Student Data Privacy Agreement review
The agreement a school or district signs with a provider of classroom software or record storage, about the student data the provider receives. The checks read for the school's ownership and control of the data, use limited to the service with no further disclosure, no targeted advertising or sale, security measures, notice of an unauthorized disclosure, parents' access and correction, and deletion at the end.
Review your document — free → See a sample report- 7 document-specific checks
- + 110 general checks
- Nothing uploaded
- Free forever (MIT)
What it checks
Student data stays the school's, under its control
Warning · SDP-001
Use limited to the service, and no further disclosure
Warning · SDP-002
No targeted advertising, and no sale of student data
Warning · SDP-003
Security measures
Warning · SDP-004
Notice of an unauthorized disclosure
Warning · SDP-005
Parents' access to, and correction of, the records
Warning · SDP-006
Deletion or return of student data at the end
Warning · SDP-007
Every run also applies 110 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.
Often reviewed with
How it works
- Open vaulytica.com — no account, nothing to install.
- Drop your PDF or DOCX, or paste the text. The document type is detected and only the checks that belong to it run, inside your browser tab.
- Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,930 checks across 285 document types.
More privacy & data protection documents
- Biometric Data Consent (BIPA-style)
- Children's Privacy Notice (COPPA)
- Cookie / Tracking Notice
- Data Sharing Agreement (Research / Inter-Agency)
- DPA — CCPA Service Provider (CPRA-aligned)
- DPA — Controller to Processor (EU/UK)
- DPA — Multi-State US (CCPA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, DPDPA)
- DPA — Processor to Sub-Processor (EU/UK GDPR)
- Data Protection Impact Assessment (GDPR Art. 35)
- Data-Incident Notification Template
- Privacy Notice (GDPR)
- Privacy Notice (US / CCPA)
- Privacy Policy Linter
- Records of Processing Activities (GDPR Art. 30)
- EU Standard Contractual Clauses — Module 2 (Controller to Processor)
- EU Standard Contractual Clauses — Module 3 (Processor to Processor)
- SMS / Telemarketing Consent Disclosure
- UK International Data Transfer Addendum / IDTA
- Vendor Security Addendum
- Vendor Security Questionnaire (SIG / CAIQ)