Last published: 8/10/2026
This Data Processing Addendum (“DPA”) is entered into by and between Student First, Inc., a Delaware corporation (“Student First”), and the customer identified in the Agreement (“Customer” and, together with Student First, the “Parties” and each a “Party”). This DPA is incorporated into and forms part of the Master Services Agreement or other written or electronic agreement between the Parties governing Customer’s access to and use of the Services (the “Agreement”). This DPA is effective as of the effective date of the Agreement.
Purpose. Student First provides a cloud-based student information system and related services to institutions of higher education. In providing the Services, Student First Processes Personal Data on behalf of and under the instructions of Customer. This DPA sets out the Parties’ respective obligations with respect to such Processing and is intended to satisfy the requirements of Applicable Data Protection Laws. Except as expressly modified here, the Agreement remains in full force and effect.
DEFINITIONS
Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. For purposes of this DPA:
”Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under this DPA, including, to the extent applicable to a given Party and a given Processing activity: (a) the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99 (“FERPA”); (b) the Gramm-Leach-Bliley Act and the Federal Trade Commission Standards for Safeguarding Customer Information, 16C.F.R. Part 314 (the “Safeguards Rule”); (c) the Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506 (“COPPA”); (d) state privacy, data protection, and data breach notification laws applicable to the Personal Data, including the California Consumer Privacy Act, as amended (the “CCPA”),and comparable comprehensive state privacy statutes. Subject to Sections 15.3 and 15.5 and to the extent the parties enter into an International Addendum, Applicable Data Protection Laws includes, as identified in the International Addendum, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, and Canadian federal or provincial privacy laws.
”Data Subject” means an identified or identifiable natural person to whom Personal Data relates, including students, applicants, prospective students, parents and guardians, and Customer’s personnel whose Personal Data is Processed under the Agreement.
”De-Identified Data” means information that was derived from Personal Data but that has been processed so that it meets the standard set out in Section 14 (De-Identified Data).
”Education Records” means education records” as defined under FERPA and its implementing regulations, to the extent Processed by Student First under the Agreement.
”Personal Data” means any information Processed by Student First on behalf of Customer under the Agreement that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Data Subject or household, including Education Records and “personally identifiable information” as defined under FERPA. Personal Data does not include De-Identified Data.
”Process” means or “Processing” means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
”Security Incident” means a breach of Student First’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Personal Data Processed by Student First or its Subprocessors. A Security Incident does not include an unsuccessful attempt or activity that does not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, and other network attacks on firewalls or networked systems, or the introduction of malware that is quarantined or otherwise prevented from accessing Personal Data.
”Services” means the student information system, financial aid, and related services made available by Student First under the Agreement.
”Subprocessor” means any third party engaged by Student First to Process Personal Data on Student First’s behalf in connection with the Services, including infrastructure and hosting providers.
Role-based terms. Where the context or Applicable Data Protection Law requires, “controller,” “processor,” “business,” “service provider,” “sell,” “share,” and “personal information” have the meanings given under the applicable statute (for example, the GDPR or the CCPA), and are applied to the Parties in the roles described in Section 2.
ROLES OF THE PARTIES; SCOPE
FERPA COMPLIANCE
FINANCIAL AID DATA; SAFEGUARDS RULE; FEDERAL TAX INFORMATION
DATA OF MINORS
STUDENT FIRST PROCESSING OBLIGATIONS
SECURITY
SUBPROCESSORS
CUSTOMER-ENGAGED INTEGRATION AND IMPLEMENTATION VENDORS
SECURITY INCIDENT RESPONSE
ASSISTANCE WITH DATA SUBJECT RIGHTS
ASSISTANCE WITH COMPLIANCE OBLIGATIONS
RECORDS AND AUDITS
DE-IDENTIFIED DATA
ARTIFICIAL INTELLIGENCE
PROCESSING LOCATIONS AND INTERNATIONALTRANSFERS
RETURN AND DELETION OF PERSONAL DATA
LIABILITY
GENERAL
Student First’s current Subprocessors are listed below. Student First may maintain an up-to-date list at studentfirst.com/legal/subprocessors, which is incorporatedby reference.
This Schedule sets out obligations that are specific to a particular Applicable Data Protection Law and are not capable of harmonization into a single standard under Section 2.4. Each item applies only to Personal Data within the scope ofthe identified law.