If your athletic department uses ANY software that holds student data — rosters, contact info, transcripts, medical clearances, parent emails — the district legal office requires a Data Privacy Agreement (DPA) with that vendor. No DPA, no data, no exceptions in most districts.
What a DPA covers
- Data ownership. Your district owns the data. Vendor cannot sell it or use it for purposes beyond running the service.
- Data deletion. When the contract ends, the vendor must delete all student data within a specified window (usually 30–90 days).
- Subprocessors. Any third-party services the vendor uses (cloud hosting, email, analytics) must be listed and held to the same standards.
- Breach notification. If the vendor\'s systems are compromised, they must notify the district within a specified window (often 24–72 hours).
- Audit rights. The district can audit the vendor\'s data handling.
How DPAs interact with FERPA
FERPA is the federal law. A DPA is the local contract that operationalizes FERPA compliance. FERPA gives parents the rights; a DPA codifies how the vendor will respect them.
What to check before signing
- Does the vendor have a template DPA, or do you have to push them to write one? Vendors that handle student data should have one ready.
- Does the DPA reference state-specific data privacy laws (e.g., California\'s SOPIPA, NY\'s Ed Law 2-d, Illinois\'s SOPPA)? Generic DPAs often fail district legal reviews.
- Where does the data live? US-based hosting is preferred by most district legal teams; some districts ban data leaving the US entirely.
- What\'s the deletion timeline at contract end? 30 days is standard; longer than 90 days is a flag.
How Lightning handles this
Lightning for Schools ships with a pre-built, FERPA-aligned DPA template. We sign your district\'s standard DPA before any student data is loaded. The DPA covers all subprocessors (US-based cloud hosting), 30-day data deletion at contract end, 24-hour breach notification, full audit rights.