Public Aggregate Data Exemption — Applies to All States
ThinkKits collects only school-level and district-level aggregate data from federal open data sources (NCES Common Core of Data, USASpending.gov, USAC E-Rate, state education agency public releases). This data is already published by federal and state governments. ThinkKits does not collect, process, or store any individually identifiable student information. Because no student-level personal information is involved, ThinkKits operates outside the scope of student privacy laws in virtually all states, which explicitly exempt publicly available aggregate data. The matrix below documents each state's specific exemption language and our compliance posture.
Quick Reference Summary
| State | Primary Law(s) | Scope Trigger | ThinkKits Data Type | Exemption Basis | Compliance Status |
|---|---|---|---|---|---|
| California | SOPIPA, CPRA / CCPA | Covered operator collecting student PII | Public aggregate (NCES, USASpending) | No student PII; aggregate data exemption | ✓ Exempt / Compliant |
| New York | Education Law § 2-d | Third-party contractors handling student PII | Public aggregate (NCES CCD) | Not a contractor; no student PII handled | ✓ Exempt / Compliant |
| Illinois | ISSRA, BIPA | Student data; biometric identifiers | Public aggregate; no biometrics | No student records; no biometric data collected | ✓ Exempt / Compliant |
| Colorado | Student Data Transparency & Security Act | Operators with contracts to collect student PII | Public aggregate (NCES, USASpending) | No contract for student PII; aggregate only | ✓ Exempt / Compliant |
| Texas | TEC §§ 32.151–32.158 | Digital learning products collecting student data | Public school-level aggregate | Not a digital learning product; no student data | ✓ Exempt / Compliant |
| Florida | FERPA (state adoption) + F.S. 1002.222 | Student education records | Public aggregate (NCES, DOE) | Aggregate public data not an education record | ✓ Exempt / Compliant |
| Pennsylvania | Student Data Privacy Act (Act 55) | Covered operators collecting student PII | Public aggregate (NCES CCD, USASpending) | No student PII; publicly available data exemption | ✓ Exempt / Compliant |
| Ohio | ORC § 3301.0723; Student Privacy Guidelines | Third parties receiving student-level data from districts | Public aggregate (NCES, ODE public files) | No district data-sharing agreement; public data only | ✓ Exempt / Compliant |
| Georgia | O.C.G.A. § 20-2-666; Student Data Privacy Act | Operators collecting student PII under school contract | Public aggregate (NCES, GaDOE public releases) | No school contract for PII; public data only | ✓ Exempt / Compliant |
| Virginia | VCDPA, § 22.1-289.03 | Controllers processing personal data; student data operators | Public aggregate (NCES, VDOE public releases) | Aggregate data not personal data under VCDPA | ✓ Exempt / Compliant |
State-by-State Detail
- SOPIPA prohibits operators of K–12 websites/apps from using student data for targeted advertising or selling student information
- CPRA grants California consumers rights over personal information (access, deletion, opt-out of sale)
- AB 1584 requires districts to include data privacy terms in contracts with third-party operators
- "Covered operator" means an operator who knowingly markets to K–12 schools or students
- ThinkKits is a vendor intelligence tool, not a student-facing application; SOPIPA's "covered operator" definition does not apply
- No student PII is collected, stored, or processed — ThinkKits uses only NCES CCD and USASpending.gov aggregate data
- CPRA applies only to personal information of identifiable individuals; school-level aggregate data is not personal information
- No AB 1584 contract required because no student data passes to ThinkKits
- Ed Law § 2-d restricts disclosure of student personally identifiable information (PII)
- Third-party contractors who receive student PII must sign a Data Privacy and Security Agreement (DPSA)
- Contractors must appoint a Chief Privacy Officer and post a Parents’ Bill of Rights
- Applies to data shared by educational agencies with contractors under a contract or agreement
- ThinkKits has no contract with NY educational agencies to receive student PII; law applies only to contractors receiving PII under such agreements
- All NY school data on ThinkKits is sourced from NCES CCD — a federal public dataset published by NYSED and NCES jointly
- No DPSA required because no student PII is transmitted to ThinkKits
- ThinkKits does not market to or collect data from NY students
- ISSRA (Illinois School Student Records Act) protects confidentiality of student school records; governs third-party access to records
- BIPA (Biometric Information Privacy Act) requires written consent before collecting biometric identifiers (fingerprints, iris scans, facial geometry)
- SOPPA (SB 1870, 2021) regulates operators of websites/apps used by students, prohibiting sale of student data and targeted advertising
- ISSRA covers records maintained by schools; ThinkKits uses only NCES aggregate public data, not school-maintained records
- ThinkKits collects zero biometric data; BIPA does not apply
- SOPPA applies to operators of online services used by K–12 students; ThinkKits is a vendor intelligence platform, not a student-facing service
- No student login, no student interaction, no student data flow into ThinkKits
- Requires a student data transparency plan posted publicly by each school district
- Operators collecting student PII under a contract with a school must sign a data use agreement
- "Student personally identifiable information" means information that identifies an individual student
- Prohibits operators from selling student data or using it for behavioral advertising
- ThinkKits has no contract with any Colorado school district to collect student PII — the triggering condition for operator obligations
- Colorado school data on ThinkKits comes from NCES CCD public releases and USASpending.gov — both federally published open data
- Aggregate school-level data does not constitute "student personally identifiable information" under CRS § 22-16-103
- No data use agreement needed; no student data sold or used for advertising
- TEC § 32.151 defines "operator" as a company operating a website, online service, or mobile app directed at K–12 students with actual knowledge it is used for K–12 purposes
- Operators must not sell student data or use it for targeted advertising
- SB 820 (2017) extended requirements and added cybersecurity planning for districts
- HB 3 created the Student Data Privacy Consortium framework for Texas
- ThinkKits is a vendor intelligence platform marketed to education vendors and district administrators — not to or directed at K–12 students; "operator" definition does not apply
- Texas school data on ThinkKits comes from NCES CCD and TEA public data releases, both openly published
- No student PII is ever received from any Texas district or school
- ThinkKits voluntarily participates in Student Data Privacy Consortium (SDPC) framework alignment
- F.S. § 1002.222 requires vendors receiving student data from school districts to comply with data security requirements and prohibits unauthorized disclosure
- Applies when a vendor receives student education records from a Florida district under a contract
- Districts must maintain a comprehensive inventory of approved vendors
- Parents have rights to review records and request corrections under F.S. § 1002.22
- ThinkKits has no contract with any Florida district to receive student education records; the triggering condition for § 1002.222 does not apply
- Florida school data comes from NCES CCD and FLDOE public datasets — not from districts sharing records
- No student-level records, enrollment files, or assessment scores are received; only publicly published aggregate statistics
- ThinkKits does not appear on any district's vendor inventory because no district data relationship exists
- Act 55 (2023) establishes "covered operators" as companies operating websites or apps knowingly used by K–12 students for educational purposes
- Covered operators must execute a data privacy agreement with districts before receiving student PII
- Prohibits selling student data, targeted advertising, and building behavioral profiles for non-educational purposes
- PDE must maintain a public list of approved operators and their data practices
- ThinkKits does not operate a service knowingly used by K–12 students; it serves vendors and district administrators, not students
- PA school data on ThinkKits is sourced from NCES CCD and USASpending.gov public releases, not from district-shared student records
- No data privacy agreement with PA districts is needed or sought because no student PII is handled
- Aggregate school statistics (enrollment, Title I status) from NCES are explicitly publicly available data, not student PII
- ORC § 3301.0723 requires ODE to develop a student privacy policy and restricts disclosure of personally identifiable student data
- Third parties who receive student data from districts under a data use agreement must comply with ODE's student data privacy requirements
- Districts are responsible for executing DUAs before sharing student-level data
- Aggregate, de-identified data shared publicly is not subject to the same restrictions
- ThinkKits has no data use agreement with any Ohio district because no student-level data is received
- Ohio school data on ThinkKits comes from NCES CCD and ODE's publicly released school report cards — not from district data sharing
- ODE's own published data (Report Card data, EMIS public extracts) is explicitly intended for public use; no PII is included
- No Ohio student enrollment records, assessment data, or disciplinary records enter ThinkKits systems
- O.C.G.A. § 20-2-666 defines "operator" as any person operating a website or online service that is designed and marketed for use by students in K–12 schools
- HB 49 (2023) strengthened requirements: operators must execute a written data governance agreement with a district before collecting student PII
- Operators may not sell student PII, use it for targeted advertising, or disclose it to third parties without consent
- GaDOE maintains a list of approved vendors on a publicly accessible portal
- ThinkKits is not designed or marketed for use by students; it serves education vendors and district administrators — placing it outside the "operator" definition
- Georgia school data on ThinkKits is sourced from NCES CCD and GaDOE public data releases (Governor's Office of Student Achievement report cards)
- No data governance agreement with Georgia districts is needed or in place because no student PII is received
- ThinkKits does not appear in GaDOE's vendor portal because it has no data-sharing relationship with Georgia districts
- VCDPA (Virginia Consumer Data Protection Act) grants consumers rights over personal data; applies to controllers processing personal data of 100,000+ Virginia residents annually
- Va. Code § 22.1-289.03 restricts disclosure of student PII and requires written agreements when districts share student data with operators
- VCDPA defines "personal data" as information linked or reasonably linkable to an identified or identifiable natural person; aggregate or de-identified data is explicitly excluded
- HB 2307 required VDOE to develop student data privacy standards and vendor approval framework
- VCDPA's definition of personal data explicitly excludes aggregate or de-identified data (Va. Code § 59.1-572); ThinkKits uses only aggregate school-level statistics
- ThinkKits does not process personal data of individual Virginia consumers in a manner triggering VCDPA; school aggregate data is not personal data under VCDPA
- Virginia school data on ThinkKits comes from NCES CCD and VDOE public data releases (School Quality Profiles), not district-shared student records
- No written agreement with Virginia districts is in place or required because no student PII flows to ThinkKits
ThinkKits Data Sources — All Public
The following federal and state sources provide all school and district data in ThinkKits. Each source is an official government open data program with no student-level PII.
| Source | Publisher | Data Type | Privacy Implication |
|---|---|---|---|
| NCES Common Core of Data (CCD) | National Center for Education Statistics (Federal) | School & district directory, enrollment aggregates, Title I status, NCES IDs | No PII. Publicly published annually. Required by law to be public. |
| USASpending.gov | U.S. Treasury / OMB (Federal) | Federal grant awards by recipient (school/district) | No PII. Federal open data. Public disclosure required for federal awards. |
| USAC E-Rate Program Data | Universal Service Administrative Co. (Federal) | E-Rate commitments by school/district | No PII. Public funding data published by USAC per FCC rules. |
| State Education Agency Open Data | State DOEs (CA, TX, FL, NY, IL, CO, PA, OH, GA, VA) | School report cards, accountability ratings, aggregate proficiency | No PII. Publicly published by each state DOE under state open records laws. |
| Census Bureau SAIPE / ACS | U.S. Census Bureau (Federal) | District-level poverty estimates, demographic aggregates | No PII. Statistically modeled aggregate estimates; no individual records. |
Frequently Asked Questions
Disclaimer
This matrix is provided for informational purposes only and does not constitute legal advice. Student privacy law is complex and evolves rapidly. Districts and vendors should consult qualified legal counsel for compliance determinations specific to their circumstances. ThinkKits makes reasonable efforts to keep this matrix current but cannot guarantee completeness as laws are amended.
ThinkKits — K-5 Education Market Intelligence · Last updated March 2026
privacy@thinkkits.com · Privacy Policy · FERPA Compliance · SDPC Compliance
← Back to Help Center