Compliance / State Student Privacy Laws
State Student Data Privacy Laws for MSPs
The patchwork of 20+ state laws — modeled on California's SOPIPA — that ban using student data for targeted advertising, sale, or non-educational profiling, sitting on top of (not replacing) FERPA and COPPA. California's CCPA/CPRA adds a further layer of consumer-privacy-style rights that can reach school vendors too.
Why this reaches an MSP, not just the client
Most SOPIPA-style laws bind the vendor directly, whether or not a contract says so — so an MSP with access to a school's student data is regulated by whichever states its clients sit in, not just by FERPA. That means "we don't sell or advertise against student data" has to be demonstrable per state, not just true in general.
What the Nexus compliance module tracks
- Posture tracked against the core vendor prohibitions each state law shares — no targeted advertising, no sale, no non-educational profiling — with the three-state model used everywhere else
- Deletion-on-request handling evidenced per student record, the specific capability most of these laws call out by name
- Evidence attached directly to the control it supports, including where CCPA/CPRA-style consumer-rights language overlaps with SOPIPA-style student-privacy duties
- Gap reporting and a QBR rollup that separate what's state-law-driven from what's FERPA/COPPA-driven, so a district doesn't have to untangle which regime a gap belongs to
This describes what the module tracks against State Student Privacy Laws — not a claim that Nexus or any client on it is certified or audited against it. See the compliance & QBR module for the full picture, or read the blog for more on how we think about compliance tooling.
Other frameworks
SOC 2
The audit framework a lot of your clients' own customers require them to answer for — and that requirement flows straight down to you as their MSP.
NIST CSF
A widely-adopted, vendor-neutral structure for cybersecurity posture — Identify, Protect, Detect, Respond, Recover — that shows up in RFPs, cyber-insurance questionnaires, and board conversations alike.
HIPAA
If any client handles protected health information, HIPAA's Security Rule reaches your MSP the moment you touch their systems — business associate agreement or not.
Ready to see State Student Privacy Laws posture tracked for real?
Join the design-partner cohort and we'll walk through the control mapping for your own clients.