Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Vendor security reviews · Public sector & education

Vendor Security Review & Questionnaire Support for School Boards & K-12 Schools

A vendor security review checks whether an edtech or SIS vendor's real practices, and its contract, are strong enough before board data reaches them, and re-checks the vendors already in place. It exists because the IPC's PowerSchool investigation found Ontario and Alberta boards had signed agreements missing basic privacy and security terms and never verified what their vendor actually retained. Boards use it to renegotiate existing contracts, vet new classroom software, and build the vendor evidence that O. Reg. 52/26 notices and OECM procurement now assume exists.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The vendor relationships carrying a board's student data

Board data lives across dozens of contracted platforms once you count school-level tools alongside the SIS, and each one is a review candidate on its own terms.

SIS and LMS vendors holding the OSR

PowerSchool SIS, MyEducation BC, an Edsembli or Sparkrock deployment, and D2L Brightspace each hold Ontario Student Record content or its equivalent, so their posture and contract terms get the deepest tier of review, the tier PowerSchool proved boards had skipped.

The classroom app long tail

Hundreds of free or low-cost tools that teachers adopt school by school carry the personal digital information an O. Reg. 52/26 notice must name, so the review needs a fast, repeatable process for tools too small to hold a SOC 2 report.

Subcontractors your SIS vendor relies on

The PowerSchool attacker reached board data through a subcontractor's credentials on a support portal, not through the vendor's own front door, so a review has to ask which fourth parties a vendor uses and how those parties are controlled.

Transportation and assessment vendors

Transportation consortia handling bus-stop and address data, and assessment platforms scoring student work, are contracted vendors like any other, and belong in the same review cycle as the SIS rather than a separate, informal track.

OECM and ECNO master agreements

Where a vendor sits under an OECM master agreement or an ECNO arrangement, the review checks what those bodies already negotiated on the board's behalf, since EDSTA amendments added supplier breach-notice and compliance-assistance terms boards can rely on.

Regulatory map

Why vendor review is now a board obligation, not a courtesy

Four instruments turn vendor diligence from prudent practice into something a regulator, an insurer or a trustee will eventually ask to see documented.

The IPC's contract-clause findings

The joint PowerSchool investigation found board agreements missing key privacy and security terms and directed boards to renegotiate contracts and monitor vendors going forward, turning vendor review into a named regulator expectation.

Primary source →

O. Reg. 52/26's vendor-by-vendor notice

Each parent or student notice must name the specific application, the vendor, the data elements disclosed and the purpose, which makes an accurate vendor-by-vendor register, the review's core output, the raw material the notice is built from.

Primary source →

MFIPPA safeguards and PIA duties

From January 1, 2027, s. 30(5) requires reasonable safeguards and s. 28 requires a PIA before new collection, and neither question can be answered honestly without first knowing what a vendor actually does with the data it is given.

Primary source →

Procurement rules that shape the review

The BPS Procurement Directive requires open competitive procurement at $121,200 and up, and the Buy Ontario Directive layers Canadian and Ontario preference onto purchasing from April 2026, so findings need to reach the RFP stage, not arrive after a vendor is already chosen.

Primary source →

The Digital Privacy Charter's vetting commitment

Boards that sign the IPC's charter commit to vetting the technology brought into classrooms, and a documented vendor review is the practical evidence that commitment is more than a pledge on paper.

Primary source →

What goes wrong

What the PowerSchool review missed, and what we check for

The joint Ontario-Alberta investigation is the sector's clearest account of how vendor oversight fails, and our review is built to catch each failure mode before it repeats.

  • A support portal with no MFA

    The attacker used a subcontractor's credentials on the PowerSource portal, which had no multi-factor authentication behind it, so evidence of MFA on every vendor's support and admin access is now a non-negotiable line in our checklist.

    Source →

  • Standing remote access nobody reviewed

    Always-on remote-access connections into board systems went unmonitored before the breach, so the review asks each vendor to show time-limited, logged access rather than a permanent open door into student data.

  • Log retention too short to investigate

    Short log retention at the vendor limited what investigators could reconstruct after the fact, so we ask vendors how long access and activity logs are kept and whether the board can obtain them quickly during an incident.

    Source →

  • Decades of data the vendor never deleted

    Records reaching back to 1965 at Peel and 1985 at TDSB sat inside PowerSchool because nobody enforced disposal, so the review checks a vendor's actual deletion practice against the board's own retention schedule, not just its stated policy.

    Source →

  • Extortion after the ransom was paid

    PowerSchool paid its attacker, and boards including TDSB and PDSB received fresh extortion demands months later regardless, a reminder that a vendor's incident-response promises need contractual teeth, not reassurance in a sales call.

    Source →

Our vendor security reviews for school boards & k-12 schools

What our vendor security review delivers for a board

The parent service's gap review, documentation guidance and control-consideration support are applied here to the specific vendors touching student and staff data, evidence in hand before a signature or a renewal.

Late-Night Developer: Hands of a Programmer at Work
  1. Evidence request and reading

    We request SOC 2 reports, ISO certificates, security whitepapers and completed questionnaires from each vendor, and read them rather than count them, flagging vague answers or expired assurance before anyone else does.

  2. Contract clause markup

    Draft agreements and renewals are marked up against the terms the IPC's report found missing: safeguards, breach-notice timelines, MFA on support access, log retention and cooperation duties, in language procurement can insert directly.

  3. The O. Reg. 52/26 evidence register

    A structured record of each vendor, the application, the data elements it receives and the purpose, built to feed straight into the fall parent and student notices rather than becoming a second inventory project.

  4. Risk-tiered review cycle

    SIS-level vendors get full annual review, mid-tier tools get a lighter refresh, and free classroom apps get a fast intake check, so effort matches what each vendor actually holds about students.

  5. A decision memo for senior administration

    Findings, residual risk and recommended conditions written for the Superintendent of Business and, where a purchase needs one, a trustee report, with technical detail kept in an appendix.

How the engagement runs

How a vendor review runs for a school board

We plan reviews around procurement timelines and the school year, so findings land before a signature, not after one.

  1. Step 1

    Scope by what the vendor will hold

    We start from the data at stake, OSR content, payment details, staff records, or a smaller classroom footprint, and set the review depth to match.

  2. Step 2

    Collect vendor evidence

    We request assurance reports, contract drafts and questionnaire answers directly from the vendor, and chase incomplete responses so board staff are not doing that follow-up themselves.

  3. Step 3

    Verify against the IPC's findings

    Every review checks the specific gaps the PowerSchool investigation named: contract terms, MFA, remote-access controls, log retention and data minimization.

  4. Step 4

    Mark up and negotiate

    We hand back contract language and a short list of conditions, and support the negotiation call if a vendor resists terms your board now needs in writing.

  5. Step 5

    Feed the notice register

    Confirmed findings, data elements, purpose and vendor identity are logged in the format the O. Reg. 52/26 notice cycle will use, so review and compliance run as one workflow.

What it costs

What drives the price of a board vendor review

Cost follows the vendor and the tier: a full SIS or LMS review with contract negotiation takes longer than an intake check on a free classroom app, and a board with dozens of school-level tools needs a program rather than a single review. Whether an existing vendor's evidence is current and cooperative, or has to be chased, also moves the estimate.

Many boards run their SIS and top payment or transportation vendors through a full review first, matching the IPC's own priorities, then phase the classroom-app long tail behind it. Vendor oversight is also included in our Virtual Privacy Office retainer for boards expecting several reviews a year. We quote fixed fees per vendor tier after a short intake call.

School Boards & K-12 Schools: Vendor security reviews questions, answered

The November 2025 report found board agreements lacking clear privacy and security safeguards, defined breach-notification timelines, MFA requirements for vendor remote access, log-retention commitments, and enforceable data-minimization terms, and directed boards to renegotiate. We use that finding as a checklist: every contract we review is marked against those same gaps, whether the vendor is your SIS provider or a much smaller platform, because the IPC named a pattern, not a single vendor's failing.

Treat the Charter's twelve commitments as a short intake form rather than a full audit. Ask what data the app collects about students, whether it trains a model, where it is hosted, how long it is kept, and whether the vendor will sign even a light data-handling addendum. A free tool that refuses basic answers or has no privacy policy fails the check regardless of price, and that decision belongs on the register feeding your O. Reg. 52/26 notices.

Ask in writing, under NDA if needed, and treat a refusal as an answer in itself. Reputable SIS, LMS and platform vendors will provide a SOC 2 Type II summary or ISO certificate to a paying institutional customer; smaller edtech firms sometimes have neither, in which case we substitute a structured questionnaire covering hosting, retention and incident notice. A vendor that still won't engage earns a documented risk flag for the Superintendent of Business, and on significant purchases a procurement condition.

Escalate the gap rather than accept it quietly. We document which term is missing and the risk it leaves open, so the Superintendent of Business or CIO can weigh it against switching costs, an easier conversation with the IPC's own findings attached. For SIS-level vendors this often lands at renewal, where leverage is highest; for smaller tools, replacing an uncooperative vendor is frequently the cheaper path.

Directly: a maturity assessment scores whether the board manages third-party and supply-chain risk, and a documented, risk-tiered review program is the evidence an assessor looks for. Boards that build the register early are not reconstructing vendor history when the first assessment comes due by July 1, 2027, because the two workstreams share the same evidence.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.