Research only

Schools, districts, colleges, and universities

Explore the policy documents and regulatory sources relevant to this industry. Assessment checks for this profile are in development.

Research listings are separate from implemented scans. No quote or assessment is available for this profile yet. Public uploads must contain no patient data or other restricted information.

Documents to review

  • Student records policyResearch document type
  • Data access procedureResearch document type
  • Vendor data policyResearch document type
  • Incident response planResearch document type

Scope questions

Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.

  • Where does the organization operate, and which regulator, license, permit or contract governs the activity?
  • Which business activities, data types and organization roles does the document describe?
  • Do the relevant thresholds or exceptions change which requirements apply?

Unknown answers stay unresolved. Document detection does not answer these questions for you.

A fictional example to explore

This short policy outline demonstrates the document's structure and research questions. It is a navigation example; scans for this profile are not available yet.

PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.

Regulations and frameworks to explore

These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.

Research only

Family Educational Rights and Privacy Act

20 USC 1232g; 34 CFR Part 99

For educational agencies/institutions receiving funds under US Department of Education programs. Confirm funding and education-record scope; not every private school is automatically covered. Rights transfer to eligible students at age 18 or attendance at a postsecondary institution. Vendor access and disclosures require their own exception and control review.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Does the educational institution receive covered Department of Education funding and maintain education records?
  • Are the relevant rights held by a parent or an eligible student, and what authorizes any vendor access/disclosure?
Research only

NIST Cybersecurity Framework 2.0

NIST CSWP 29

Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.

Jurisdictions: GLOBAL

Research applicability questions
  • Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
  • Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?