Skip to content
Vizipp

Security

Compliance, built into your systems

We help schools, agencies and businesses put the technical controls behind FERPA, COPPA, HIPAA, GLBA, GDPR and India’s DPDP Act in place — working alongside your legal counsel.

Our approach

How we help you meet your obligations

Compliance is a shared effort between your teams, your legal counsel and us. We focus on the systems and software that make it work day to day.

Gap assessment

Review your systems and processes against the requirements that apply to you, and prioritize the technical work.

Data mapping & inventory

Document what personal data you hold, where it lives, who can reach it and where it flows.

Privacy features in your apps

Notices, consent capture, access and deletion requests, and retention rules built into the software we deliver.

Access control, encryption & MFA

Role-based access, encryption in transit and at rest, and multi-factor authentication.

Audit logging & monitoring

Record who accessed what and when, and alert on unusual activity.

Vendor & data-sharing reviews

Review how vendors and partners handle your data, and the technical safeguards behind your agreements.

Secure development

Privacy by design and secure coding practices in every application we build on Nodio.

Documentation & evidence

Policies, system documentation and evidence your auditors and regulators can review.

Regulations

The regulations we support

A plain-language overview of each regulation, what it requires and where we can help.

United States

FERPA

Family Educational Rights and Privacy Act (1974)

FERPA protects the privacy of student education records and gives parents — and students once they become “eligible students” — rights over those records.

Who it applies to

Schools, districts and other educational agencies and institutions that receive funds under applicable US Department of Education programs. That includes most public K-12 districts and most colleges and universities. Rights pass from parents to the student at age 18 or when the student attends a postsecondary institution.

Key requirements

  • Let parents and eligible students inspect and review education records.
  • Let them request amendment of records they believe are inaccurate or misleading.
  • Obtain written consent before disclosing personally identifiable information from education records, unless an exception applies — for example, school officials with a legitimate educational interest, properly designated directory information, or health and safety emergencies.
  • Vendors and ed-tech providers may receive student data as “school officials” only when they perform an institutional service, are under the school’s direct control for how the records are used and maintained, and do not redisclose the data without authorization.
  • Notify parents and eligible students of their FERPA rights annually, and keep a record of disclosures.

How Vizipp helps

  • Map where student records live across your SIS, learning apps and ed-tech vendors.
  • Role-based access so teachers, counselors and staff see only the students and records they need.
  • Audit logs of who viewed or exported student data, supporting your record of disclosures.
  • Directory-information opt-outs and consent tracking built into the apps we build.
  • Technical review of ed-tech vendors’ data handling to support your data-sharing agreements.

Many states add their own student-privacy laws on top of FERPA. We can help map those requirements into your systems too.

United States

COPPA

Children’s Online Privacy Protection Act (1998) and the FTC’s COPPA Rule

COPPA gives parents control over the personal information that websites, apps and online services collect from children under 13.

Who it applies to

Operators of commercial websites and online services, including apps, that are directed to children under 13 — and general-audience services that have actual knowledge they collect personal information from children under 13. It is enforced by the Federal Trade Commission (FTC).

Key requirements

  • Post a clear, complete online privacy policy and give parents direct notice of your practices.
  • Obtain verifiable parental consent before collecting, using or disclosing a child’s personal information.
  • Let parents review their child’s information, have it deleted and refuse further collection.
  • Keep children’s information confidential, secure and accurate.
  • Retain it only as long as reasonably necessary for the purpose it was collected, then delete it securely.
  • The FTC updated the COPPA Rule in 2025, adding requirements such as a written information security program, a written data retention policy and separate parental consent before disclosing children’s information to third parties.

How Vizipp helps

  • Age screening and parental-consent flows designed into your apps.
  • Data minimization — collecting only what a feature actually needs from young users.
  • Parent dashboards to review, delete and withdraw consent for a child’s data.
  • Retention schedules with automatic, verifiable deletion.
  • Security controls and documentation that support a written information security program.

Under FTC guidance, a school may be able to consent in place of parents when an ed-tech service collects student data solely for the school’s educational use and for no other commercial purpose. Confirm the details with your counsel.

United States

HIPAA

Health Insurance Portability and Accountability Act (1996)

HIPAA protects protected health information (PHI). PHI held or sent electronically is electronic PHI, or ePHI.

Who it applies to

Covered entities — health plans, health care clearinghouses and health care providers that conduct certain transactions electronically — and their business associates: vendors that create, receive, maintain or transmit PHI on their behalf. It is enforced by the HHS Office for Civil Rights.

Key requirements

  • Privacy Rule: limit uses and disclosures of PHI, apply the minimum necessary standard, and honor patients’ rights such as access to their records.
  • Security Rule: administrative, physical and technical safeguards for ePHI, including a required risk analysis and risk management.
  • Breach Notification Rule: notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured PHI, and notify HHS.
  • Notify prominent media outlets when a breach affects more than 500 residents of a state or jurisdiction.
  • Put Business Associate Agreements (BAAs) in place with business associates.

How Vizipp helps

  • Technical input to your Security Rule risk analysis.
  • Access controls, unique user IDs and automatic logoff for systems that handle ePHI.
  • Encryption of ePHI in transit and at rest.
  • Audit logging and monitoring that help you detect and investigate unauthorized access.
  • Minimum-necessary access built into the workflows of the apps we build.

Student health records kept by K-12 schools are generally education records under FERPA rather than PHI under HIPAA. School-based health centers, district health plans and healthcare partners may be subject to HIPAA, so confirm which law applies to each system.

United States

GLBA

Gramm-Leach-Bliley Act (1999)

GLBA protects customers’ nonpublic personal information (NPI) held by financial institutions, through the Financial Privacy Rule and the FTC’s Safeguards Rule.

Who it applies to

Companies significantly engaged in providing financial products or services — such as banks, lenders, mortgage brokers and tax preparers — and colleges and universities that participate in federal student financial aid programs.

Key requirements

  • Financial Privacy Rule: provide privacy notices and let customers opt out of certain sharing with nonaffiliated third parties.
  • Safeguards Rule: a written information security program run by a designated Qualified Individual, based on a written risk assessment.
  • Access controls, an inventory of data and systems, encryption of customer information in transit and at rest, and multi-factor authentication.
  • Secure development practices, secure disposal of customer information, change management, and monitoring and logging of user activity.
  • Continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months; security awareness training; oversight of service providers; and a written incident response plan.
  • The Qualified Individual reports to the board at least annually, and the FTC must be notified no later than 30 days after discovering a security event involving unencrypted information of at least 500 consumers.

How Vizipp helps

  • Data and system inventory for customer and student financial information.
  • Encryption, MFA and least-privilege access for systems holding NPI.
  • Secure development and change management for the applications we build.
  • User-activity logging and monitoring.
  • Secure disposal features and retention rules in your applications.
  • Documentation that supports your written information security program.

For colleges and universities, GLBA commonly applies to financial aid, billing and enrollment systems that handle student and family financial information.

European Union

GDPR

General Data Protection Regulation — Regulation (EU) 2016/679

The GDPR has applied since 25 May 2018 and governs how the personal data of people in the EU is processed.

Who it applies to

Organizations in the EU, and organizations outside the EU that offer goods or services to, or monitor the behavior of, people in the EU — including processors acting on behalf of such organizations.

Key requirements

  • Follow the core principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.
  • Rely on one of six lawful bases: consent, contract, legal obligation, vital interests, public task or legitimate interests.
  • Honor data-subject rights: to be informed, access, rectification, erasure, restriction, data portability, objection, and rights related to automated decision-making and profiling.
  • Keep records of processing, apply data protection by design and by default, run DPIAs for high-risk processing, appoint a DPO where required, and use written contracts with processors.
  • Notify the supervisory authority of a personal data breach within 72 hours where feasible, and affected individuals when the risk to them is high.
  • Safeguard transfers outside the EU, for example through adequacy decisions or Standard Contractual Clauses. Fines can reach €20 million or 4% of worldwide annual turnover, whichever is higher.

How Vizipp helps

  • Data mapping that supports your records of processing activities.
  • Consent, preference and lawful-basis tracking built into your apps.
  • Self-service tools for access, rectification, erasure and portability requests.
  • Technical input to DPIAs, and privacy by design in the software we build.
  • Logging and monitoring that help you detect breaches early enough to meet the 72-hour window.

India

DPDP Act

Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025

India’s DPDP Act governs digital personal data. It is implemented through the DPDP Rules, 2025, which phase obligations in over time.

Who it applies to

Digital personal data processed in India, and processing outside India connected with offering goods or services to people in India. Key roles are the Data Fiduciary (who decides why and how data is processed), the Data Processor, the Data Principal (the individual), Consent Managers and the Data Protection Board of India.

Key requirements

  • Give a clear, itemized notice, and obtain consent that is free, specific, informed, unconditional and unambiguous — and as easy to withdraw as to give.
  • Process data only for the stated purpose or certain legitimate uses, with reasonable security safeguards to prevent breaches.
  • Notify the Data Protection Board and each affected Data Principal of a personal data breach.
  • Erase data once the purpose is served or consent is withdrawn, unless the law requires retention, and publish contact details for grievances.
  • Obtain verifiable parental consent before processing a child’s data (anyone under 18), with no tracking, behavioral monitoring or targeted advertising directed at children.
  • Significant Data Fiduciaries must appoint a Data Protection Officer based in India and an independent data auditor, and run periodic DPIAs and audits. Penalties can reach ₹250 crore per instance.

How Vizipp helps

  • Consent and notice flows, including withdrawal, built into your apps.
  • Tools for Data Principals to access, correct and erase their data and raise grievances.
  • Verifiable parental-consent flows for users under 18.
  • Security safeguards and logging that support breach detection and reporting.
  • Retention rules with automatic erasure when the purpose is served.

FAQ

Compliance questions, answered

Is this legal advice?

No. Vizipp provides technical and operational implementation support. Work with qualified legal counsel to interpret how each law applies to your organization.

Which of these regulations apply to us?

It depends on who you serve, what data you hold and where your users are. A K-12 district typically works with FERPA and, through its ed-tech vendors, COPPA; a healthcare partner with HIPAA; a college’s financial aid office with GLBA. Your counsel confirms the list — we map it into your systems.

We build ed-tech for schools. Can you help?

Yes. We build FERPA- and COPPA-aware features such as role-based access, audit logs, consent flows and data deletion into applications for schools, including those built on our Nodio platform.

Can you add these controls to our existing applications?

Yes. We review existing systems and add access controls, encryption, audit logging, consent and retention features where they are missing.

Do you certify that we are compliant?

No. We help you implement controls and prepare documentation and evidence. Compliance decisions rest with you and your counsel, and any formal certification or audit opinion comes from independent auditors.

Make compliance part of how your systems work

Tell us which regulations you’re working with and we’ll help you plan the technical work alongside your legal counsel.

Vizipp

We help organizations thrive in the digital age — building custom software, web and mobile applications, and AI-powered tools on our Nodio platform.

hr@vizipp.com
Proud member of TIPS-USA

© 2026 Vizipp Inc. All rights reserved.