01-projects/printables-product

Scribble Works school phase — FERPA and the state-by-state student-privacy plan

2026-09-02·research-note·status: reference
printables-productscribble-worksferpastudent-privacycoppalegalschool-phase

Scribble Works school phase: FERPA and the state-by-state plan

Companion to [[2026-09-02-account-relationship-model-decision]], split out of it so the v2 decision brief stays a v2 decision brief. Acronyms used here: DPA (data privacy agreement, the contract a district hands a vendor), LEA (local education agency, meaning a school district), SDPC (Student Data Privacy Consortium), NDPA (its National Data Privacy Agreement), TSDS (Texas Student Data System), FDUTPA (Florida Deceptive and Unfair Trade Practices Act), TEA (Texas Education Agency). Founder ruling 27, 2026-09-02 11:22 ET: "We will have more legal to cover and we can plan it out state by state." This is that plan. None of it gates v2, because today a teacher is an ordinary household and we receive no school data. It becomes live when the §1a tells fire.

Not legal advice. Rows were read against primary text on 2026-09-02 except where a row says otherwise; items that could not be verified are named as unverified rather than filled with a plausible-sounding citation. The Texas coverage test is the one substantive gap.

The law

What FERPA would mean

The Family Educational Rights and Privacy Act (FERPA) binds schools; it would reach us only through its school-official exception, §99.31(a)(1)(i)(B) — perform a service the school would otherwise staff, sit under the school's direct control as to education records, honor §99.33(a)'s redisclosure limit. (The commonly-cited fourth condition, the annual notification naming who counts as a school official, lives at §99.7(a)(3)(iii); the difference matters in a contract.) None of it attaches today, because we receive no education records. Per ED's 2014 guidance a signed contract is the usual way direct control is established and terms of service can suffice; ED's Model Terms of Service previews the demands. Note the Federal Trade Commission (FTC) never codified a school-consent exception. It was dropped from the 2025 Children's Online Privacy Protection Act (COPPA) final rule pending the Department of Education's own rulemaking (90 FR 16918, preamble Part I.A), so school consent lives in FTC staff guidance (COPPA FAQ Section N) only.

The state table

Order of work: Florida first (Ray Data LLC's principal place of business and registered foreign-entity state — ruling 23), then the largest markets. Verified against primary text 2026-09-02.

State Student-privacy statute What it obligates a vendor Breach clock to the school DPA norm Notes
Florida Florida Student Online Personal Information Protection Act (the Florida operator act; do not shorten it to SOPIPA, which in this note means California's), Fla. Stat. §1006.1494 (SB 662, eff. 7/1/2023) The trigger is disjunctive (§1006.1494(1)(e)): an operator is one with actual knowledge the service "is used primarily for K–12 school purposes, or the site, service, or application was designed and marketed for K–12 school purposes." School-facing marketing alone can trigger it. Bans targeted ads, profiling outside K-12 purposes, and sharing, selling or renting covered information; requires reasonable security. Deletion at the conclusion of the course and no later than 90 days after a student is no longer enrolled, upon notice by the school district, yielding to express parent consent to retain. No written-agreement-before-collection duty. §1006.1494 sets none; it runs through Fla. Stat. §501.171(6)(a) — third-party agent notifies the covered entity within 10 days. Florida Student Privacy Alliance (SDPC); Fla. Admin. Code R. 6A-1.09550 makes districts put FERPA/COPPA/SOPIPA compliance and re-disclosure bans into vendor contracts. Home state, and the one that does not fit the "we are a parent product" argument, because of the marketing prong. Whether the school-to-parents growth test trips it is a live question for counsel, not a v3 one. Enforcement is FDUTPA via the Dept. of Legal Affairs; no private right of action. §1002.22 and §1002.222 bind districts, not us.
California Student Online Personal Information Protection Act (SOPIPA), Cal. B&P §22584 Operator test at (a)(7) is three-part: actual knowledge + used primarily for K-12 + designed and marketed for K-12. Bans ads, profiling, sale; requires security and deletion on LEA request. SOPIPA sets none; Civ. Code §1798.82(a)(2)(A) sets 30 calendar days (SB 446, eff. 1/1/2026). Educ. Code §49073.1 mandates a written LEA contract with nine enumerated terms; CA-NDPA in use. The three-part test is conjunctive, which makes it the escape hatch for a parent-marketed product; the classroom tier would fail it. Note the contrast with Florida, whose test is disjunctive. Pre-K has its own chapter (§§22586–22587).
Texas Educ. Code ch. 32 subch. D "Student Information," §§32.151–32.157 (H.B. 2087, eff. 9/1/2017) §32.152 bans ads, profiling, sale and rental; §32.155 security plus TSDS identifier masking (H.B. 1525, eff. 9/1/2023); §32.156 deletion within 60 days of a district request. No agreement-before-collection duty. Who the subchapter covers (§32.151, the trigger) was not reached in primary text — the Texas statutes site now serves a JavaScript shell. Treat the coverage test as unverified. Subch. D sets none; Bus. & Com. Code §521.053(c) says "immediately" — unmeasurable. TXSPA; TX-NDPA v1r6 with Exhibit G Texas terms, which imposes 72-hour notice to the LEA by contract. The contract clock, not the statute, is the real engineering SLA here.
New York Educ. Law §2-d + 8 NYCRR Part 121 §121.6(a) security and privacy plan in every contract; §121.3(b)–(c) Parents' Bill of Rights plus per-contract supplemental information; alignment with the National Institute of Standards and Technology Cybersecurity Framework; no sale or marketing use. 7 calendar days — 8 NYCRR §121.10(a), not §2-d itself (the statute says only "without unreasonable delay"). NYSED-driven §2-d / Part 121 riders. No SDPC alliance confirmed either way. Strictest of the five. Penalties split by violation type: §121.11(a) covers failure to notify of a breach at the greater of $5,000 or up to $10 per student, teacher and principal, capped by General Business Law §899-aa(6)(a); all other §2-d violations fall under §121.11(b) at up to $1,000 / $5,000 / $10,000 by offense count.
Illinois Student Online Personal Protection Act (SOPPA), 105 ILCS 85 §15(4): a written agreement with the school must exist BEFORE covered information is transferred, designating us a school official under direct control and allocating breach costs. The duty opens "Except for a nonpublic school," so private schools sit outside it. §10 bans selling or renting student information. 30 calendar days (§15(5)); the school posts the agreement publicly within 10 business days (§27(c)). IL-NDPA v1.0a. The "before transfer" rule means a teacher at an Illinois public school cannot simply start using a school-facing tier; the nonpublic-school carve-out means a private-school teacher can.

Three findings worth carrying. (1) Only Illinois and New York put the vendor-to-school clock inside the student-privacy law; Florida, California and Texas route it through the general breach statute, so a vendor reading only the student-privacy act concludes it has no notification duty and is wrong. (2) The coverage tests are not interchangeable. California's is conjunctive and forgiving to a parent-marketed product; Florida's is disjunctive and can be tripped by school-facing marketing alone. Summarizing the five as one shared hook is the mistake to avoid. (3) Florida's law is real and vendor-facing, so the home state is not the easy one by default.

Still unverified, and deliberately not filled: Texas §32.151, the coverage/trigger section (the state statutes site serves a JavaScript shell to non-browser fetches); the FL-NDPA version and originating district (registry is login-gated); whether an SDPC New York alliance exists; what Texas' §32.155(b) "state-required student data sharing agreement" actually is (the TEA page 404s).

How to work it. One state at a time, in the order above, each gated on a real prospect in that state — not a speculative sweep. The reusable artifact is a completed National Data Privacy Agreement (NDPA) v2.2, Nov 19 2025 package (privacy.a4l.org) with its Exhibit E "General Offer": sign once and any district in that alliance can countersign, which turns one negotiation into a credential. Standing NDPA terms to price in before signing anything: the local education agency (LEA) owns the data, purpose limitation, no sale/targeted ads/profiling, subprocessors bound "no less stringent," annual audit against a recognized framework, breach notice within 72 hours, return-or-destroy in 60 days. The shortest clock governs, and 72 hours is a real obligation for a one-person company — that, not the schema, is the actual cost of the school phase.

Related