Before the First Bell: What California's Student-Data Rules Already Require of Your EdTech Contracts

CoSN's 2026 survey put it at 79 percent: districts nationally that now report AI guidelines, up from 57 percent a year earlier. That is real progress, and it shows districts moving from improvisation toward something that reads like governance. But a guideline and a contract are different documents. A guideline directs district behavior. The contract, and the statutes underneath it, govern what a vendor may do with student data. As tools get onboarded for the new school year, that second document is the one that often goes unread.

A policy guides your staff. It sets expectations for teachers, students, and administrators, and it is a necessary thing. It has no purchase on what an edtech company does with student data once that data leaves your network. The vendor is not governed by your acceptable-use policy. The vendor is governed by the contract it signed and by the statutes that bind operators directly. In California, the first of those is a section of the Education Code that has governed these contracts since 2015 and that most districts have not reread since.

The contract statute for covered vendor relationships: Education Code § 49073.1

California enacted § 49073.1 through AB 1584 in 2014. It requires specified terms in covered contracts: an agreement with a third party for the digital storage, management, and retrieval of pupil records, or for digital educational software that authorizes a vendor to access, store, and use pupil records. That reaches a large share of the software a district runs, though not literally every tool. The statute also defines "local educational agency" to include school districts, county offices of education, and charter schools, so the obligations reach the county level as well.

The statute does not leave the required terms to negotiation. It lists them. Read against the current codified text, a covered contract must contain:

Ownership. A statement that pupil records remain the property of and under the control of the district.

Pupil-generated content. Where applicable, a description of how pupils can keep possession and control of their own pupil-generated content, including options to move it to a personal account.

A purpose limitation. A prohibition on the vendor using information in the pupil record for any purpose other than those required or specifically permitted by the contract. This is a use limit tied to the contract, not a freestanding ban on all commercial activity.

Parent access and correction. A description of how a parent, guardian, or eligible pupil reviews personally identifiable information and corrects errors.

Security, with designated and trained people. A description of the actions the vendor will take to secure the records, including the designation and training of the responsible individuals. The statute adds a line worth reading twice: meeting this requirement does not, by itself, absolve the vendor of liability if records are disclosed. The paperwork is not a defense.

Breach notification. A description of the procedures for notifying the affected parent, guardian, or eligible pupil of an unauthorized disclosure.

Non-retention at contract end. A certification that a pupil's records will not be retained or available to the vendor once the contract is complete, and a description of how that is enforced. Note the trigger: completion of the contract, not the day a student leaves the district. Pupil-generated-content accounts a student chooses to keep are the exception.

Joint FERPA compliance. A description of how the district and the vendor will jointly comply with the federal Family Educational Rights and Privacy Act. The statute names FERPA. It does not, in its own text, require a joint COPPA-compliance clause, though COPPA still applies independently.

No targeted advertising. A prohibition on the vendor using personally identifiable information in pupil records to engage in targeted advertising.

One more feature matters for how you enforce it. A noncompliant contract is not automatically void. Under subdivision (c), it becomes void only if, upon notice and a reasonable opportunity to cure, the noncompliant party fails to fix the defect, at which point all pupil records must be returned. Any party to the contract may give that notice. It is a real remedy, but it runs through notice and a cure period, not an instant nullification. The practical takeaway is unchanged: the clauses either appear in your agreements or they don't, and finding out in August beats finding out in a breach.

The federal floor moved: the amended COPPA Rule

While § 49073.1 sat unchanged, the federal ground shifted. The FTC's amended COPPA Rule reached its compliance deadline for most provisions on April 22, 2026. Two points matter for schools.

First, the treatment of third-party disclosures. The amended Rule treats a disclosure of a child's personal information to a third party for advertising, for monetary or other consideration, or for training or developing artificial intelligence as not integral to the service. A disclosure like that now requires separate verifiable parental consent. That consent may be obtained in the same flow as consent to ordinary collection and use, but it must be a distinct affirmative choice. This is about disclosing data to third parties, not about policing every internal feature a vendor ships, so read it for what it is: a consent gate on the handoff of children's data for advertising, consideration, or AI training.

Second, the school-authorization question. Edtech operators have long leaned on the idea that a school can consent on parents' behalf. The FTC proposed a formal school-authorization exception in its 2024 rulemaking, then did not finalize the proposed edtech and school-authorization amendments at this time, and said it would continue enforcement under existing guidance. That guidance limits school authorization in the under-13 context to educational purposes. Districts should not assume ordinary school authorization covers a third-party AI-training disclosure. The maximum civil penalty for a COPPA violation has been up to $53,088 per violation since January 2025. COPPA directly regulates the covered operator. That does not remove the district's procurement or contractual exposure.

The California layer: KOPIPA

Sitting alongside these is KOPIPA, California's K-12 student online privacy law, formerly known and still often referenced as SOPIPA. It binds covered operators directly, whether or not your contract restates it. KOPIPA prohibits using covered student information to engage in targeted advertising, selling that information, and amassing profiles of students except in furtherance of K-12 school purposes. It is not new and not controversial. It is another set of obligations your vendors carry that a policy document can neither create nor waive.

## What AB 1159 would add, and why the stakes rise

AB 1159, Assemblymember Dawn Addis's student-personal-information bill, is the part of this still in motion. It has advanced through its Senate policy committees and is set for Senate Appropriations on August 3. It is not law yet, and details can change, so treat what follows as "if enacted in its current form."

AB 1159 does more than re-enforce the existing rules. It adds a substantive, AI-specific prohibition: covered operators could not use covered student information to train a generative AI system or service, or to develop an artificial intelligence system. It broadens the reach of the covered-operator rules under KOPIPA and ELPIPA. It enacts a parallel regime for higher education, the Higher Education Student Information Protection Act, or HESIPA. And it creates a private enforcement path.

That last piece is the change in kind. Today, enforcement of California's student-privacy statutes runs through regulators and the terms of the contract itself. AB 1159 would permit a pupil or student, or a parent or guardian, who suffers actual damages as a result of an operator's noncompliance to bring an action, on their own behalf and on behalf of a similarly situated class. The relief on offer is the greater of actual damages or $500 per plaintiff per violation, plus injunctive relief, punitive damages, and reasonable attorney's fees and costs. The action is subject to a 45-day written notice-and-demand process, with different cure provisions for individual and class claims. It moves the risk from "a regulator might notice" to "a plaintiff might file," and it attaches that risk to AI training on student data, the exact question districts are least equipped to audit in a hurry.

The honest read: AB 1159 would layer a new prohibition and a new enforcer on top of controls that already exist. If your contracts already carry the § 49073.1 terms, and your vendors already comply with COPPA and KOPIPA, the bill is a smaller lift for you. If they don't, it converts a quiet gap into a nameable claim with a dollar figure attached.

Higher education, briefly

Higher education should not treat this as a K-12 problem. AB 1159's HESIPA provisions are written to become operative July 1, 2027, which is under a year out, not a comfortable horizon. HESIPA would extend KOPIPA-style protections, including the AI-training prohibition, to students at higher-education institutions. Higher education also has a different data-governance environment. HESIPA would be a separate statutory regime, while § 49073.1's contract requirements remain K-12-specific. Institutions that inventory their AI-enabled vendor contracts now will spend 2027 refining. The ones that wait will spend it discovering.

The moving target

A fair caveat. Much of the AI-specific material in this space is guidance, not mandate. The California Department of Education's AI guidance frames expectations and expressly says it is nonmandatory; it does not carry the force of § 49073.1 or COPPA. Reasonable people land in different places on how permissive a district's AI posture should be, and this piece takes no position on that. The binding obligations are the statutes and the contract. Those are the ones worth auditing before the guidance catches up, because the guidance will keep moving and the statutes are already here.

Before the first bell: a working checklist

Use the weeks before the year starts to close the gap between the policy you have and the contracts you signed.

Pull the contracts. Identify third-party contracts for the digital storage, management, and retrieval of pupil records, and for digital educational software that authorizes provider access to, storage of, or use of those records. That is your § 49073.1 population.

Read for the terms, not the vibe. For each contract, confirm the specific § 49073.1 clauses are present: LEA ownership and control; pupil-generated-content options where applicable; the contract-purpose limitation; parent review and correction; security with designated and trained responsible individuals; breach-notification procedures; non-retention at contract completion; a joint FERPA-compliance description; and the targeted-advertising prohibition.

Ask the AI question directly. For any tool with AI features, ask in writing whether student information is used to train a generative AI system or to develop an AI system, whether the vendor retains it, and whether it is disclosed to any third party. Get the answer in the contract, not an email.

Check the consent chain. For a covered operator handling an under-13 child's information, a third-party disclosure for advertising, monetary or other consideration, or AI training or development requires separate verifiable parental consent. Districts should not assume ordinary school authorization supplies that distinct consent.

Fix the renewals first. The tools you are re-signing this month are the fastest to correct. Make the missing § 49073.1 terms a condition of renewal, and define contractual remedies for breach.

Date your review. Write down when you checked and against what. This area moves, AB 1159 has an August hearing, and a governance program that cannot show its work is a policy on paper, not compliance.

The back-to-school question is not whether your district has an AI policy. It is whether the agreements being signed this month say what the law already requires. AB 1159 would not create a procurement gap. It would make a preexisting one more consequential, by adding an express AI-use prohibition and a private enforcement path on top of it.

Next
Next

The HIPAA Minimum Necessary Standard: History, Enforcement, and What AI Actually Changes