SOPIPA is California's student privacy law, and the template most other US states adopted. Where FERPA regulates what a school may disclose, SOPIPA regulates the operator directly: it prohibits targeted advertising to students, profiling for non-educational purposes, and the sale of student data, and requires deletion at a school's request.
SOPIPA
Statute United States (California, and state adoptions)
SOPIPA shifted the obligation. FERPA governs the institution and reaches vendors through contract; SOPIPA binds the operator of the service directly, regardless of what the contract says. That change — plus adoption in some form by a majority of US states — is why student data is one of the more tightly constrained categories in American privacy law.
- No targeted advertising - Advertising to students based on information gathered through the service is prohibited outright.
- No profiling for other purposes - Profiles may not be built for anything other than K-12 educational purposes.
- No sale of student data - A flat prohibition rather than an opt-out.
- Deletion on request - A school can require deletion, which has to propagate to every system holding the data.
- Binds the operator directly - The vendor is liable on its own account, not only through the district’s contract.
SOPIPA and its state analogues are the reason the K-12 segment carries obligations closer to a regulated financial market than to ordinary SaaS — and The State of Education & EdTech APIs finds that segment publishing a machine-readable contract 15.9% of the time, with a governance facet of 3.3. A deletion obligation that has to propagate across every downstream system is an integration problem, and the interfaces that would make it tractable are largely unpublished.