Illinois SOPPA Compliance: The Plain-English Guide
Illinois SOPPA compliance means following the Student Online Personal Protection Act, 105 ILCS 85, the state’s student data privacy law. Illinois lawmakers passed the original version in 2017. Public Act 101-0516 rewrote and expanded it, effective July 1, 2021.
SOPPA does not replace the federal FERPA law. It sits on top of it. FERPA sets the federal baseline for education records. SOPPA adds Illinois-specific rules for schools, districts, the Illinois State Board of Education (ISBE), and the EdTech vendors that touch student data.
If you run IT for an Illinois district, or you sell software into Illinois schools, SOPPA is not optional reading. It sets real deadlines, real contract requirements, and a real enforcement path through the Illinois Attorney General.
Key Takeaways
- SOPPA (105 ILCS 85) is Illinois’s state student-data-privacy law. It layers on top of FERPA, not in place of it.
- SOPPA’s operator duties apply to K-12 only. Higher education is outside its scope.
- Any EdTech vendor receiving student data needs a signed Data Privacy Agreement (DPA) before that data can move.
- Vendors must tell the school about a breach within 30 calendar days. Schools then have 30 calendar days to tell parents.
- Districts can name a privacy officer, and that role can be combined with the records-custodian job.
Who SOPPA Applies To
SOPPA governs three groups: Illinois public schools and districts, ISBE, and “operators.” An operator is any company running a website, app, or online service that schools use.
Not every EdTech company that touches a classroom counts as an operator under the law. SOPPA uses a specific two-part test.
The Two-Part Operator Test
A vendor is an “operator” under SOPPA only if both of these are true:

- The vendor has actual knowledge its product is used primarily for K-12 school purposes.
- The product was designed and marketed for K-12 school purposes.
This test matters for vendor scoping. A general-purpose tool, like a mainstream video conferencing or file-storage product, can fall outside SOPPA’s operator definition even when a school uses it. A purpose-built classroom app cannot dodge the definition just because a few non-school users sign up too.
K-12 Only, Not Higher Education
SOPPA’s operator duties are scoped to “K through 12 school purposes.” That phrase covers purposes a school, teacher, or district directs, or that customarily happen at their direction.
The law does not extend those duties to higher education. A vendor whose product only serves an Illinois college or university is not an “operator” under SOPPA, even though FERPA itself does cover postsecondary institutions. This is one of the clearest differences between the two laws, and it trips up vendors who assume “student privacy law” always means the same coverage.
What Counts as Covered Information
SOPPA protects “covered information”: personally identifiable information that is not otherwise publicly available. It has to be created or provided by a student, parent, or school employee, or gathered by an operator running a K-12 site, service, or app.
In practice, covered information can include things like:
- A student’s name and contact details
- Grades, transcripts, and test results
- Discipline and behavior records
- Special education records
- Biometric data
- Geolocation data captured through a school-used app or device
The point of the definition is broad coverage. If it identifies a specific student and isn’t already public, treat it as covered information until you have a reason not to.
What SOPPA Requires From Operators
Once a company qualifies as an operator, SOPPA imposes four core duties. Each one has its own statute reference and its own deadline or requirement.
| Operator Duty | Statute | What It Requires |
|---|---|---|
| No targeted ads, profiling, or sale | 105 ILCS 85/10 | Cannot use covered information for targeted advertising, non-educational profiling, or sale of student data |
| Written Data Privacy Agreement | 105 ILCS 85/15 | A signed or click-wrap DPA must exist before any covered information transfers |
| Breach notice to the school | 105 ILCS 85/15 | Must notify the district within 30 calendar days of determining a breach occurred |
| Delete or return data | 105 ILCS 85/15 | Must delete or transfer data back once it’s no longer needed, unless a parent consents to retention |
No Targeted Ads, No Profiling, No Selling Student Data
Section 10 draws a hard line. Operators cannot use covered information to target advertising at a student. They cannot build a profile of a student for anything other than a K-12 school purpose. They cannot sell covered information, full stop.
This is the provision that separates a legitimate EdTech tool from one that treats student data as a monetization source.
The Data Privacy Agreement (DPA)
Before any covered information moves from a school, district, or ISBE to an operator, the two sides need a written Data Privacy Agreement. It can be executed electronically or as a click-wrap agreement. This requirement has no direct FERPA equivalent; FERPA leaves vendor obligations to contract language the school chooses to write in.

At minimum, the DPA has to spell out:
- The categories of covered information being shared
- A description of the product or service the operator provides
- A statement that the operator is acting as a FERPA “school official” with a legitimate educational interest, under the school’s direct control
- How costs are split if a breach happens
- A concrete deletion or transfer timeline once the data is no longer needed
Districts also have to make their DPAs available so parents can see them. ISBE keeps a published SOPPA contracts list that districts and vendors use to track which agreements are on file. If your district’s IT partner cannot produce a signed DPA for a vendor touching student data, that is a gap to close now, not at renewal time.
Operator Breach Notification: 30 Days to Tell the School
This clock runs from the vendor to the district, and it runs first. An operator must notify the school of a breach “in the most expedient time possible and without unreasonable delay,” and no later than 30 calendar days after the operator determines a breach occurred.
That 30-day window is separate from, and comes before, the district’s own 30-day clock to notify parents. A vendor cannot sit on a breach and let the district find out on its own timeline. The contract should say so explicitly.
Deleting or Returning Data When It’s No Longer Needed
Once covered information is no longer needed for the purpose it was collected for, the operator has to delete it or transfer it back to the school. The only exception is if a student or parent consents to the operator keeping it.
“We’ll delete it eventually” does not satisfy this duty. The DPA itself has to name a concrete window for deletion or transfer once the operator learns the data is no longer needed.
What SOPPA Requires From Schools and Districts
Operators are not the only party with duties under SOPPA. Schools and districts carry their own obligations, and these are the ones a district’s own IT program has to demonstrate directly.
Reasonable Security Procedures
Section 27 requires Illinois schools and districts to keep “reasonable security procedures and practices that otherwise meet or exceed industry standards” for covered information. That standard is more specific than FERPA’s federal-level “reasonable methods” language, and it is the closer analogue to a real technical requirement.
In practice, this means access controls, monitoring, and documented security practices that a district can point to and defend, not just a policy document in a drawer.
The 30-Day Parent Breach Notice
If a breach involving a student’s covered information happens, the school must notify affected parents within 30 calendar days of learning about it. The notice has to describe what was compromised and provide contact information for relevant agencies.
Pair this with the operator’s own 30-day notice duty above, and a district effectively gets its own clock started only after the vendor’s clock runs. That is exactly why the vendor-to-school notice deadline matters so much in a DPA.
Designating a Privacy Officer
Districts have an option, not a mandate, here. Under Section 27, a school or district may designate a staff member as a privacy officer responsible for SOPPA compliance. That role does not require a new hire. It can be combined with the district’s existing records custodian position.
For a smaller district, this is often the most realistic way to build accountability into SOPPA compliance without adding headcount.
Parent and Eligible-Student Rights Under Section 33
Section 33 gives parents specific rights over their child’s covered information. These rights apply to parents of students in Illinois public schools. Nonpublic school parents are excluded from this section specifically.
- Inspect and review the student’s covered information, whether it’s held by the school, ISBE, or an operator
- Request paper or electronic copies, though the school may charge a capped, reasonable cost
- Request correction of factual inaccuracies
Correction requests carry real deadlines. The school, or the operator or ISBE if they hold the record, has 90 calendar days to fix it. It must then confirm the fix to the parent within 10 business days.
Section 33 does not create a standalone deletion right. That surprises people. If a parent wants covered information deleted from an operator’s system, that request has to run through the school. The school then invokes its own authority under Section 15 and Section 27(g) of the Act. Section 33 preserves whatever rights a parent already holds under the Illinois School Student Records Act and FERPA. It doesn’t replace them.
De-Identified Data: What Operators Can Still Do (Section 25)
SOPPA restricts a lot. It does not ban analytics outright.
Section 25 carves out uses that don’t require restriction, as long as the data isn’t tied to an identified student:
- Improving the educational effectiveness of the operator’s product
- Demonstrating a product’s effectiveness, including in marketing
- Sharing de-identified covered information to help develop or improve other educational sites, services, or apps
- Using recommendation engines to serve content or suggest services to a student
One limit applies to that last point. A recommendation can’t be based on payment from a third party. Outside that, de-identified and aggregate data work continues even under SOPPA’s otherwise tight rules.
What’s Exempt From SOPPA (Section 30)
Not every tool a school uses falls under SOPPA’s operator rules. Section 30 lists specific carve-outs.
| Exemption | What It Covers |
|---|---|
| Law enforcement access | Data shared for law enforcement purposes |
| Adaptive/customized learning | Tools built around individualized instruction |
| General audience sites | Used with a school login, but not built for schools |
| Internet service providers | ISPs acting only as the network conduit |
| Parent-initiated marketing | Operator marketing directly to parents, not from covered information, when the parent starts contact |
| App stores/marketplaces | Providers that just distribute an app |
| Third-party content hosts | Interactive computer service providers, for third-party content only |
| Student’s own data export | A student exporting their own account content |
| Yearbook/class-photo vendors | Operating under a written agreement with the school |
One more point matters as much as the exemption list itself. Section 30 confirms SOPPA doesn’t supersede FERPA or the Illinois School Student Records Act. All three regimes stack. None of them replaces the others.
Enforcement: The Illinois Attorney General Has Real Teeth Here
FERPA enforcement runs through federal funding. SOPPA enforcement runs through a different lever entirely.
SOPPA violations are treated as unlawful business practices under Illinois consumer protection law, and the Illinois Attorney General can enforce them directly.
This is a state-level enforcement path FERPA doesn’t have. Violations count as unlawful practices under the Consumer Fraud and Deceptive Business Practices Act. That statute gives the Illinois Attorney General direct authority to act.
A district or operator can’t treat SOPPA as a lower-stakes cousin of FERPA. SOPPA lacks FERPA’s funding-withholding hammer, but that doesn’t make it weaker. The consumer-protection route brings its own investigative and legal exposure. It doesn’t require a federal complaint to get started.
For what these violations can look like in practice, see real-world FERPA violation examples.
SOPPA vs. FERPA: Side by Side
Both laws protect student data. They regulate different things, in different ways.
| SOPPA (105 ILCS 85) | FERPA (federal) | |
|---|---|---|
| Scope | Illinois only | Nationwide |
| Who’s regulated | IL public schools, districts, ISBE, and K-12 EdTech operators | Any school/institution receiving federal education funds, K-12 through postsecondary |
| Vendor agreement | Mandatory written DPA before data transfer (105 ILCS 85/15) | No mandatory agreement; vendor access typically runs through the “school official” contract exception |
| Breach notification | Vendor to school: 30 calendar days. School to parent: 30 calendar days | No specific breach-notification deadline written into the law |
| Enforcement | Illinois Attorney General, under the Consumer Fraud and Deceptive Business Practices Act | U.S. Dept. of Education’s Student Privacy Policy Office, complaint-driven, funding-based remedies |
Neither law replaces the other for an Illinois district. Both apply, at the same time, to the same student data.
See Where You Stand
Reading through statute sections is one thing. Knowing where your own district’s access controls, vendor agreements, and breach-notification readiness actually stand is another. Take the free 2-minute FERPA & SOPPA Risk-Check. It asks plain-English questions about access controls, vendor agreements, and breach-notification readiness. You’ll get a gap list at the end, no sign-up required.
free 2-minute FERPA & SOPPA Risk-Check
Related Guides
- The FERPA IT Compliance Checklist for Illinois Schools
- FERPA Violation Examples: What They Look Like and How Schools Prevent Them
- EdTech Vendor Vetting Checklist: FERPA & SOPPA Questions to Ask Before You Sign
Frequently Asked Questions
No. FERPA is a federal law that applies nationwide to schools receiving federal education funding. SOPPA is an Illinois state law that adds extra rules on top of FERPA, specifically for Illinois public schools, districts, ISBE, and K-12 EdTech vendors. Neither law replaces the other. Illinois districts have to follow both at the same time.
SOPPA’s core framework targets Illinois public schools, districts, and the Illinois State Board of Education. Section 33’s parent inspection and correction rights specifically exclude parents of students at nonpublic schools. If you run IT for a private school in Illinois, FERPA and the Illinois School Student Records Act are still worth reviewing, but SOPPA’s operator-facing structure is built around the public school relationship.
A data privacy agreement, or DPA, is the written contract SOPPA requires between a school (or district or ISBE) and an EdTech operator before any student data can transfer. It has to list the categories of data being shared, describe the product, confirm the operator is acting as a FERPA school official under the school’s direct control, spell out who pays if a breach happens, and set a concrete deletion or transfer timeline. It can be signed electronically or as a click-wrap agreement.
An operator has to notify the school in the most expedient time possible, and no later than 30 calendar days after it determines a breach occurred. That deadline runs separately from, and before, the school’s own 30-day deadline to notify parents. The vendor’s clock has to run first so the school has time to act on its own notice.
No. SOPPA’s operator duties are scoped to K-12 school purposes only. A vendor whose product is used solely by an Illinois college or university doesn’t meet SOPPA’s definition of an operator, even though FERPA itself does cover postsecondary institutions. Higher education stays under FERPA alone in Illinois.
SOPPA violations count as unlawful practices under the Illinois Consumer Fraud and Deceptive Business Practices Act. That gives the Illinois Attorney General authority to bring enforcement action. It’s a separate, state-level path that runs independently of FERPA’s federal, funding-based enforcement process.
Get Your District’s SOPPA and FERPA Compliance Handled
Reading the statute is the easy part. Building the access controls, vendor vetting process, and breach-notification runbook it demands is harder. That’s what an Illinois district’s IT program actually has to demonstrate. For the technical side of FERPA specifically, see the FERPA IT compliance checklist for Illinois schools.
LeadingIT works with Illinois districts on exactly this. Our school IT compliance services are built around SOPPA and FERPA together. Vendor DPA review runs through our EdTech vendor vetting checklist.
If you want a second set of eyes on where your district stands, book a call or contact us directly.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
