← Pretoni Education

Reference

What actually governs an education product.

Selling into education means clearing four overlapping regimes at once: data protection, children's privacy, accessibility, and public procurement. They differ by country — and in the United States, by state. This is the map we work from.

A note on what this is. A working engineering reference, not legal advice. Regimes change, and your obligations depend on your data, your users and your contracts. We build to these requirements and work alongside your counsel — we don't replace them.

By region

The regimes, named.

United States & Canada

Federal, state and provincial

FERPA
Education records, directory information, school-official exception
COPPA
Under-13 data, verifiable parental consent, school consent pathway
PPRA
Surveys and protected categories of information
State student-privacy laws
SOPIPA (CA), Ed Law 2-d (NY), SOPPA (IL) and ~40 more
Section 508 / ADA
Public-sector procurement, WCAG-conformant delivery
PIPEDA · Quebec Law 25
Canadian federal and provincial privacy

Europe & United Kingdom

Union-wide and national

GDPR
Lawful basis, DPIAs, minimisation, subject rights, transfers
UK GDPR & DPA 2018
Plus DfE expectations for data in schools
Children's Code
Age-appropriate design, profiling and nudge constraints
European Accessibility Act
Applicable since June 2025; EN 301 549
Data residency
EU/EEA hosting, transfer mechanisms, sub-processor mapping

Asia-Pacific

Rapidly diverging regimes

India — DPDP Act
Children's data, verifiable parental consent, consent managers
India — NEP 2020
Curriculum alignment; CBSE / NCERT mapping
Australia — Privacy Act
Plus ACARA curriculum alignment
Japan — APPI · Singapore — PDPA
Consent, cross-border transfer rules
China — PIPL
Minors' provisions, localisation, sector restrictions

Latin America, Middle East & Africa

Often overlooked, increasingly enforced

Brazil — LGPD & ECA
Data protection plus statutory child protection
Mexico — LFPDPPP
Notice, consent and ARCO rights
UAE & Saudi — PDPL
Data residency and localisation expectations
South Africa — POPIA
Processing of children's personal information

In practice

How this shows up in the build.

01

Map the data before writing the feature

Every field a learner produces gets an owner, a lawful basis, a retention period and a deletion path — recorded once, in a register that survives staff turnover. Retro-fitting this after launch is where budgets go to die.

02

Treat accessibility as a build constraint

Keyboard paths, focus order, contrast and screen-reader semantics are part of the component's definition of done, not an audit finding. Interactive maths is the hard case, and it is solvable.

03

Design consent for the age of the user

Under-13 in the US, under-18 in India, age-appropriate design in the UK — these are different mechanisms, not one toggle. School-consent and parental-consent pathways are built as distinct flows.

04

Keep residency and sub-processors legible

Which vendor sees what, hosted where, under which transfer mechanism. A district security review or an EU procurement will ask, and the answer needs to be a document, not an investigation.

05

Build for the integrations institutions require

LTI 1.3 for launch, OneRoster for rostering, QTI for items, Caliper and xAPI for evidence. Without these an institutional sale stalls regardless of product quality.

06

Produce the artefacts buyers ask for

DPIA, records of processing, VPAT/ACR, security questionnaire responses, sub-processor list. These are deliverables with owners and review dates, not documents written the night before diligence.

Cross-cutting

Standards we build to.

Accessibility

  • WCAG 2.2 AA
  • EN 301 549
  • VPAT / ACR
  • Screen-reader & keyboard paths

Interoperability

  • LTI 1.3
  • OneRoster
  • QTI
  • Caliper
  • SCORM
  • xAPI

Security

  • ISO/IEC 27001-aligned ISMS
  • SOC 2 readiness
  • Threat modelling
  • Pen-test remediation

Data governance

  • Data mapping & RoPA
  • DPIA / TIA
  • Retention & deletion
  • Sub-processor register

Entering a new market, or blocked on a security review?

Book a 15-minute callpretonitech@gmail.com