Privacy Law Library

Student personal information; school service providers and school-issued devices

VA student data privacy

Students · Children · Location

Virginia's K-12 student privacy law. Edtech providers and school device providers must publish clear privacy policies, run information security programs, let students and parents access and correct data, delete data on request, and use data only with consent or as the school contract allows. They may not use student data for targeted advertising, build non-school profiles, or sell it, and may not remotely use school-issued devices' location, camera, microphone, or interaction monitoring except for limited educational, support, proctoring, or safety purposes.

Where
Virginia
Citation
Va. Code § 22.1-289.01
Status
In force
In force since
2015-07-01
Last amended
2025-07-01
Enforced by
Not stated in the section (enforced mainly through school division contracts)
People can sue
No
Penalties
The section sets no specific penalty.
Applies to
  • School service providers operating websites, apps, or online services under contract with a Virginia school division (22.1-289.01(A))
  • School technology providers supplying school-issued devices under contract, and school boards or schools issuing devices themselves (22.1-289.01(B))
  • Providers in operation on June 30, 2016 are covered once their contract is renewed (22.1-289.01(F))

What a privacy notice must say

  • Provide clear information about the student data collected and how it is used and shared; maintain a privacy policy and give prominent notice before material changes.Va. Code § 22.1-289.01(B)(1)-(2)

Rights it gives people

  • Facilitate student or parent access to and correction of student personal information, and provide an electronic copy on request.Va. Code § 22.1-289.01(B)(4), (B)(10)

Practices it requires

  • Collect, use, and share student data only with student or parent consent or as the school contract authorizes; get consent for uses inconsistent with the privacy policy.Va. Code § 22.1-289.01(B)(5)-(6)
  • Do not knowingly use student data for targeted advertising, build non-school personal profiles, or sell it (except to an acquiring successor).Va. Code § 22.1-289.01(C)(1)-(3)
  • Do not access or monitor school-issued devices' location tracking, audio or video features, or student interactions except for noncommercial educational purposes, technical support, exam proctoring, or permitted safety monitoring.Va. Code § 22.1-289.01(C)(4); (E)(4)
  • Bind successors and contractors to the privacy policy and security program; delete student data on the school's request; wipe returned school-issued devices before reissue or transfer.Va. Code § 22.1-289.01(B)(7)-(9)

Security duties

  • Maintain a comprehensive information security program with administrative, technological, and physical safeguards.Va. Code § 22.1-289.01(B)(3)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Effective dates inferred from Virginia's default July 1 effective date for regular-session acts (history notes); enacting bill pages not checked. History: 2015, c. 728; 2016, cc. 438, 439, 468; 2017, c. 518; 2025, c. 364. What the 2025 amendment changed was not compared.

Research reference, not legal advice.