State Student Privacy Law Posture
Pearl Education serves districts and agencies across many states, each with its own student-privacy law. Across all of them, Pearl’s baseline commitments are the same and are set in its MSA and DPA: Pearl acts as a FERPA school official (MSA §5.3); it will not sell Student Data, use it for targeted or behavioral advertising to students, or build commercial student profiles except as needed to provide the Services (MSA §5.7; DPA §4.2); it secures data and notifies on incidents (MSA §4.3, §4.5; DPA Art. VI–VII); and it returns or deletes data on request (MSA §4.6; DPA Art. VIII). Pearl will also sign state-required addenda. This page summarizes Pearl’s posture for major state laws in plain language; it is not a legal opinion on any specific contract.
New York — Education Law §2-d
New York Education Law §2-d and its implementing regulations (8 NYCRR Part 121) apply to Pearl as a “third-party contractor” that receives personally identifiable information from New York educational agencies — K-12 school districts, the State Education Department and other state agencies, and BOCES. (Section 2-d governs elementary and secondary education agencies, not higher-education institutions.) For New York customers, Pearl signs the educational agency’s Parents’ Bill of Rights for Data Privacy and Security, together with the required supplemental information, and maintains a data security and privacy program aligned with the NIST Cybersecurity Framework, the standard §2-d adopts (DPA §6.1). Pearl’s bright-line student-data commitments (no sale, no targeted advertising, no unauthorized profiles) and its security and breach-notification commitments map to §2-d’s requirements (MSA §5.7, §4.3, §4.5; DPA §4.2, Art. VI–VII). Section 2-d does not require a third-party contractor to register with the State; obligations are met through the agreement with each educational agency.
Illinois — SOPPA
As an “operator” under the Illinois Student Online Personal Protection Act (SOPPA), Pearl complies with SOPPA’s operator duties — maintaining reasonable security, honoring the prohibitions on selling data and on targeted advertising to students, and deleting data at the school’s direction — and signs the district’s required written agreement, often the Illinois NDPA (MSA §4.3, §4.5, §4.6, §5.7; DPA §4.2, Art. VI–VIII). Under SOPPA, the school district publicly posts the data-sharing information (including the agreement and the categories of data shared); SOPPA does not require operators to register with the State or with an alliance. Pearl provides the district the information it needs for that posting.
California — SOPIPA
Pearl complies with California’s Student Online Personal Information Protection Act (SOPIPA) as an operator: Pearl does not sell Student Data, does not engage in targeted advertising to students, does not amass student profiles for non-educational purposes, maintains reasonable security, and deletes data at the school’s direction (MSA §5.7, §4.3, §4.6; DPA §4.2, Art. VIII). SOPIPA applies directly to operators; it does not by itself require signing an addendum and does not require operator registration with the State. Where a California district requires its own data privacy agreement, Pearl will sign it.
Other States (Colorado, Connecticut, Texas, Virginia, and Similar)
Many states — including Colorado, Connecticut, Texas, and Virginia — impose comparable requirements: a signed data privacy agreement, prohibitions on selling data and on advertising to students, reasonable security, breach notification, and data deletion. Pearl’s MSA and DPA already provide these protections (MSA §5–6; DPA Art. IV–VIII), and Pearl will sign the state- or district-required addendum. As with Illinois and California, these laws generally place any state registration or public-posting duties on the school district rather than on the vendor.
Requesting State-Specific Terms
To request Pearl’s signature on a state-required addendum, or to ask how Pearl meets a specific state law, use the contact form on poweredbypearl.com (select the privacy or student-data request type), your Pearl account contact, or privacy@poweredbypearl.com. See also NDPA and State Addenda and the Pearl Compliance Overview.
