← Policies
SDPC NDPA Aligned

Student Data Privacy Agreement

National Data Privacy Agreement (NDPA) Template — ThinkKits LLC

Template version 1.0  ·  Aligned with SDPC NDPA v1.0  ·  Updated March 2026

How to use this template: This is the standard Data Privacy Agreement between your school district and ThinkKits LLC, aligned with the Student Data Privacy Consortium (SDPC) National DPA framework. Fill in each highlighted field with your district's information, then have your authorized representative sign. Send the completed agreement to privacy@thinkkits.com to execute.
Fillable field — district completes these fields before execution
Student Data Privacy Consortium — National Data Privacy Agreement

Data Privacy Agreement

Between the Local Education Agency and ThinkKits LLC

Local Education Agency (LEA)
[District Legal Name]

[District Street Address]
[City, State, ZIP]

Provider
ThinkKits LLC

7930 Jones Branch Drive, Suite 400
McLean, VA 22102

Effective Date: [Effective Date — MM/DD/YYYY]

Section 1

Recitals and Purpose

This Data Privacy Agreement ("Agreement" or "DPA") is entered into as of the Effective Date by and between [District Legal Name] (the "LEA" or "District"), a local education agency organized under the laws of the State of [State], and ThinkKits LLC, a Virginia limited liability company ("Provider").

WHEREAS, the LEA desires to obtain certain education technology services from the Provider as described in the associated Order Form or Service Agreement ("Services Agreement"); and

WHEREAS, in the course of providing those services, the Provider may receive, access, or process Student Data (as defined herein) on behalf of the LEA; and

WHEREAS, the LEA and Provider desire to set forth the terms governing the collection, use, protection, and deletion of Student Data in compliance with applicable federal and state law;

NOW, THEREFORE, in consideration of the mutual covenants and promises set forth herein and for other good and valuable consideration, the parties agree as follows.

Section 2

Definitions

As used in this Agreement, the following terms have the meanings set forth below. Capitalized terms not defined herein have the meanings ascribed in the Services Agreement.

"Student Data" Any personally identifiable information (PII) that is directly related to an identifiable student and that is provided to or collected by the Provider on behalf of the LEA, including data described in Exhibit A.
"Covered Information" All Student Data, metadata, and de-identified information derived from Student Data.
"FERPA" The Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99.
"COPPA" The Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506, and the FTC's implementing rule at 16 C.F.R. Part 312.
"Breach" Any unauthorized acquisition, access, use, or disclosure of Student Data that compromises the security, confidentiality, or integrity of such data.
"De-Identified Data" Data from which all personally identifiable information has been removed or obscured such that no individual student can be reasonably identified, whether directly or indirectly.
"Subprocessor" Any third party engaged by the Provider to process Student Data in connection with the Services.
"Targeted Advertising" Presenting advertisements to a student where the advertisement is selected based on information obtained or inferred from that student's online behavior, use of applications, or Student Data.
Section 3

Description of Student Data

The categories of Student Data that the Provider may receive or process under this Agreement are limited to those set forth in Exhibit A attached hereto and incorporated by reference. The LEA represents that it has the authority to provide such data to the Provider under FERPA and applicable state law.

3.1 Scope of Data

Provider shall collect and process only the minimum Student Data necessary to perform the Services. The parties agree that Exhibit A accurately describes the full scope of Student Data to be shared. Any expansion of data scope requires a written amendment signed by both parties.

3.2 LEA Responsibility

The LEA is responsible for ensuring that Student Data transmitted to Provider is accurate, complete, and transmitted through secure means. The LEA shall notify Provider promptly of any known inaccuracies in Student Data.

3.3 No Sale of Data

Provider shall not sell Student Data. "Sale" means the exchange of Student Data for monetary or other valuable consideration, as defined under applicable state law including but not limited to the California Student Privacy Act and state equivalents in the LEA's jurisdiction.

Section 4

Data Use Restrictions

Compliance note: Provider's use of Student Data is strictly limited to the purposes below. Any use not expressly authorized herein requires prior written consent from the LEA.

4.1 Permitted Uses

Provider may use Student Data solely for the following purposes:

  • Providing, maintaining, and improving the Services as described in the Services Agreement;
  • Responding to technical support requests initiated by the LEA or its authorized users;
  • Complying with applicable legal requirements or valid legal process;
  • Enforcing Provider's rights under this Agreement or the Services Agreement;
  • Such other uses as are expressly authorized in writing by the LEA.

4.2 Prohibited Uses

Provider shall NOT use Student Data for any of the following purposes:

  • Targeted advertising to students, parents, or guardians;
  • Creating advertising profiles of students;
  • Selling, renting, leasing, or trading Student Data to any third party;
  • Disclosing Student Data for purposes unrelated to the Services without prior written consent of the LEA;
  • Informing, influencing, or enabling product or service offerings directed at students based on Student Data from the Services;
  • Combining Student Data with data from other sources in a manner that could identify individual students, except as necessary to provide the Services.

4.3 De-Identified Data

Provider may use De-Identified Data for product development, research, and improvement of educational services, provided that: (a) the data has been de-identified in accordance with FERPA standards; (b) Provider does not attempt to re-identify the data; and (c) Provider contractually prohibits any recipient of such data from attempting re-identification.

4.4 Research and Evaluation

Provider may use Student Data to conduct research only if such research is: (i) for the improvement of educational products and services; (ii) conducted on behalf of and with the written authorization of the LEA; and (iii) compliant with all applicable legal requirements including IRB review where applicable.

Section 5

Data Security Obligations

5.1 Security Program

Provider shall maintain a comprehensive written information security program ("WISP") that includes administrative, technical, and physical safeguards reasonably designed to protect Student Data against unauthorized access, use, modification, disclosure, or destruction. Such safeguards shall be no less protective than those Provider applies to its own confidential information and shall meet or exceed industry-standard practices for educational technology providers.

5.2 Minimum Security Standards

Provider's security program shall include, at a minimum:

  • Encryption of Student Data in transit using TLS 1.2 or higher;
  • Encryption of Student Data at rest using AES-256 or equivalent;
  • Role-based access controls limiting Student Data access to personnel with a legitimate need;
  • Multi-factor authentication for administrative access to systems processing Student Data;
  • Periodic security assessments and vulnerability scanning;
  • Documented incident response and data breach notification procedures;
  • Employee security training at hire and at least annually thereafter;
  • Secure software development lifecycle (SDLC) practices.

5.3 Access Controls

Provider shall ensure that only authorized employees, contractors, and Subprocessors with a documented need have access to Student Data. Provider shall maintain access logs and shall make such logs available to LEA upon request.

5.4 Security Assessments

Provider shall conduct or obtain a third-party security assessment at least annually and shall provide a summary of findings and remediation status to the LEA upon written request. Provider shall remediate any high or critical vulnerabilities within 30 days of discovery.

5.5 LEA Audit Rights

Upon reasonable written notice (no less than 10 business days), the LEA may audit Provider's data security practices, or designate a qualified third party to do so, no more than once per calendar year. Provider shall cooperate fully with any such audit.

Section 6

Data Breach Notification

Notice timelines: Initial notice within 24 hours of discovery; full written report within 48 hours of initial notice. These timelines are in addition to any applicable state-law requirements.

6.1 Initial Notification

Provider shall notify the LEA's designated Privacy Officer or Authorized Representative of any confirmed or reasonably suspected Breach of Student Data within 24 hours of Provider's discovery of such Breach, regardless of whether Provider has completed its investigation. Notification shall be made via the contact information in Section 13 and confirmed in writing by email.

6.2 Full Written Report

Within 48 hours of the initial notification, Provider shall deliver a written incident report to the LEA that includes, to the extent then known:

  • A description of the nature of the Breach;
  • The categories and approximate number of students and Student Data records affected;
  • The likely consequences of the Breach;
  • The measures taken or proposed to address the Breach and mitigate its effects;
  • The name and contact information of the Provider's data protection contact person.

Provider shall supplement this report as additional information becomes available and shall provide updates to the LEA at least every 48 hours until the Breach is fully contained and remediated.

6.3 Cooperation and Remediation

Provider shall promptly take all reasonable steps to contain the Breach, investigate its scope and cause, and remediate the underlying vulnerability. Provider shall cooperate fully with the LEA's investigation and any regulatory inquiries. Provider shall bear all reasonable costs of investigation, notification, and remediation attributable to Provider's failure to maintain required security standards.

6.4 Parent and Student Notification

The LEA retains the authority and responsibility for notifying affected students and parents/guardians of any Breach as required by applicable law. Provider shall provide all reasonable assistance to the LEA in preparing and delivering such notifications, including providing affected student lists and supporting documentation.

6.5 Law Enforcement Delay

In the event a law enforcement agency requests that notification be delayed, Provider shall notify the LEA of such request immediately and shall delay notification only for the period expressly requested by law enforcement. Provider shall notify the LEA when the law enforcement delay has been lifted.

Section 7

Data Deletion and Return Upon Termination

7.1 Deletion or Return Election

Upon expiration or termination of the Services Agreement, or upon written request by the LEA at any time, Provider shall, at the LEA's election within 30 days of such termination or request:

  • Return: Provide the LEA with a complete export of all Student Data in a standard machine-readable format (CSV, JSON, or equivalent); or
  • Delete: Securely destroy all Student Data in Provider's possession, including data held by Subprocessors, using NIST SP 800-88 Guidelines for Media Sanitization or equivalent standard.

7.2 Certification of Deletion

Within 10 business days of completing deletion, Provider shall deliver to the LEA a written certification confirming that all Student Data has been deleted or destroyed, identifying the deletion method used and the systems from which data was removed.

7.3 Legal Hold Exception

Notwithstanding the foregoing, Provider may retain Student Data for the minimum period required by applicable federal or state law, or pursuant to a valid legal hold, provided that Provider: (a) notifies the LEA in writing of such retention and its legal basis; (b) limits access to retained data to personnel required for legal compliance purposes; and (c) deletes such data immediately upon expiration of the required retention period.

7.4 Backup Media

Provider shall delete Student Data from backup media within the normal backup rotation schedule, not to exceed 90 days after the date of the return or deletion election, unless otherwise prohibited by law.

7.5 Continued Data Use Prohibition

After termination of the Services Agreement, Provider shall have no right to use, access, or process Student Data for any purpose, including product development or research, unless expressly authorized in a separate written agreement executed after termination.

Section 8

Subprocessor Consent and Management

8.1 Current Subprocessors

Provider's current Subprocessors who may process Student Data are listed in Exhibit B attached hereto. The LEA consents to Provider's use of the Subprocessors listed in Exhibit B as of the Effective Date.

8.2 New Subprocessors

Provider shall provide the LEA with written notice at least 30 days prior to engaging any new Subprocessor to process Student Data. Such notice shall identify the Subprocessor, the nature of the processing, and the data to be shared. The LEA may object to the use of a new Subprocessor on reasonable data privacy grounds within 15 days of receipt of such notice. If the LEA objects and the parties cannot reach resolution within 15 days of the objection, either party may terminate the Services Agreement without penalty on 30 days' written notice.

8.3 Subprocessor Obligations

Provider shall ensure that all Subprocessors are bound by written agreements that impose data protection obligations no less protective than those imposed on Provider under this Agreement, including but not limited to: data use restrictions, security standards, breach notification timelines, and deletion requirements. Provider remains fully liable to the LEA for the acts and omissions of its Subprocessors with respect to Student Data.

8.4 Subprocessor Audit

Provider shall conduct annual due diligence reviews of Subprocessors' data security practices and shall maintain records of such reviews. Provider shall make such records available to the LEA upon written request.

Section 9

Governing Law and Jurisdiction

9.1 Governing Law

This Agreement shall be governed by and construed in accordance with the laws of the State of [LEA's State], without regard to its conflict-of-law provisions, except to the extent that federal law (including FERPA, COPPA, and IDEA) preempts state law.

9.2 Jurisdiction

Any dispute arising out of or relating to this Agreement that cannot be resolved by the parties through good-faith negotiation shall be submitted to binding arbitration under the rules of the American Arbitration Association, conducted in [City, State], unless the LEA elects to pursue resolution in a court of competent jurisdiction located in [LEA's State].

9.3 Federal and State Compliance

Both parties shall comply with all applicable federal and state laws governing student data privacy, including without limitation: FERPA (20 U.S.C. § 1232g); COPPA (15 U.S.C. §§ 6501–6506); IDEA (20 U.S.C. § 1400 et seq.); applicable state student privacy statutes; and any successor statutes or regulations. In the event of a conflict between this Agreement and applicable law, applicable law shall control.

Section 10

Term and Termination

10.1 Term

This Agreement shall be effective as of the Effective Date and shall remain in effect for the duration of the Services Agreement, unless earlier terminated as provided herein.

10.2 Termination for Cause

Either party may terminate this Agreement immediately upon written notice if the other party commits a material breach of this Agreement and fails to cure such breach within 30 days of receipt of written notice specifying the breach in reasonable detail.

10.3 Effect of Termination

Sections 4 (Data Use Restrictions), 5 (Security Obligations), 7 (Deletion and Return), 9 (Governing Law), and 11 (Miscellaneous) shall survive termination or expiration of this Agreement.

Section 11

Miscellaneous Provisions

11.1 Entire Agreement

This Agreement, together with its Exhibits and the Services Agreement, constitutes the entire agreement between the parties with respect to the privacy and security of Student Data and supersedes all prior and contemporaneous agreements, representations, and understandings.

11.2 Amendment

This Agreement may be amended only by a written instrument signed by authorized representatives of both parties. No oral modification shall be effective.

11.3 Severability

If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall continue in full force and effect.

11.4 No Waiver

Failure by either party to enforce any provision of this Agreement shall not constitute a waiver of that party's right to enforce such provision or any other provision in the future.

11.5 Counterparts and Electronic Signatures

This Agreement may be executed in counterparts, each of which shall be deemed an original, and all of which together shall constitute one agreement. Electronic signatures shall be deemed valid and binding to the same extent as original signatures.

11.6 Assignment

Neither party may assign this Agreement without the prior written consent of the other party, except that Provider may assign this Agreement to a successor entity in connection with a merger, acquisition, or sale of substantially all of its assets, provided that: (a) Provider notifies the LEA in writing at least 30 days prior to such assignment; and (b) the assignee agrees in writing to be bound by all terms of this Agreement.

Section 12

FERPA & Data Classification

Provider is a data aggregator of publicly available school-level records published by federal agencies (NCES, CRDC, USAC, Census). Provider does not access, receive, store, or process student education records as defined under FERPA (20 U.S.C. § 1232g). Provider is not designated as a “school official” under 34 C.F.R. § 99.31(a)(1) and does not rely on the school official exception. If LEA elects to upload district-specific data, such data remains the property of the LEA and is governed by the data handling terms in this Agreement.

Section 13

Notices and Designated Privacy Contacts

LEA Privacy Contact

[Authorized Representative Name]
[Title / Role]
[District Legal Name]
[District Street Address]
[City, State, ZIP]
[Email Address]
[Phone Number]

Provider Privacy Contact

Privacy Officer
ThinkKits LLC
7930 Jones Branch Drive, Suite 400
McLean, VA 22102
privacy@thinkkits.com
(800) 555-0199

Notices regarding data breaches shall be provided via email to the addresses above and confirmed by telephone for time-sensitive matters.

Exhibit A

Description of Student Data

The following categories of Student Data may be provided by the LEA to Provider in connection with the Services. The LEA shall mark each applicable category prior to execution.

Data Category Examples Applicable
Directory Information Student name, grade level, school enrollment [Y/N]
Demographic Information Age, gender, race/ethnicity, ELL status [Y/N]
Program Participation Title I, IDEA/IEP, 504, gifted designation [Y/N]
Assessment Results State assessment scores, interim assessment data [Y/N]
Attendance and Discipline Attendance records, disciplinary actions [Y/N]
Account / Login Information Usernames, SSO tokens (not passwords) [Y/N]
Other (specify) [Describe] [Y/N]
Exhibit B

Authorized Subprocessors

The following Subprocessors are authorized by the LEA as of the Effective Date to process Student Data on behalf of Provider in connection with the Services:

Subprocessor Purpose Location
Amazon Web Services (AWS) Cloud infrastructure and data hosting United States
Railway (Railway Corp.) Application deployment and database hosting United States
Clerk (Clerk, Inc.) Authentication and identity management United States
Neo4j, Inc. Knowledge graph database (Railway-hosted Neo4j) United States

Provider will notify LEA of any changes to this list in accordance with Section 8.2.

Signatures

By signing below, the authorized representatives of each party agree to be bound by the terms of this Data Privacy Agreement.

Local Education Agency
[District Legal Name]
[Authorized Representative Name]
[Title / Role]
Provider
ThinkKits LLC
Ready to execute your DPA? Send your completed agreement to privacy@thinkkits.com. Our compliance team will countersign and return an executed copy within 2 business days.
Send to ThinkKits

Was this article helpful?

← Back to Help Center