Student Data Privacy Agreement (FERPA): DRAFT TEMPLATE
DRAFT TEMPLATE. NOT LEGAL ADVICE. ATTORNEY REVIEW REQUIRED BEFORE USE.
This is a starting point for counsel, not a signable agreement. A licensed attorney must review and finalize it before it is offered to or signed with any school or district. Complete every bracketed
[ ]field. If a district supplies its own agreement (for example an SDPC National Data Privacy Agreement or a state specific version), route that to counsel rather than substituting this one. Governing law, breach notification timelines, and indemnification are legal decisions, not defaults filled in here.
This Student Data Privacy Agreement ("Agreement") is entered into as of [EFFECTIVE DATE] by and between [SCHOOL OR DISTRICT LEGAL NAME] ("School"), and [SIZZLEGO LEGAL ENTITY NAME], operator of SizzleGo at SizzleGo.com ("Provider").
1. Purpose and scope
The School has engaged the Provider to deliver the services described in Exhibit A ("Services"). In delivering the Services, the Provider may receive or have access to Student Data (defined below). This Agreement governs the Provider's collection, use, protection, and disposal of that data, and establishes the Provider as a "school official" with a "legitimate educational interest" under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. 1232g and 34 CFR Part 99.
2. Definitions
- Education Records has the meaning given in FERPA, 34 CFR 99.3.
- Student Data means any Education Record and any personally identifiable information relating to a student that the Provider receives from, or creates on behalf of, the School under this Agreement. Under the Services, Student Data is limited to the data elements listed in Exhibit A (in general, a student's name and, where applicable, a classroom or grouping), entered by an adult. Students do not create accounts and do not submit their own data.
- De-Identified Data means data from which all personally identifiable information has been removed such that a student cannot reasonably be identified.
- School Official has the meaning given in FERPA, 34 CFR 99.31(a)(1).
- Subprocessor means a third party engaged by the Provider that processes Student Data. The current Subprocessors are listed in Exhibit B.
3. School official designation and direct control
The School designates the Provider as a School Official with a legitimate educational interest in the Student Data necessary to perform the Services. The Provider agrees that, with respect to Student Data:
- It performs an institutional service or function for which the School would otherwise use its own employees.
- It is under the direct control of the School regarding the use and maintenance of Education Records.
- It uses Student Data only for the authorized purposes described in this Agreement and Exhibit A.
- It does not redisclose Student Data to any party except as permitted in Section 6.
4. Ownership of data
Student Data is and remains the property of the School and, as applicable, the parents and eligible students. The Provider obtains no ownership rights in Student Data by performing the Services. The Provider acts solely as a processor of Student Data on the School's behalf.
5. Permitted use; purpose limitation
The Provider shall use Student Data only to provide and support the Services and for no other purpose. Specifically, the Provider shall not:
- Use Student Data for advertising or marketing, or to target advertising to students or families. The Provider's advertising features (AdGo) operate on organizer and campaign data only and are separated from Student Data.
- Sell, rent, or trade Student Data.
- Use Student Data to build a personal profile of a student other than in furtherance of the Services.
- Use Student Data for any commercial purpose beyond the Services.
The Provider may use De-Identified Data only to operate, maintain, and improve the Services, and shall not attempt to re-identify De-Identified Data.
6. No redisclosure; subprocessors
The Provider shall not disclose Student Data to any third party except:
- To the Subprocessors listed in Exhibit B, each of which is bound by written obligations no less protective than this Agreement and processes Student Data only to support the Services.
- As directed in writing by the School.
- As required by law, in which case the Provider shall, unless legally prohibited, give the School prior notice.
The Provider shall maintain the Subprocessor list, review it at least annually, and provide the School notice before adding a new Subprocessor that processes Student Data where required by this Agreement or by [NOTICE REQUIREMENT: e.g. no fewer than 30 days].
7. Security
The Provider shall protect Student Data using administrative, technical, and physical safeguards that are reasonable and appropriate to its sensitivity, including:
- Access control. Access to Student Data is limited to those with a legitimate need, enforced by authenticated accounts and role based access.
- Tenant isolation. Each school's data is logically isolated so that one school cannot access another school's data. Isolation is enforced in the application and covered by an automated test suite.
- Encryption. Student Data is encrypted in transit (TLS) and at rest (at rest provided by the Provider's infrastructure subprocessors).
- Audit logging. Sensitive actions, including data exports, are recorded in an audit trail available to the School's administrators.
- Monitoring. The Provider monitors for errors and security relevant events.
- No card data. The Provider does not store payment card numbers; card processing is handled by a PCI compliant payment subprocessor.
The Provider shall review its safeguards periodically and update them as appropriate.
8. Data incident and breach notification
Upon becoming aware of an unauthorized access, use, or disclosure of Student Data ("Data Incident"), the Provider shall:
- Notify the School without unreasonable delay and in no case later than
[BREACH NOTIFICATION TIMELINE: e.g. 72 hours]after confirming the Data Incident. - Provide the School the information known about the Data Incident, including its nature, the data involved, and the steps taken to contain and remediate it.
- Cooperate with the School's investigation and, as directed and to the extent caused by the Provider, support the School's notification obligations to affected parties.
Allocation of notification costs is [TO BE NEGOTIATED WITH COUNSEL].
9. Parental and eligible student rights
The School retains responsibility for responding to requests from parents and eligible students to access, review, or correct Education Records. The Provider shall, at the School's direction and within [RESPONSE WINDOW: e.g. 10 business days], assist the School in fulfilling such requests by making the relevant Student Data available to the School.
10. Directory information
The Provider shall treat all Student Data as non directory information unless the School designates otherwise in writing. Directory information designations vary by School and govern only within the scope the School specifies.
11. Data return and destruction
Upon the earlier of the School's written request or the termination or expiration of this Agreement, the Provider shall, at the School's election:
- Return the School's Student Data in a commonly readable electronic format, and then
- Destroy the School's Student Data, including copies held by Subprocessors, within
[DESTRUCTION WINDOW: e.g. 30 days], except where retention is required by law.
Upon completion, the Provider shall provide the School a written certificate of destruction in the form of Exhibit C. The Provider may retain De-Identified Data and records required for legal or accounting purposes.
12. Retention
The Provider shall retain Student Data only as long as necessary to provide the Services, or as the School directs, or as required by law, whichever is longest, and shall not retain Student Data beyond that period.
13. Compliance with law
The Provider shall comply with FERPA and, to the extent applicable to its performance of the Services, the Children's Online Privacy Protection Act (COPPA), the Protection of Pupil Rights Amendment (PPRA), and applicable state student privacy laws, including [STATE STUDENT PRIVACY LAW(S), e.g. Missouri]. The Provider represents that the Services do not collect data directly from students and do not knowingly collect data from children under 13 without the consent the School is authorized to provide for educational use.
14. Term and termination
This Agreement takes effect on the Effective Date and continues for the term of the Services. Either party may terminate for material breach not cured within [CURE PERIOD: e.g. 30 days] of written notice. Sections concerning data ownership, no redisclosure, security, breach notification, return and destruction, and retention survive termination until the Provider has returned or destroyed all Student Data.
15. Miscellaneous
- Order of precedence. If this Agreement conflicts with the underlying Services agreement as to Student Data, this Agreement controls.
- Amendment. Any amendment must be in writing and signed by both parties.
- Governing law.
[GOVERNING STATE LAW]. - Entire agreement. This Agreement, with its Exhibits, is the entire agreement between the parties regarding Student Data.
- No third party beneficiaries. Except as FERPA provides for parents and eligible students.
Signatures
| School | Provider | |---|---| | Signature: ______________________ | Signature: ______________________ | | Name: [ ] | Name: [ ] | | Title: [ ] | Title: [ ] | | Date: [ ] | Date: [ ] |
Exhibit A: Description of Services and Student Data collected
Services provided: [LIST THE SPECIFIC GO PRODUCTS THIS SCHOOL USES, e.g. SchoolConferenceGo, FrontOfficeGo].
Student Data elements collected: [COMPLETE FROM THE PRODUCTS IN USE. In general: student name; classroom or grouping where applicable. No birthdate, age, or other student attribute is collected. Data is entered by an adult (parent or organizer); students do not create accounts or submit their own data.]
Purpose of collection: [e.g. scheduling parent teacher conferences; managing front office rosters and family communication].
Exhibit B: Subprocessors
The Provider's current Subprocessors and the data each processes are maintained in the Provider's subprocessor register (see docs/SUBPROCESSORS.md, published at SizzleGo.com/subprocessors). Attach the current version. Subprocessors that may process Student Data: [list from the register, e.g. RavenDB Cloud (database), Render (hosting), Resend (email), and the SMS provider used for this School].
Exhibit C: Certificate of destruction
Upon return and destruction under Section 11, the Provider shall deliver a certificate stating: the School's name; the categories of Student Data destroyed; the date range covered; the date of destruction; the method of destruction; confirmation that Subprocessor copies were destroyed; and the name and title of the Provider representative certifying destruction.
Certified by: ______________________ Name/Title: [ ] Date: [ ]