Home / Compliance

Education Data Deserves Enterprise-Grade Protection.

Built for GCC schools. Ready for global education. Spark-Ed is designed to support privacy, security and compliance work — it is not certified for every regulation.

Compliance matrix

Statuses reflect what is implemented today, not what we aim to offer.

FrameworkRegionEducation relevanceSpark-Ed controlsStatus
Saudi PDPLSaudi ArabiaStudent, parent and staff personal data; consent; data-subject rightsPrivacy policy, role-based access, data minimisation by design; customer-configured retention and requests◐ Configurable
GCC privacy laws (UAE, Qatar, Bahrain, Oman, Kuwait)GCCCross-border schools and multi-campus groupsSame design controls as above; country review is a customer responsibility◐ Configurable
GDPREuropean UnionSchools with EU-resident data subjectsGDPR information page published; data-processing terms to be formalised◐ Configurable
FERPAUnited StatesUS school records and parent/student access rightsRole-based access to student records; customer controls disclosure◐ Configurable
COPPAUnited StatesServices directed to children under 13School-managed accounts; parental-consent workflows to be confirmed○ Roadmap
CCPA / CPRACalifornia, USCalifornia residents’ personal informationPrivacy policy; request handling via support◐ Configurable
ISO/IEC 27001InternationalInformation security management systemSecurity practices aligned with the standard; certification status to be verified before publishing○ Roadmap
ISO/IEC 27017 / 27018InternationalCloud security and PII in public cloudNot certified○ Roadmap
SOC 2InternationalVendor assurance for security, availability, confidentialityNot audited; aligned practices only○ Roadmap
OWASP practicesInternationalWeb application securitySecure-development practices; independent testing to be verified◐ Configurable
Role-based access (RBAC)PlatformSeparate access for owners, principals, teachers, parents, students, ITRole-based portals and permissions✓ Available
SSO, OAuth 2.0 / OIDCPlatformSingle sign-on with school identity providersNot yet available○ Roadmap
Open APIPlatformIntegration with school systemsOpen API available✓ Available
OneRoster, LTI, SCORM, xAPI, Ed-Fi, CEDS, 1EdTech, CASE, Common CartridgeInternationalEducation data interoperabilityPlanned / Integration Roadmap○ Roadmap
Regional data residencySaudi Arabia / GCCHosting in-country or in-regionRegional data residency options are part of the deployment roadmap○ Roadmap

✓ Available   ◐ Configurable   ○ Roadmap   — N/A

Saudi Arabia — Built for PDPL-Aware Education Environments

Spark-Ed is designed with the Saudi Personal Data Protection Law (PDPL) in mind. Education platforms handle personal data and, in some cases, sensitive personal data about students, parents and staff. Our design objectives cover consent, data-subject rights (access, correction, deletion), data retention and minimisation, data sharing with third-party processors, international transfers, security controls, audit logging, access controls and breach-response processes. Which of these are configured and enforced depends on each customer deployment.

Spark-Ed provides technical and organizational capabilities intended to support organizations in meeting applicable privacy obligations. Customers remain responsible for determining their legal obligations and configuring the platform appropriately.

GCC Privacy Overview

The platform is designed for schools in Saudi Arabia, the UAE, Qatar, Bahrain, Oman and Kuwait, each of which has its own data-protection requirements. We describe design objectives common to these regimes rather than claiming country-specific compliance. Arabic and English interfaces, multi-campus groups and role-based access support organisations operating across the region.

  • 🇸🇦 Saudi Arabia
  • 🇦🇪 United Arab Emirates
  • 🇶🇦 Qatar
  • 🇧🇭 Bahrain
  • 🇴🇲 Oman
  • 🇰🇼 Kuwait

United States — FERPA, COPPA, CCPA/CPRA

For US schools, Spark-Ed is designed to support FERPA-style controls over education records, school-managed accounts for children under 13 (COPPA), and California privacy request handling (CCPA/CPRA). State student-privacy laws vary; schools should confirm their own requirements. We do not claim FERPA or COPPA compliance on behalf of customers.

European Union — GDPR

Spark-Ed is designed to help organisations handling EU personal data apply GDPR principles such as lawfulness, minimisation, purpose limitation, data-subject rights and security. See our GDPR page. Data-processing terms and a sub-processor list are being formalised.

International Privacy

Beyond the regions above, the same design objectives apply: collect only what is needed, give schools control over access, and keep records of who did what. Customers outside the listed regions should confirm local requirements with their advisers.

Education Data Standards

Spark-Ed offers an open API today. 1EdTech, OneRoster, LTI, Common Cartridge, CASE, Ed-Fi, CEDS, SCORM and xAPI are labelled Planned / Integration Roadmap — they are not currently implemented.

See the compliance matrix

Security by Design

Security is part of the design: role-based portals, separation of student, parent and staff access, and secure web practices. We publish only controls we have verified; see the Security page. Encryption, audit-log coverage, backup and penetration-test details will be added once independently confirmed.

See the compliance matrix

Responsible AI & Education Data

AI features are on the product roadmap and are not live. When introduced, student data will not be used to train third-party models without explicit customer agreement, and AI features will be optional for schools. See AI & Privacy.

Child & Student Safety

Student accounts are managed by the school. Access to student data is limited by role, and parents see only their own children. See Child Safety.

Data Residency

Regional data residency options are part of the deployment roadmap. We do not currently claim in-country hosting in Saudi Arabia or the GCC.

Identity & Access

Role-based access is available. SSO and OAuth 2.0 / OpenID Connect are on the roadmap.

Data Governance

Schools decide who can see which records. Retention periods, export and deletion requests are handled with the customer under the agreement; see Data Retention.

Compliance Roadmap

Planned work: regional data residency options, SSO/OIDC, formal data-processing agreement and sub-processor list, independent security testing, and evaluation of ISO/IEC 27001 and SOC 2 audits. Timing is not committed.

Frequently asked questions

Is Spark-Ed certified or fully compliant with PDPL, GDPR or FERPA?

No. Spark-Ed is designed to support organisations working toward these obligations. Compliance depends on how each school configures and uses the platform.

Does Spark-Ed host data in Saudi Arabia?

Regional data residency options are part of the deployment roadmap.

Does Spark-Ed hold ISO 27001 or SOC 2 certification?

Not at this time. We follow aligned practices and will update this page if certification is independently verified.

Privacy & security documents

Compliance Notice

The information presented on this page describes technical and organizational features and design objectives of Spark-Ed. It does not constitute legal advice, certification, or a guarantee of compliance with any law or regulatory framework.

Applicable requirements vary according to jurisdiction, organization, deployment model, contracts, data processing activities and configuration. Schools and organizations are responsible for determining their own legal and regulatory obligations and obtaining appropriate professional advice.

Where Spark-Ed references a third-party framework, standard or regulation, the reference does not imply certification unless explicitly stated and independently verifiable.