EduLens and Illinois SOPPA
What Illinois SOPPA requires of school software vendors: written agreements with every operator, public posting of those agreements, annual data element disclosure, breach notification, and prohibitions on selling student data or targeted advertising.
- Governing law
- 105 ILCS 85 — Student Online Personal Protection Act
- Status
- Comprehensive statute
What does Illinois SOPPA require of school software vendors?
Illinois SOPPA, the Student Online Personal Protection Act, requires school districts to enter a written agreement with every operator that receives student data, and to post those agreements publicly along with an annual list of the data elements collected. Operators may not sell or rent student data or use it for targeted advertising, must maintain reasonable security practices, and must notify the district of a breach. SOPPA took effect July 1, 2021.
Last reviewed August 2026
What applies in Illinois
- Written agreement with every operator
- A district may not share covered information with an operator without a written agreement in place first. There is no informal path — the paperwork precedes the data.
- Public posting
- Districts must post those agreements online, and must annually post the data elements they collect, maintain, or disclose. Your agreement becomes a public document.
- No sale, rent, or targeted advertising
- Operators may not sell or rent covered information, and may not use it to serve targeted advertising. Data may be used only for K-12 school purposes.
- Reasonable security practices
- Agreements must include a provision that the operator maintains reasonable security procedures and practices appropriate to the data.
- Breach notification
- Operators must notify the district of a breach of covered information within the timeline SOPPA specifies, and districts carry their own downstream notification duties to parents.
How Illinois districts actually paper this
Most Illinois districts do not negotiate bespoke contracts. They use the Illinois student data privacy alliance within the Student Data Privacy Consortium, which maintains a standard agreement and a public registry of signed vendors.
The practical effect for a vendor: if you are already in the registry with a signed agreement, a district can adopt the existing agreement and move on. If you are not, the district has to run a new agreement through counsel, which adds weeks and gives a cautious business official a reason to wait.
Why the public posting requirement matters more than it sounds
SOPPA makes district agreements public documents. That means your data privacy agreement is readable by any parent, any competitor, and any other district evaluating you.
It also means districts are visibly accountable for who they share data with. An Illinois technology director has a strong incentive to choose vendors whose agreements they are comfortable publishing, which favors vendors with clear sub-processor disclosure and plain retention terms.
What Illinois districts ask vendors first
In practice the first three questions are: are you in the registry, what data elements do you collect, and who are your sub-processors. A vendor who can answer all three in one email moves faster than one who has to assemble it.
The data element list is worth preparing in advance, since districts must post it annually. Giving them a clean list rather than a link to a privacy policy saves their staff work and makes you easier to say yes to.
What EduLens provides a Illinois district
- A data privacy agreement covering the required SOPPA provisions, ready for district counsel review
- A documented list of the data elements EduLens collects, by module, for the district posting requirement
- Sub-processor disclosure naming every third party that touches district data
- Configurable retention policies and complete deletion workflows
- Full access audit trails showing who viewed which student record and when
- Breach notification commitments written into the agreement
- No sale of student data, no rental, and no advertising of any kind in the platform
Illinois student data privacy — common questions
Compliance under SOPPA is established by a signed written agreement between the district and the operator, so it is a district determination rather than a vendor claim. EduLens can sign an agreement containing the provisions SOPPA requires, provides the data element list districts must post, and discloses sub-processors. We do not sell or rent student data and run no advertising.
SOPPA is directed at public school districts. Nonpublic schools in Illinois are generally outside its scope, though many adopt similar agreements voluntarily and their insurers or dioceses may require comparable terms. Confirm with your own counsel.
It depends almost entirely on whether an agreement already exists in the state alliance registry. With an existing agreement a district can often move in days. Without one, expect counsel review and a timeline measured in weeks.
Other states
This summary reflects our reading of publicly available statutes and state guidance as of August 2026. It is not legal advice. Student privacy law changes and district requirements vary. Confirm current obligations with your district's counsel and technology office before making a purchasing decision.
Evaluating EduLens for a Illinois school?
We'll send the data privacy agreement, data element inventory, and sub-processor disclosure before the first call if that's useful.