Student Privacy Pledge 2020
The Student Privacy Pledge 2020, managed by the Future of Privacy Forum (FPF) and The Software & Information Industry Association (SIIA), is a voluntary industry commitment by education technology companies to safeguard student privacy. Signatories commit to responsible data handling practices aligned with FERPA, COPPA, and state student privacy laws. Over 400 companies have signed the pledge.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (26)
Access Control
| Code | Title |
|---|---|
| SPP-14 | Identity and access management for student data |
Access and Compliance
| Code | Title |
|---|---|
| SPP-11 | Use student data only as authorized by schools or parents |
| SPP-12 | Allow parents and schools to enforce the pledge |
Accountability
| Code | Title |
|---|---|
| SPP-12 | Allow parents and schools to enforce the pledge |
Advertising Restrictions
| Code | Title |
|---|---|
| SPP-02 | No behavioral advertising using student data |
Awareness
| Code | Title |
|---|---|
| SPP-16 | Workforce privacy training |
Change Management
| Code | Title |
|---|---|
| SPP-08 | Provide notice of material policy changes |
Cryptographic Controls
| Code | Title |
|---|---|
| SPP-13 | Encryption of student data in transit and at rest |
Customer Control
| Code | Title |
|---|---|
| SPP-10 | Allow schools to access and control student data |
Customer Enablement
| Code | Title |
|---|---|
| SPP-20 | Integration with school customer compliance obligations |
Data Collection and Use
Commitments regarding student data collection and use
Data Collection and Use Limitations
| Code | Title |
|---|---|
| SPP-1 | Purpose Limitation |
| SPP-2 | No Sale of Student Data |
| SPP-3 | No Behavioral Advertising |
Data Minimization
| Code | Title |
|---|---|
| SPP-17 | Data minimization in product features |
Data Retention
| Code | Title |
|---|---|
| SPP-06 | Limit retention to educational purpose |
Data Sales Prohibition
| Code | Title |
|---|---|
| SPP-01 | No selling of student personal information |
Data Subject Rights
| Code | Title |
|---|---|
| SPP-04 | Honor parent and school data access and correction |
Data Use Restrictions
| Code | Title |
|---|---|
| SPP-4 | No Personal Profile Building |
| SPP-5 | Retention Limitations |
De Identification
| Code | Title |
|---|---|
| SPP-18 | De identification and aggregation standards |
Incident Response
| Code | Title |
|---|---|
| SPP-15 | Breach detection and notification |
Information Security
| Code | Title |
|---|---|
| SPP-05 | Maintain a comprehensive security program |
Profiling Limits
| Code | Title |
|---|---|
| SPP-03 | No personal profile building for non-educational purposes |
Public Commitment
| Code | Title |
|---|---|
| SPP-19 | Public signatory accountability |
Purpose Limitation
| Code | Title |
|---|---|
| SPP-11 | Use student data only as authorized by schools or parents |
Security and Governance
DLT security and governance standards
Transparency
| Code | Title |
|---|---|
| SPP-07 | Transparent privacy policies in plain language |
Transparency and Notice
| Code | Title |
|---|---|
| SPP-6 | Privacy Policy Changes |
| SPP-7 | Privacy Education Resources |
| TN-1 | Privacy Policy Disclosure |
| TN-2 | Direct Notice to Parents |
| TN-3 | Material Change Notification |
| TN-4 | Data Practice Descriptions |
Vendor Management
| Code | Title |
|---|---|
| SPP-09 | Restrict third party access to authorized purposes |
Your Compliance Coverage
If you comply with Student Privacy Pledge 2020, you already cover:
Digital Services Act (DSA) - Regulation (EU) 2022/2065
13%
4 controls mapped
Compare →eIDAS 2.0 — EU Digital Identity Regulation
13%
4 controls mapped
Compare →China Personal Information Protection Law (PIPL)
13%
4 controls mapped
Compare →+ 350 more: Egypt Personal Data Protection Law (Law No. 151 of 2020) (13%), Serbia Law on Personal Data Protection (2018) (13%)
See all 353 mapped frameworks ↓Maps to 353 other frameworks
Frequently Asked Questions
What is Student Privacy Pledge 2020?
Student Privacy Pledge 2020 is a compliance framework from United States (Voluntary) with 26 domains and 33 controls. The Student Privacy Pledge 2020, managed by the Future of Privacy Forum (FPF) and The Software & Information Industry Association (SIIA), is a voluntary industry commitment by education technology companies to safeguard student privacy. Signatories commit to responsible data handling practices aligned with FERPA, COPPA, and state student privacy laws. Over 400 companies have signed the pledge. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Student Privacy Pledge 2020 have?
Student Privacy Pledge 2020 has 33 controls organised across 26 domains. The largest domains are Transparency and Notice (6 controls), Data Collection and Use Limitations (3 controls), Access and Compliance (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Student Privacy Pledge 2020 map to?
Student Privacy Pledge 2020 maps to 353 other compliance frameworks. The top mapping partners are Digital Services Act (DSA) - Regulation (EU) 2022/2065 (13% coverage), eIDAS 2.0 — EU Digital Identity Regulation (13% coverage), China Personal Information Protection Law (PIPL) (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Student Privacy Pledge 2020 compliance?
Start your Student Privacy Pledge 2020 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Student Privacy Pledge 2020 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required