhibit B attached hereto. The LEA consents to Provider's use of the Subprocessors listed in Exhibit B as of the Effective Date.
8.2 New Subprocessors
Provider shall provide the LEA with written notice at least 30 days prior to engaging any new Subprocessor to process Student Data. Such notice shall identify the Subprocessor, the nature of the processing, and the data to be shared. The LEA may object to the use of a new Subprocessor on reasonable data privacy grounds within 15 days of receipt of such notice. If the LEA objects and the parties cannot reach resolution within 15 days of the objection, either party may terminate the Services Agreement without penalty on 30 days' written notice.
8.3 Subprocessor Obligations
Provider shall ensure that all Subprocessors are bound by written agreements that impose data protection obligations no less protective than those imposed on Provider under this Agreement, including but not limited to: data use restrictions, security standards, breach notification timelines, and deletion requirements. Provider remains fully liable to the LEA for the acts and omissions of its Subprocessors with respect to Student Data.
8.4 Subprocessor Audit
Provider shall conduct annual due diligence reviews of Subprocessors' data security practices and shall maintain records of such reviews. Provider shall make such records available to the LEA upon written request.
Governing Law and Jurisdiction
9.1 Governing Law
This Agreement shall be governed by and construed in accordance with the laws of the State of [LEA's State], without regard to its conflict-of-law provisions, except to the extent that federal law (including FERPA, COPPA, and IDEA) preempts state law.
9.2 Jurisdiction
Any dispute arising out of or relating to this Agreement that cannot be resolved by the parties through good-faith negotiation shall be submitted to binding arbitration under the rules of the American Arbitration Association, conducted in [City, State], unless the LEA elects to pursue resolution in a court of competent jurisdiction located in [LEA's State].
9.3 Federal and State Compliance
Both parties shall comply with all applicable federal and state laws governing student data privacy, including without limitation: FERPA (20 U.S.C. § 1232g); COPPA (15 U.S.C. §§ 6501–6506); IDEA (20 U.S.C. § 1400 et seq.); applicable state student privacy statutes; and any successor statutes or regulations. In the event of a conflict between this Agreement and applicable law, applicable law shall control.
Term and Termination
10.1 Term
This Agreement shall be effective as of the Effective Date and shall remain in effect for the duration of the Services Agreement, unless earlier terminated as provided herein.
10.2 Termination for Cause
Either party may terminate this Agreement immediately upon written notice if the other party commits a material breach of this Agreement and fails to cure such breach within 30 days of receipt of written notice specifying the breach in reasonable detail.
10.3 Effect of Termination
Sections 4 (Data Use Restrictions), 5 (Security Obligations), 7 (Deletion and Return), 9 (Governing Law), and 11 (Miscellaneous) shall survive termination or expiration of this Agreement.
Miscellaneous Provisions
11.1 Entire Agreement
This Agreement, together with its Exhibits and the Services Agreement, constitutes the entire agreement between the parties with respect to the privacy and security of Student Data and supersedes all prior and contemporaneous agreements, representations, and understandings.
11.2 Amendment
This Agreement may be amended only by a written instrument signed by authorized representatives of both parties. No oral modification shall be effective.
11.3 Severability
If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall continue in full force and effect.
11.4 No Waiver
Failure by either party to enforce any provision of this Agreement shall not constitute a waiver of that party's right to enforce such provision or any other provision in the future.
11.5 Counterparts and Electronic Signatures
This Agreement may be executed in counterparts, each of which shall be deemed an original, and all of which together shall constitute one agreement. Electronic signatures shall be deemed valid and binding to the same extent as original signatures.
11.6 Assignment
Neither party may assign this Agreement without the prior written consent of the other party, except that Provider may assign this Agreement to a successor entity in connection with a merger, acquisition, or sale of substantially all of its assets, provided that: (a) Provider notifies the LEA in writing at least 30 days prior to such assignment; and (b) the assignee agrees in writing to be bound by all terms of this Agreement.
FERPA & Data Classification
Provider is a data aggregator of publicly available school-level records published by federal agencies (NCES, CRDC, USAC, Census). Provider does not access, receive, store, or process student education records as defined under FERPA (20 U.S.C. § 1232g). Provider is not designated as a “school official” under 34 C.F.R. § 99.31(a)(1) and does not rely on the school official exception. If LEA elects to upload district-specific data, such data remains the property of the LEA and is governed by the data handling terms in this Agreement.
Notices and Designated Privacy Contacts
[Authorized Representative Name]
[Title / Role]
[District Legal Name]
[District Street Address]
[City, State, ZIP]
[Email Address]
[Phone Number]
Privacy Officer
ThinkKits LLC
7930 Jones Branch Drive, Suite 400
McLean, VA 22102
privacy@thinkkits.com
(800) 555-0199
Notices regarding data breaches shall be provided via email to the addresses above and confirmed by telephone for time-sensitive matters.
Description of Student Data
The following categories of Student Data may be provided by the LEA to Provider in connection with the Services. The LEA shall mark each applicable category prior to execution.
| Data Category | Examples | Applicable |
|---|---|---|
| Directory Information | Student name, grade level, school enrollment | [Y/N] |
| Demographic Information | Age, gender, race/ethnicity, ELL status | [Y/N] |
| Program Participation | Title I, IDEA/IEP, 504, gifted designation | [Y/N] |
| Assessment Results | State assessment scores, interim assessment data | [Y/N] |
| Attendance and Discipline | Attendance records, disciplinary actions | [Y/N] |
| Account / Login Information | Usernames, SSO tokens (not passwords) | [Y/N] |
| Other (specify) | [Describe] | [Y/N] |
Authorized Subprocessors
The following Subprocessors are authorized by the LEA as of the Effective Date to process Student Data on behalf of Provider in connection with the Services:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure and data hosting | United States |
| Railway (Railway Corp.) | Application deployment and database hosting | United States |
| Clerk (Clerk, Inc.) | Authentication and identity management | United States |
| Neo4j, Inc. | Knowledge graph database (Railway-hosted Neo4j) | United States |
Provider will notify LEA of any changes to this list in accordance with Section 8.2.
Signatures
By signing below, the authorized representatives of each party agree to be bound by the terms of this Data Privacy Agreement.