• What is SOPPA?
    What happens to the student data that we send to a third-party vendor?  Information like names, birthdates, etc… may be provided by Rantoul Township School District 193 to the third party like IXL, NWEA MAP, etc…  What protections do those companies have in place to make sure that our student’s data is not sold or freely given to others?  This is exactly what SOPPA looks to address.

    As part of SOPPA, these companies must enter into Data Privacy Agreements (DPA) with each district they work with.  These agreements outline what data is stored, how it is protected, what the company can and cannot do with that data, and what they will do in the event of a data breach.

    SOPPA Compliance List

    Links for SOPPA

    Videos

    Student Data and Online Privacy

    Student Online Privacy Protection Act (SOPPA)

    • District 193 is a member of the Illinois Student Privacy Alliance. You can find all vendor privacy agreements between District 193 and vendors we do business with by clicking here.

      Effective July 1, 2021, school districts will be required by the Student Online Personal Protection Act (SOPPA) to provide additional guarantees that student data is protected when collected by educational technology companies, and that data is used for beneficial purposes only (105 ILCS 85).

      SOPPA applies to all Illinois school districts, the Illinois State Board of Education, and operators of online services and applications. 

      Below is a high-level overview of the new requirements. 

      School districts must:

      1. Enter into written agreements with all K-12 service providers who collect student data. You can find all written agreements by clicking here.
      2. Implement and maintain reasonable security practices. Agreements with vendors in which information is shared must include a provision that the vendor maintains reasonable security procedures and practices.
      3. Post on their website: 
        • A list of all operators of online services or applications utilized by the district (annually). 
          • Click here for a list of all operators.
        • All data elements that the school collects, maintains, or discloses to any person, entity, third party, or governmental agency (annually). 105 ILCS 85/27(a)(1), added by P.A. 101-516, eff. 7-1-21. This information must also explain how the school uses the data, and to whom and why it discloses the data.
          • Data elements can be found by hovering over the image on the far right (Under Data) of each operator listed:Book Creator Image for Reference
        • Contracts for each operator within 10 days of signing. See above.
        • Subcontractors for each operator (annually). See above.
        • The process for how parents can exercise their rights to inspect, review and correct information maintained by the school, operator, or ISBE. Parents can contact gregvanhoorn@rths193.org if they wish to inspect, review, or correct information held in D193 databases.
        • Data breaches within 10 days and notify parents within 30 days. Should a data breach occur, parents will be notified via email and a list of breaches of covered information maintained by the school or operator involving 10% or more of the District's student enrollment will be posted on this page, including:
          • Number of students whose covered information was involved in the breach, unless the breach involved personal information as defined in the Personal Information Protection Act, 815 ILCS 530/5, in which case the number of students involved may not be disclosed.
          • Date, estimated date, or estimated date range of each breach
          • Name of the operator, in applicable
          • Per 105 ILCS 85/27(a)(5), added by P.A. 101-516, eff. 7-1-21. The District must update breach information by Jan. 31 and July 31 each year, and it must remain on the District's website for at least five years after the District adds it to the list.
        • Create a policy for who can sign contracts with operators. See Board Policy 7:345.

       

      RTHS Data Collected
      7-345-AP, E2 Student Data Privacy; Notice to Parents about Educational Technology Vendors  
      7-345-AP Use of Educational Technologies; Study Data Privacy and Security
      7-345-Administrative Procedures
      7-345-AP Right to Inspect Language
      Parent Letter in case of data breach

      Breaches

      None have been reported.