Reference
Selling into education means clearing four overlapping regimes at once: data protection, children's privacy, accessibility, and public procurement. They differ by country — and in the United States, by state. This is the map we work from.
A note on what this is. A working engineering reference, not legal advice. Regimes change, and your obligations depend on your data, your users and your contracts. We build to these requirements and work alongside your counsel — we don't replace them.
By region
Federal, state and provincial
Union-wide and national
Rapidly diverging regimes
Often overlooked, increasingly enforced
In practice
01
Every field a learner produces gets an owner, a lawful basis, a retention period and a deletion path — recorded once, in a register that survives staff turnover. Retro-fitting this after launch is where budgets go to die.
02
Keyboard paths, focus order, contrast and screen-reader semantics are part of the component's definition of done, not an audit finding. Interactive maths is the hard case, and it is solvable.
03
Under-13 in the US, under-18 in India, age-appropriate design in the UK — these are different mechanisms, not one toggle. School-consent and parental-consent pathways are built as distinct flows.
04
Which vendor sees what, hosted where, under which transfer mechanism. A district security review or an EU procurement will ask, and the answer needs to be a document, not an investigation.
05
LTI 1.3 for launch, OneRoster for rostering, QTI for items, Caliper and xAPI for evidence. Without these an institutional sale stalls regardless of product quality.
06
DPIA, records of processing, VPAT/ACR, security questionnaire responses, sub-processor list. These are deliverables with owners and review dates, not documents written the night before diligence.
Cross-cutting