SOC 2
Independent audit of security, availability, processing integrity, confidentiality, and privacy controls over time.
AICPA (official site)Trust & compliance
Schoolyi is built for schools that must answer procurement, board, and DPO questions with evidence — 30 real frameworks with official references, not brochure badges.

Coverage
Every listing links to the official standard or regulator. Schoolyi aligns controls, exports, and deployment documentation so your school can demonstrate compliance — not just claim it.
Why schools ask
Principals, bursars, and IT leads evaluate ERP vendors on student data — not just features. These are the frameworks procurement teams reference most often.
SOC 2 Type II, ISO/IEC 27001, 27701, 27017, and 27018 — mapped to role-based access, encrypted sessions, and audit-friendly exports for school operations.
GDPR, UK GDPR, CCPA/CPRA, PIPEDA, LGPD, PDPA, UAE PDPL, India DPDP, POPIA, and more — so international school groups can document cross-border student data handling.
FERPA, COPPA, SOPIPA, and HIPAA-aligned clinic workflows — unpublished marks and internal notes stay off family portals until coordinators release them.
WCAG 2.2 AA, Section 508, and EN 301 549 — keyboard navigation, contrast, and semantic forms for staff, students, and guardians.
Framework
8 standards and regulations with official references — filter the full directory below or browse this category.
Independent audit of security, availability, processing integrity, confidentiality, and privacy controls over time.
AICPA (official site)International standard for information security management systems (ISMS) — risk assessment, policies, and continuous improvement.
International Organization for Standardization (official site)Privacy extension to ISO 27001 — privacy information management for controllers and processors handling personal data.
International Organization for Standardization (official site)Code of practice for information security controls for cloud services.
International Organization for Standardization (official site)Protection of personally identifiable information (PII) in public clouds acting as PII processors.
International Organization for Standardization (official site)Cloud Security Alliance Security, Trust, Assurance, and Risk registry and attestation programme.
Cloud Security Alliance (official site)Framework
9 standards and regulations with official references — filter the full directory below or browse this category.
EU regulation on personal data processing — lawful basis, data subject rights, DPIAs, and cross-border transfers.
European Union (official site)UK post-Brexit data protection regime — mirrors GDPR with UK-specific guidance for schools and MATs.
Information Commissioner's Office (UK) (official site)California Consumer Privacy Act and Privacy Rights Act — disclosure, access, deletion, and opt-out rights.
California Privacy Protection Agency (official site)Canadian federal private-sector privacy law — consent, accountability, and breach notification.
Office of the Privacy Commissioner of Canada (official site)Lei Geral de Proteção de Dados — Brazil's comprehensive data protection law for personal data processing.
Autoridade Nacional de Proteção de Dados (ANPD) (official site)Singapore Personal Data Protection Act — consent, purpose limitation, and Do Not Call rules.
Personal Data Protection Commission Singapore (official site)Framework
4 standards and regulations with official references — filter the full directory below or browse this category.
Family Educational Rights and Privacy Act — US student education record privacy and parent access rights.
US Department of Education (official site)Children's Online Privacy Protection Rule — parental consent and data practices for services directed to children under 13.
US Federal Trade Commission (official site)Student Online Personal Information Protection Act — restricts K-12 edtech use of student data for advertising and profiling.
California State Legislature (official site)Health Insurance Portability and Accountability Act — safeguards for protected health information where clinics process medical records.
US HHS Office for Civil Rights (official site)Framework
3 standards and regulations with official references — filter the full directory below or browse this category.
Web Content Accessibility Guidelines — perceivable, operable, understandable, and robust interfaces.
W3C Web Accessibility Initiative (official site)US federal accessibility requirements for electronic and information technology procured by government agencies.
US General Services Administration (official site)European accessibility standard for ICT procurement in the public sector, harmonised with WCAG.
European Telecommunications Standards Institute (official site)Framework
6 standards and regulations with official references — filter the full directory below or browse this category.
Australian privacy principles for organisations handling personal information, including APP 11 security.
Office of the Australian Information Commissioner (official site)New Zealand privacy law — purpose limitation, security, and mandatory breach notification.
Office of the Privacy Commissioner (New Zealand) (official site)Act on the Protection of Personal Information — Japan's core data protection statute.
Personal Information Protection Commission (Japan) (official site)Personal Information Protection Act — consent, purpose specification, and security measures in South Korea.
Personal Information Protection Commission (Korea) (official site)Federal Act on Data Protection — revised Swiss law aligned with GDPR-style rights and cross-border transfer rules.
Federal Data Protection and Information Commissioner (Switzerland) (official site)Approved contractual clauses for transferring personal data from the EEA to third countries under GDPR Chapter V.
European Commission (official site)Full directory
Filter by category. Each card explains what the framework requires and how Schoolyi supports your school's compliance programme.
AICPA
Independent audit of security, availability, processing integrity, confidentiality, and privacy controls over time.
Schoolyi: Schoolyi maps platform controls to AICPA Trust Services Criteria — role-based access, encrypted sessions, change review gates, and audit-friendly activity exports for fee, exam, and roster workflows.
International Organization for Standardization
International standard for information security management systems (ISMS) — risk assessment, policies, and continuous improvement.
Schoolyi: Operations follow ISO 27001-aligned practices: asset inventory, access control, secure development, incident response playbooks, and backup verification suitable for school ERP deployments.
International Organization for Standardization
Privacy extension to ISO 27001 — privacy information management for controllers and processors handling personal data.
Schoolyi: Student, staff, and guardian records are handled with data-minimization defaults, purpose limitation, and export tooling so schools can meet processor obligations under ISO 27701-aligned programmes.
International Organization for Standardization
Code of practice for information security controls for cloud services.
Schoolyi: Cloud deployment guidance covers tenant isolation, shared responsibility documentation, and secure configuration baselines for multi-school groups.
International Organization for Standardization
Protection of personally identifiable information (PII) in public clouds acting as PII processors.
Schoolyi: Guardian portals, admissions forms, and student profiles are scoped so cloud operators and schools can demonstrate PII handling consistent with ISO 27018 expectations.
Cloud Security Alliance
Cloud Security Alliance Security, Trust, Assurance, and Risk registry and attestation programme.
Schoolyi: Infrastructure and SaaS posture documentation supports CSA Cloud Controls Matrix mapping for districts evaluating cloud school ERP vendors.
National Institute of Standards and Technology (US)
Voluntary framework to manage and reduce cybersecurity risk — Identify, Protect, Detect, Respond, Recover.
Schoolyi: Security reviews with US K-12 IT leads reference NIST CSF functions: identity management, vulnerability patching cadence, logging, and recovery objectives for academic-year continuity.
PCI Security Standards Council
Payment Card Industry Data Security Standard for organisations that store, process, or transmit cardholder data.
Schoolyi: Online fee collection integrates with PCI-compliant payment gateways — card data is tokenised and never stored in Schoolyi roster or finance modules.
European Union
EU regulation on personal data processing — lawful basis, data subject rights, DPIAs, and cross-border transfers.
Schoolyi: Schoolyi supports GDPR-aligned operations: role-scoped access, data export for subject access requests, retention configuration, and DPA templates for EU and international schools.
Information Commissioner's Office (UK)
UK post-Brexit data protection regime — mirrors GDPR with UK-specific guidance for schools and MATs.
Schoolyi: Independent and state schools in England, Scotland, Wales, and Northern Ireland can map pupil records, parent communications, and safeguarding notes to UK GDPR roles and retention schedules.
California Privacy Protection Agency
California Consumer Privacy Act and Privacy Rights Act — disclosure, access, deletion, and opt-out rights.
Schoolyi: US schools with California residents can document processing purposes for admissions CRM data and configure exports to honour access and deletion workflows.
Office of the Privacy Commissioner of Canada
Canadian federal private-sector privacy law — consent, accountability, and breach notification.
Schoolyi: Canadian independent schools and groups can align guardian portals and staff HR records with PIPEDA fair-information principles.
Autoridade Nacional de Proteção de Dados (ANPD)
Lei Geral de Proteção de Dados — Brazil's comprehensive data protection law for personal data processing.
Schoolyi: Brazilian and Latin American schools can configure lawful bases, DPO contact points, and export paths for student and employee records processed in Schoolyi.
Personal Data Protection Commission Singapore
Singapore Personal Data Protection Act — consent, purpose limitation, and Do Not Call rules.
Schoolyi: International schools in Singapore can align parent SMS and email outreach with PDPA consent and notification requirements.
UAE Data Office
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data in the United Arab Emirates.
Schoolyi: Schools in Dubai, Abu Dhabi, and wider UAE can document cross-border transfers and parent consent for student records under UAE PDPL expectations.
Government of India
India's national framework for processing digital personal data — notice, consent, and data fiduciary obligations.
Schoolyi: Indian K-12 groups can map student Aadhaar-adjacent workflows, fee receipts, and parent notifications to DPDP-aligned retention and grievance processes.
Information Regulator (South Africa)
Protection of Personal Information Act — conditions for lawful processing in South Africa.
Schoolyi: South African schools can demonstrate accountability, security safeguards, and data subject participation for learner and staff records.
US Department of Education
Family Educational Rights and Privacy Act — US student education record privacy and parent access rights.
Schoolyi: Directory information flags, transcript exports, and role boundaries keep unpublished grades and discipline notes off parent portals until coordinators release them — supporting FERPA-aligned workflows.
US Federal Trade Commission
Children's Online Privacy Protection Rule — parental consent and data practices for services directed to children under 13.
Schoolyi: Admissions and student portals separate public apply flows from authenticated workspaces; schools control which modules minors access and what data is collected at enrollment.
California State Legislature
Student Online Personal Information Protection Act — restricts K-12 edtech use of student data for advertising and profiling.
Schoolyi: Schoolyi does not use student operational data for third-party advertising; processing stays within the school's educational purpose and configured integrations.
US HHS Office for Civil Rights
Health Insurance Portability and Accountability Act — safeguards for protected health information where clinics process medical records.
Schoolyi: Health clinic and medical visit modules support restricted roles, audit context, and minimum-necessary access patterns schools expect when storing clinic notes alongside student records.
W3C Web Accessibility Initiative
Web Content Accessibility Guidelines — perceivable, operable, understandable, and robust interfaces.
Schoolyi: Marketing pages and authenticated workspaces target WCAG 2.2 AA patterns — semantic markup, keyboard navigation, contrast, and form labels for staff and family portals.
US General Services Administration
US federal accessibility requirements for electronic and information technology procured by government agencies.
Schoolyi: US public charter networks and districts referencing Section 508 in RFPs can review VPAT-aligned accessibility documentation on request.
European Telecommunications Standards Institute
European accessibility standard for ICT procurement in the public sector, harmonised with WCAG.
Schoolyi: EU and UK schools subject to public procurement accessibility schedules can map Schoolyi UI components to EN 301 549 checkpoints.
Office of the Australian Information Commissioner
Australian privacy principles for organisations handling personal information, including APP 11 security.
Schoolyi: Australian independent and Catholic school systems can align enrolment, fee, and pastoral notes with APP breach notification and access request workflows.
Office of the Privacy Commissioner (New Zealand)
New Zealand privacy law — purpose limitation, security, and mandatory breach notification.
Schoolyi: NZ schools can configure retention and export for NCEA and pastoral records processed in Schoolyi.
Personal Information Protection Commission (Japan)
Act on the Protection of Personal Information — Japan's core data protection statute.
Schoolyi: International schools in Japan can document cross-border transfers and parental notification for student data hosted on Schoolyi.
Personal Information Protection Commission (Korea)
Personal Information Protection Act — consent, purpose specification, and security measures in South Korea.
Schoolyi: Korean international schools can align admissions CRM and fee modules with PIPA consent and destruction schedules.
Federal Data Protection and Information Commissioner (Switzerland)
Federal Act on Data Protection — revised Swiss law aligned with GDPR-style rights and cross-border transfer rules.
Schoolyi: Swiss private and international schools can map student dossiers and HR payroll data to FADP accountability and data security requirements.
European Commission
Approved contractual clauses for transferring personal data from the EEA to third countries under GDPR Chapter V.
Schoolyi: Cross-border school groups can execute EU SCCs with Schoolyi as processor when student data leaves the EEA — supporting Schrems II due diligence.
Procurement
Most schools schedule a compliance conversation before board sign-off. This sequence covers the questions data protection officers and security reviewers ask most often.
Share GDPR, FERPA, SOC 2, ISO 27001, or regional privacy laws your board or district requires. We map each to Schoolyi controls and documentation.
Walk through admissions, roster, fees, exams, and parent portals. Confirm who sees draft marks, finance adjustments, and HR records.
Discuss deployment region, backups, EU SCCs, and payment gateways. Procurement teams receive subprocessor lists and DPA templates on request.
Validate activity log exports, subject access workflows, and retention settings your DPO or auditor will ask for before go-live.
Straight answers about Schoolyi alignment with SOC 2, ISO, GDPR, FERPA, and regional school data laws.
Schoolyi aligns platform controls with AICPA Trust Services Criteria used in SOC 2 Type II audits — access control, encryption, change management, and monitoring. Contact us for current attestation status and audit letters for your procurement pack.
Yes. Schoolyi supports GDPR-aligned processing: role-scoped access, data export for subject access requests, retention configuration, and DPA templates. UK schools can map pupil records to ICO guidance under UK GDPR and the Data Protection Act 2018.
Schoolyi workflows support FERPA-aligned handling of education records — directory information flags, coordinator publish gates before families see grades, and staff-only discipline notes. Your school remains the data controller and configures release policies.
Operations align with ISO/IEC 27001 information security, ISO/IEC 27701 privacy extension, ISO/IEC 27017 cloud security, and ISO/IEC 27018 PII in public clouds. Each framework on our Certifications page links to the official ISO reference.
Marketing pages and authenticated workspaces target WCAG 2.2 Level AA patterns. US public procurement teams can request Section 508 documentation; EU buyers can map EN 301 549 checkpoints.
Each listing names the real standards body or regulator — AICPA, ISO, ICO, US ED, W3C, and others — with a link to the official website. Badge artwork on this page identifies the framework; formal certificates are shared during procurement.
Requirements vary by country and school group. Contact us with your jurisdiction and we will share compliance documentation, subprocessors, and deployment options. See our security overview and privacy policy for operational detail.

We can review frameworks, roles, portals, and hosting with your DPO, bursar, or IT lead.
Already using Schoolyi? Sign in