Pearl Education Privacy Commitments & Frameworks

Pearl Education makes public commitments to protect student data, evidenced by the agreements it signs and the security frameworks it follows. (The industry “Student Privacy Pledge” formerly stewarded by the Future of Privacy Forum was retired in 2025; Pearl’s commitments are anchored in the signed agreements and recognized frameworks below).

Student Data Privacy Consortium (SDPC) NDPA

Pearl adheres to the SDPC National Data Privacy Agreement (NDPA) framework and will execute a district’s or state’s NDPA. Pearl has executed NDPAs with school districts and a multi-state consortium (including an 11-state consortium NDPA). Pearl is not a member of the Access 4 Learning (A4L) Community or SDPC; membership is not required to adopt or sign the NDPA. Executed agreements are provided on request, typically under NDA or after contracting, and are not posted publicly. See NDPA and State Addenda.

CISA K-12 Secure by Design Pledge

Pearl intends to sign the CISA K-12 Education Technology Secure by Design Pledge, a voluntary commitment for K-12 software providers built around three principles: (1) take ownership of customer security outcomes, (2) embrace radical transparency and accountability, and (3) lead from the top. Pearl already meets much of the pledge — a published vulnerability-disclosure policy, single sign-on available at no additional cost, and named executive ownership of security — and is advancing multi-factor authentication coverage, the principal area still in progress.

Pearl’s Bright-Line Student-Data Commitments

These commitments are in Pearl’s MSA and DPA and apply to every customer:

  • No sale of student data (MSA §5.7; DPA §4.2).
  • No targeted or behavioral advertising directed at students (MSA §5.7; DPA §4.2).
  • No commercial student profiles except as needed to provide the Services (MSA §5.7; DPA §4.2).
  • Use only for authorized educational purposes, at the school’s direction, as a FERPA school official (MSA §5.2–5.3; DPA §4.1).
  • A written security program with encryption in transit and at rest and least-privilege access (MSA §4.3; DPA §6.1).
  • Retention only as needed, with deletion on the MSA/DPA timelines (MSA §4.6; DPA Art. VIII).
  • Notice before material changes to the categories of Student Data collected (DPA §1.2).
  • Access, correction, and deletion supported through the school; direct parent requests are referred to the school (DPA §2.2–2.3).

A Note on De-identified Data

Consistent with FERPA, Pearl may create and use de-identified and aggregated data for research, benchmarking, and service improvement under a documented de-identification methodology and data-use agreements that prohibit re-identification (MSA §6; DPA Art. V). This is not a sale of student data and does not involve advertising to students.