Scope
Defines who the policy covers (students, staff, guests), what devices and networks are included, and whether personal devices are subject to the same rules when used on school systems.
An AUP clarifies acceptable behavior, protects student privacy, reduces cybersecurity risk, and documents disciplinary processes. It helps administrators and teachers enforce consistent rules, informs parents and students of expectations, and supports legal compliance with federal standards such as FERPA and ESIGN where electronic acknowledgements are used.
Primary users include school administrators, IT staff, teachers, students, and parents who must understand and acknowledge acceptable technology practices.
Policies are most effective when stakeholders receive training, regular reminders, monitoring, and documented acknowledgements from administrators.
Defines who the policy covers (students, staff, guests), what devices and networks are included, and whether personal devices are subject to the same rules when used on school systems.
Lists acceptable academic, research, and communication activities, including approved educational apps and sites; clarifies acceptable personal use limits and expectations during school hours and on school networks.
Specifies banned behaviors such as hacking, unauthorized access, cyberbullying, cheating, inappropriate content sharing, and circumvention of security controls, with examples to reduce ambiguity and support enforcement.
Describes collection, storage, and access to education records and device logs; explains FERPA protections, data minimization, conditional disclosures, and parental notification requirements where applicable and procedures.
Sets disciplinary measures, escalation procedures, appeal rights, and responsible offices; aligns sanctions with student code of conduct and ensures documented steps before account suspension or device restrictions.
Provides reporting channels for violations, incident response timelines, investigation procedures, and roles for IT, administration, and law enforcement when incidents involve criminal conduct or significant data exposure.
| Field | Configuration |
|---|---|
| Consent Disclosure | ESIGN consumer disclosure required when applicable |
| Authentication | Email link with optional SMS code or SSO |
| Acknowledgement | Required checkbox plus timestamped signature field |
| Retention | Retain signed record per retention policy and export options |
Digital AUPs should be compatible with student information systems, learning platforms, and cloud storage used by the district.
Review and update policy at least once per year.
Collect signed acknowledgement during initial registration or onboarding.
Report security incidents within district-defined timelines, often 24–72 hours.
Provide advance notice to families and obtain re-acknowledgement when material changes occur.
Retention period begins on effective date or student withdrawal.
An urban district issued a digital AUP for 50,000 students to standardize device rules and reduce incidents of unauthorized access.
A charter network created a concise AUP for families, emphasizing BYOD rules, acceptable apps, and parental consent workflows.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies | Varies | Varies |