Scope
Define covered systems, datasets, and user roles. Include explicit exclusions to avoid scope creep and to limit access to only what the recipient needs.
A written EDA clarifies legal obligations, documents security commitments, and reduces disputes by specifying permitted uses, retention, and audit rights under FERPA and applicable state law.
Typical users span institutional, vendor, and legal roles that manage or process education data.
Parties should align on technical controls, legal basis, and retention before any data exchange begins.
Define covered systems, datasets, and user roles. Include explicit exclusions to avoid scope creep and to limit access to only what the recipient needs.
Catalog each data category and sensitivity level, such as directory, educational records, special education, and health‑related information tied to FERPA or HIPAA regimes.
Specify technical controls (encryption in transit and at rest, MFA, logging) and minimum standards for vendor security to support breach investigations and compliance.
Require periodic audit reports, real‑time access logs, and an agreed incident reporting cadence to demonstrate compliance and enable oversight.
Set retention periods, archival formats, and secure deletion methods that reflect federal and state recordkeeping obligations and program needs.
Allocate indemnity, limitation of liability, and remediation steps for unauthorized disclosures or repeated compliance failures to manage institutional risk.
| Field | Configuration |
|---|---|
| Signer Order | Sequential or parallel routing depending on approvals |
| Authentication | Email plus optional SMS code or KBA for high‑risk access |
| Audit Trail | Enable IP, timestamp, and action logging |
| Document Retention | Set automatic archival and export to secure storage |
Choose delivery channels and integrations that meet security and audit requirements before execution.
Complete legal and security review at least 30 days before data exchange.
Obtain all required signatures prior to any data transfer or system access provisioning.
Follow HIPAA or contract breach notice timelines; HIPAA uses specific notification rules for breaches.
Schedule annual or event-driven audits and deliver reports within agreed timeframes.
Issue renewal or termination notices 60 days before contract end.
| Criteria | Education EDA | Data Processing Agreement |
|---|---|---|
| Purpose | data sharing for education | data processing under controller/processor model |
| Signatory Parties | institution and vendor | controller and processor |
| Regulatory Focus | ferpa and state privacy | gdpr/industry data protection where applicable |
| Typical Retention | program‑based terms | processor follows controller instructions |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes (Business Premium) | Varies | Varies | Varies | Varies |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |