EdLaw nat/us/state/ca/sopipa/README.md

language: en · status: in-force · last checked: 2026-09-04

Student Online Personal Information Protection Act (SOPIPA)

California state law (Cal. Bus. & Prof. Code §§22584–22585) binding operators of online services used primarily for K-12 school purposes. The model for many later state student-privacy laws: it prohibits targeted advertising, non-educational profiling, and sale or disclosure of covered information; requires reasonable security; and requires deletion of covered information at a school or district's request. The current text also interlocks with the California Consumer Privacy Act (CCPA) — see the definitions in the fact document.

Applicability to EdTech

Binds the vendor directly (like COPPA, unlike FERPA) whenever a service is designed, marketed and used for California K-12 school purposes. The prohibitions on targeted advertising, profiling and sale of student data are the statutory backbone of the "signed DPA" clauses US districts request.

Contents

Document Covers
OPERATOR-DUTIES.md §§22584–22585 — definitions, prohibitions, security and deletion duties, permitted uses

Sources

Meta

Built and re-verified mechanically — see tools/us-states: build_ca.py / build_ca.py verify. Do not hand-edit statute text.