# National Data Privacy Agreement (NDPA)

### Standard Student Data Privacy Agreement — SDPC / US School Districts

> **Template notice.** This document mirrors the structure of the Student Data
> Privacy Consortium (SDPC) **National Data Privacy Agreement (NDPA)**, the
> standard many US school districts require in place of a vendor's own contract.
> It is a starting template, not legal advice. Have it reviewed by qualified
> legal counsel before you send or sign it, and replace every `[BRACKETED]`
> placeholder. You can open and edit this file directly, or paste it into Google
> Docs / Microsoft Word and export a PDF for signing.
>
> **Which US document should we use?** If your district has adopted the SDPC
> NDPA (most have), use **this** agreement — it is our primary US option. If your
> district instead wants a vendor-provided contract, use our COPPA/FERPA Data
> Processing Agreement. You do not need both.

---

This National Data Privacy Agreement (this "DPA") is entered into as of
**[EFFECTIVE DATE]** by and between:

- **Local Education Agency ("LEA"):** **[DISTRICT LEGAL NAME]**, located at
  **[DISTRICT ADDRESS]**; and
- **Provider:** **[YOUR LEGAL COMPANY NAME]**, operator of the **[PRODUCT NAME]**
  math-learning platform.

The LEA and Provider are each a "Party" and together the "Parties." This DPA is
incorporated into and governs the **Service Agreement** between the Parties for
the [PRODUCT NAME] service (the "Services").

---

## Article I — Purpose and Scope

1. **Purpose.** This DPA describes the duties of the Provider with respect to
   Student Data transmitted to or created by the Provider through the Services.
2. **Student Data to be provided.** The categories of Student Data shared under
   the Service Agreement are described in **Exhibit "B" (Schedule of Data)**.
3. **DPA definitions.** Capitalized terms have the meanings given in
   **Exhibit "C" (Definitions)**, consistent with FERPA (20 U.S.C. § 1232g),
   COPPA (15 U.S.C. § 6501–6506), PPRA, and applicable state student-privacy law.

## Article II — Data Ownership and Authorized Access

1. **Student Data property of LEA.** All Student Data transmitted under the
   Service Agreement is and remains the property of, and under the control of,
   the LEA. Provider acts as a **school official** with a legitimate educational
   interest under FERPA.
2. **Parent access.** The LEA may access and review Student Data at any time, and
   Provider will cooperate with parent/eligible-student access, correction, and
   deletion requests routed through the LEA.
3. **No unauthorized use.** Provider will not use Student Data for any purpose
   other than providing the Services, and will not sell Student Data or use it
   for targeted advertising or to build a non-educational profile of a student.

## Article III — Duties of the LEA

1. The LEA will provide data in compliance with FERPA, COPPA, PPRA, and
   applicable state laws.
2. The LEA is responsible for obtaining any parental consent it deems necessary
   and for maintaining its own annual FERPA notice designating Provider as a
   school official.

## Article IV — Duties of the Provider

1. **Compliance.** Provider will comply with FERPA, COPPA, PPRA, and applicable
   state student-privacy laws in performing the Services.
2. **Authorized use only.** Provider will use Student Data only to provide the
   Services described in the Service Agreement and Exhibit "A."
3. **Subprocessors.** Provider will enter written agreements with subprocessors
   requiring them to safeguard Student Data to the same standard, and maintains a
   current list of subprocessors (see our Subprocessors page).
4. **No disclosure.** Provider will not disclose Student Data to third parties
   except subprocessors under (3), as directed by the LEA, or as required by law
   (with notice to the LEA unless legally prohibited).

## Article V — Data Provisions

1. **Data security.** Provider will implement the administrative, physical, and
   technical safeguards described in **Exhibit "F" (Data Security Requirements)**,
   including encryption of Student Data in transit and at rest.
2. **Data breach.** In the event of an unauthorized disclosure or breach of
   Student Data, Provider will notify the LEA without unreasonable delay and no
   later than **[NUMBER]** days after confirming the incident, and will cooperate
   with the LEA's notification obligations. See our Breach Response Runbook.
3. **Return or destruction.** Upon request or upon termination, Provider will
   return or destroy all Student Data within **[NUMBER]** days and certify the
   disposition in writing (**Exhibit "D"**).

## Article VI — General Offer of Terms

Provider may, by signing **Exhibit "E" (General Offer of Privacy Terms)**, extend
the terms of this DPA to any other subscribing LEA in the same state, so districts
can adopt these terms without renegotiating.

## Article VII — Miscellaneous

1. **Term.** This DPA is effective on the date signed and remains in effect until
   the Service Agreement ends or the DPA is terminated.
2. **Governing law.** This DPA is governed by the laws of the State of
   **[STATE]**, without regard to conflict-of-laws principles.
3. **Priority.** In the event of a conflict between this DPA and the Service
   Agreement, this DPA controls with respect to Student Data.
4. **Entire agreement.** This DPA and its Exhibits constitute the entire
   agreement of the Parties with respect to Student Data.

---

## Signatures

**Local Education Agency ([DISTRICT LEGAL NAME])**

- Signature: ______________________________
- Name / Title: **[NAME], [TITLE]**
- Date: ______________________________

**Provider ([YOUR LEGAL COMPANY NAME])**

- Signature: ______________________________
- Name / Title: **[NAME], [TITLE]**
- Date: ______________________________

---

## Exhibit "A" — Description of Services

[Describe the [PRODUCT NAME] adaptive mathematics service provided to the LEA.]

## Exhibit "B" — Schedule of Data

List the categories of Student Data collected (e.g., student nickname/display
name, school-assigned identifier, grade level, math progress and performance
data). Note that [PRODUCT NAME] minimizes collection: it does not require legal
student names and collects birth month/year only, not a full date of birth.

## Exhibit "C" — Definitions

Standard SDPC NDPA definitions (Student Data, De-Identified Data, School Official,
Targeted Advertising, Subprocessor, etc.), aligned with FERPA, COPPA, and PPRA.

## Exhibit "D" — Directive for Disposition of Data

Form the LEA uses to instruct Provider to return and/or destroy Student Data.

## Exhibit "E" — General Offer of Privacy Terms

Provider's optional offer to extend these terms to other LEAs in the same state.

## Exhibit "F" — Data Security Requirements

Encryption in transit and at rest, access controls, logging, subprocessor
requirements, and breach-notification commitments.

---

*Prepared by [YOUR LEGAL COMPANY NAME]. This template mirrors the SDPC National
Data Privacy Agreement structure for convenience and is not affiliated with or
endorsed by the Student Data Privacy Consortium. Confirm your district's required
version and any state-specific exhibit before signing.*
