Utah

Utah Student Data Privacy

Requires Signed Agreement
Does not require signed agreement

Utah requires strong contract-based controls for third-party contractors that receive personally identifiable student data under Utah Code § 53E-9-309. Effective July 1, 2026, HB 55 strengthens these requirements by adding vendor privacy compliance, remediation, and contract termination obligations for certain violations of state or federal privacy law.

Utah Student Privacy and Data Protection Guide

Primary Law
Student Privacy and Data Protection — third-party contractor requirements for personally identifiable student data, including 2026 requirements for education technology vendor privacy compliance

Citation
Utah Code Title 53E, Chapter 9, Part 3 (Student Data Protection), notably § 53E-9-309; Utah HB 55 (2026), Privacy Compliance for Education Technology Vendors

Official Text

Utah HB 55 (2026) — Official Bill Page:
https://le.utah.gov/~2026/bills/static/HB0055.html

Utah HB 55 (2026) — Enrolled Text:
https://le.utah.gov/Session/2026/bills/enrolled/HB0055.pdf

Overview

Utah has a dedicated student privacy framework that addresses how student data is collected, used, shared, and safeguarded. A key compliance element is how Utah regulates third-party contractors that receive personally identifiable student data under a contract with a public education entity.

In 2026, Utah strengthened these protections through HB 55, Privacy Compliance for Education Technology Vendors, which amended Utah Code § 53E-9-309. Effective July 1, 2026, the law adds specific requirements for responding to certain vendor privacy violations, terminating contracts when violations are not remedied, protecting education entities from financial liability for required termination, and increasing state oversight of third-party contractor compliance.

For districts, the operational takeaway is clear: when a vendor will receive student PII, districts should use signed agreements that define permitted use, prohibit unauthorized redisclosure, and require appropriate security and data lifecycle controls. Districts also need processes to identify and respond when a vendor's use of student data violates applicable state or federal privacy law.

Applicability and Scope

Utah's student data protection requirements are most relevant when:

  • A district contracts with a vendor that receives or processes personally identifiable student data
  • Tools integrate with district systems (SIS, identity providers, learning platforms) and receive roster or student performance data
  • Districts need a consistent process to review, approve, and monitor edtech vendors
  • Districts need to respond to vendor practices that may violate Utah or federal student privacy requirements

Third-Party Contractor Requirements

Utah's framework establishes expectations for contractors that receive student PII under a contract, including purpose limitation and protections against misuse or unauthorized disclosure. Districts should ensure vendor terms match actual data flows and that subcontractors are controlled.

Third-party contractors are subject to restrictions governing how student data may be collected, used, stored, and shared, and contracts must contain provisions necessary for the education entity to ensure compliance with Utah's student data protection requirements.

New Requirements Under Utah HB 55

Effective July 1, 2026, HB 55 strengthens Utah's existing requirements for third-party education technology contractors.

Under the amended law, education entities and government agencies contracting on their behalf must include provisions in applicable vendor contracts describing their statutory duty to terminate the contract for covered privacy violations. Contracts must also prohibit termination fees or other financial liability when termination is required under the law.

When an education entity or government agency discovers a third-party contractor's unauthorized use of student data or information in violation of applicable state or federal privacy laws — including Utah's student privacy law, FERPA, and COPPA — the entity must provide notice to the contractor within 30 days of discovering the violation.

After receiving notice, the contractor must remedy the privacy violation to the greatest extent practicable and establish processes and procedures designed to prevent the compliance failure from recurring. If the contractor fails to satisfy those requirements, the education entity or government agency must terminate the contract as provided by the statute.

HB 55 also establishes a process for suspected violations to be reported to the Utah State Board of Education's student data privacy team. Reports determined to be credible, relevant, and sufficiently specific may lead to a compliance audit or investigation.

For Utah districts, this makes ongoing vendor oversight increasingly important. Privacy compliance is not limited to reviewing a vendor when a tool is initially approved; districts also need visibility into vendor practices throughout the relationship so they can identify and respond to compliance concerns.

Security and Data Lifecycle Controls

Districts should verify that vendors have reasonable safeguards appropriate to the sensitivity of student data and maintain clear procedures governing retention and deletion.

HB 55 also strengthens end-of-contract requirements. When a contract with an education entity is completed and has not been renewed, the third-party contractor must return or delete personally identifiable student data under the education entity's control unless the student's parent provides written consent allowing the contractor to maintain the data.

This makes data lifecycle management an important component of Utah edtech oversight, from initial approval through contract expiration or termination.

How Can EdPrivacy Help Utah Schools

Utah's framework is easiest to implement when districts can consistently document which vendors receive student PII, what contract terms apply, and what security and data lifecycle controls are in place. HB 55 makes ongoing oversight even more important by requiring education entities to respond when certain vendor practices violate state or federal privacy requirements.

EdPrivacy helps districts centralize approvals, vendor reviews, contracts, and supporting documentation so oversight remains consistent across many tools.

The platform helps districts:

  • Track which tools and integrations receive personally identifiable student data
  • Store signed DPAs/contracts, privacy terms, and security documentation in one place
  • Document approval conditions, including purpose limitation, disclosure controls, retention, and deletion expectations
  • Identify potential privacy concerns in vendor policies and practices
  • Monitor vendor changes and schedule periodic re-review
  • Maintain documentation to support ongoing vendor oversight and compliance decisions

Summary

Utah districts should be prepared to:

  • Use appropriate vendor agreements whenever student PII is shared with a third-party contractor
  • Confirm vendor use of student data remains within the permitted purposes and contractual terms
  • Ensure applicable contracts address the termination requirements added by HB 55
  • Establish a process for identifying, documenting, and responding to covered vendor privacy violations
  • Verify security safeguards and clear data lifecycle controls
  • Ensure student PII is returned or deleted when applicable contracts end
  • Maintain consistent documentation and ongoing monitoring across the district's EdTech ecosystem

Utah Code § 53E-9-309 has long supported a contract-driven approach that makes enforceable safeguards central to protecting student data. HB 55 strengthens that framework by adding specific notification, remediation, and termination requirements when third-party contractors fail to comply with applicable student privacy laws, making ongoing vendor compliance an increasingly important responsibility for Utah schools.