3-UT NDPA v2-2 VENDOR-SPECIFIC.pdf
PDF 3 MB Posted
- Attached to
- PCSD Grades 6 - 8 Math Instructional Materials State and local contract opportunity
- Solicitation number
- 102120262
- Issued by
- Utah
About this file
This is a National Data Privacy Agreement (NDPA) Version 2.2 template developed by the Student Data Privacy Consortium (SDPC) for use between Park City School District (LEA) located at 2700 Kearns Boulevard, Park City, Utah 84060, and a vendor provider of educational or digital services. The agreement establishes the framework for protecting student data and compliance with federal privacy laws including FERPA, PPRA, and COPPA. The DPA is a vendor-specific modified template with exhibits that detail the products and services covered, schedule of student data to be processed, definitions, disposition instructions, general offer of privacy terms, cybersecurity frameworks, Utah supplemental state terms, and any agreed-to modifications. The designated LEA representative is Andrew Frink, Executive Director of Data and Technology, with contact information provided for both parties. The agreement remains in effect as long as the provider retains student data and can be terminated by either party if the other breaches its terms, or by the LEA if it reasonably believes a successor in a change of control cannot uphold the agreement's conditions.
The DPA does not specify pricing terms or cost structures, as it is a privacy and data protection agreement separate from commercial terms. The agreement requires providers to maintain administrative, physical, and technical safeguards for student data and comply with one or more nationally or internationally recognized cybersecurity frameworks listed in Exhibit F, including NIST standards, ISO 27000 series, CIS Critical Security Controls, or CMMC certification. Providers must notify the LEA of any confirmed data breaches within seventy-two hours and maintain a written data breach response plan. The agreement prohibits targeted advertising, sale of student data, and re-identification of de-identified data without LEA direction. Under Utah Code 53E-9-309, the LEA retains audit rights to verify provider compliance, and the LEA has a statutory duty to terminate the agreement upon discovering an unremedied privacy violation. Subprocessor agreements must include equivalent data protection terms, and providers must disclose all subprocessors who may access student data.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| 4-RFP 102120262 - PCSD EHMS Math Curriculum.pdf | ||
| 2-Offeror Information Form.pdf | ||
| 1-PCSD TCAgencyGoodsServices-05 29 20 JD.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
National Data Privacy Agreement (NDPA), Version 2.2 Page | 1
VENDOR-SPECIFIC (‘MODIFIED’)
STUDENT DATA PRIVACY AGREEMENT
(UTAH National Data Privacy Agreement (NDPA) Modified VERSION 2.2)
And
Version 2.2
Authored by Members of the Student Data Privacy Consortium (SDPC) &
Mark Williams, Fagen, Friedman & Fulfrost LLP
© Access 4 Learning (A4L) Community. All Rights Reserved.
This document may only be used by A4L Community members and may not be altered in any substantive manner.
MODIFIED STUDENT DATA PRIVACY AGREEMENT Version 2.2
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 2
This Student Data Privacy Agreement (“DPA”) is entered into on the date of full execution (the “Effective Date”) and is entered into by and between:
PREAMBLE
WHEREAS, the Provider is providing educational or digital Services, as defined in Exhibit “A” (the “Services”), to LEA, which Services may include: (a) cloud-based Services for the digital storage, management, and retrieval of Student Data; and/or (b) digital educational software that authorizes Provider to access, store, and use Student
Data; and
WHEREAS, the Provider and LEA have entered into a Service Agreement (as defined herein), to provide certain
Services to the LEA as set forth in the Service Agreement, and this DPA (collectively the “Agreement”), WHEREAS, the Provider and LEA recognize the need to protect Student Data and other regulated data exchanged between them as required by applicable laws and regulations, such as the Family Educational Rights and Privacy Act (“FERPA”) at 20 U.S.C. 1232g (34 C.F.R. Part 99); the Protection of Pupil Rights Amendment
(“PPRA”) at 20 U.S.C. 1232h; and the Children’s Online Privacy Protection Act (“COPPA”) at 15 U.S.C. 6501-
6506 (16 C.F.R. Part 312), WHEREAS, the Provider and LEA desire to enter into this DPA for the purpose of establishing their respective obligations and duties in order to comply with applicable laws and regulations.
NOW THEREFORE, for good and valuable consideration, LEA and Provider agree as follows:
LEA and Provide agree to the additional terms or modification details in Exhibit “H”.
Special Provisions. (Check if Required)
If checked, the Supplemental State Terms attached hereto as Exhibit “G” are hereby incorporated by reference into this DPA in their entirety.
General Offer of Privacy Terms.
If checked, the Provider has signed Exhibit “E” to the Standard Clauses, otherwise known as “General
Offer of Privacy Terms” enabling other LEAs to enter into the same terms of this DPA with Provider.
(the “LEA”) and located at (the “Provider”).
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 3
The designated representative for the LEA for this DPA is:
Name: Title:
Address:
Phone: Email:
The designated representative for the Provider for this DPA is:
Name: Title:
Address:
Phone: Email:
IN WITNESS WHEREOF, LEA and Provider execute this DPA as of the Effective Date.
LEA:
Signed By: Date:
Printed Name: Title/Position:
Date:
PROVIDER:
Signed By:
Printed Name: Title/Position:
Each Party is responsible to promptly notify the other Party of changes to the notice information.
Notices to Provider
With a copy to (if provided):
Notices to LEA
With a copy to (if provided):
Security Notices to Provider (Required per Section 5.3) Security Notices to LEA (Required per Section 5.3)
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 4
STANDARD CLAUSES
ARTICLE I: PURPOSE AND SCOPE
1.1 Purpose of DPA.
The purpose of this DPA is to describe the duties and responsibilities to protect Student Data including compliance with all applicable federal and state privacy laws, rules, and regulations, all as may be amended from time to time. In performing the Services, the Provider shall be considered a School Official with a legitimate educational interest, and performing Services otherwise provided by the LEA. With respect to its use and maintenance of Student Data, Provider shall be under the direct control and supervision of the LEA as set forth in this DPA and the Service Agreement.
1.2 Description of Products and Services.
A description of all products and services covered by the Agreement, and information specific to this DPA, are listed in Exhibit "A". If a Provider needs to update any information on Exhibit “A” (such as updating with new provided services), they may do so by completing the Addendum template provided by the A4L Community and sending a copy to the LEA.
Provider may add or delete products or services subject to this DPA under the following circumstances:
1. Deleted products or services: The products or services have been discontinued and are no longer available from the Provider.
2. Added products or services: The added products or services are either:
a. a direct replacement, or substantially equivalent to the original products or services listed in the DPA, or
b. the added products or services result in new or enhanced capabilities, new modules, technology advancements, and/or service categories relating to the listed products or services that Provider did not have at the time the DPA was signed.
If an added product or service requires additional Data Elements, Provider must complete the relevant portion of the Addendum template to update Exhibit “B”.
Provider may not make any change to Exhibit “A” via an Addendum, except adding or deleting products or services. LEA is under no obligation to acquire added products or services and has no ability under the DPA to prevent deletion of products or services. The Provider must notify the LEA, in accordance with the notification provisions of this DPA, of the existence and contents of an Addendum modifying Exhibit “A”. The LEA will have thirty (30) days from receipt to object in writing to the Addendum. If no written objection is received it will become incorporated into the DPA between the parties.
1.3 Student Data to Be Provided.
In order to perform the services, the Provider shall process Student Data as identified by the Provider in the
Schedule of Data, attached hereto as Exhibit “B”. Student Data may be provided by the LEA or created by students, as set forth fully in the definition of Student Data in Exhibit “C”. If a Provider needs to update any information on Exhibit “B”, they may do so by completing the Addendum template provided by the A4L
Community and sending a copy to the LEA.
Provider may delete data elements from Exhibit “B” if they are no longer used by the Provider.
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 5
Provider must add data elements to Exhibit “B”, when a material change has occurred, regardless of whether the added data elements are either one of the following:
1. used to better deliver the original products or services listed in the DPA, or
2. used to deliver added products or services that result in new or enhanced capabilities, new modules, technology advancements, and/or service categories relating to the listed products or services that Provider did not have at the time the DPA was signed. Such new products or services must be designated in the Addendum template as changes to Exhibit “A”.
The Provider must notify the LEA, in accordance with the notification provisions of this DPA, of the existence and contents of an Addendum modifying Exhibit “B”. The LEA will have thirty (30) days from receipt to object to the Addendum. If no written objection is received it will become incorporated into the DPA between the parties.
1.4 DPA Definitions.
Capitalized terms used in this DPA shall have the meanings set forth in Exhibit “C”. With respect to the treatment of Student Data, in the event of a conflict, definitions used in this DPA shall prevail over terms used in any other writing, including, but not limited to, the Service Agreement.
ARTICLE II: DATA OWNERSHIP AND AUTHORIZED ACCESS
2.1 Student Data Property of LEA.
As between LEA and Provider, all Student Data processed by the Provider, or created by students (as set forth fully in the definition of Student Data in Exhibit “C”), pursuant to the Agreement is and will continue to be the property of and under the control of the LEA. The Provider further acknowledges and agrees that all copies of such Student Data processed by the Provider, including any modifications or additions or any portion thereof from any source, are also subject to the provisions of this DPA in the same manner as the original Student Data.
The Parties agree that as between them, all rights, including all intellectual property rights in and to Student Data contemplated per the Service Agreement, shall remain the exclusive property of the LEA.
2.2 Parent, Legal Guardian, and Student Access.
The LEA shall establish reasonable procedures by which a parent, legal guardian, or eligible student (as defined in FERPA) may review Student Data and request deletion or modification, and request delivery of a copy of the
Student Data. In support of this, the Provider shall establish reasonable procedures by which the LEA may access, and correct, if necessary, Education Records and/or Student Data, and make a copy of the data available to the LEA or (at the LEA’s direction) to the parent, legal guardian, or eligible student directly. If the LEA is not able to review or update the Student Data itself, Provider shall respond in a reasonably timely manner (and no later than thirty (30) days from the date of the request or pursuant to the time frame required under state law for an LEA to respond to a parent, legal guardian, or student, whichever is sooner) to the LEA’s request for Student
Data held by the Provider to view or correct as necessary.
In the event that a parent or legal guardian of a student or eligible student contacts the Provider to correct, delete, review, or request delivery of a copy of any of the Student Data collected by or generated through the Services, the Provider shall refer that person to the LEA, who will follow the necessary and proper procedures regarding
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 6 the requested information. In the event that any person other than those listed contacts the Provider about any
Student Data, the Provider shall refer that person to the LEA, except as provided in Section 4.4.
2.2.1 This DPA does not impede the ability of students to download, export, or otherwise save or maintain their own Student Generated Content directly from Provider or for Provider to provide a mechanism for such download, export, transfer, or saving to students, or the student’s parent or legal guardians. Nor does it impede the ability of Providers to offer LEAs features to allow such ability.
2.2.2 In the event that Student Generated Content is transferred to the control of the student, parent, or legal guardian, the copy of such Student Generated Content that is in the control of such person is no longer considered Student Data.
2.3 Subprocessors.
Provider shall enter into a Subprocessor Agreement with all Subprocessors performing functions for the Provider in order for the Provider to provide the Services pursuant to the Service Agreement, whereby the Subprocessors agree to protect Student Data in a manner no less stringent than the terms of this DPA. Every Subprocessor
Agreement must provide that the Subprocessor will not sell the Student Data. The terms of a Subprocessor
Agreement shall not be materially modified by the Subprocessor unless notice is provided to the Provider.
ARTICLE III: DUTIES OF LEA
3.1 Provide Data in Compliance with Applicable Laws.
LEA shall use the Services and provide Student Data in compliance with all applicable federal and state privacy laws, rules, and regulations, all as may be amended from time to time.
3.2 Annual Notification of Rights.
If the LEA has a policy of disclosing Education Records and/or Student Data under FERPA (34 CFR §
99.31(a)(1)), LEA shall include a specification of criteria for determining who constitutes a School Official and what constitutes a legitimate educational interest in its annual notification of rights.
3.3 Reasonable Precautions.
LEA shall employ administrative, physical, and technical safeguards designed to protect usernames, passwords, and any other means of gaining access to the Services and/or hosted Student Data from unauthorized access, disclosure, or acquisition by an unauthorized person.
3.4 Unauthorized Access Notification and Assistance.
LEA shall notify Provider within seventy-two (72) hours of any confirmed Data Breach to the Services, LEA’s account, or any Student Data that poses a privacy or security risk. If requested by Provider, LEA will provide reasonable assistance to Provider in any efforts by Provider to investigate and respond to such Data Breach.
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 7
ARTICLE IV: DUTIES OF PROVIDER
4.1 Privacy and Security Compliance.
The Provider shall comply with all laws and regulations applicable to Provider’s protection of Student Data privacy and security, and at the direction of the LEA shall cooperate with any state or federal government-initiated audit of the LEA’s use of the Services.
4.2 Authorized Use.
The Student Data processed pursuant to the Services shall be used by the Provider for no purpose other than performing the Services outlined in Exhibit “A”, or as instructed by the LEA.
4.3 Provider Employee Obligation.
Provider shall require all of Provider’s employees who have access to Student Data to comply with all applicable provisions of this DPA with respect to the Student Data shared under the Service Agreement. Provider agrees to require and maintain an appropriate confidentiality agreement from each employee with access to Student
Data pursuant to the Service Agreement.
4.4 No Disclosure.
Provider acknowledges and agrees that it shall not sell or disclose any Student Data or any portion thereof, including without limitation, user content or other non-public information and/or Personally Identifiable
Information contained in the Student Data.
4.4.1 Exceptions to No Disclosure.
4.4.1.1 This prohibition against disclosure will not apply to Student Data where disclosure is directed or permitted by the LEA or this DPA.
4.4.1.2 The provision to not sell Student Data shall not apply to a Change of Control.
4.4.1.3 This prohibition against disclosure shall not apply to Student Data disclosed pursuant to a judicial order or lawfully issued subpoena or warrant.
4.4.1.4 This prohibition against disclosure shall not apply to Student Data disclosed to
Subprocessors performing Services on behalf of the Provider pursuant to this DPA.
4.4.1.5 Should law enforcement or other government entities (“Requesting Party(ies)”) provide a judicial order or lawfully issued subpoena or warrant to the Provider with a request for
Student Data held by the Provider pursuant to the Services, the Provider shall notify the
LEA in advance of a compelled disclosure to the Requesting Party.
4.4.1.6 Notification under 4.4.1.5 is not required if the judicial order or lawfully issued subpoena or warrant states not to inform the LEA of the request.
4.4.1.7 Should the LEA be presented with a judicial order or lawfully issued subpoena or to disclose Student Generated Content or other Student Data, the Provider shall cooperate with the LEA in delivering such data.
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 8
4.4.1.8 This prohibition against disclosure shall not apply to LEA-authorized users of the
Services, which may include parents and legal guardians.
4.4.1.9 This prohibition against disclosure shall not apply to protect the safety of users or others, if and only if, an LEA employee who has specifically been authorized to declare a health or safety emergency has done so and all requirements under 34 CFR §§
99.31(a)(10) and 99.36 have been fulfilled by the LEA.
4.4.1.10 This prohibition against disclosure shall not apply to protect the integrity or security of the Service, where such disclosure is made to a Subprocessor engaged by for the specific purpose of investigating a potential Data Breach as set forth in 5.4.
4.5 De-Identified Data
Provider agrees not to attempt to re-identify De-Identified Data without the written direction of the LEA. De-
Identified Student Data may be used by the Provider for those purposes allowed under applicable laws, for the purposes allowed for the processing of Student Data under this DPA, as well as the following purposes: (1) assisting the LEA or other governmental agencies in conducting research and other studies; (2) research, development, and improvement of the Provider's educational sites, Services, or applications, and to demonstrate the effectiveness of the Services; and (3) for adaptive learning purpose and for customized student learning.
Provider's use of De-Identified Data shall survive termination of this DPA or any request by LEA to return or dispose of Student Data. Except for Subprocessors, Provider agrees not to transfer De-Identified Data to any third party unless the transfer is expressly directed or permitted by the LEA or this DPA. Such Subprocessors must be subject to equivalent terms of the DPA including this one. Prior to publishing any document that names the LEA, the Provider shall obtain the LEA’s written approval of the manner in which De-Identified Data is presented. If Provider chooses to create De-Identified Data, its process must comply with either NIST de-identification standards or US Department of Education guidance on de-identification.
4.6 Disposition of Student Data.
Upon written request from the LEA, Provider shall dispose of or provide a mechanism for the LEA to transfer
Student Data obtained under the Service Agreement, within sixty (60) days of the date of said request and according to a schedule and procedure as the Parties may reasonably agree.
If the Provider has a standard retention and destruction schedule, that schedule shall apply to Student Data as long as this DPA is active. The Provider’s practice relating to retention and disposition of Student Data shall be provided to the LEA upon request.
At the termination of this DPA, the Provider shall, unless directed otherwise by the LEA, dispose of, or delete
Student Data obtained by the Provider under the Agreement within sixty (60) days of termination (unless otherwise required by law). If the Agreement has lapsed or is not terminated, the Student Data shall be deleted when directed or permitted by the LEA, according to Provider’s standard destruction schedule, or as otherwise required by law. The LEA may provide the Provider with special instructions for the disposition of the Student
Data, by transmitting to Provider Exhibit “D”, attached hereto. The duty of the Provider to dispose of or delete
Student Data shall not extend to De-Identified Data or to Student-Generated Content that has been transferred or kept pursuant to Section 2.2.2.
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 9
4.7 Advertising Limits.
Provider is prohibited from using, disclosing, or selling Student Data to (a) inform, influence, or enable Targeted
Advertising; (b) develop a profile of a student, family member/guardian, or group, for any purpose other than providing the Service to LEA; or (c) for any commercial purpose other than to provide the Service to the LEA, or as authorized by the LEA or the parent/guardian. Targeted Advertising is strictly prohibited. However, this section does not prohibit Provider from using Student Data (i) for adaptive learning or customized student learning
(including generating personalized learning recommendations); (ii) to make product recommendations to account holders that are not considered Targeted Advertising (this exception does not apply where the Provider is relying on the LEA to provide consent on behalf of the parent under COPPA); or (iii) to notify account holders about new education product updates, features, or Services that are not considered Targeted Advertising or from otherwise using Student Data as permitted in this DPA and its accompanying exhibits.
Before making product recommendations under section (ii) above, Provider must disclose the existence of those recommendations to LEA in writing, in sufficient detail that LEA can fulfill any obligations under applicable law
(e.g. PPRA).
ARTICLE V: DATA SECURITY AND BREACH PROVISIONS
5.1 Data Storage.
If Student Data is stored outside the United States, Provider will provide a list of countries where data is stored, in Exhibit “B”.
5.2 Security Audits.
Provider will conduct a security audit or assessment no less than once per year, and upon a Data Breach. Upon
10 days’ notice and execution of confidentiality agreement, Provider will provide the LEA with a copy of the audit report, subject to reasonable and appropriate redaction.
5.3 Data Security.
The Provider agrees to utilize administrative, physical, and technical safeguards designed to protect Student
Data from unauthorized access, disclosure, acquisition, destruction, use, or modification. The Provider shall adhere to any applicable law relating to data security of Student Data. The Provider shall implement an adequate
Cybersecurity Framework that incorporates one or more of the nationally or internationally recognized standards set forth in Exhibit “F”. Additionally, Provider may choose to further detail its security programs and measures in
Exhibit “F”. Provider shall provide, in the Preamble to the DPA, contact information of an employee who LEA may contact if there are any data security concerns or questions.
5.4 Data Breach.
In the event that Provider confirms a Data Breach, the Provider shall provide notification to LEA within seventy-two (72) hours of confirmation of the Data Breach, unless notification within these time limits would disrupt investigation of the Data Breach by law enforcement. In such an event, notification shall be made within a reasonable time after the Data Breach. Provider shall follow the following process:
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 10
(1) The Data Breach notification described above shall include, at a minimum, the following information to the extent known by the Provider and as it becomes available:
(a) The name and contact information of the Provider subject to this section,
(b) the date of the notice,
(c) the date of the Data Breach, the estimated date of the Data Breach, or the date range within which the Data Breach occurred,
(d) Whether the notification was delayed as a result of a law enforcement investigation, if legally permissible to share that information,
(e) A general description of the Data Breach, if that information is possible to determine at the time the notice is provided,
(f) A description of the Student Data reasonably believed to have been the subject of the Data Breach; and
(g) Identification of impacted individuals.
(2) Provider agrees to adhere to all applicable federal and state laws with respect to a Data Breach related to the Student Data, including any required responsibilities and procedures for notification and mitigation of any such Data Breach.
(3) Provider further acknowledges and agrees to have a written Data Breach response plan that is consistent with applicable industry standards and federal and state law for responding to a Data
Breach, involving Student Data and agrees to provide LEA, upon reasonable written request, with a summary of said written Data Breach response plan.
(4) LEA shall provide notice and facts surrounding the Data Breach to the affected students, parents, or guardians.
(5) In the event of a Data Breach originating from LEA’s use of the Service or otherwise a result of
LEA’s actions or inactions, Provider shall reasonably cooperate with LEA to the extent necessary to expeditiously secure Student Data and may request costs incurred as a result of such Data
Breach.
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 11
CONTRACT TERMS
Term and Termination. In the event that either Party seeks to terminate this DPA, they may do so by written notice if the Service Agreement has lapsed or has been terminated. Either party may terminate this DPA and any Service Agreement or contract if the other party breaches any terms of this DPA. This DPA shall stay in effect for as long as the Provider retains the Student Data, as set forth in section Article IV, Section 4.6. In the case of a Change of Control the LEA has the authority to terminate the DPA if it reasonably believes that the successor cannot uphold the terms and conditions herein or having a contract with the successor would violate the LEA’s policies or state or federal law.
Data Disposition on Service Agreement Termination. If the Service Agreement is terminated, the Provider shall dispose of all of LEA’s Student Data pursuant to Article IV, Section 4.6 of the Standard Clauses.
Notices. All notices or other communication required or permitted to be given hereunder must be made in writing and may be given via e-mail transmission, first-class mail, or a mutually agreed upon method sent to the designated representatives documented in the Preamble.
Priority of Agreements. This DPA shall govern the treatment of Student Data in order to comply with the privacy protections, including those found in FERPA and all applicable privacy statutes identified in this DPA. With respect to the treatment of Student Data only, in the event there is conflict between the terms of the DPA and the Service Agreement, Terms of Service, Privacy Policies, or with any other bid/RFP, license agreement, or writing, the terms of this DPA shall apply and take precedence. In the event of a conflict between Exhibit “H”, the
SDPC Standard Clauses, and/or the Supplemental State Terms in Exhibit “G”, Exhibit “H” will control, followed by Exhibit “G”. Except as described in this paragraph herein, all other provisions of the Service Agreement shall remain in effect.
Entire Agreement. This DPA and the Service Agreement (“the Agreement”) constitute the entire agreement of the Parties relating to the subject matter hereof and supersedes all prior communications, representations, or agreements, oral or written, by the Parties relating thereto. This DPA may be amended and the observance of any provision of this DPA may be waived (either generally or in any particular instance and either retroactively or prospectively) only with the signed written consent of both Parties.
Severability. Any provision of this DPA that is prohibited or unenforceable in any jurisdiction shall, as to such jurisdiction, be ineffective to the extent of such prohibition or unenforceability without invalidating the remaining provisions of this DPA, and any such prohibition or unenforceability in any jurisdiction shall not invalidate or render unenforceable such provision in any other jurisdiction. Notwithstanding the foregoing, if such provision could be more narrowly drawn so as not to be prohibited or unenforceable in such jurisdiction while, at the same time, maintaining the intent of the Parties, it shall, as to such jurisdiction, be so narrowly drawn without invalidating the remaining provisions of this DPA or affecting the validity or enforceability of such provision in any other jurisdiction.
Governing Law, Venue, and Jurisdiction. This DPA will be governed by and construed in accordance with the laws of the state of the LEA, without regard to conflicts of law principles. Each party consents and submits to the sole and exclusive jurisdiction to the state and federal courts for the county of the LEA for any dispute arising out of or relating to this DPA or the transactions contemplated hereby.
Successors Bound. This DPA is and shall be binding upon the respective successors in interest to Provider in the event of a Change of Control. In the event of a Change of Control, the Provider shall provide written notice to the LEA no later than sixty (60) days after the closing date of such Change of Control. Such notice shall include
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 12 a written, signed assurance that the successor will assume the obligations of the DPA and any obligations with respect to Student Data within the Service Agreement.
Authority. Each signatory confirms they are authorized to bind their institution to this DPA in its entirety.
Waiver. No delay or omission by either party to exercise any right here under shall be construed as a waiver of any such right and both parties reserve the right to exercise any such right from time to time, as often as may be deemed expedient.
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 13
EXHIBIT A: PRODUCTS AND SERVICES
's existing Services described below This DPA covers access to and use of that collect, process, or transmit Student Data, as identified below:
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 14
EXHIBIT B: SCHEDULE OF STUDENT DATA
All data elements identified in this Exhibit are correct at time of signature. Data elements collected by product - Indicate Required (R) or Optional (O).
Category of Data /
Data Elements
Application Technology Metadata
IP Addresses of users, use of cookies, etc.
Other application technology metadata
If ‘Other’ checked, please specify below checked box:
Application Use Statistics
Metadata on user interaction with application
Assessment
Standardized test scores
Observation data
Voice recordings
Other assessment data
If ‘Other’ checked, please specify below checked box:
Attendance
Student school (daily) attendance data
Student class attendance data
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 15
Category of Data /
Data Elements
Communication
Online communication captured (emails, blog entries)
Conduct
Conduct or behavioral data
Demographics
Date of birth
Place of birth
Gender
Ethnicity or race
Language information (native, or primary language spoken by student)
Other demographic information
If ‘Other’ checked, please specify below checked box:
Enrollment
Student school enrollment
Student grade level
Homeroom
Guidance counselor
Specific curriculum programs
Year of graduation
Other enrollment information
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 16
Category of Data /
Data Elements
If ‘Other’ checked, please specify below checked box:
Parent/Guardian Contact Information
Address
Phone
Parent/Guardian ID
Parent ID number (created to link parents to students)
Parent/Guardian Name
First and/or last
Schedule
Student scheduled courses
Teacher names
Special Indicator
English language learner information
Low-income status
Medical alerts/health data
Student disability information
Specialized education
Services (IEP or 504)
Living situations (homeless/foster care)
Other indicator information
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 17
Category of Data /
Data Elements
If ‘Other’ checked, please specify below checked box:
Student Contact Information
Address
Phone
Student Identifiers
Local (school district) ID number
State ID number
Provider/app assigned student ID number
Student app username
Student app passwords
Student Name
First and/or last
Student In App Performance
Program/application performance (e.g. typing program – student types 60 wpm, reading program – student reads below grade level)
Student Program Membership
Academic or extracurricular activities a student may belong to or participate in
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 18
Category of Data /
Data Elements
Student Survey Responses
Student responses to surveys or questionnaires
Student Work
Student Generated
Content; writing, pictures, etc.
Other student work data
If ‘Other’ checked, please specify below checked box:
Transcript
Student course grades
Student course data
Student course grades/performance scores
Other transcript data
If ‘Other’ checked, please specify below checked box:
Transportation
Student bus assignment
Student pick up and/or drop off location
Student bus card ID number
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 19
Category of Data /
Data Elements
Other transportation data
If ‘Other’ checked, please specify below checked box:
Other
Other data collected
If ‘Other’ checked, please list each additional data element used, stored, or collected by your application below checked box:
None
No Student Data collected at this time. Provider will immediately notify LEA if this designation is no longer applicable.
If Student Data is stored outside the United States, Provider shall list below the countries where data is stored:
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 20
EXHIBIT C: DEFINITIONS
Change of Control: Any merger, acquisition, consolidation, or other business reorganization or sale of all or substantially all of the assets of Provider or of the portion of Provider that performs the Services in the Service
Agreement.
Contextual Advertising: Contextual advertising is the delivery of advertisements based upon a current visit to a website or a single search query, without the collection and retention of data about the consumer’s online activities over time.
Data Breach: An unauthorized release, access to, disclosure, or acquisition of Student Data that compromises the security, confidentiality or integrity of the Student Data maintained by the Provider in violation of applicable state or federal law.
De-Identified Data: Records and information are considered to be De-Identified Data when all Personally
Identifiable Information has been removed or obscured, such that the remaining information does not reasonably identify a specific student, including, but not limited to, any information that, alone or in combination is linkable to a specific student.
Education Records: Education Records shall have the meaning set forth under FERPA 20 U.S.C. 1232 g(a)(4) and 34 CFR § 99.3. For additional context see also the ‘Student Data’ definition.
LEA: For the purpose of this DPA, the LEA is the educational entity that is a Party to this Agreement. An LEA can be a state agency, an educational service agency, a charter school, school system, or a private school or school system, in addition to the federal definition of Local Education Agency (LEA).
Metadata: Means information that provides meaning and context to other data being collected including, but not limited to date and time records and purpose of creation. Metadata that have been stripped of all direct and indirect identifiers are not considered Personally Identifiable Information or Student Data.
Originating LEA: An educational entity otherwise meeting the definition of LEA that originally executes the DPA in its entirety (including the marked checkbox enabling Exhibit “E”) with the Provider.
Personally Identifiable Information: Means Personally Identifiable Information or PII as defined in 34 C.F.R.
§ 99.3 and as defined under any applicable state law.
School Official: For the purposes of this DPA and pursuant to FERPA 34 CFR § 99.31(a)(1)(i)(B), a School
Official is a contractor that: (1) Performs an institutional service or function for which the agency or institution would otherwise use employees; (2) Is under the direct control of the agency or institution with respect to the use and maintenance of Student Data including Education Records; and (3) Is subject to FERPA 34 CFR §
99.33(a) governing the use and re-disclosure of Personally Identifiable Information from Education Records.
Service Agreement: Refers to the quote, corresponding contract, purchase order, terms of service, and/or terms of use.
Student Data: Student Data includes any data, whether gathered, created, or inferred by Provider or provided by LEA or its users, students, or students’ parents/guardians, for a school purpose, that is descriptive of the student including, but not limited to, information in the student’s Education Record, persistent unique identifiers, or any other information or identification number that would provide information about a specific student. Student
Data includes Metadata that has not been stripped of all direct and indirect identifiers. Student Data further
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 21 includes Personally Identifiable Information (PII). Student Data shall constitute Education Records for the purposes of this DPA, and for the purposes of federal, state, and local laws and regulations. Student Data as specified in Exhibit “B” is confirmed to be collected or processed by the Provider pursuant to the Services.
Student Data shall not include properly De-Identified Data or anonymous usage data regarding a student’s or
LEA’s use of Provider’s Services.
Student Generated Content: The term Student Generated Content means materials or content created by a student in the services including, but not limited to, essays, research reports, portfolios, creative writing, music or other audio files, photographs, videos, and account information that enables ongoing ownership of student content. Student Generated Content does not include student responses to a standardized assessment where student possession and control would jeopardize the validity and reliability of that assessment.
Subprocessor: For the purposes of this DPA, the term Subprocessor (sometimes referred to as the
“subcontractor”) means a party other than LEA or Provider, who Provider uses for data collection, analytics, storage, or other service to operate and/or improve its service, and who has access to or storage of Student
Data, including security, storage, analytics, and other processing activities necessary to perform a Provider business purpose.
Subprocessor Agreement: An agreement between Provider and a third party Subprocessor. A Subprocessor
Agreement includes either a written agreement or an acceptance of terms and conditions (e.g., click through agreements).
Subscribing LEA: An educational entity otherwise meeting the definition of LEA that was not party to the original
Service Agreement and who accepts the Provider’s General Offer of Privacy Terms by executing Exhibit “E”.
Targeted Advertising: Targeted Advertising means presenting an advertisement to a student where the selection of the advertisement is based on Student Data or inferred over time from the usage of the Provider
Internet website, online service, or mobile application by such student or the retention of such student's online activities or requests over time for the purpose of targeting subsequent advertisements. Targeted Advertising does not include Contextual Advertising.
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 22
EXHIBIT D: SPECIAL INSTRUCTIONS FOR DISPOSITION OF
STUDENT DATA
After this DPA takes effect, if the LEA has special requirements for the disposition of Student Data that are not expressed in 4.6 Disposition of Student Data, the LEA may fill in this form and deliver it to the Provider.
The Provider and the LEA must not fill in this form at the initiation of the DPA.
The Provider shall act on Exhibit “D” from the designated representative of the LEA or their designee (Preamble or Exhibit “E” for Subscribing LEA).
[ Insert Name of District or LEA ] (“LEA”) instructs Provider to dispose of Student Data obtained by Provider pursuant to the terms of the DPA between LEA and Provider. The terms of the disposition are set forth below:
1. Extent of Disposition
[ ] Disposition is partial. The scope of Student Data to be disposed of is set forth below or found in an attachment to this form:
[ Insert categories of Student Data here ]
[ ] Disposition is complete. Disposition extends to all Student Data.
2. Nature of Disposition
[ ] Disposition shall be by destruction or deletion of Student Data.
[ ] Disposition shall be by a transfer of Student Data. The Student Data shall be transferred to the following site as follows:
[ Insert or attach special instructions ]
3. Timing of Disposition
Student Data shall be disposed of by the following date:
[ ] As soon as commercially practicable
[ ] On Provider’s standard destruction schedule
[ ] By [ Insert Date ]
4. De-Identified Data
[ ] The Provider certifies that they have de-identified the Student Data, as defined elsewhere in this
Agreement, and disposed of all copies of Student Data that were not de-identified in accordance with this
Schedule and the DPA. The Provider will notify LEA in accordance with the notification requirements of the DPA using this form.
As of [ Insert Date ]
5. Other:
Signature(s) Notice of Verified Disposition of Data
Authorized Representative of
LEA
Date Authorized Representative of Provider
Date
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 23
EXHIBIT E: GENERAL OFFER OF PRIVACY TERMS
Page 1 of 3: OFFER OF TERMS
Provider and the Subscribing LEA (named below) agree by signing this General Offer of Privacy Terms (“General
Offer”) that they are bound by the same terms as the DPA between Provider and
________________________________________________ (“Originating LEA”) dated _______________.
Provider and Subscribing LEA agree that the information below will be replaced throughout the DPA with the information specific to the Subscribing LEA filled in below for the Subscribing LEA. This General Offer shall extend only to the terms set forth in this DPA and shall not necessarily bind Provider or Subscribing LEA to any other terms entered into between Provider and Originating LEA. Any commercial terms, such as price, term, or schedule of Services, relating to Subscribing LEA’s use of the Provider’s Services shall be determined solely between Provider and Subscribing LEA.
If Provider makes changes to Exhibit “A” or Exhibit “B” in accordance with sections 1.2 and 1.3, respectively, Provider must complete the Addendum template provided by the A4L Community and notify the Originating LEA and all Subscribing LEAs in accordance with the notification provisions of this DPA, of the Addendum’s existence and contents. With regard to a Subscribing LEA, an Addendum is automatically incorporated into this DPA when
Subscribing LEA is notified by Provider. If an Addendum modifies Exhibit “B”, the LEA will have thirty (30) days from receipt to object. If no written objection is received it will become incorporated into the DPA between the parties.
The Provider may withdraw the General Offer (for future use or for LEAs that have not already accepted it) in the event of: (1) a material change in the applicable privacy statutes; or (2) a material change in the Services and products listed in the Service Agreement. Notification of a withdrawal shall be submitted to ndpa_requests@A4L.org.
Subscribing LEAs shall send the signed Exhibit “E” to Provider at the following email address:
The below signatory confirms they are authorized to bind their institution to this DPA as in its entirety.
PROVIDER:
Signed By:
Printed Name:
Date:
Title/Position:
mailto:ndpa_requests@A4L.org
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 24
EXHIBIT E - Page 2 of 3: RESOURCE NAME(S):
Originating LEA: _______________________________________________
Provider Name: ________________________________________________
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 25
EXHIBIT E - Page 3 of 3: “SUBSCRIBING LEA”
Originating LEA: _______________________________________________
Provider Name: ________________________________________________
A Subscribing LEA, by signing a separate Service Agreement with Provider, and by its signature below, accepts the General Offer of Privacy Terms. The Subscribing LEA and the Provider shall therefore be bound by the same terms of this DPA for the term of the DPA between the Originating LEA and the Provider. **PRIOR TO ITS
EFFECTIVENESS, SUBSCRIBING LEA MUST DELIVER NOTICE OF ACCEPTANCE TO PROVIDER.**
Please note, by signing this Exhibit you are also agreeing to any language that may be included in Exhibits to the Originating DPA beyond this Exhibit “E”. The below signatory confirms they are authorized to bind their institution to this DPA as in its entirety.
Date:
Title/Position:
Subscribing LEA:
Signed By:
Printed Name:
School District Name:
Designated Representative of LEA:
Name: Title:
Address:
Telephone: Email:
Notices to Subscribing LEA: The Provider and Subscribing LEA are each responsible to promptly notify the other Party of changes to the notice information.
Security Notices to Subscribing LEA
With a copy to (if provided):
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 26
EXHIBIT F: ADEQUATE CYBERSECURITY FRAMEWORKS
Provider must mark one or more frameworks with which it complies.
The Provider may change which framework it complies with without invalidating or changing the DPA, but must notify the LEA of such change in accordance with the notification requirements of the DPA.
FRAMEWORK(S)
NIST Cybersecurity Framework (CSF)
NIST SP 800-53 Security and Privacy Controls for Information systems and organizations
NIST SP 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
ISO 27000 series, Standards for implementing organization security and management practices
CIS Center for Internet Security Critical Security Controls
Cybersecurity Maturity Model Certification (CMMC, ~FAR/DFAR)
This space is provided for optional security programs and measures as noted in section 5.3:
Global Education Security Standard - https://privacy.A4L.org/gess/
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 27
EXHIBIT G: Supplemental SDPC State Terms for Utah
1. Utah Student Data Audit Rights
(1) Under Utah Code § 53E-9-309, a contract between an LEA and a third-party contractor must include an agreement by the third-party contractor that, at the request of the education entity that is a party to the contract, the education entity or the education entity's designee may audit the third-party contractor to verify compliance with the contract. For the purposes of meeting the audit requirements of a contract subject to Subsection 53E-9-309, Utah Administrative Rule R277-487 states that a third-party contractor may:
(a) provide an LEA or the Utah State Board of Education Superintendent a self-assessment of their compliance with the contract and the effectiveness of the information security program;
(b) provide responses to a questionnaire provided by the LEA or the Utah State
Board of Education Superintendent;
(c) provide a report of an industry-recognized privacy and security audit, such as an
SOC2 or SOC3; or
(d) submit to an onsite audit, if agreed upon by the third-party contract and the LEA or the Utah State Board of Education Superintendent.
2. Termination Due to Privacy Violations
(1) “Privacy Violation” means Provider’s unauthorized usage of Student Data or information in violation of state or federal privacy laws, including the Family Education Rights and Privacy Act and related provisions under 20 U.S.C. Secs. 1232g and 1232h, the Children's Online Privacy Protection Act, 15 U.S.C. Sec. 6501 et seq. and any associated regulations, and U.C.A. Title 53E Chapter 9 Parts 2 and 3, Utah Administrative Rule R277-487, and any associated administrative rules.
(2) Under UCA § 53E-9-309, LEA has a statutory duty to terminate the Service Agreement in the case of a confirmed and unremedied Privacy Violation.
(3) In the event that LEA discovers a Privacy Violation by Provider, LEA shall provide written notice to Provider describing the violation and LEA’s duty to terminate the Service Agreement (“Notice of Privacy Violation”).
(4) Within 30 days of receipt of the Notice of Privacy Violation, Provider shall:
(a) Remedy the Privacy Violation to the greatest extent practicable, in determination of LEA;
(b) Establish processes and procedures to prevent the failure of compliance from reoccurring; and
(c) Provide documentation of the established processes and procedures to LEA.
(5) If Provider fails to remedy the Privacy Violation, LEA shall provide written notice of duty to terminate (“Notice of Termination Due to Privacy Violation”) no sooner than 30 days after receipt of the Notice of Privacy Violation. Provider may not impose a fee, seek damages, or otherwise assert any financial liability against LEA as a result of termination under this Exhibit.
(2) The Provider shall fully cooperate with any audits conducted, as described above.
Penny Murray Cross-Out
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 28
3. Subprocessor Identification.
(1) Under Utah Code § 53E-9-309, a contract between an LEA and a third-party contractor must include a description of a person, or type of person, including an affiliate of the third-party contractor, with whom the third-party contractor may share Student Data.
(2) In the space below, Provider shall include a link to a list of Subprocessors who, by virtue of their agreement with the Provider, may have access to Student Data or process Student Data. If no link is available, Provider shall provide in the space below a detailed description of the Subprocessors who, by virtue of their agreement with the Provider, may have access to Student Data or process Student Data.
(3) If Provider does not share Student Data with Subprocessors, Provider should indicate “No Student Data shared with Subprocessors” in the space provided below.
4. Employee Data
(1) Under Utah's Government Data Privacy Act (Utah Code § 63A-19), LEAs are required to document and report on the personal data shared with third-parties.
(2) Provider shall indicate below the data that will be shared with, collected by, or processed by
Provider related to employees of the LEA as a part of providing the Services.
© Access 4 Learning (A4L) Community. All Rights Reserved. Page | 29
Category of Data Elements Data Shared with or
Collected by Provider:
Application Technology Meta Data
IP Addresses of users, Use of cookies etc.
Other application technology meta data:
Application Use Statistics Meta data on user interaction with application
Communications Online communications that are captured (emails, blog entries)
Demographics Date of Birth
Place of Birth
Social Security Number
Ethnicity or race
Other demographic information:
Personal Contact Information
Personal Address
Personal Email
Personal Phone
Financial and Benefits Information
Direct Deposit Information
Benefit elections
Other financial…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .