Vendor security reviews · Public sector & education
Vendor Security Review & Questionnaire Support for School Boards & K-12 Schools
A vendor security review checks whether an edtech or SIS vendor's real practices, and its contract, are strong enough before board data reaches them, and re-checks the vendors already in place. It exists because the IPC's PowerSchool investigation found Ontario and Alberta boards had signed agreements missing basic privacy and security terms and never verified what their vendor actually retained. Boards use it to renegotiate existing contracts, vet new classroom software, and build the vendor evidence that O. Reg. 52/26 notices and OECM procurement now assume exists.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The vendor relationships carrying a board's student data
Board data lives across dozens of contracted platforms once you count school-level tools alongside the SIS, and each one is a review candidate on its own terms.
SIS and LMS vendors holding the OSR
PowerSchool SIS, MyEducation BC, an Edsembli or Sparkrock deployment, and D2L Brightspace each hold Ontario Student Record content or its equivalent, so their posture and contract terms get the deepest tier of review, the tier PowerSchool proved boards had skipped.
The classroom app long tail
Hundreds of free or low-cost tools that teachers adopt school by school carry the personal digital information an O. Reg. 52/26 notice must name, so the review needs a fast, repeatable process for tools too small to hold a SOC 2 report.
Subcontractors your SIS vendor relies on
The PowerSchool attacker reached board data through a subcontractor's credentials on a support portal, not through the vendor's own front door, so a review has to ask which fourth parties a vendor uses and how those parties are controlled.
Transportation and assessment vendors
Transportation consortia handling bus-stop and address data, and assessment platforms scoring student work, are contracted vendors like any other, and belong in the same review cycle as the SIS rather than a separate, informal track.
OECM and ECNO master agreements
Where a vendor sits under an OECM master agreement or an ECNO arrangement, the review checks what those bodies already negotiated on the board's behalf, since EDSTA amendments added supplier breach-notice and compliance-assistance terms boards can rely on.
Regulatory map
Why vendor review is now a board obligation, not a courtesy
Four instruments turn vendor diligence from prudent practice into something a regulator, an insurer or a trustee will eventually ask to see documented.
The IPC's contract-clause findings
The joint PowerSchool investigation found board agreements missing key privacy and security terms and directed boards to renegotiate contracts and monitor vendors going forward, turning vendor review into a named regulator expectation.
O. Reg. 52/26's vendor-by-vendor notice
Each parent or student notice must name the specific application, the vendor, the data elements disclosed and the purpose, which makes an accurate vendor-by-vendor register, the review's core output, the raw material the notice is built from.
MFIPPA safeguards and PIA duties
From January 1, 2027, s. 30(5) requires reasonable safeguards and s. 28 requires a PIA before new collection, and neither question can be answered honestly without first knowing what a vendor actually does with the data it is given.
Procurement rules that shape the review
The BPS Procurement Directive requires open competitive procurement at $121,200 and up, and the Buy Ontario Directive layers Canadian and Ontario preference onto purchasing from April 2026, so findings need to reach the RFP stage, not arrive after a vendor is already chosen.
The Digital Privacy Charter's vetting commitment
Boards that sign the IPC's charter commit to vetting the technology brought into classrooms, and a documented vendor review is the practical evidence that commitment is more than a pledge on paper.
What goes wrong
What the PowerSchool review missed, and what we check for
The joint Ontario-Alberta investigation is the sector's clearest account of how vendor oversight fails, and our review is built to catch each failure mode before it repeats.
A support portal with no MFA
The attacker used a subcontractor's credentials on the PowerSource portal, which had no multi-factor authentication behind it, so evidence of MFA on every vendor's support and admin access is now a non-negotiable line in our checklist.
Standing remote access nobody reviewed
Always-on remote-access connections into board systems went unmonitored before the breach, so the review asks each vendor to show time-limited, logged access rather than a permanent open door into student data.
Log retention too short to investigate
Short log retention at the vendor limited what investigators could reconstruct after the fact, so we ask vendors how long access and activity logs are kept and whether the board can obtain them quickly during an incident.
Decades of data the vendor never deleted
Records reaching back to 1965 at Peel and 1985 at TDSB sat inside PowerSchool because nobody enforced disposal, so the review checks a vendor's actual deletion practice against the board's own retention schedule, not just its stated policy.
Extortion after the ransom was paid
PowerSchool paid its attacker, and boards including TDSB and PDSB received fresh extortion demands months later regardless, a reminder that a vendor's incident-response promises need contractual teeth, not reassurance in a sales call.
Our vendor security reviews for school boards & k-12 schools
What our vendor security review delivers for a board
The parent service's gap review, documentation guidance and control-consideration support are applied here to the specific vendors touching student and staff data, evidence in hand before a signature or a renewal.

Evidence request and reading
We request SOC 2 reports, ISO certificates, security whitepapers and completed questionnaires from each vendor, and read them rather than count them, flagging vague answers or expired assurance before anyone else does.
Contract clause markup
Draft agreements and renewals are marked up against the terms the IPC's report found missing: safeguards, breach-notice timelines, MFA on support access, log retention and cooperation duties, in language procurement can insert directly.
The O. Reg. 52/26 evidence register
A structured record of each vendor, the application, the data elements it receives and the purpose, built to feed straight into the fall parent and student notices rather than becoming a second inventory project.
Risk-tiered review cycle
SIS-level vendors get full annual review, mid-tier tools get a lighter refresh, and free classroom apps get a fast intake check, so effort matches what each vendor actually holds about students.
A decision memo for senior administration
Findings, residual risk and recommended conditions written for the Superintendent of Business and, where a purchase needs one, a trustee report, with technical detail kept in an appendix.
How the engagement runs
How a vendor review runs for a school board
We plan reviews around procurement timelines and the school year, so findings land before a signature, not after one.
Step 1
Scope by what the vendor will hold
We start from the data at stake, OSR content, payment details, staff records, or a smaller classroom footprint, and set the review depth to match.
Step 2
Collect vendor evidence
We request assurance reports, contract drafts and questionnaire answers directly from the vendor, and chase incomplete responses so board staff are not doing that follow-up themselves.
Step 3
Verify against the IPC's findings
Every review checks the specific gaps the PowerSchool investigation named: contract terms, MFA, remote-access controls, log retention and data minimization.
Step 4
Mark up and negotiate
We hand back contract language and a short list of conditions, and support the negotiation call if a vendor resists terms your board now needs in writing.
Step 5
Feed the notice register
Confirmed findings, data elements, purpose and vendor identity are logged in the format the O. Reg. 52/26 notice cycle will use, so review and compliance run as one workflow.
What it costs
What drives the price of a board vendor review
Cost follows the vendor and the tier: a full SIS or LMS review with contract negotiation takes longer than an intake check on a free classroom app, and a board with dozens of school-level tools needs a program rather than a single review. Whether an existing vendor's evidence is current and cooperative, or has to be chased, also moves the estimate.
Many boards run their SIS and top payment or transportation vendors through a full review first, matching the IPC's own priorities, then phase the classroom-app long tail behind it. Vendor oversight is also included in our Virtual Privacy Office retainer for boards expecting several reviews a year. We quote fixed fees per vendor tier after a short intake call.
School Boards & K-12 Schools: Vendor security reviews questions, answered
The November 2025 report found board agreements lacking clear privacy and security safeguards, defined breach-notification timelines, MFA requirements for vendor remote access, log-retention commitments, and enforceable data-minimization terms, and directed boards to renegotiate. We use that finding as a checklist: every contract we review is marked against those same gaps, whether the vendor is your SIS provider or a much smaller platform, because the IPC named a pattern, not a single vendor's failing.
Treat the Charter's twelve commitments as a short intake form rather than a full audit. Ask what data the app collects about students, whether it trains a model, where it is hosted, how long it is kept, and whether the vendor will sign even a light data-handling addendum. A free tool that refuses basic answers or has no privacy policy fails the check regardless of price, and that decision belongs on the register feeding your O. Reg. 52/26 notices.
Ask in writing, under NDA if needed, and treat a refusal as an answer in itself. Reputable SIS, LMS and platform vendors will provide a SOC 2 Type II summary or ISO certificate to a paying institutional customer; smaller edtech firms sometimes have neither, in which case we substitute a structured questionnaire covering hosting, retention and incident notice. A vendor that still won't engage earns a documented risk flag for the Superintendent of Business, and on significant purchases a procurement condition.
Escalate the gap rather than accept it quietly. We document which term is missing and the risk it leaves open, so the Superintendent of Business or CIO can weigh it against switching costs, an easier conversation with the IPC's own findings attached. For SIS-level vendors this often lands at renewal, where leverage is highest; for smaller tools, replacing an uncooperative vendor is frequently the cheaper path.
Directly: a maturity assessment scores whether the board manages third-party and supply-chain risk, and a documented, risk-tiered review program is the evidence an assessor looks for. Boards that build the register early are not reconstructing vendor history when the first assessment comes due by July 1, 2027, because the two workstreams share the same evidence.
More for school boards & k-12 schools
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.