State Privacy Riders
Per-state additions on top of HallPal's default posture·Source: docs/legal/STATE_PRIVACY_RIDERS.md
Draft — pending final legal review. Text marked {{PLACEHOLDER}}is filled in by counsel before publication. Content shown here is a good- faith draft + reflects HallPal's current operational posture, but is not a substitute for legal advice.
HallPal State Privacy Riders
Suggested public route: /legal/state-privacy-riders
Last updated: 2026-08-08
What this page is
The Privacy Policy, Student Data Agreement, and Data Processing Addendum set out HallPal's default, state-agnostic privacy commitments. This page ADDS state-specific commitments where a US state's student-privacy law requires terms stricter than the default OR requires specific attestations.
Each rider below applies automatically to districts + LEAs in that state — no separate signature is required. Where a district executes an SDPC NDPA or negotiated MSA that includes an equivalent or stricter provision, the district-signed version controls.
Where a state's requirement is stricter than the default, the state's rider controls. Where it is looser or silent, the default controls.
If you're a district in a state not listed here, HallPal's default posture applies as-is. If you need specific language for your statute, contact legal@hallpal.divz.io.
1. California — AB 1584 + SOPIPA + CCPA/CPRA
Statute: California Ed Code § 49073.1 (AB 1584); Cal. Bus. & Prof. Code § 22584–22585 (SOPIPA); Cal. Civ. Code § 1798.100+ (CCPA/CPRA).
1.1 AB 1584 required contract terms
For any HallPal contract with a California LEA, HallPal commits:
- Ownership of student records. Pupil records continue to be the property of + under the control of the LEA.
- Access + review. Parents, legal guardians, or eligible pupils may review personally-identifiable information in pupil records + correct erroneous information via the LEA. HallPal will complete LEA-authorized corrections within 5 business days.
- Security procedures. HallPal will maintain the security procedures + practices detailed in PRIVACY.md §12 + STUDENT_DATA_AGREEMENT.md §8.
- Prohibition on targeted advertising. HallPal will not use any information in a pupil record for any purpose other than those required or specifically permitted by the contract.
- Return + destruction on termination. On contract termination, HallPal will delete pupil records + provide a Certificate of Destruction per STUDENT_DATA_AGREEMENT.md §6.2.
- Data breach notification. HallPal will notify the LEA of any unauthorized disclosure of pupil records within 72 hours per STUDENT_DATA_AGREEMENT.md §9.
1.2 SOPIPA restrictions
For California LEAs, HallPal additionally commits — as required by SOPIPA — not to:
- Engage in targeted advertising on our site or service or on any other site, service, or application when the targeting is based on information (including "covered information" as defined by SOPIPA) that HallPal has acquired because of the use of our service.
- Use information — including persistent unique identifiers — created or gathered by our service to amass a profile about a K-12 student except in furtherance of K-12 school purposes.
- Sell or rent a student's information, including covered information.
- Disclose covered information unless the disclosure is:
- For the K-12 school purposes of the site, service, or application;
- To ensure legal + regulatory compliance;
- To respond to or participate in a judicial process;
- To protect the safety of users or others or the security of the site, service, or application;
- To a service provider (Subprocessor) that has agreed to equivalent restrictions.
1.3 CCPA/CPRA — Service Provider status
For Personal Data of California residents subject to CCPA/CPRA (not limited to student data), HallPal operates as a Service Provider (not a Third Party). The commitments in DPA.md §11 apply. Additionally:
- HallPal will not "sell" or "share" (as defined by CCPA/CPRA) any Personal Data.
- California residents (or their parents / legal guardians on behalf of a minor) may exercise CCPA rights (access, deletion, correction, portability, opt-out) via the LEA; the LEA is the correct point of contact for pupil records.
2. New York — Education Law § 2-d + Part 121
Statute: N.Y. Education Law § 2-d; 8 NYCRR Part 121.
2.1 Third-party contractor obligations
HallPal operates as a "Third-Party Contractor" under Ed Law § 2-d
- commits:
- Purpose limitation. HallPal will not use student data, teacher data, or principal data for any commercial or marketing purpose or in connection with the sale or marketing of a product.
- Data security + privacy plan. HallPal will implement a data security + privacy plan aligned with the NIST Cybersecurity Framework at least at the level required by 8 NYCRR § 121.6. Summary of controls: PRIVACY.md §12.
- Subcontractor management. HallPal ensures each Subprocessor
(listed in SUBPROCESSORS.md) is subject
to written contractual terms as protective of student, teacher,
- principal data as HallPal's own.
- Data breach + unauthorized disclosure notification. HallPal will notify the LEA no later than 7 calendar days after discovering an unauthorized release of protected data, as required by 8 NYCRR § 121.10. HallPal's own default is 72 hours (STUDENT_DATA_AGREEMENT.md §9).
- Parents' Bill of Rights. HallPal will include the LEA's
Parents' Bill of Rights for Data Privacy + Security (supplemented
by HallPal-specific information) with every contract with an NY
LEA. A supplemental Parents' Bill of Rights attachment specific to
HallPal is
PARENTS_BILL_OF_RIGHTS.md(suggested public route:/legal/parents-bill-of-rights) + will be attached to every executed NY-LEA contract. - Location of data. Student data is stored at {{DB_HOSTING_LOCATION}}, USA. No student data is stored outside the United States.
- Data deletion + destruction on contract termination. Per STUDENT_DATA_AGREEMENT.md §6.2.
2.2 Special note: NYC DOE
NYC DOE typically requires its own contract exhibit ("Chancellor's Regulations A-820" attachments + a specific data-use agreement). Contact legal@hallpal.divz.io to receive HallPal's completed NYC DOE-specific packet.
3. Illinois — SOPPA
Statute: 105 ILCS 85 (Student Online Personal Protection Act).
3.1 Required contract terms
For Illinois LEAs, HallPal commits (per 105 ILCS 85/25):
- Data collection limits. HallPal will collect only data reasonably necessary to provide the service.
- Advertising + marketing. No targeted advertising to students or students' parents. No sale of student data. No use of student data to compile a personal profile of a student except for furthering the school purposes.
- Deletion on request. Within 30 school business days of LEA request, HallPal will delete a student's data.
- Deletion on contract termination. Per STUDENT_DATA_AGREEMENT.md §6.2.
- Breach notification. HallPal will notify the LEA within 30 calendar days of discovery of an unauthorized disclosure of covered information, per 105 ILCS 85/30. HallPal's default is 72 hours.
3.2 Public posting
HallPal understands that per 105 ILCS 85/33, the LEA is required to post its contract with HallPal on the LEA's website. HallPal consents to this posting; the executed contract does not contain HallPal confidential business information.
4. Texas — TEC § 32.155 + § 32.156
Statute: Tex. Ed. Code § 32.155 (Data Ownership) + § 32.156 (Data Sharing).
4.1 Data ownership + sharing
For Texas LEAs, HallPal commits:
- LEA ownership. All personally-identifiable information + other student information is owned + controlled by the LEA.
- No sale or use for advertising. HallPal will not sell student information or use it for targeted advertising to students.
- Directory information default. HallPal defaults to treating student information as non-directory. Any use for a non-service purpose requires explicit LEA opt-in.
- Data return + destruction on termination. Per STUDENT_DATA_AGREEMENT.md §6.2.
4.2 SB 820 cybersecurity coordinator
The LEA-designated cybersecurity coordinator is HallPal's primary point of contact for security incidents affecting a Texas LEA.
5. Colorado — HB 16-1423 + Colorado Privacy Act
Statute: Colo. Rev. Stat. § 22-16-101 et seq. (Student Data Transparency + Security Act); Colo. Rev. Stat. § 6-1-1301+ (Colorado Privacy Act, CPA).
5.1 Student data transparency
For Colorado LEAs, HallPal commits:
- Data-elements notice. HallPal will provide the LEA with a complete list of student personally-identifiable information it collects, before or upon contracting. This list is maintained at STUDENT_DATA_AGREEMENT.md §3 and is refreshed with any change.
- Public transparency. HallPal will not require a Colorado LEA to keep the terms of the operating agreement confidential except where required by law. The signed agreement may be posted on the LEA's website.
- Deletion on termination. Per STUDENT_DATA_AGREEMENT.md §6.2.
- Breach notification. HallPal will notify the LEA within 30 calendar days of discovery of a data breach. HallPal's default is 72 hours.
5.2 CPA — Processor status
For Personal Data of Colorado residents subject to CPA, HallPal operates as a Processor per DPA.md §11.
6. Connecticut — § 10-234aa + Data Privacy Act
Statute: Conn. Gen. Stat. § 10-234aa (Student Data Privacy) + Conn. Gen. Stat. § 42-515+ (Connecticut Data Privacy Act, CTDPA).
6.1 Student data commitments
For Connecticut LEAs, HallPal commits:
- No secondary use. Student data may be used only for the educational purpose specified in the agreement.
- No sale, no advertising. No sale of student information. No targeted advertising.
- Deletion on request or termination. Per STUDENT_DATA_AGREEMENT.md §6.
- Breach notification. HallPal will notify the LEA of a breach affecting student data within 30 days per § 10-234dd. HallPal's default is 72 hours.
- Encryption. All student data is encrypted in transit + at rest per PRIVACY.md §12.
6.2 CTDPA — Processor status
Per DPA.md §11.
7. Louisiana — RS 17:3914
Statute: La. R.S. § 17:3914.
7.1 Advertising + secondary-use ban
For Louisiana LEAs, HallPal commits:
- No advertising. HallPal will not use student information for advertising purposes.
- No sale. HallPal will not sell student information.
- Data return on termination. Per STUDENT_DATA_AGREEMENT.md §6.2.
7.2 Parental review
LEA-authorized parental requests to inspect student records are handled per STUDENT_DATA_AGREEMENT.md §7.
8. Utah — Utah Consumer Privacy Act + Student Data Protection Act
Statute: Utah Code § 13-61-101+ (Utah Consumer Privacy Act); Utah Code § 53E-9-301+ (Student Data Protection Act).
8.1 Student data protection
For Utah LEAs, HallPal commits:
- Purpose limitation. Student data is used only for the contracted educational purpose.
- Prohibition on targeted advertising. Applies to Utah students.
- Data retention. Per STUDENT_DATA_AGREEMENT.md §6.
- Breach notification. Per HallPal's 72-hour default.
8.2 UCPA — Processor status
Per DPA.md §11.
9. Other states — Processor / Service Provider status
For LEAs + customers in the following states, HallPal operates as a Processor / Service Provider per DPA.md §11 + follows the applicable state law's specific requirements:
- Virginia — Va. Code § 59.1-575+ (Virginia Consumer Data Protection Act, VCDPA).
- Iowa — Iowa Code § 715D (Iowa Consumer Data Protection Act).
- Indiana — Ind. Code § 24-15 (Indiana Consumer Data Protection Act, effective 2026).
- Tennessee — Tenn. Code § 47-18-3201+ (Tennessee Information Protection Act).
- Montana — Mont. Code § 30-14-2801+ (Montana Consumer Data Privacy Act).
- Oregon — Or. Rev. Stat. § 646A.570+ (Oregon Consumer Privacy Act).
- Texas — Tex. Bus. & Com. Code § 541 (Texas Data Privacy + Security Act — TDPSA), separate from Ed Code § 32.155/32.156 covered in §4 above.
- Delaware — Del. Code Tit. 6, § 12D-101+ (Delaware Personal Data Privacy Act, effective January 2026).
For LEAs in states with student-privacy laws not enumerated above, HallPal's default posture per STUDENT_DATA_AGREEMENT.md applies. Please contact legal@hallpal.divz.io to raise state-specific requirements + we will add a rider here.
10. Federal law
Nothing in this page limits HallPal's obligations under federal law, including:
- FERPA (34 C.F.R. Part 99) — see STUDENT_DATA_AGREEMENT.md §1.
- COPPA (15 U.S.C. § 6501+) — see PRIVACY.md §8.
- Section 504 + ADA — accessibility commitments in ACCESSIBILITY.md.
Where federal law is stricter than a state law, federal law controls.
Contact
State-specific commitments + district questions: legal@hallpal.divz.io Privacy: privacy@hallpal.divz.io Security: security@hallpal.divz.io