Skip to main content
Plio Academy
← Compliance Documentation

Plio Academy

Compliance Matrix

Effective: May 2026 · Full documentation: plio.academy/trust/compliance

This matrix is designed for district IT officers, procurement teams, and district counsel. It summarises Plio Academy's compliance position across federal and state student-privacy laws. It is not a substitute for a signed Data Processing Agreement. Contact compliance@plio.academy to request a DPA or state-specific addendum.

Federal Laws & Programs

Law / ProgramKey RequirementStatusNotes
FERPASchool official status, no sale of education records, RBAC, audit logs.CompliantDPA available. Role-based access enforced at DB layer. Privileged access fully audit-logged.
COPPAOperator status. Verifiable parental consent for under-13. No behavioral tracking.CompliantGuardian account creation = verifiable consent. School consent exception supported. No ad trackers.
CIPASchools must deploy internet content filter as E-Rate condition.N/APlio is not a content filter. Allowlist plio.academy in your existing filter. No unfiltered internet exposure.
E-Rate Cat. 1Telecom / connectivity services.Not ApplicablePlio is a cloud-hosted educational app, not a telecom. Category 1 ineligible by design.
E-Rate Cat. 2Internal connections, managed Wi-Fi, qualifying managed services.Potentially EligibleMay qualify under certain district procurement structures. Consult your E-Rate coordinator.

State Student Privacy Laws

StateLawKey RequirementStatusNotes
ILSOPPA (105 ILCS 85)Operators must sign a Data Privacy Agreement, prohibit behavioral advertising, and delete data on request.CompliantDPAs signed on request. No behavioral advertising on student-facing pages. Data deleted within 30 days.
CAAB 1584 (Ed. Code §49073.1)Data ownership stays with district/student. Sale of student data prohibited. Data deletion required.CompliantStudent data owned by student/guardian. No data sales. DPA clauses available for district contracts.
NYEducation Law 2-dContractors must sign Parents' Bill of Rights appendix, restrict data use to contracted purposes, report breaches within 7 days.CompliantParents' Bill of Rights appendix available. Breach notification within 72 hours (exceeds 7-day requirement).
TXSB 820 (Ed. Code §32.151)No sale of student data, no targeted advertising, no profiling unrelated to K-12 purposes.CompliantNo data sales, no advertising, no third-party profiling. Data used only for in-app educational features.
WAOSPI Student Privacy / RCW 28A.604SDPC agreement or equivalent required. Data restricted to K-12 purposes. Re-identification prohibited.CompliantSDPC-compatible DPA language available. No re-identification. District agreements executed on request.

Contact

Compliance and procurement questions:
compliance@plio.academy · We respond within 2 business days.

Full compliance documentation: plio.academy/trust/compliance
Trust Center: plio.academy/trust
For Districts: plio.academy/for-districts

Plio Academy · 501(c)(3) nonprofit · plio.academy · compliance@plio.academy

This document was last updated May 2026. Check plio.academy/trust/compliance for the most current version. This is not legal advice.