Skip to content
COPPA · 16 CFR Part 312

Our COPPA
posture.

We don’t serve children directly. Schools may consent on parents’ behalf for educational use, consistent with long-standing FTC COPPA guidance. The amended COPPA Rule’s compliance date was April 22, 2026. Here’s how our schools product is designed to support COPPA obligations.

Amended Rule compliance date: April 22, 2026 · Posture: school-authorized agent

What COPPA actually requires

The Children’s Online Privacy Protection Act (1998) and its implementing rule (16 CFR Part 312) apply to operators of websites or online services directed at children under 13, or that have actual knowledge they are collecting personal information from children under 13. Operators must:

  • Provide a clear privacy notice describing what is collected and how it is used
  • Obtain verifiable parental consent before collecting personal information from a child
  • Give parents the ability to review, delete, and refuse further collection of their child’s data
  • Maintain reasonable security and limit retention to the minimum necessary
  • Avoid conditioning a child’s participation on disclosure of more information than is reasonably necessary

The school-consent exception lets schools stand in for parents when (and only when) the operator uses the data solely for the use and benefit of the school and for no other commercial purpose.Long-standing FTC COPPA guidance

What changed in the 2024–2025 Final Rule

In January 2025 the FTC published the first major COPPA rule update since 2013. The amended COPPA Rule’s compliance date was April 22, 2026. The headline changes:

Separate consent for advertising

Operators must obtain a separate, specific opt-in consent before disclosing personal information to third parties for targeted advertising. Bundled consent is no longer valid.

Expanded definition of personal information

Biometric identifiers and government-issued identifiers (other than persistent identifiers) are now explicitly covered. Combinations of data that could identify a child are also in scope.

Stricter retention limits

Operators must retain personal information only as long as reasonably necessary for the specific purpose collected. Indefinite retention is prohibited; written retention policies are mandatory.

Stronger security requirements

Written information security program, annual review, and contractual obligations on third-party processors to maintain equivalent safeguards.

School authorization

Schools may consent on parents’ behalf for educational use, consistent with long-standing FTC COPPA guidance. The amended COPPA Rule’s compliance date was April 22, 2026. School consent covers data used solely for the use and benefit of the school and for no other commercial purpose.

Our COPPA posture, in plain language

Four design choices shape how our schools product is designed to support COPPA obligations.

Districts contract; we never serve children directly

INCLUXA for schools is sold to school districts and institutions, not to families. There are no student or parent logins: students are identified only by an opaque school or LMS ID.

School-authorized agent

A signed district agreement (SDPC National DPA v2.0 + the state exhibit for your state) records the district as the consenting authority. We process student data only on the district’s documented instructions, only for accessibility delivery.

Minimal student data

We store an opaque student ID, the accommodation types, a short description and a supporting quote from the redacted IEP (encrypted at rest), plus the uploaded file name. The IEP file itself is deleted right after parsing. Teachers review every suggestion before anything is applied.

No advertising. No commercial use. Ever.

Student data is never used for targeted advertising, commercial profiling, or sale. There is no “data for free service” trade. Districts pay; data stays with the district.

The school-consent exception, step by step

School consent only works if every link in the chain holds. Here is how each one is handled.

The district signs a written DPA

SDPC National DPA v2.0 plus the state exhibit for your state (e.g. California, Illinois, New York, Colorado, Texas; other states on request). The agreement records the district as consenting on parents’ behalf for educational use.

The district provides parental notice

The district gives parents notice through its usual process, describing the categories of student data processed and the purpose (accessibility delivery). The data we store is listed on this page.

INCLUXA processes only on documented instructions

IEP automation, the teacher dashboard and LMS connections stay locked until the district agreement is signed. We process student data only for accessibility delivery.

No commercial use, no advertising, no resale

No third-party analytics or ad trackers; first-party usage events only.

Parents retain rights through the school

Parents address review / deletion / refusal requests to the district. The district can view a student’s IEP record and delete their IEP data in the portal; a full export or deletion of other student data is available on request via privacy@incluxa.com, and the district’s retention setting removes the rest.

What districts must do (and avoid)

The school-consent exception puts a few responsibilities on the district. Most of them are one-time setup; a few are ongoing.

Do

  • ✓Sign the district agreement (Settings → Schools) before using IEP, teacher, or LMS features
  • ✓Give parents notice through your usual district process describing what data is processed
  • ✓Honor parental review and deletion requests — delete a student’s IEP data from the IEP screen, and email privacy@incluxa.com for a full export or deletion of other student data
  • ✓Limit INCLUXA access to staff with a legitimate educational interest
  • ✓Ask us to close the INCLUXA account when the district contract ends — IEP, profile and usage data are purged 30 days after deletion; audit logs (which may contain student IDs and file names) are kept for 2 years

Don’t

  • ✕Share staff logins with students — there are no student or parent accounts
  • ✕Use INCLUXA student data for marketing, advertising, or any commercial purpose unrelated to accessibility
  • ✕Expect IEP features before the agreement is signed — they stay locked until then
  • ✕Send raw IEP PDFs to anyone outside the district’s authorized staff
  • ✕Keep student data longer than you need it — set the retention period (1–120 months) in Settings → Schools

How COPPA and FERPA work together

For K–12, both laws apply at the same time. They cover different things, and one district agreement is designed to support both.

COPPA

Federal consumer-protection law. Governs collection of personal information from children under 13 by online services. Enforced by the FTC. Penalties: civil penalties per violation, adjusted annually for inflation.

FERPA

Federal education-privacy law. Governs disclosure of student education records by schools to third parties. Enforced by the U.S. Department of Education. Penalty: loss of federal funding.

Our approach: One district agreement supports both. The district consents on parents’ behalf for educational use under COPPA and designates INCLUXA as a FERPA “school official with a legitimate educational interest.”34 CFR § 99.31(a)(1)(i)(B)

Not legal advice

This page describes our compliance posture and product behavior. It is not a substitute for guidance from your district’s counsel. The amended COPPA Rule’s compliance date was April 22, 2026. Districts should review their parental notices and internal data-governance policies with counsel.

Ready to formalize the relationship?

Sign the district agreement in Settings → Schools. IEP automation, the teacher dashboard and LMS connections unlock once the agreement is signed.

Back to Schools overview State-by-state lawsRead FERPA detail