COPPA Compliance
How Impact Suite complies with the Children's Online Privacy Protection Act through the school-consent model.
Short answer: Yes. Impact Suite complies with the Children’s Online Privacy Protection Act (COPPA) for students under 13, operating under the model established for K-12 educational technology: the school district — not Impact Suite — is the consenting authority, and we act as a school official under FERPA in service of the district’s legitimate educational purpose.
How COPPA applies to a K-12 platform
COPPA governs online services that collect personal information from children under 13 and normally requires verifiable parental consent. The FTC’s long-standing guidance provides a school-consent exception: when a service is used solely for a school-authorized educational purpose, the school may provide consent on behalf of parents. Impact Suite operates under this exception.
- The district authorizes our collection and use of student data for its educational and student-safety purposes; the district stands in for the parent for consent purposes.
- We act as a school official with a legitimate educational interest under FERPA. FERPA is our primary student-privacy framework; COPPA is satisfied through the same school-authorized relationship.
What we do that satisfies COPPA
- Data minimization — we collect only the personal information necessary for the contracted educational and safety purpose.
- No secondary use — we never sell or rent student data, never use it for advertising or behavioral profiling, and never use student data to train AI models (see AI data handling).
- Security — student data is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256), with role-based, audited access.
- Access and deletion — we support parent/student access rights through the district and provide self-service export plus secure NIST 800-88 deletion (see Data Transition and Secure Deletion).
- Aligned agreements — our Data Processing Agreement aligns to state student-privacy laws that layer on top of COPPA (e.g. California SOPIPA, New York Education Law 2-d, the Florida NDPA and other National Data Privacy Agreement templates).
Scope and honest caveats
- Compliance runs through the district. Our COPPA posture depends on the district being the consenting authority and deploying Impact Suite for an educational purpose. The school-consent exception covers educational use, not a consumer or non-educational context.
- We are not a COPPA “Safe Harbor”-certified vendor. We comply with the COPPA statute and FTC guidance; we do not currently hold a seal from an FTC-approved Safe Harbor program (e.g. iKeepSafe, kidSAFE). “Compliant with the law” is distinct from “certified by a Safe Harbor program,” and we state that plainly.
A dedicated Data Protection Officer oversees privacy compliance (support@impactsuite.com).