R
ROSTER ACCESS

SOPPA Compliance Document

Data Privacy Agreement

Template for Illinois Schools under SOPPA (105 ILCS 85/)

DATA PRIVACY AGREEMENT

Student Online Personal Protection Act Compliance

This Data Privacy Agreement ("Agreement") is entered into by and between:

SCHOOL/DISTRICT:

Address:

OPERATOR:

Roster Access

Service:

Roster Management & QR Code Sharing

1. PURPOSE

This Agreement establishes the terms under which Roster Access ("Operator") will collect, maintain, use, and protect student data provided by the School/District in compliance with the Illinois Student Online Personal Protection Act (SOPPA), 105 ILCS 85/.

2. DEFINITIONS

"Covered Information" means personally identifiable information or materials about a student in any media or format that is:

  • Created or provided by a student or parent to the Operator
  • Created or provided by an employee of the School/District to the Operator
  • Gathered by the Operator through the operation of its website, service, or application

3. DATA ELEMENTS COLLECTED

The Operator may collect and process the following student data elements through the Service:

  • Student names
  • Jersey/uniform numbers
  • Grade levels
  • Team positions
  • Sport participation information
  • School affiliation

4. OPERATOR OBLIGATIONS

The Operator agrees to:

  • Use covered information solely for the contracted K-12 school purposes of roster management and game-day sharing
  • NOT engage in targeted advertising based on student data
  • NOT use information to amass profiles about students for non-educational purposes
  • NOT sell, rent, lease, or trade covered information
  • NOT disclose covered information except as required by law or as authorized in this Agreement
  • Implement and maintain reasonable security procedures appropriate to the nature of the covered information
  • Delete covered information within 160 days of a request from the School/District
  • Automatically delete roster data 160 days after upload

5. DATA BREACH NOTIFICATION

In the event of an unauthorized release, disclosure, or acquisition of covered information, the Operator shall notify the School/District within thirty (30) days of confirming the breach. The notification shall include:

  • A description of the incident
  • The types of information involved
  • Steps taken to investigate and remediate
  • Contact information for further inquiries

6. SUBCONTRACTORS

The Operator uses the following subcontractors who may have access to covered information:

  • Vercel Inc. - Hosting and infrastructure services
  • Supabase Inc. - Authentication and database services

All subcontractors are contractually bound to maintain the same level of data protection required under this Agreement and SOPPA.

7. SCHOOL/DISTRICT OBLIGATIONS

The School/District agrees to:

  • Post on its website that the Operator is an approved operator under SOPPA
  • Disclose the data elements being collected
  • Make a copy of this Agreement available to parents upon request
  • Ensure that only authorized personnel upload student data to the Service
  • Notify parents of any data breach within 30 days as required by SOPPA

8. PARENT AND STUDENT RIGHTS

Parents and eligible students have the right to:

  • Inspect covered information held by the Operator
  • Request correction of inaccurate information
  • Request deletion of covered information
  • Obtain a copy of this Agreement from the School/District

Such requests shall be made through the School/District, which will coordinate with the Operator.

9. DATA RETENTION AND DELETION

Roster data is automatically deleted 160 days after upload. Upon termination of this Agreement or upon request by the School/District, the Operator will delete all covered information within 160 days.

10. TERM AND TERMINATION

This Agreement shall remain in effect for one (1) year from the date of execution and shall automatically renew for successive one-year terms unless either party provides written notice of termination at least 30 days prior to the end of the current term.

11. GOVERNING LAW

This Agreement shall be governed by and construed in accordance with the laws of the State of Illinois, including the Student Online Personal Protection Act (105 ILCS 85/).

SIGNATURES

FOR THE SCHOOL/DISTRICT:

Signature:

Printed Name:

Title:

Date:

FOR ROSTER ACCESS:

Signature:

Printed Name:

Title:

Date:

← Back to Roster AccessView SOPPA ComplianceView Privacy Policy