Privacy & compliance · by region

Your school's privacy obligations, and exactly how we support them

Every province, state and country writes the rules differently, but they all ask the same things of a school's software vendor: be transparent, keep data safe, keep it only as long as needed, help the school answer to parents and regulators, and put it all in writing. Scroll to your region to see what applies to your school, what MySchool.Life already does, and what we hand you for your own privacy assessment.

In place today Provided on request Planned

Canada · federal

Canada — PIPEDA and how we work with public school boards

Public school boards are public bodies under their province's privacy statute; they collect student information under legal authority, not consent. InterconX Limited, as a commercial vendor, is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) for its own handling of personal information — and processes your school's data as your service provider under a written agreement. Independent schools deal with us under PIPEDA or the equivalent provincial private-sector law.

In place today

  • Public privacy policy written to PIPEDA's ten principles — purposes by role, named providers and countries, your rights, how to complain
  • Named Privacy Officer: [email protected]
  • Cross-border processing disclosed plainly (hosting in the United States; optional AI providers by country)
  • Encryption in transit, role-based access, per-school data isolation, field-level audit log with tamper-evident hashes, 7-year retention
  • Optional two-factor authentication for every account
  • Cookieless analytics on this website; no analytics or trackers inside the app
  • Deletion and export requests via myschool.life/delete-me.html, acknowledged in 5 business days, completed in 30

Provided on request

  • Service-provider agreement (information manager / data-processing agreement) with purpose limits, safeguards, sub-processors, breach notice, audit rights, and return & certified destruction at end of contract
  • Vendor privacy assessment for your PIA: data inventory by role, data-flow diagram, storage locations, safeguards, retention schedule
  • Current sub-processor register, with 30 days' notice before any change that touches student data
  • Breach-response procedure summary and our incident register format

Planned

  • Canadian data-centre hosting option for Canadian schools
  • In-app "delete my account" and "download my data" for parents and staff
  • Recorded, per-school opt-in switches for AI processing and any processing outside Canada, visible in your admin console
  • Independent security attestation (SOC 2)
Your obligation (PIPEDA / board statute)How MySchool.Life helpsStatus
Accountability — a written agreement with every service providerAgreement template ready to sign; we accept audit and inspection clausesOn request
Openness — policies readily availablePolicy, provider list and this page are public; dated versions keptIn place
Limiting collection, use and retentionWe collect only what each feature needs; retention set by your school; audit logs 7 yearsIn place
Safeguards proportionate to sensitivityTLS, RBAC, isolation, audit log, optional 2FA, rate limiting, in-house error trackingIn place
Individual access within 30 daysHandled through your school or directly by us; export tooling comingIn place
Breach of security safeguards — report, notify, keep records 24 monthsWe notify you within 72 hours and keep an incident register so you can meet your own dutiesIn place
Transparency about processing outside CanadaDisclosed in the policy; contractual safeguards with each providerIn place
Meaningful consent for uses beyond core operation (AI, cross-border)School-wide AI on/off and per-user controls exist; recorded opt-in switches comingPlanned

Plain statement on hosting. MySchool.Life is hosted with DigitalOcean in the United States today. No Canadian statute forbids that outright for most boards, but your privacy impact assessment must consider it — our vendor assessment gives you the wording. A Canadian data-centre option is planned; ask us for the timeline.

Alberta

Alberta — Protection of Privacy Act (POPA), PIPA and the Student Record Regulation

Public and charter schools are public bodies under the Protection of Privacy Act (in force June 2025, replacing the privacy half of FOIP). POPA makes a privacy impact assessment mandatory for new systems that use innovative technology or handle sensitive information about many people — AI-assisted grading qualifies — and some PIAs go to the Information and Privacy Commissioner before launch. InterconX is subject to Alberta's Personal Information Protection Act for information it holds in its own right. The Education Act and Student Record Regulation (AR 225/2006) govern the student record, which stays with the board.

In place today

  • Everything in the Canada section above
  • Policy names every country where data may be processed (US hosting; optional AI providers) — the PIPA requirement
  • Attendance and assessment records stay exportable so the board remains record-keeper under AR 225/2006
  • School-wide AI switch and per-user controls, so a board can run MSL with AI features off while its PIA is reviewed

Provided on request

  • POPA s. 26 PIA support pack — written to the Commissioner's PIA template headings so your privacy officer can paste it in
  • Information Manager Agreement naming POPA, breach notice without unreasonable delay, and support for Commissioner and Minister notifications
  • Training text and a vendor sheet for the board's privacy management program (POPA s. 25)

Planned

  • Canadian data-centre hosting — the item most Alberta RFPs ask for
  • PowerSchool roster sync and single sign-on, with PASI-aware identifiers
Your obligationHow MySchool.Life helpsStatus
Mandatory PIA before implementation (POPA s. 26)Pre-written vendor assessment in the OIPC template structureOn request
Reasonable security arrangements for information held by contractorsSafeguards above + agreement clauses; audit rightIn place
Breach: notify individual, Commissioner and Minister on real risk of significant harm72-hour notice to the board with the facts needed for the notificationsIn place
Privacy management program (s. 25)Vendor sheet, training text, annual attestation letterOn request
List countries outside Canada (PIPA)Published in the privacy policyIn place
Student record retention and dispositionExport at any time; return and certified destruction at end of contractIn place

British Columbia

British Columbia — FIPPA, the School Act and privacy management programs

School districts are public bodies under the Freedom of Information and Protection of Privacy Act. Since the 2021 amendments, storing personal information outside Canada is permitted, but a system in which sensitive information is stored outside Canada needs a privacy impact assessment under s. 69 — and student information is treated as sensitive. Districts must run privacy management programs (s. 36.2) and report breaches that could cause significant harm to affected people and the Commissioner (s. 36.3). InterconX is subject to BC's PIPA for information it holds itself.

In place today

  • Everything in the Canada section above
  • US hosting and every provider location disclosed so the s. 33.1 / s. 69 analysis can be done on facts
  • Breach notice to the district within 72 hours, with the details s. 36.3 notifications require

Provided on request

  • s. 69 PIA support pack, including the "sensitive information stored outside Canada" section
  • Service agreement naming FIPPA, disclosure limits and the district's audit rights
  • Annual vendor attestation for your privacy management program

Planned

  • Canadian data-centre hosting — removes the outside-Canada PIA section entirely
  • MyEducation BC roster import
  • Accessibility conformance statement (Accessible BC Act)
Your obligationHow MySchool.Life helpsStatus
PIA for a new system (s. 69), incl. outside-Canada storage of sensitive informationVendor assessment with the data-residency section pre-writtenOn request
Disclosure outside Canada only per regulation (s. 33.1)Full location disclosure; contractual safeguards; Canadian option plannedIn place
Privacy management program (s. 36.2)Vendor sheet + annual attestationOn request
Breach notification (s. 36.3)72-hour notice; incident registerIn place
Permanent Student Record (M082/09) stays with the districtMSL holds working records only; export any timeIn place

Ontario

Ontario — MFIPPA, the Ontario Student Record and the IPC's Digital Privacy Charter

School boards are institutions under the Municipal Freedom of Information and Protection of Privacy Act. The Education Act (s. 266) governs the Ontario Student Record, which the board keeps; MySchool.Life holds working records the board chooses to place in it. Mandatory breach reporting for school boards takes effect 1 January 2027. Since July 2026 boards must maintain a software inventory and notify parents about each digital tool they use. Ontario's Accessibility for Ontarians with Disabilities Act applies to what boards procure.

In place today

  • Everything in the Canada section above
  • Working records only — the OSR stays with the board; exports on demand
  • Breach cooperation today at the standard the 2027 duty will require (RROSH assessment support, IPC and parent notification facts, incident records)
  • Interfaces built and tested against measured WCAG contrast ratios, dark and light

Provided on request

  • Software-inventory information sheet and ready-to-send parent notice for your board's digital-tools register
  • "How MySchool.Life supports the IPC Digital Privacy Charter for Ontario Schools" one-pager
  • Service agreement naming MFIPPA and OSR custody
  • Vendor privacy assessment for your board's PIA practice

Planned

  • French-language privacy policy and parent notices for French-language boards; French interface to follow
  • AODA / WCAG 2.1 AA conformance statement after the remaining contrast fixes
  • Canadian data-centre hosting
Your obligationHow MySchool.Life helpsStatus
Reasonable measures to protect personal information held by contractors (MFIPPA)Safeguards + agreement clausesIn place
Software inventory & per-tool parent notice (O. Reg. 51/26, 52/26)Pre-written vendor sheet and notice paragraphOn request
Breach reporting to the IPC and individuals (mandatory from 2027-01-01)72-hour notice; records; annual statistics supportIn place
OSR custody and retention (Education Act s. 266)Board remains record-keeper; export/return at any timeIn place
Digital Privacy Charter commitments (voluntary)Mapping documentOn request
AODA accessibility in procurementMeasured contrast system; conformance statement comingPlanned

Québec

Québec — Law 25 and the Charter of the French Language

School service centres and school boards are public bodies under the Act respecting Access to documents held by public bodies, as modernised by Law 25. Any communication of personal information outside Québec — including hosting elsewhere in Canada — requires a prior privacy impact assessment (s. 70.1) and a written agreement reflecting it. InterconX is subject to the private-sector Act when it handles Québec residents' information. Under the Charter of the French Language, public bodies contract and communicate in French, and software must be available in French.

In place today

  • Everything in the Canada section above
  • Person responsible for the protection of personal information reachable at [email protected]nous répondons en français
  • Collection notice elements of s. 8 covered in the policy: purposes, means, rights, third parties, communication outside Québec
  • Technology that verifies location (geofence / school network check-in) is disclosed (s. 8.1)
  • A teacher makes every final grading decision — no decision rests exclusively on automated processing (s. 12.1)

Provided on request

  • Pre-filled cross-border PIA annex (EFVP) for communication outside Québec, with the written agreement it requires
  • Confidentiality-incident procedure and register format (s. 3.5)
  • Service agreement in French

Planned

  • Full French versions of the privacy policy, this page, the deletion page and in-app notices — published before any Québec deployment
  • French user interface and French support
  • Parental consent flow for minors under 14 where we collect directly
Votre obligation / your obligationHow MySchool.Life helpsStatus
PIA before communicating information outside Québec (s. 70.1) + written agreementPre-filled EFVP annex and agreementOn request
Published contact of the person responsible (s. 3.1 private Act)Published in the policy; postal address added on requestIn place
Notice at collection (s. 8) and of profiling/locating technology (s. 8.1)Covered in policy; French version plannedIn place
Automated-decision notice (s. 12.1)Not triggered — humans decide; documentedIn place
Confidentiality incidents: notify CAI and individuals; keep a register (s. 3.5)72-hour notice; registerIn place
French-language service, documents and software (Charter s. 52.1)French documents first, interface nextPlanned
Consent of a parent for minors under 14 (s. 4.1)School-created accounts today; direct-collection flow comingPlanned

Avant tout déploiement au Québec : nous publierons la version française intégrale de nos politiques et fournirons l'annexe d'évaluation des facteurs relatifs à la vie privée. Écrivez-nous en français à [email protected].

Nova Scotia

Nova Scotia — FOIPOP and PIIDPA

Regional centres for education are public bodies under FOIPOP and the Personal Information International Disclosure Protection Act (PIIDPA), which — until the new FOIPOP takes effect in April 2027 — requires personal information to be stored and accessed only in Canada except in narrow cases. This is the strictest residency rule in the country.

In place today

  • Everything in the Canada section above
  • Full transparency: our hosting is in the United States today, so we say so before you start, not after

Provided on request

  • Vendor privacy assessment and agreement template (as for the rest of Canada)
  • Written statement of current data locations for a head's determination under PIIDPA, if your centre chooses to seek one

Planned

  • Canadian data-centre hosting with Canadian-only access — the prerequisite for Nova Scotia public schools
  • Alignment with the new FOIPOP's breach and outside-Canada regulations when published

Straight answer for Nova Scotia public schools: until our Canadian hosting option is live, MySchool.Life does not meet PIIDPA's in-Canada rule. Independent schools in Nova Scotia are not bound by PIIDPA and can use MySchool.Life today. Contact us to be told the moment Canadian hosting is available.

Saskatchewan · Manitoba · New Brunswick · Newfoundland and Labrador

Other provinces — LA FOIP, FIPPA, RTIPPA and ATIPPA

School divisions and districts are local public bodies under Saskatchewan's LA FOIP, Manitoba's FIPPA, New Brunswick's RTIPPA and Newfoundland and Labrador's ATIPPA, 2015. None imposes a blanket in-Canada rule; each expects a risk assessment for cloud services and has its own breach regime — Saskatchewan and Manitoba on real risk of significant harm, New Brunswick to individuals and the Ombud, and Newfoundland and Labrador requires every breach to be reported to the Commissioner.

In place today

  • Everything in the Canada section above
  • Breach notice to your division within 72 hours with the facts each regulator asks for

Provided on request

  • Vendor privacy assessment aligned to your Commissioner's or Ombud's cloud-service guidance
  • Service agreement with the breach clause naming your regulator (SK IPC, Manitoba Ombudsman, NB Ombud, NL OIPC)

Planned

  • Canadian data-centre hosting
  • Bilingual parent notices and support for New Brunswick

United States · federal

United States — FERPA, COPPA and the National Data Privacy Agreement

FERPA binds schools that receive federal funds; a vendor receives education records as a "school official" under the school's direct control, uses them only for the authorised purpose and never re-discloses them. COPPA (as amended by the 2025 rule) applies to any personal information collected from children under 13; schools may authorise collection for an educational purpose with no other commercial use. The Student Data Privacy Consortium's National Data Privacy Agreement (NDPA) is the standard contract most districts now ask for.

In place today

  • We operate as a FERPA school official: purpose-limited use, no re-disclosure, no marketing use, deletion or return at end of contract
  • No advertising, no behavioural profiling, no sale of student data, no AI training — the core of COPPA's school-authorisation conditions and every state student-privacy law
  • Parents' access and amendment rights supported through the school, with export on request
  • Safeguards: TLS, role-based access, per-school isolation, audit log, optional 2FA
  • Public data-deletion page for account holders (Google Play / App Store requirement)

Provided on request

  • NDPA v2 (with the General Offer of Privacy Terms) — sign once, and other districts in your state alliance can adopt it
  • Description of data collected, and review / delete / stop-collection paths for school-authorised COPPA consent
  • Security overview and breach-notification procedure

Planned

  • Written information-security program and retention policy published in COPPA 2025 form
  • Clever / ClassLink rostering and SSO
  • SOC 2 Type II; accessibility conformance report (VPAT)
  • In-app account deletion and data download
Your obligationHow MySchool.Life helpsStatus
FERPA school-official exception — direct control, purpose limits, no re-disclosureWritten into our agreement and how the product worksIn place
Written data-privacy agreementNDPA v2 or your district's formOn request
COPPA school authorisation for under-13s (if any)Data description + review/delete/stop paths; written security program comingPlanned
Parent inspection within 45 daysExport via the school or directlyIn place
Deletion / return at end of contractReturn in machine-readable form; written confirmation of destructionIn place

United States · state laws

US states — California, New York, Illinois, Colorado, Connecticut, Utah

Most states layer a student-data-privacy statute on top of FERPA. They share a core — no targeted ads, no profiling, no sale, reasonable security, deletion on request and at end of contract, breach notice to the district — and differ in the paperwork: California's SOPIPA and AB 1584 contract terms; New York's Education Law §2-d Parents' Bill of Rights, encryption and 7-day breach notice; Illinois' SOPPA public agreements and 30-day notice; Colorado's public vendor lists; Connecticut's required contract provisions; Utah's contracted-purpose rules.

In place today

  • The shared core: no ads, no profiling, no sale, no AI training; district owns its data; deletion or return at end of contract
  • Breach notice to the district within 72 hours — inside Illinois' 30-day and Connecticut's 60-day windows
  • Encryption in transit; audit log; role-based access

Provided on request

  • NDPA v2 with the state exhibit for your state
  • California AB 1584 contract terms; New York Parents' Bill of Rights supplemental information; Illinois data-element list for public posting; Colorado / Connecticut / Utah privacy and security information sheets

Planned

  • New York §2-d: encryption at rest across all stores, NIST Cybersecurity Framework alignment statement and 7-day breach SLA
  • Clever / ClassLink SSO and rostering
  • SOC 2 Type II

Australia

Australia — the Privacy Act, the APPs, ST4S and state departments

Australian schools and their departments expect vendors to meet the Australian Privacy Principles — an APP 1 privacy policy, notice at collection (APP 5), use only for the primary purpose (APP 6), accountability for overseas disclosures (APP 8), security and destruction (APP 11) — and the Notifiable Data Breaches scheme. Safer Technologies 4 Schools (ST4S) is the national assessment of school software; Victorian government schools may only buy products that pass it. New South Wales requires parental consent before student information enters non-department software; Queensland and Western Australia have their own transfer and breach rules.

In place today

  • Privacy policy written to the APP 1 headings, naming overseas recipients by country (hosting in the United States; optional AI providers)
  • No ads, no sale, no profiling, no AI training on student data
  • Safeguards: TLS, role-based access, per-school isolation, audit log, optional 2FA
  • Breach notice to your school within 72 hours so departmental and NDB notifications can be made in time
  • Access and correction requests answered within 30 days (APP 12 / 13)

Provided on request

  • Vendor privacy and security questionnaire responses (NSW due-diligence checklist, Queensland app approval, Victorian Arc submissions)
  • Parental-consent notice text for NSW schools
  • Service agreement with APP 8 accountability and NDB cooperation clauses

Planned

  • ST4S Readiness Check and full assessment, including the Responsible AI module
  • Australian (Sydney) hosting region for Australian schools
  • Automated-decision-making disclosure in the form required from December 2026; alignment with the Children's Online Privacy Code once registered
Your obligationHow MySchool.Life helpsStatus
APP 1 policy and APP 5 noticePublished; notice text supplied for enrolment packsIn place
APP 8 overseas disclosure — reasonable steps and accountabilityContractual safeguards with each provider; AI providers restricted on request; Australian region plannedIn place
APP 11 security and destructionSafeguards above; return and destruction at end of contractIn place
Notifiable Data Breaches scheme72-hour notice; assessment supportIn place
ST4S assessment (mandatory for Victorian government schools)Readiness check scheduledPlanned
NSW parental consent for non-department softwareConsent notice text suppliedOn request

Not in the list, or your privacy officer has a question we have not answered? Write to [email protected]. We would rather answer a hard question before you sign than after. Full details: privacy policy · data deletion.