Ask Before You App / Learn / Glossary
Every acronym, clause, and legal term you will run into when reviewing vendor agreements, explained in plain language.
You should not need a law degree to protect your students. Start here.
Showing 19 of 53 terms matching "NDPA"
The delivery of advertisements based on a user's current visit to a website or a single search query, without the collection and retention of data about the consumer's online activities.
The NDPA prohibition on targeted advertising does not extend to contextual advertising. A student uses an online dictionary and sees an ad for a thesaurus: that is contextual. Targeted advertising, which tracks and acts on student behavior across sessions, is prohibited. The distinction matters in DPA reviews.
A version of the National Data Privacy Agreement utilized when edits are made to specifically address one district's needs. Because these modifications are highly localized, no Exhibit E (piggyback clause) is offered.
This is the custom-tailored version. It solves your district's specific problem, but other districts can't sign on. For statewide efficiency, the standard or vendor-specific NDPA is usually the better path.
Records and information where all Personally Identifiable Information has been removed or obscured, ensuring the remaining information cannot reasonably identify a specific student, including any information that, alone or in combination, is linkable to a specific student.
The word "reasonably" does a lot of heavy lifting here. A vendor that wants to use student data to improve its algorithm can use De-Identified Data (anonymous test scores, completion rates) to protect privacy. But with enough data points, de-identified data can sometimes be re-identified. That is why the NDPA has strict rules around this.
A document within the NDPA that allows a vendor to make a general public offer of their agreed-upon privacy terms, letting other LEAs ("Subscribing LEAs") piggyback onto the contract without negotiating a new one.
This is the single most powerful efficiency tool in the NDPA system. One district negotiates, and 50 more can sign on. That is why the SDPC registry exists: to make Exhibit E discoverable. A small charter school can execute an Exhibit E to adopt an existing NDPA without a full individual negotiation.
An optional NDPA exhibit generated by State Alliances to address state-specific data privacy legislative requirements.
Every state has its own privacy laws on top of FERPA. Utah has SB 267 (which directs USBE to study software use in public schools) and Utah Code §53E-9 (Student Privacy and Data Protection). California has SOPIPA. Exhibit G is where state-specific requirements get folded in. For Utah, audit and sub-processor disclosure requirements come from §53E-9, not SB 267.
The specific section of the NDPA where all modifications, redlines, or edits to the standard clauses must be documented. If changes are made but not listed here, the contract legally loses the right to use the official NDPA moniker.
This is the honesty clause. If a vendor says "we signed the NDPA" but there are undocumented changes, it is not actually an NDPA. Exhibit H keeps everyone accountable. Both the LEA and the vendor sign it to confirm all parties agree to the alterations.
The foundational U.S. federal law protecting student data privacy. It governs the disclosure of education records and parental access rights.
FERPA is from 1974. It predates the internet by decades. It still applies to every ed-tech vendor touching student data, and it is the legal backbone that everything else (COPPA, state laws, the NDPA) builds on. Parents have the right to inspect and review their child's Education Records, request amendments, and must give consent before records are shared with third parties outside of recognized exceptions.
The educational entity entering into the privacy agreement. This encompasses state agencies, educational service agencies, charter schools, private schools, or local school districts.
When the NDPA says "LEA," it means whoever is signing on behalf of the students. That is usually the district, but it can be a charter school, a state agency, or a regional service center. For the purpose of the DPA, the LEA is the entity responsible for making sure all schools within its boundaries comply with federal and state student data privacy laws.
A standardized, community-created legal contract designed to streamline educational app contracting, standardize data protection expectations, and eliminate the need for districts to negotiate one-off contracts with vendors.
Before the NDPA, every district was negotiating its own agreement with every vendor. One district might have 200+ vendors. Multiply that by thousands of districts and you see the problem. The NDPA is the solution: one standard contract that works everywhere. When a teacher wants to use a new tool, the IT department can check the NDPA registry first to see if a signed agreement already exists.
A companion document to the NDPA utilized for standardizing data-sharing agreements between schools/districts and researchers under FERPA's "Studies Exception."
Research partnerships are valuable but tricky. The NRDPA gives districts a standardized way to share data with researchers without building a custom legal agreement every time.
The membership-elected leadership group that reviews the work of the Legal Project Team and approves new versions of the NDPA.
These are the people who decide what goes into the next version of the NDPA. If you want to influence the standard, this is the room to be in.
The underlying business contract (e.g., terms of service, quote, or purchase order) that dictates the commercial relationship. The NDPA supersedes this agreement regarding the treatment of student data.
The Service Agreement is the business deal. The NDPA is the privacy deal. When they conflict on how student data is handled, the NDPA wins. That is by design.
A third-party subcontractor utilized by the primary Provider for data collection, analytics, security, or storage, and who has access to or storage of Student Data. They must be subject to privacy terms no less stringent than the NDPA.
Your vendor signed a DPA. Great. But does their cloud hosting provider? Their analytics subcontractor? Their customer support company? Subprocessor disclosure is one of the most commonly missed items in DPA reviews. The DPA requires the main vendor to ensure that its Subprocessors also comply with the privacy protections.
Digital materials explicitly created by a student (e.g., essays, photos, audio files, portfolios). This does not include student responses to standardized assessments.
A student's essay belongs to the student. A student's test answers belong to the assessment. The NDPA draws that line clearly, and it affects what a vendor can keep after the contract ends. A student's digital art portfolio is their intellectual property, and the vendor cannot use it for commercial purposes.
A centralized platform and two-sided marketplace where Alliances manage privacy frameworks, districts track and search for signed agreements, and vendors manage their DPA portfolios.
The Registry is the source of truth for who has signed what. ABYA sits on top of it, surfacing each district's agreements in one hub a parent or board member can actually read. When a district IT director wants to see if an NDPA already exists for a new tool, this is where they look first.
A special interest group of the A4L Community comprising districts, states, and vendors. It was created to address real-world student data privacy issues and establish common market expectations.
SDPC is the engine behind the NDPA, the Resource Registry, and the entire framework most districts use for vendor privacy management. If you are in K-12 privacy, you are working within the SDPC ecosystem whether you realize it or not.
A district or school that was not a party to the original Service Agreement but legally signs onto the Provider's General Offer of Privacy Terms (via Exhibit E).
This is the piggyback mechanism in action. One district negotiated. You benefit. But you still need to sign Exhibit E to make it official. A charter school in a different county can become a Subscribing LEA by executing Exhibit E, which binds them to the pre-existing NDPA.
Presenting advertisements to a student based on their Student Data or behavior inferred over time from usage of the Provider's website, online service, or mobile application. The NDPA strictly prohibits Targeted Advertising, though it allows for adaptive learning customizations or product recommendations permitted by the LEA.
This is a bright line. No vendor can target ads at students based on their behavior. Period. If a DPA does not explicitly prohibit this, that is a red flag worth catching. A student uses an educational app and starts seeing ads based on their in-app activity? That is Targeted Advertising and it violates the NDPA.
A modified version of the NDPA used when there are agreed-upon edits that are approved by Alliance leadership for all member districts. In this setup, the vendor has the option to sign Exhibit E to allow other districts to piggyback.
This is the middle ground between a standard NDPA and a district-modified one. The vendor gets some customization, but it is approved at the Alliance level, so the piggyback option stays open.
ABYA pulls a district's vendors, agreements, and compliance docs into one public hub, and trains the staff on the terms above. The words on this page are what your hub makes visible and legible to parents and boards.
Free course, 50 minutes
Our NDPA training course walks through every exhibit, every clause, and what to do when a vendor pushes back. You leave with something you can use and cite.