SOPPA-NJ
New Jersey Student Online Personal Protection Act
- Statute
- N.J.S.A. 56:8-215 et seq.
- Regulations
- None specified
- Enacted / Last Major Amendment
- P.L. 2019, c.494 (A4978); signed Jan 21, 2020; effective Jul 19, 2020
- Jurisdictional Layer
- New Jersey (state)
Summary
Student-side operator privacy law. Prohibits operators of K-12 online services from selling student data, using it for targeted advertising, or building non-educational student profiles. Requires reasonable security and deletion on request. Schools must execute written agreements with edtech vendors defining data-protection duties.
Key Terms
- Operator
- An entity operating a K-12 online site, service, or app used for school purposes that handles student covered information.
- Covered information
- Personally identifiable information about a student created or gathered through a K-12 online service.
School-side obligations
- Execute written agreements with operators that define data-protection duties
- Maintain an inventory of operators with which the school has agreements
Vendor-side obligations
- Do not sell, rent, or trade student covered information
- Do not use student covered information for targeted advertising
- Do not create non-K-12 student profiles
- Maintain reasonable security procedures and practices
- Delete student covered information on school request or at contract termination
- Limit use to providing, supporting, and maintaining the K-12 service plus limited research
Breach notification
Governed by the NJ data breach notification law (N.J.S.A. 56:8-161 et seq.): notice in the most expedient time possible without unreasonable delay.
Enforcement
NJ Division of Consumer Affairs (Department of Law and Public Safety); Commissioner of Education consulted on rulemaking.
NCSC AI Toolkit — Scanner Fields
These fields in the NCSC AI Toolkit derive from this statute:
Case Law — Verification Queue
Pending vLex verification. Never cite these without verification.
- SOPPA-NJ constructionTBDvLex query: '56:8-215' OR 'Student Online Privacy' /s charter
Open Questions / Unsettled Law
- Sub-processor flow-through when an MSP engages downstream vendors
- Free-tier edtech via teacher self-signup is the largest compliance gap