← Help Center

State Student Privacy Law Compliance Matrix

How ThinkKits addresses state-level student data privacy requirements across the top 10 states by enrollment and regulatory activity.

Last updated: March 2026 10 states covered Public aggregate data only

Public Aggregate Data Exemption — Applies to All States

ThinkKits collects only school-level and district-level aggregate data from federal open data sources (NCES Common Core of Data, USASpending.gov, USAC E-Rate, state education agency public releases). This data is already published by federal and state governments. ThinkKits does not collect, process, or store any individually identifiable student information. Because no student-level personal information is involved, ThinkKits operates outside the scope of student privacy laws in virtually all states, which explicitly exempt publicly available aggregate data. The matrix below documents each state's specific exemption language and our compliance posture.

Quick Reference Summary

State Primary Law(s) Scope Trigger ThinkKits Data Type Exemption Basis Compliance Status
California SOPIPA, CPRA / CCPA Covered operator collecting student PII Public aggregate (NCES, USASpending) No student PII; aggregate data exemption Exempt / Compliant
New York Education Law § 2-d Third-party contractors handling student PII Public aggregate (NCES CCD) Not a contractor; no student PII handled Exempt / Compliant
Illinois ISSRA, BIPA Student data; biometric identifiers Public aggregate; no biometrics No student records; no biometric data collected Exempt / Compliant
Colorado Student Data Transparency & Security Act Operators with contracts to collect student PII Public aggregate (NCES, USASpending) No contract for student PII; aggregate only Exempt / Compliant
Texas TEC §§ 32.151–32.158 Digital learning products collecting student data Public school-level aggregate Not a digital learning product; no student data Exempt / Compliant
Florida FERPA (state adoption) + F.S. 1002.222 Student education records Public aggregate (NCES, DOE) Aggregate public data not an education record Exempt / Compliant
Pennsylvania Student Data Privacy Act (Act 55) Covered operators collecting student PII Public aggregate (NCES CCD, USASpending) No student PII; publicly available data exemption Exempt / Compliant
Ohio ORC § 3301.0723; Student Privacy Guidelines Third parties receiving student-level data from districts Public aggregate (NCES, ODE public files) No district data-sharing agreement; public data only Exempt / Compliant
Georgia O.C.G.A. § 20-2-666; Student Data Privacy Act Operators collecting student PII under school contract Public aggregate (NCES, GaDOE public releases) No school contract for PII; public data only Exempt / Compliant
Virginia VCDPA, § 22.1-289.03 Controllers processing personal data; student data operators Public aggregate (NCES, VDOE public releases) Aggregate data not personal data under VCDPA Exempt / Compliant

State-by-State Detail

CA
California
SOPIPA (SB 1177, 2014) · CPRA / CCPA (2020/2023) · AB 1584 (2014)
Exempt & Compliant
Key Requirements
  • SOPIPA prohibits operators of K–12 websites/apps from using student data for targeted advertising or selling student information
  • CPRA grants California consumers rights over personal information (access, deletion, opt-out of sale)
  • AB 1584 requires districts to include data privacy terms in contracts with third-party operators
  • "Covered operator" means an operator who knowingly markets to K–12 schools or students
How ThinkKits Complies
  • ThinkKits is a vendor intelligence tool, not a student-facing application; SOPIPA's "covered operator" definition does not apply
  • No student PII is collected, stored, or processed — ThinkKits uses only NCES CCD and USASpending.gov aggregate data
  • CPRA applies only to personal information of identifiable individuals; school-level aggregate data is not personal information
  • No AB 1584 contract required because no student data passes to ThinkKits
NY
New York
Education Law § 2-d (2020 regulations) · NYSED Student Data Privacy
Exempt & Compliant
Key Requirements
  • Ed Law § 2-d restricts disclosure of student personally identifiable information (PII)
  • Third-party contractors who receive student PII must sign a Data Privacy and Security Agreement (DPSA)
  • Contractors must appoint a Chief Privacy Officer and post a Parents’ Bill of Rights
  • Applies to data shared by educational agencies with contractors under a contract or agreement
How ThinkKits Complies
  • ThinkKits has no contract with NY educational agencies to receive student PII; law applies only to contractors receiving PII under such agreements
  • All NY school data on ThinkKits is sourced from NCES CCD — a federal public dataset published by NYSED and NCES jointly
  • No DPSA required because no student PII is transmitted to ThinkKits
  • ThinkKits does not market to or collect data from NY students
IL
Illinois
ISSRA (105 ILCS 85) · BIPA (740 ILCS 14) · Student Online Personal Protection Act (SOPPA)
Exempt & Compliant
Key Requirements
  • ISSRA (Illinois School Student Records Act) protects confidentiality of student school records; governs third-party access to records
  • BIPA (Biometric Information Privacy Act) requires written consent before collecting biometric identifiers (fingerprints, iris scans, facial geometry)
  • SOPPA (SB 1870, 2021) regulates operators of websites/apps used by students, prohibiting sale of student data and targeted advertising
How ThinkKits Complies
  • ISSRA covers records maintained by schools; ThinkKits uses only NCES aggregate public data, not school-maintained records
  • ThinkKits collects zero biometric data; BIPA does not apply
  • SOPPA applies to operators of online services used by K–12 students; ThinkKits is a vendor intelligence platform, not a student-facing service
  • No student login, no student interaction, no student data flow into ThinkKits
CO
Colorado
Student Data Transparency and Security Act (HB 16-1423) · CRS § 22-16-101 et seq.
Exempt & Compliant
Key Requirements
  • Requires a student data transparency plan posted publicly by each school district
  • Operators collecting student PII under a contract with a school must sign a data use agreement
  • "Student personally identifiable information" means information that identifies an individual student
  • Prohibits operators from selling student data or using it for behavioral advertising
How ThinkKits Complies
  • ThinkKits has no contract with any Colorado school district to collect student PII — the triggering condition for operator obligations
  • Colorado school data on ThinkKits comes from NCES CCD public releases and USASpending.gov — both federally published open data
  • Aggregate school-level data does not constitute "student personally identifiable information" under CRS § 22-16-103
  • No data use agreement needed; no student data sold or used for advertising
TX
Texas
TEC §§ 32.151–32.158 (Student Privacy, 2015) · SB 820 (2017) · HB 3 (2019)
Exempt & Compliant
Key Requirements
  • TEC § 32.151 defines "operator" as a company operating a website, online service, or mobile app directed at K–12 students with actual knowledge it is used for K–12 purposes
  • Operators must not sell student data or use it for targeted advertising
  • SB 820 (2017) extended requirements and added cybersecurity planning for districts
  • HB 3 created the Student Data Privacy Consortium framework for Texas
How ThinkKits Complies
  • ThinkKits is a vendor intelligence platform marketed to education vendors and district administrators — not to or directed at K–12 students; "operator" definition does not apply
  • Texas school data on ThinkKits comes from NCES CCD and TEA public data releases, both openly published
  • No student PII is ever received from any Texas district or school
  • ThinkKits voluntarily participates in Student Data Privacy Consortium (SDPC) framework alignment
FL
Florida
F.S. § 1002.222 (Student Data Privacy, 2014) · F.S. § 1002.22 (Rights of Parents) · FERPA incorporation
Exempt & Compliant
Key Requirements
  • F.S. § 1002.222 requires vendors receiving student data from school districts to comply with data security requirements and prohibits unauthorized disclosure
  • Applies when a vendor receives student education records from a Florida district under a contract
  • Districts must maintain a comprehensive inventory of approved vendors
  • Parents have rights to review records and request corrections under F.S. § 1002.22
How ThinkKits Complies
  • ThinkKits has no contract with any Florida district to receive student education records; the triggering condition for § 1002.222 does not apply
  • Florida school data comes from NCES CCD and FLDOE public datasets — not from districts sharing records
  • No student-level records, enrollment files, or assessment scores are received; only publicly published aggregate statistics
  • ThinkKits does not appear on any district's vendor inventory because no district data relationship exists
PA
Pennsylvania
Student Data Privacy Act (Act 55 of 2023) · PA School Code § 1409
Exempt & Compliant
Key Requirements
  • Act 55 (2023) establishes "covered operators" as companies operating websites or apps knowingly used by K–12 students for educational purposes
  • Covered operators must execute a data privacy agreement with districts before receiving student PII
  • Prohibits selling student data, targeted advertising, and building behavioral profiles for non-educational purposes
  • PDE must maintain a public list of approved operators and their data practices
How ThinkKits Complies
  • ThinkKits does not operate a service knowingly used by K–12 students; it serves vendors and district administrators, not students
  • PA school data on ThinkKits is sourced from NCES CCD and USASpending.gov public releases, not from district-shared student records
  • No data privacy agreement with PA districts is needed or sought because no student PII is handled
  • Aggregate school statistics (enrollment, Title I status) from NCES are explicitly publicly available data, not student PII
OH
Ohio
ORC § 3301.0723 (Student Data, 2015) · ODE Student Privacy Guidelines · FERPA incorporation
Exempt & Compliant
Key Requirements
  • ORC § 3301.0723 requires ODE to develop a student privacy policy and restricts disclosure of personally identifiable student data
  • Third parties who receive student data from districts under a data use agreement must comply with ODE's student data privacy requirements
  • Districts are responsible for executing DUAs before sharing student-level data
  • Aggregate, de-identified data shared publicly is not subject to the same restrictions
How ThinkKits Complies
  • ThinkKits has no data use agreement with any Ohio district because no student-level data is received
  • Ohio school data on ThinkKits comes from NCES CCD and ODE's publicly released school report cards — not from district data sharing
  • ODE's own published data (Report Card data, EMIS public extracts) is explicitly intended for public use; no PII is included
  • No Ohio student enrollment records, assessment data, or disciplinary records enter ThinkKits systems
GA
Georgia
O.C.G.A. § 20-2-666 (Student Data Privacy, 2014) · HB 49 Student Data Privacy Act (2023)
Exempt & Compliant
Key Requirements
  • O.C.G.A. § 20-2-666 defines "operator" as any person operating a website or online service that is designed and marketed for use by students in K–12 schools
  • HB 49 (2023) strengthened requirements: operators must execute a written data governance agreement with a district before collecting student PII
  • Operators may not sell student PII, use it for targeted advertising, or disclose it to third parties without consent
  • GaDOE maintains a list of approved vendors on a publicly accessible portal
How ThinkKits Complies
  • ThinkKits is not designed or marketed for use by students; it serves education vendors and district administrators — placing it outside the "operator" definition
  • Georgia school data on ThinkKits is sourced from NCES CCD and GaDOE public data releases (Governor's Office of Student Achievement report cards)
  • No data governance agreement with Georgia districts is needed or in place because no student PII is received
  • ThinkKits does not appear in GaDOE's vendor portal because it has no data-sharing relationship with Georgia districts
VA
Virginia
VCDPA (Va. Code § 59.1-571 et seq., 2023) · Va. Code § 22.1-289.03 (Student Privacy, 2015) · HB 2307 (2022)
Exempt & Compliant
Key Requirements
  • VCDPA (Virginia Consumer Data Protection Act) grants consumers rights over personal data; applies to controllers processing personal data of 100,000+ Virginia residents annually
  • Va. Code § 22.1-289.03 restricts disclosure of student PII and requires written agreements when districts share student data with operators
  • VCDPA defines "personal data" as information linked or reasonably linkable to an identified or identifiable natural person; aggregate or de-identified data is explicitly excluded
  • HB 2307 required VDOE to develop student data privacy standards and vendor approval framework
How ThinkKits Complies
  • VCDPA's definition of personal data explicitly excludes aggregate or de-identified data (Va. Code § 59.1-572); ThinkKits uses only aggregate school-level statistics
  • ThinkKits does not process personal data of individual Virginia consumers in a manner triggering VCDPA; school aggregate data is not personal data under VCDPA
  • Virginia school data on ThinkKits comes from NCES CCD and VDOE public data releases (School Quality Profiles), not district-shared student records
  • No written agreement with Virginia districts is in place or required because no student PII flows to ThinkKits

ThinkKits Data Sources — All Public

The following federal and state sources provide all school and district data in ThinkKits. Each source is an official government open data program with no student-level PII.

Source Publisher Data Type Privacy Implication
NCES Common Core of Data (CCD) National Center for Education Statistics (Federal) School & district directory, enrollment aggregates, Title I status, NCES IDs No PII. Publicly published annually. Required by law to be public.
USASpending.gov U.S. Treasury / OMB (Federal) Federal grant awards by recipient (school/district) No PII. Federal open data. Public disclosure required for federal awards.
USAC E-Rate Program Data Universal Service Administrative Co. (Federal) E-Rate commitments by school/district No PII. Public funding data published by USAC per FCC rules.
State Education Agency Open Data State DOEs (CA, TX, FL, NY, IL, CO, PA, OH, GA, VA) School report cards, accountability ratings, aggregate proficiency No PII. Publicly published by each state DOE under state open records laws.
Census Bureau SAIPE / ACS U.S. Census Bureau (Federal) District-level poverty estimates, demographic aggregates No PII. Statistically modeled aggregate estimates; no individual records.

Frequently Asked Questions

Does ThinkKits require a Data Processing Agreement (DPA) or Student Data Privacy Agreement?
No. DPAs and student data privacy agreements are triggered when a vendor receives student PII from a district. Because ThinkKits never receives student PII from any district — all data comes from public federal datasets — no DPA is required. Districts do not need to add ThinkKits to their vendor inventory or approved vendor list.
Does ThinkKits store student records?
No. ThinkKits does not have access to, and does not store, any student education records as defined under FERPA, SOPIPA, or any state student privacy law. The only school-related data in our system is aggregate, publicly available statistics at the school and district level.
Which states have the strictest student privacy laws?
California (SOPIPA + CPRA), New York (Ed Law § 2-d), and Illinois (ISSRA + BIPA) are generally considered the most comprehensive. Colorado and Pennsylvania have also passed strong recent legislation. In all cases, the laws apply to operators handling student PII — a category ThinkKits does not fall into.
Can a school district use ThinkKits to access its own student data?
No. ThinkKits does not provide student-level data to anyone. Districts using ThinkKits are viewing publicly available aggregate data about schools and districts — the same data published by NCES and state DOEs — organized for market intelligence and funding research purposes.
How do I request ThinkKits's privacy documentation for a procurement review?
Contact us at privacy@thinkkits.com. We can provide our data inventory, data flow diagrams, and this compliance matrix in formatted document form for inclusion in your district's vendor review package.

Disclaimer

This matrix is provided for informational purposes only and does not constitute legal advice. Student privacy law is complex and evolves rapidly. Districts and vendors should consult qualified legal counsel for compliance determinations specific to their circumstances. ThinkKits makes reasonable efforts to keep this matrix current but cannot guarantee completeness as laws are amended.

ThinkKits — K-5 Education Market Intelligence · Last updated March 2026

privacy@thinkkits.com · Privacy Policy · FERPA Compliance · SDPC Compliance

← Back to Help Center

Was this article helpful?

← Back to Help Center