Skip to main content
Schoolyi

Trust & compliance

Certifications, standards, and regulatory alignment

Schoolyi is built for schools that must answer procurement, board, and DPO questions with evidence — 30 real frameworks with official references, not brochure badges.

School IT administrator securing a server room with badge access

Coverage

One platform, global compliance context

Every listing links to the official standard or regulator. Schoolyi aligns controls, exports, and deployment documentation so your school can demonstrate compliance — not just claim it.

Frameworks
30
Categories
5
Regions
25
Official links
30

Why schools ask

Compliance built into school operations

Principals, bursars, and IT leads evaluate ERP vendors on student data — not just features. These are the frameworks procurement teams reference most often.

  • Security audit standards

    SOC 2 Type II, ISO/IEC 27001, 27701, 27017, and 27018 — mapped to role-based access, encrypted sessions, and audit-friendly exports for school operations.

  • Global privacy law coverage

    GDPR, UK GDPR, CCPA/CPRA, PIPEDA, LGPD, PDPA, UAE PDPL, India DPDP, POPIA, and more — so international school groups can document cross-border student data handling.

  • Education-specific protections

    FERPA, COPPA, SOPIPA, and HIPAA-aligned clinic workflows — unpublished marks and internal notes stay off family portals until coordinators release them.

  • Accessible for every role

    WCAG 2.2 AA, Section 508, and EN 301 549 — keyboard navigation, contrast, and semantic forms for staff, students, and guardians.

Framework

Security & audit standards

8 standards and regulations with official references — filter the full directory below or browse this category.

Framework

Privacy & data protection

9 standards and regulations with official references — filter the full directory below or browse this category.

Framework

Education & student data

4 standards and regulations with official references — filter the full directory below or browse this category.

Framework

Accessibility standards

3 standards and regulations with official references — filter the full directory below or browse this category.

Framework

Regional laws & regulations

6 standards and regulations with official references — filter the full directory below or browse this category.

Full directory

Browse all certifications and regulations

Filter by category. Each card explains what the framework requires and how Schoolyi supports your school's compliance programme.

  • SOC 2 logo

    SOC 2 Type II

    AICPA

    Independent audit of security, availability, processing integrity, confidentiality, and privacy controls over time.

    Schoolyi: Schoolyi maps platform controls to AICPA Trust Services Criteria — role-based access, encrypted sessions, change review gates, and audit-friendly activity exports for fee, exam, and roster workflows.

    GlobalUnited StatesCanada
    Official SOC 2 reference
  • ISO 27001 logo

    ISO/IEC 27001

    International Organization for Standardization

    International standard for information security management systems (ISMS) — risk assessment, policies, and continuous improvement.

    Schoolyi: Operations follow ISO 27001-aligned practices: asset inventory, access control, secure development, incident response playbooks, and backup verification suitable for school ERP deployments.

    GlobalEuropean UnionUnited Kingdom+2 more
    Official ISO 27001 reference
  • ISO 27701 logo

    ISO/IEC 27701

    International Organization for Standardization

    Privacy extension to ISO 27001 — privacy information management for controllers and processors handling personal data.

    Schoolyi: Student, staff, and guardian records are handled with data-minimization defaults, purpose limitation, and export tooling so schools can meet processor obligations under ISO 27701-aligned programmes.

    GlobalEuropean UnionUnited Kingdom
    Official ISO 27701 reference
  • ISO 27017 logo

    ISO/IEC 27017

    International Organization for Standardization

    Code of practice for information security controls for cloud services.

    Schoolyi: Cloud deployment guidance covers tenant isolation, shared responsibility documentation, and secure configuration baselines for multi-school groups.

    Global
    Official ISO 27017 reference
  • ISO 27018 logo

    ISO/IEC 27018

    International Organization for Standardization

    Protection of personally identifiable information (PII) in public clouds acting as PII processors.

    Schoolyi: Guardian portals, admissions forms, and student profiles are scoped so cloud operators and schools can demonstrate PII handling consistent with ISO 27018 expectations.

    GlobalEuropean Union
    Official ISO 27018 reference
  • CSA STAR logo

    CSA STAR

    Cloud Security Alliance

    Cloud Security Alliance Security, Trust, Assurance, and Risk registry and attestation programme.

    Schoolyi: Infrastructure and SaaS posture documentation supports CSA Cloud Controls Matrix mapping for districts evaluating cloud school ERP vendors.

    GlobalUnited States
    Official CSA STAR reference
  • NIST CSF logo

    NIST Cybersecurity Framework

    National Institute of Standards and Technology (US)

    Voluntary framework to manage and reduce cybersecurity risk — Identify, Protect, Detect, Respond, Recover.

    Schoolyi: Security reviews with US K-12 IT leads reference NIST CSF functions: identity management, vulnerability patching cadence, logging, and recovery objectives for academic-year continuity.

    United StatesGlobal
    Official NIST CSF reference
  • PCI DSS logo

    PCI DSS

    PCI Security Standards Council

    Payment Card Industry Data Security Standard for organisations that store, process, or transmit cardholder data.

    Schoolyi: Online fee collection integrates with PCI-compliant payment gateways — card data is tokenised and never stored in Schoolyi roster or finance modules.

    Global
    Official PCI DSS reference
  • GDPR logo

    General Data Protection Regulation (GDPR)

    European Union

    EU regulation on personal data processing — lawful basis, data subject rights, DPIAs, and cross-border transfers.

    Schoolyi: Schoolyi supports GDPR-aligned operations: role-scoped access, data export for subject access requests, retention configuration, and DPA templates for EU and international schools.

    European UnionEEAInternational schools (EU families)
    Official GDPR reference
  • UK GDPR logo

    UK GDPR & Data Protection Act 2018

    Information Commissioner's Office (UK)

    UK post-Brexit data protection regime — mirrors GDPR with UK-specific guidance for schools and MATs.

    Schoolyi: Independent and state schools in England, Scotland, Wales, and Northern Ireland can map pupil records, parent communications, and safeguarding notes to UK GDPR roles and retention schedules.

    United Kingdom
    Official UK GDPR reference
  • CCPA logo

    CCPA / CPRA (California)

    California Privacy Protection Agency

    California Consumer Privacy Act and Privacy Rights Act — disclosure, access, deletion, and opt-out rights.

    Schoolyi: US schools with California residents can document processing purposes for admissions CRM data and configure exports to honour access and deletion workflows.

    United States (California)
    Official CCPA reference
  • PIPEDA logo

    PIPEDA

    Office of the Privacy Commissioner of Canada

    Canadian federal private-sector privacy law — consent, accountability, and breach notification.

    Schoolyi: Canadian independent schools and groups can align guardian portals and staff HR records with PIPEDA fair-information principles.

    Canada
    Official PIPEDA reference
  • LGPD logo

    LGPD (Brazil)

    Autoridade Nacional de Proteção de Dados (ANPD)

    Lei Geral de Proteção de Dados — Brazil's comprehensive data protection law for personal data processing.

    Schoolyi: Brazilian and Latin American schools can configure lawful bases, DPO contact points, and export paths for student and employee records processed in Schoolyi.

    BrazilLatin America
    Official LGPD reference
  • PDPA SG logo

    PDPA (Singapore)

    Personal Data Protection Commission Singapore

    Singapore Personal Data Protection Act — consent, purpose limitation, and Do Not Call rules.

    Schoolyi: International schools in Singapore can align parent SMS and email outreach with PDPA consent and notification requirements.

    SingaporeSoutheast Asia
    Official PDPA SG reference
  • UAE PDPL logo

    UAE Personal Data Protection Law

    UAE Data Office

    Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data in the United Arab Emirates.

    Schoolyi: Schools in Dubai, Abu Dhabi, and wider UAE can document cross-border transfers and parent consent for student records under UAE PDPL expectations.

    United Arab EmiratesMiddle East
    Official UAE PDPL reference
  • DPDP Act logo

    India Digital Personal Data Protection Act

    Government of India

    India's national framework for processing digital personal data — notice, consent, and data fiduciary obligations.

    Schoolyi: Indian K-12 groups can map student Aadhaar-adjacent workflows, fee receipts, and parent notifications to DPDP-aligned retention and grievance processes.

    India
    Official DPDP Act reference
  • POPIA logo

    POPIA (South Africa)

    Information Regulator (South Africa)

    Protection of Personal Information Act — conditions for lawful processing in South Africa.

    Schoolyi: South African schools can demonstrate accountability, security safeguards, and data subject participation for learner and staff records.

    South AfricaAfrica
    Official POPIA reference
  • FERPA logo

    FERPA

    US Department of Education

    Family Educational Rights and Privacy Act — US student education record privacy and parent access rights.

    Schoolyi: Directory information flags, transcript exports, and role boundaries keep unpublished grades and discipline notes off parent portals until coordinators release them — supporting FERPA-aligned workflows.

    United States
    Official FERPA reference
  • COPPA logo

    COPPA

    US Federal Trade Commission

    Children's Online Privacy Protection Rule — parental consent and data practices for services directed to children under 13.

    Schoolyi: Admissions and student portals separate public apply flows from authenticated workspaces; schools control which modules minors access and what data is collected at enrollment.

    United States
    Official COPPA reference
  • SOPIPA logo

    SOPIPA (California Student Privacy)

    California State Legislature

    Student Online Personal Information Protection Act — restricts K-12 edtech use of student data for advertising and profiling.

    Schoolyi: Schoolyi does not use student operational data for third-party advertising; processing stays within the school's educational purpose and configured integrations.

    United States (California)
    Official SOPIPA reference
  • HIPAA logo

    HIPAA-aligned health records

    US HHS Office for Civil Rights

    Health Insurance Portability and Accountability Act — safeguards for protected health information where clinics process medical records.

    Schoolyi: Health clinic and medical visit modules support restricted roles, audit context, and minimum-necessary access patterns schools expect when storing clinic notes alongside student records.

    United States
    Official HIPAA reference
  • WCAG 2.2 logo

    WCAG 2.2 Level AA

    W3C Web Accessibility Initiative

    Web Content Accessibility Guidelines — perceivable, operable, understandable, and robust interfaces.

    Schoolyi: Marketing pages and authenticated workspaces target WCAG 2.2 AA patterns — semantic markup, keyboard navigation, contrast, and form labels for staff and family portals.

    GlobalUnited StatesEuropean Union+1 more
    Official WCAG 2.2 reference
  • Section 508 logo

    Section 508

    US General Services Administration

    US federal accessibility requirements for electronic and information technology procured by government agencies.

    Schoolyi: US public charter networks and districts referencing Section 508 in RFPs can review VPAT-aligned accessibility documentation on request.

    United States
    Official Section 508 reference
  • EN 301 549 logo

    EN 301 549

    European Telecommunications Standards Institute

    European accessibility standard for ICT procurement in the public sector, harmonised with WCAG.

    Schoolyi: EU and UK schools subject to public procurement accessibility schedules can map Schoolyi UI components to EN 301 549 checkpoints.

    European UnionUnited Kingdom
    Official EN 301 549 reference
  • Privacy Act logo

    Australian Privacy Act 1988

    Office of the Australian Information Commissioner

    Australian privacy principles for organisations handling personal information, including APP 11 security.

    Schoolyi: Australian independent and Catholic school systems can align enrolment, fee, and pastoral notes with APP breach notification and access request workflows.

    AustraliaOceania
    Official Privacy Act reference
  • NZ Privacy logo

    New Zealand Privacy Act 2020

    Office of the Privacy Commissioner (New Zealand)

    New Zealand privacy law — purpose limitation, security, and mandatory breach notification.

    Schoolyi: NZ schools can configure retention and export for NCEA and pastoral records processed in Schoolyi.

    New Zealand
    Official NZ Privacy reference
  • APPI logo

    APPI (Japan)

    Personal Information Protection Commission (Japan)

    Act on the Protection of Personal Information — Japan's core data protection statute.

    Schoolyi: International schools in Japan can document cross-border transfers and parental notification for student data hosted on Schoolyi.

    Japan
    Official APPI reference
  • PIPA KR logo

    PIPA (South Korea)

    Personal Information Protection Commission (Korea)

    Personal Information Protection Act — consent, purpose specification, and security measures in South Korea.

    Schoolyi: Korean international schools can align admissions CRM and fee modules with PIPA consent and destruction schedules.

    South Korea
    Official PIPA KR reference
  • FADP logo

    Swiss FADP

    Federal Data Protection and Information Commissioner (Switzerland)

    Federal Act on Data Protection — revised Swiss law aligned with GDPR-style rights and cross-border transfer rules.

    Schoolyi: Swiss private and international schools can map student dossiers and HR payroll data to FADP accountability and data security requirements.

    Switzerland
    Official FADP reference
  • EU SCCs logo

    EU Standard Contractual Clauses

    European Commission

    Approved contractual clauses for transferring personal data from the EEA to third countries under GDPR Chapter V.

    Schoolyi: Cross-border school groups can execute EU SCCs with Schoolyi as processor when student data leaves the EEA — supporting Schrems II due diligence.

    European UnionGlobal school groups
    Official EU SCCs reference

Procurement

What to review with your DPO or IT lead

Most schools schedule a compliance conversation before board sign-off. This sequence covers the questions data protection officers and security reviewers ask most often.

  1. 1

    List your mandatory frameworks

    Share GDPR, FERPA, SOC 2, ISO 27001, or regional privacy laws your board or district requires. We map each to Schoolyi controls and documentation.

  2. 2

    Review roles and data flows

    Walk through admissions, roster, fees, exams, and parent portals. Confirm who sees draft marks, finance adjustments, and HR records.

  3. 3

    Confirm hosting and subprocessors

    Discuss deployment region, backups, EU SCCs, and payment gateways. Procurement teams receive subprocessor lists and DPA templates on request.

  4. 4

    Export and audit evidence

    Validate activity log exports, subject access workflows, and retention settings your DPO or auditor will ask for before go-live.

Certifications and compliance FAQs

Straight answers about Schoolyi alignment with SOC 2, ISO, GDPR, FERPA, and regional school data laws.

Is Schoolyi SOC 2 Type II certified?+

Schoolyi aligns platform controls with AICPA Trust Services Criteria used in SOC 2 Type II audits — access control, encryption, change management, and monitoring. Contact us for current attestation status and audit letters for your procurement pack.

Does Schoolyi comply with GDPR and UK GDPR?+

Yes. Schoolyi supports GDPR-aligned processing: role-scoped access, data export for subject access requests, retention configuration, and DPA templates. UK schools can map pupil records to ICO guidance under UK GDPR and the Data Protection Act 2018.

Is Schoolyi FERPA compliant for US schools?+

Schoolyi workflows support FERPA-aligned handling of education records — directory information flags, coordinator publish gates before families see grades, and staff-only discipline notes. Your school remains the data controller and configures release policies.

Which ISO standards does Schoolyi follow?+

Operations align with ISO/IEC 27001 information security, ISO/IEC 27701 privacy extension, ISO/IEC 27017 cloud security, and ISO/IEC 27018 PII in public clouds. Each framework on our Certifications page links to the official ISO reference.

Do you support accessibility standards like WCAG?+

Marketing pages and authenticated workspaces target WCAG 2.2 Level AA patterns. US public procurement teams can request Section 508 documentation; EU buyers can map EN 301 549 checkpoints.

Where do certification logos and links come from?+

Each listing names the real standards body or regulator — AICPA, ISO, ICO, US ED, W3C, and others — with a link to the official website. Badge artwork on this page identifies the framework; formal certificates are shared during procurement.

Need audit letters or a DPA?

Requirements vary by country and school group. Contact us with your jurisdiction and we will share compliance documentation, subprocessors, and deployment options. See our security overview and privacy policy for operational detail.

Students walking together across a school campus at sunset

Request a compliance walkthrough

We can review frameworks, roles, portals, and hosting with your DPO, bursar, or IT lead.

Already using Schoolyi? Sign in