Oliver Page

Case study

August 6, 2025

What to Know About the Texas Student Privacy Act

(Ed Code §32.151)

Why Understanding the Texas Student Privacy Act is Critical for K-12 Schools

What to Know About the Texas Student Privacy Act (Ed Code §32.151) is that it protects student data used by educational websites, online services, and mobile apps. Passed in 2017 as House Bill 2087, the Act restricts how EdTech vendors use student information and grants parents significant rights over their children's data.

Key Provisions:

The law defines an "operator" as a provider of an online platform used for school purposes. These operators must follow strict rules for handling "covered information"—any student data not publicly available.

Recent amendments have strengthened the law, requiring parental consent for more software and setting stricter standards for school devices. For IT directors, this means carefully vetting vendor contracts and ensuring cybersecurity training covers these requirements. The Act supplements federal FERPA protections by adding specific restrictions on the commercial use of student data.

Infographic showing the five key components of the Texas Student Privacy Act: Who (K-12 schools and EdTech vendors), What (student personally identifiable information protection), When (effective 2017 with recent amendments), Where (Texas public schools), and Why (protect student privacy from commercial exploitation) - What to Know About the Texas Student Privacy Act (Ed Code §32.151) infographic

Understanding the Core Mandates of the Texas Student Privacy Act (Ed Code §32.151)

The core of What to Know About the Texas Student Privacy Act (Ed Code §32.151) is House Bill 2087, which took effect on September 1, 2017. As K-12 education acceptd online services and mobile apps, legislators recognized the need for stronger data protection. The law's primary goal is to prevent the commercial exploitation of student information, ensuring that data collected for educational purposes is used only for education.

This digital fence around student data prevents a student's activity on an educational app from being used for marketing or tracking their browsing habits. For legal details, the Full text of the Texas Education Code Chapter 32 is available online.

Key Definitions You Need to Know

Understanding these terms makes the Act clearer:

Prohibited Uses of Covered Information

The Act draws clear lines about what operators cannot do with student data:

Permitted Uses and Disclosures

The Act allows for responsible data handling that supports education:

Requirements for School Districts and EdTech Providers

Compliance with the Texas Student Privacy Act is a team effort between schools and their EdTech partners. What to Know About the Texas Student Privacy Act (Ed Code §32.151) is that it requires an ongoing partnership to protect student data. School districts act as the primary guardians, while EdTech providers are trusted partners who must handle that data responsibly.

a checklist for school administrators - What to Know About the Texas Student Privacy Act (Ed Code §32.151)

Responsibilities of School Districts

As data protectors, school districts have several key responsibilities:

Obligations for Website and App Operators (Vendors)

EdTech vendors working with Texas schools must:

How Recent Amendments Have Changed the Landscape

Texas lawmakers have worked to keep student privacy protections current with evolving technology. What to Know About the Texas Student Privacy Act (Ed Code §32.151) includes understanding that recent amendments have given parents more control and schools clearer guidance.

These changes reflect a demand for more transparency and control over the digital tools students use. The Texas Education Agency (TEA) now plays a more active role in setting standards, with a focus on minimizing data collection—if an app doesn't need certain information to function, it shouldn't collect it.

a timeline of key Texas student privacy laws - What to Know About the Texas Student Privacy Act (Ed Code §32.151)

HB 18 (2023) significantly strengthened parental rights regarding educational software.

Stricter Standards for Electronic Devices and Software

The Texas Education Agency now sets clearer standards for educational technology, helping schools make safer decisions.

These stricter standards require both districts and vendors to improve their practices. Districts must be more selective with technology, and vendors must build privacy and security into their products from the start.

Comparing the Texas Student Privacy Act with FERPA

While the Family Educational Rights and Privacy Act (FERPA) is the federal cornerstone of student privacy, What to Know About the Texas Student Privacy Act (Ed Code §32.151) is that it builds upon these federal protections. The two laws work together to create a comprehensive shield for student data.

FERPA sets the basic rules for all schools receiving federal funds, while the Texas Act adds specific protections for the digital age, particularly regarding EdTech vendors.

The key difference is their focus: FERPA primarily regulates schools, while the Texas Act directly targets third-party vendors.

How the Texas Act Supplements Federal Law

The Texas Act fills gaps where federal law is less specific for the modern digital classroom.

What to Know About the Texas Student Privacy Act (Ed Code §32.151) and Directory Information

The Texas Act aligns with FERPA's concept of "directory information"—basic details like a student's name, address, and activities that schools can share without specific consent after providing an opt-out opportunity.

Since "covered information" under the Texas law excludes publicly available directory information, the Act's main prohibitions don't typically apply to it. However, the law reinforces the importance of parental opt-out rights and requires schools to be transparent about their directory information policies. This ensures a balance between operational needs and family privacy preferences.

Parental Rights, Enforcement, and Penalties

Empowering parents is a core principle of student privacy law. What to Know About the Texas Student Privacy Act (Ed Code §32.151) is that it gives parents enforceable rights over their child's educational data. Violations of these rights carry serious consequences.

a parent and student looking at a tablet together - What to Know About the Texas Student Privacy Act (Ed Code §32.151)

Your Rights as a Parent or Guardian

As a parent or guardian in Texas, you have several key rights:

Penalties for Violating the Act

The Texas Student Privacy Act has significant enforcement power:

These penalties ensure that all parties take their responsibility to protect student data seriously.

Conclusion

Understanding What to Know About the Texas Student Privacy Act (Ed Code §32.151) is about more than compliance; it's about fostering a safe digital environment for students to learn and thrive. The Act represents Texas's commitment to protecting student privacy, evolving from its 2017 foundation to meet the challenges of modern educational technology.

The key takeaways are clear: EdTech companies cannot use student data for commercial purposes like targeted advertising, parents have meaningful rights to control their children's information, and school districts must be proactive partners in this protection. The law powerfully supplements federal FERPA protections by specifically addressing the commercial exploitation of student data by third-party vendors.

For school districts, proactive compliance is essential for building trust and avoiding serious penalties. However, policies alone are not enough. Student data privacy and cybersecurity are inextricably linked. Strong privacy rules are meaningless if a simple phishing email can compromise your entire system.

This is why a comprehensive approach to digital security is crucial. At CyberNut, we understand the unique challenges K-12 schools face. Our automated, gamified training helps your staff recognize and avoid phishing attempts that could expose sensitive student data. Our approach is designed to be effective and engaging for busy educators, strengthening your security without adding to your staff's workload.

Are you confident your school's defenses can protect the student data you are legally required to safeguard? Don't wait for a breach to find your vulnerabilities.

Get a complimentary Phishing Audit for your school district to see how your team would handle real-world phishing attempts. You can also Learn more about cybersecurity training for schools to see how our custom approach can strengthen your overall security posture.

Oliver Page

Some more Insigths

Back