Privacy Compliance for Education Technology Vendors
HB0055, titled "Privacy Compliance for Education Technology Vendors," revises Utah Code Section 53E-9-309 governing third-party contractors that receive personally identifiable student data from education entities. The bill requires contracts with ed-tech vendors to include specific privacy and data-handling provisions, including limits on collection, use, storage, sharing, deletion, and secondary use of student data, as well as audit rights for the education entity. It also requires contracts to spell out the vendor’s obligation to comply with state and federal privacy laws and the education entity’s duty to terminate the contract if a privacy violation is not remedied.
The bill adds a notice-and-cure process: once an education entity or government agency discovers an unauthorized use or sale of student data in violation of privacy law, it must notify the contractor within 30 days, and if the contractor does not remedy the violation and establish procedures to prevent recurrence, the contract must be terminated no sooner than 30 days after notice. The bill also bars vendors from charging fees or seeking damages for termination based on a privacy violation, requires the State Board of Education to review credible complaints and conduct compliance audits or investigations, and directs the board to create guidance materials for contractors. It preserves certain permitted uses, such as adaptive learning, functionality, some marketing to parents, and limited scholarship/nonprofit referrals with written authorization, while repealing a prior provision allowing contractors to respond directly to student requests for information or feedback.
HB0055 amends Utah’s student data privacy law to impose more detailed contractual, enforcement, and oversight requirements on education technology vendors and the education entities that hire them. It strengthens state-level compliance mechanisms by mandating notice, termination, audit, and investigation procedures, and by clarifying prohibited practices such as targeted advertising and unauthorized sale of student data. The bill also affects the State Board of Education by assigning it a more active role in complaint review, audits, investigations, and contractor guidance, while leaving in place certain exceptions for general audience applications, internet service, directory information, and lawful disclosures.
The available voting history shows strong, unanimous support at every stage, with no recorded opposition in either chamber or committee votes. The bill advanced through the House and Senate with broad bipartisan approval and was ultimately signed by the governor, suggesting the legislation was viewed as a straightforward privacy and consumer-protection measure rather than a controversial policy change. No committee transcripts were provided, so there is no recorded floor or committee debate indicating significant resistance.
There is little evidence of major contention in the legislative record provided, given the unanimous votes and lack of recorded transcript discussion. The most likely areas of policy sensitivity are the bill’s mandatory contract termination requirement, the prohibition on vendor fees or damages after termination, and the expanded role of the State Board of Education in audits and investigations. Another possible point of concern is the bill’s balance between restricting student-data use and preserving limited vendor functions such as adaptive learning, recommendation tools, and certain marketing or scholarship referrals with parental or adult-student authorization.