EduLens and Connecticut student data privacy
What Connecticut General Statutes 10-234aa through 10-234dd require of educational technology contracts, what provisions must appear in a vendor agreement, and how districts register vendors with the state.
- Governing law
- Conn. Gen. Stat. §§ 10-234aa – 10-234dd
- Status
- Comprehensive statute with mandated contract terms
What does Connecticut student data privacy law require of vendors?
Connecticut General Statutes sections 10-234aa through 10-234dd require school districts to enter written contracts with any educational technology provider that receives student information, and those contracts must contain specific statutory protections for personally identifiable information. Connecticut also operates a state registration process where contractors provide supporting documentation demonstrating compliance.
Last reviewed August 2026
What applies in Connecticut
- Written contract required
- Districts must contract with any educational technology provider whose service captures or accesses student information, data, or records.
- Specific mandated provisions
- The statute prescribes protections that must appear in the contract itself. A generic terms of service does not satisfy this — the required language has to be present.
- State registration and documentation
- Connecticut's registration process asks contractors to supply supporting documentation such as a sample contract, data privacy agreement, or addendum demonstrating compliance.
- Student Data Privacy Pledge as an alternative path
- Districts may contract directly, or may ask vendors to sign onto the Student Data Privacy Pledge as an alternative route.
Connecticut expects documentation up front
Connecticut is more prescriptive than most states about what must appear in the contract, and it maintains a state-level process where vendors supply their agreement and supporting materials.
For a vendor this is actually an advantage: the requirements are written down. A vendor who arrives with a compliant agreement, a data element list, and sub-processor disclosure has answered most of what a Connecticut district will ask.
Prescriptive law favors prepared vendors
When a statute specifies contract language, districts stop improvising and start checking boxes. That rewards vendors who have already assembled the documentation and penalizes those who treat each district as a fresh negotiation.
It also means a Connecticut district can move quickly once satisfied, because the standard is external and objective rather than a matter of local comfort.
What EduLens provides a Connecticut district
- A data privacy agreement written to carry the provisions Connecticut requires, for district counsel review
- Documentation package: data element inventory, sub-processor disclosure, retention and deletion policy, security overview
- Configurable retention and complete deletion workflows
- Complete access audit trails
- No sale of student data, no rental, and no advertising in the platform
Connecticut student data privacy — common questions
Connecticut requires specific provisions to appear in the contract between the district and the provider, so satisfaction is determined by the executed agreement rather than by a vendor assertion. EduLens provides an agreement written to carry those provisions along with the supporting documentation Connecticut districts are asked to collect.
It is a public commitment by education technology providers to a set of student data handling principles. Connecticut allows districts to use a signed pledge as an alternative to direct contracting in some circumstances. Districts should confirm which path their counsel prefers.
Other states
This summary reflects our reading of publicly available statutes and state guidance as of August 2026. It is not legal advice. Student privacy law changes and district requirements vary. Confirm current obligations with your district's counsel and technology office before making a purchasing decision.
Evaluating EduLens for a Connecticut school?
We'll send the data privacy agreement, data element inventory, and sub-processor disclosure before the first call if that's useful.