Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Illinois SOPPA Compliance: The Plain-English Guide

August 11, 2026
hero-illinois-soppa-compliance-guide-1.png

Illinois SOPPA compliance means following the Student Online Personal Protection Act, 105 ILCS 85, the state’s student data privacy law. Illinois lawmakers passed the original version in 2017. Public Act 101-0516 rewrote and expanded it, effective July 1, 2021.

SOPPA does not replace the federal FERPA law. It sits on top of it. FERPA sets the federal baseline for education records. SOPPA adds Illinois-specific rules for schools, districts, the Illinois State Board of Education (ISBE), and the EdTech vendors that touch student data.

If you run IT for an Illinois district, or you sell software into Illinois schools, SOPPA is not optional reading. It sets real deadlines, real contract requirements, and a real enforcement path through the Illinois Attorney General.

Key Takeaways

  • SOPPA (105 ILCS 85) is Illinois’s state student-data-privacy law. It layers on top of FERPA, not in place of it.
  • SOPPA’s operator duties apply to K-12 only. Higher education is outside its scope.
  • Any EdTech vendor receiving student data needs a signed Data Privacy Agreement (DPA) before that data can move.
  • Vendors must tell the school about a breach within 30 calendar days. Schools then have 30 calendar days to tell parents.
  • Districts can name a privacy officer, and that role can be combined with the records-custodian job.

Who SOPPA Applies To

SOPPA governs three groups: Illinois public schools and districts, ISBE, and “operators.” An operator is any company running a website, app, or online service that schools use.

Not every EdTech company that touches a classroom counts as an operator under the law. SOPPA uses a specific two-part test.

The Two-Part Operator Test

A vendor is an “operator” under SOPPA only if both of these are true:

SOPPA Operator Status Test
  1. The vendor has actual knowledge its product is used primarily for K-12 school purposes.
  2. The product was designed and marketed for K-12 school purposes.

This test matters for vendor scoping. A general-purpose tool, like a mainstream video conferencing or file-storage product, can fall outside SOPPA’s operator definition even when a school uses it. A purpose-built classroom app cannot dodge the definition just because a few non-school users sign up too.

K-12 Only, Not Higher Education

SOPPA’s operator duties are scoped to “K through 12 school purposes.” That phrase covers purposes a school, teacher, or district directs, or that customarily happen at their direction.

The law does not extend those duties to higher education. A vendor whose product only serves an Illinois college or university is not an “operator” under SOPPA, even though FERPA itself does cover postsecondary institutions. This is one of the clearest differences between the two laws, and it trips up vendors who assume “student privacy law” always means the same coverage.

What Counts as Covered Information

SOPPA protects “covered information”: personally identifiable information that is not otherwise publicly available. It has to be created or provided by a student, parent, or school employee, or gathered by an operator running a K-12 site, service, or app.

In practice, covered information can include things like:

  • A student’s name and contact details
  • Grades, transcripts, and test results
  • Discipline and behavior records
  • Special education records
  • Biometric data
  • Geolocation data captured through a school-used app or device

The point of the definition is broad coverage. If it identifies a specific student and isn’t already public, treat it as covered information until you have a reason not to.

What SOPPA Requires From Operators

Once a company qualifies as an operator, SOPPA imposes four core duties. Each one has its own statute reference and its own deadline or requirement.

Operator DutyStatuteWhat It Requires
No targeted ads, profiling, or sale105 ILCS 85/10Cannot use covered information for targeted advertising, non-educational profiling, or sale of student data
Written Data Privacy Agreement105 ILCS 85/15A signed or click-wrap DPA must exist before any covered information transfers
Breach notice to the school105 ILCS 85/15Must notify the district within 30 calendar days of determining a breach occurred
Delete or return data105 ILCS 85/15Must delete or transfer data back once it’s no longer needed, unless a parent consents to retention

No Targeted Ads, No Profiling, No Selling Student Data

Section 10 draws a hard line. Operators cannot use covered information to target advertising at a student. They cannot build a profile of a student for anything other than a K-12 school purpose. They cannot sell covered information, full stop.

This is the provision that separates a legitimate EdTech tool from one that treats student data as a monetization source.

The Data Privacy Agreement (DPA)

Before any covered information moves from a school, district, or ISBE to an operator, the two sides need a written Data Privacy Agreement. It can be executed electronically or as a click-wrap agreement. This requirement has no direct FERPA equivalent; FERPA leaves vendor obligations to contract language the school chooses to write in.

Spec block listing the four elements an Illinois SOPPA data protection agreement must contain.

At minimum, the DPA has to spell out:

  • The categories of covered information being shared
  • A description of the product or service the operator provides
  • A statement that the operator is acting as a FERPA “school official” with a legitimate educational interest, under the school’s direct control
  • How costs are split if a breach happens
  • A concrete deletion or transfer timeline once the data is no longer needed

Districts also have to make their DPAs available so parents can see them. ISBE keeps a published SOPPA contracts list that districts and vendors use to track which agreements are on file. If your district’s IT partner cannot produce a signed DPA for a vendor touching student data, that is a gap to close now, not at renewal time.

Operator Breach Notification: 30 Days to Tell the School

This clock runs from the vendor to the district, and it runs first. An operator must notify the school of a breach “in the most expedient time possible and without unreasonable delay,” and no later than 30 calendar days after the operator determines a breach occurred.

That 30-day window is separate from, and comes before, the district’s own 30-day clock to notify parents. A vendor cannot sit on a breach and let the district find out on its own timeline. The contract should say so explicitly.

Deleting or Returning Data When It’s No Longer Needed

Once covered information is no longer needed for the purpose it was collected for, the operator has to delete it or transfer it back to the school. The only exception is if a student or parent consents to the operator keeping it.

“We’ll delete it eventually” does not satisfy this duty. The DPA itself has to name a concrete window for deletion or transfer once the operator learns the data is no longer needed.

What SOPPA Requires From Schools and Districts

Operators are not the only party with duties under SOPPA. Schools and districts carry their own obligations, and these are the ones a district’s own IT program has to demonstrate directly.

Reasonable Security Procedures

Section 27 requires Illinois schools and districts to keep “reasonable security procedures and practices that otherwise meet or exceed industry standards” for covered information. That standard is more specific than FERPA’s federal-level “reasonable methods” language, and it is the closer analogue to a real technical requirement.

In practice, this means access controls, monitoring, and documented security practices that a district can point to and defend, not just a policy document in a drawer.

The 30-Day Parent Breach Notice

If a breach involving a student’s covered information happens, the school must notify affected parents within 30 calendar days of learning about it. The notice has to describe what was compromised and provide contact information for relevant agencies.

Pair this with the operator’s own 30-day notice duty above, and a district effectively gets its own clock started only after the vendor’s clock runs. That is exactly why the vendor-to-school notice deadline matters so much in a DPA.

Designating a Privacy Officer

Districts have an option, not a mandate, here. Under Section 27, a school or district may designate a staff member as a privacy officer responsible for SOPPA compliance. That role does not require a new hire. It can be combined with the district’s existing records custodian position.

For a smaller district, this is often the most realistic way to build accountability into SOPPA compliance without adding headcount.

Parent and Eligible-Student Rights Under Section 33

Section 33 gives parents specific rights over their child’s covered information. These rights apply to parents of students in Illinois public schools. Nonpublic school parents are excluded from this section specifically.

  • Inspect and review the student’s covered information, whether it’s held by the school, ISBE, or an operator
  • Request paper or electronic copies, though the school may charge a capped, reasonable cost
  • Request correction of factual inaccuracies

Correction requests carry real deadlines. The school, or the operator or ISBE if they hold the record, has 90 calendar days to fix it. It must then confirm the fix to the parent within 10 business days.

Section 33 does not create a standalone deletion right. That surprises people. If a parent wants covered information deleted from an operator’s system, that request has to run through the school. The school then invokes its own authority under Section 15 and Section 27(g) of the Act. Section 33 preserves whatever rights a parent already holds under the Illinois School Student Records Act and FERPA. It doesn’t replace them.

De-Identified Data: What Operators Can Still Do (Section 25)

SOPPA restricts a lot. It does not ban analytics outright.

Section 25 carves out uses that don’t require restriction, as long as the data isn’t tied to an identified student:

  • Improving the educational effectiveness of the operator’s product
  • Demonstrating a product’s effectiveness, including in marketing
  • Sharing de-identified covered information to help develop or improve other educational sites, services, or apps
  • Using recommendation engines to serve content or suggest services to a student

One limit applies to that last point. A recommendation can’t be based on payment from a third party. Outside that, de-identified and aggregate data work continues even under SOPPA’s otherwise tight rules.

What’s Exempt From SOPPA (Section 30)

Not every tool a school uses falls under SOPPA’s operator rules. Section 30 lists specific carve-outs.

ExemptionWhat It Covers
Law enforcement accessData shared for law enforcement purposes
Adaptive/customized learningTools built around individualized instruction
General audience sitesUsed with a school login, but not built for schools
Internet service providersISPs acting only as the network conduit
Parent-initiated marketingOperator marketing directly to parents, not from covered information, when the parent starts contact
App stores/marketplacesProviders that just distribute an app
Third-party content hostsInteractive computer service providers, for third-party content only
Student’s own data exportA student exporting their own account content
Yearbook/class-photo vendorsOperating under a written agreement with the school

One more point matters as much as the exemption list itself. Section 30 confirms SOPPA doesn’t supersede FERPA or the Illinois School Student Records Act. All three regimes stack. None of them replaces the others.

Enforcement: The Illinois Attorney General Has Real Teeth Here

FERPA enforcement runs through federal funding. SOPPA enforcement runs through a different lever entirely.

SOPPA violations are treated as unlawful business practices under Illinois consumer protection law, and the Illinois Attorney General can enforce them directly.

This is a state-level enforcement path FERPA doesn’t have. Violations count as unlawful practices under the Consumer Fraud and Deceptive Business Practices Act. That statute gives the Illinois Attorney General direct authority to act.

A district or operator can’t treat SOPPA as a lower-stakes cousin of FERPA. SOPPA lacks FERPA’s funding-withholding hammer, but that doesn’t make it weaker. The consumer-protection route brings its own investigative and legal exposure. It doesn’t require a federal complaint to get started.

For what these violations can look like in practice, see real-world FERPA violation examples.

SOPPA vs. FERPA: Side by Side

Both laws protect student data. They regulate different things, in different ways.

SOPPA (105 ILCS 85)FERPA (federal)
ScopeIllinois onlyNationwide
Who’s regulatedIL public schools, districts, ISBE, and K-12 EdTech operatorsAny school/institution receiving federal education funds, K-12 through postsecondary
Vendor agreementMandatory written DPA before data transfer (105 ILCS 85/15)No mandatory agreement; vendor access typically runs through the “school official” contract exception
Breach notificationVendor to school: 30 calendar days. School to parent: 30 calendar daysNo specific breach-notification deadline written into the law
EnforcementIllinois Attorney General, under the Consumer Fraud and Deceptive Business Practices ActU.S. Dept. of Education’s Student Privacy Policy Office, complaint-driven, funding-based remedies

Neither law replaces the other for an Illinois district. Both apply, at the same time, to the same student data.

See Where You Stand

Reading through statute sections is one thing. Knowing where your own district’s access controls, vendor agreements, and breach-notification readiness actually stand is another. Take the free 2-minute FERPA & SOPPA Risk-Check. It asks plain-English questions about access controls, vendor agreements, and breach-notification readiness. You’ll get a gap list at the end, no sign-up required.

free 2-minute FERPA & SOPPA Risk-Check

Frequently Asked Questions

No. FERPA is a federal law that applies nationwide to schools receiving federal education funding. SOPPA is an Illinois state law that adds extra rules on top of FERPA, specifically for Illinois public schools, districts, ISBE, and K-12 EdTech vendors. Neither law replaces the other. Illinois districts have to follow both at the same time.

SOPPA’s core framework targets Illinois public schools, districts, and the Illinois State Board of Education. Section 33’s parent inspection and correction rights specifically exclude parents of students at nonpublic schools. If you run IT for a private school in Illinois, FERPA and the Illinois School Student Records Act are still worth reviewing, but SOPPA’s operator-facing structure is built around the public school relationship.

A data privacy agreement, or DPA, is the written contract SOPPA requires between a school (or district or ISBE) and an EdTech operator before any student data can transfer. It has to list the categories of data being shared, describe the product, confirm the operator is acting as a FERPA school official under the school’s direct control, spell out who pays if a breach happens, and set a concrete deletion or transfer timeline. It can be signed electronically or as a click-wrap agreement.

An operator has to notify the school in the most expedient time possible, and no later than 30 calendar days after it determines a breach occurred. That deadline runs separately from, and before, the school’s own 30-day deadline to notify parents. The vendor’s clock has to run first so the school has time to act on its own notice.

No. SOPPA’s operator duties are scoped to K-12 school purposes only. A vendor whose product is used solely by an Illinois college or university doesn’t meet SOPPA’s definition of an operator, even though FERPA itself does cover postsecondary institutions. Higher education stays under FERPA alone in Illinois.

SOPPA violations count as unlawful practices under the Illinois Consumer Fraud and Deceptive Business Practices Act. That gives the Illinois Attorney General authority to bring enforcement action. It’s a separate, state-level path that runs independently of FERPA’s federal, funding-based enforcement process.

Get Your District’s SOPPA and FERPA Compliance Handled

Reading the statute is the easy part. Building the access controls, vendor vetting process, and breach-notification runbook it demands is harder. That’s what an Illinois district’s IT program actually has to demonstrate. For the technical side of FERPA specifically, see the FERPA IT compliance checklist for Illinois schools.

LeadingIT works with Illinois districts on exactly this. Our school IT compliance services are built around SOPPA and FERPA together. Vendor DPA review runs through our EdTech vendor vetting checklist.

If you want a second set of eyes on where your district stands, book a call or contact us directly.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.