NDPA v2.2 Standard — clause map
1.1 Purpose — school-official designation
The purpose of this DPA is to describe the duties and responsibilities to protect Student Data including compliance with all applicable federal and state privacy laws, rules, and regulations, all as may be amended from time to time. In performing the Services, the Provider shall be considered a School Official with a legitimate educational interest, and performing Services otherwise provided by the LEA. With respect to its use and maintenance of Student Data, Provider shall be under the direct control and supervision of the LEA as set forth in this DPA and the Service Agreement.
The Exhibit C definition ties this to the regulation:
School Official: For the purposes of this DPA and pursuant to FERPA 34 CFR § 99.31(a)(1)(i)(B), a School Official is a contractor that: (1) Performs an institutional service or function for which the agency or institution would otherwise use employees; (2) Is under the direct control of the agency or institution with respect to the use and maintenance of Student Data including Education Records; and (3) Is subject to FERPA 34 CFR § 99.33(a) governing the use and re-disclosure of Personally Identifiable Information from Education Records.
4.4 No disclosure / no sale
Provider acknowledges and agrees that it shall not sell or disclose any Student Data or any portion thereof, including without limitation, user content or other non-public information and/or Personally Identifiable Information contained in the Student Data.
Exceptions (4.4.1): disclosure directed or permitted by the LEA or the DPA; the no-sale provision does not apply to a Change of Control; disclosure pursuant to judicial order, subpoena or warrant.
4.6 Disposition of Student Data
Upon written request from the LEA, Provider shall dispose of or provide a mechanism for the LEA to transfer Student Data obtained under the Service Agreement, within sixty (60) days of the date of said request and according to a schedule and procedure as the Parties may reasonably agree.
At the termination of this DPA, the Provider shall, unless directed otherwise by the LEA, dispose of, or delete Student Data obtained by the Provider under the Agreement within sixty (60) days of termination (unless otherwise required by law).
The duty does not extend to De-Identified Data or transferred Student-Generated Content; Exhibit "D" carries any special disposition instructions.
4.7 Advertising limits
Provider is prohibited from using, disclosing, or selling Student Data to (a) inform, influence, or enable Targeted Advertising; (b) develop a profile of a student, family member/guardian, or group, for any purpose other than providing the Service to LEA; or (c) for any commercial purpose other than to provide the Service to the LEA, or as authorized by the LEA or the parent/guardian. Targeted Advertising is strictly prohibited.
Carve-outs: adaptive/customized learning (including personalised learning recommendations); non-targeted product recommendations (not available where the Provider relies on the LEA to provide COPPA consent); notices of new education product updates.
5.2 Security Audits
Provider will conduct a security audit or assessment no less than once per year, and upon a Data Breach. Upon 10 days' notice and execution of confidentiality agreement, Provider will provide the LEA with a copy of the audit report, subject to reasonable and appropriate redaction.
5.3 Data Security
The Provider agrees to utilize administrative, physical, and technical safeguards designed to protect Student Data from unauthorized access, disclosure, acquisition, destruction, use, or modification. The Provider shall adhere to any applicable law relating to data security of Student Data. The Provider shall implement an adequate Cybersecurity Framework that incorporates one or more of the nationally or internationally recognized standards set forth in Exhibit "F".
Exhibits
| Exhibit | Contents |
|---|---|
| A | Products and services |
| B | Schedule of student data (data elements) |
| C | Definitions |
| D | Special instructions for disposition of data |
| E | General offer of privacy terms (extends the DPA to other LEAs) |
| F | Adequate cybersecurity frameworks |
| G | Supplemental state terms |
No AI/model-training clause
Verified absence: the v2.2 Standard text contains no provision on artificial intelligence or the training of machine-learning models (the terms "artificial intelligence", "AI", "machine learning" and "model training" do not appear in the document). District requirements prohibiting AI training on student data are therefore custom additions (typically via Exhibit G supplemental terms or service-agreement clauses), not standard NDPA terms.
Sources
- SDPC — NDPA v2.2 Standard Version (PDF) — archived copy: sources/NDPA_v2-2_STANDARD_WEB.pdf (retrieved 2026-09-04)
- SDPC — National DPA page (all v2.2 variants + usage guidelines)
Meta
Key clauses quoted verbatim from the NDPA v2.2 Standard Version PDF (extracted mechanically from the published document; line breaks joined). Article/section numbers are the NDPA's own. Clause headings carry derived attribute anchors from those printed section numbers ({#section-4-4} here corresponds to §4.4 in the PDF); the PDF has no per-provision fragment ids of its own.