Education Data Deserves Enterprise-Grade Protection.
Built for GCC schools. Ready for global education. Spark-Ed is designed to support privacy, security and compliance work — it is not certified for every regulation.
Compliance matrix
Statuses reflect what is implemented today, not what we aim to offer.
| Framework | Region | Education relevance | Spark-Ed controls | Status |
|---|---|---|---|---|
| Saudi PDPL | Saudi Arabia | Student, parent and staff personal data; consent; data-subject rights | Privacy policy, role-based access, data minimisation by design; customer-configured retention and requests | ◐ Configurable |
| GCC privacy laws (UAE, Qatar, Bahrain, Oman, Kuwait) | GCC | Cross-border schools and multi-campus groups | Same design controls as above; country review is a customer responsibility | ◐ Configurable |
| GDPR | European Union | Schools with EU-resident data subjects | GDPR information page published; data-processing terms to be formalised | ◐ Configurable |
| FERPA | United States | US school records and parent/student access rights | Role-based access to student records; customer controls disclosure | ◐ Configurable |
| COPPA | United States | Services directed to children under 13 | School-managed accounts; parental-consent workflows to be confirmed | ○ Roadmap |
| CCPA / CPRA | California, US | California residents’ personal information | Privacy policy; request handling via support | ◐ Configurable |
| ISO/IEC 27001 | International | Information security management system | Security practices aligned with the standard; certification status to be verified before publishing | ○ Roadmap |
| ISO/IEC 27017 / 27018 | International | Cloud security and PII in public cloud | Not certified | ○ Roadmap |
| SOC 2 | International | Vendor assurance for security, availability, confidentiality | Not audited; aligned practices only | ○ Roadmap |
| OWASP practices | International | Web application security | Secure-development practices; independent testing to be verified | ◐ Configurable |
| Role-based access (RBAC) | Platform | Separate access for owners, principals, teachers, parents, students, IT | Role-based portals and permissions | ✓ Available |
| SSO, OAuth 2.0 / OIDC | Platform | Single sign-on with school identity providers | Not yet available | ○ Roadmap |
| Open API | Platform | Integration with school systems | Open API available | ✓ Available |
| OneRoster, LTI, SCORM, xAPI, Ed-Fi, CEDS, 1EdTech, CASE, Common Cartridge | International | Education data interoperability | Planned / Integration Roadmap | ○ Roadmap |
| Regional data residency | Saudi Arabia / GCC | Hosting in-country or in-region | Regional data residency options are part of the deployment roadmap | ○ Roadmap |
✓ Available ◐ Configurable ○ Roadmap — N/A
Saudi Arabia — Built for PDPL-Aware Education Environments
Spark-Ed is designed with the Saudi Personal Data Protection Law (PDPL) in mind. Education platforms handle personal data and, in some cases, sensitive personal data about students, parents and staff. Our design objectives cover consent, data-subject rights (access, correction, deletion), data retention and minimisation, data sharing with third-party processors, international transfers, security controls, audit logging, access controls and breach-response processes. Which of these are configured and enforced depends on each customer deployment.
Spark-Ed provides technical and organizational capabilities intended to support organizations in meeting applicable privacy obligations. Customers remain responsible for determining their legal obligations and configuring the platform appropriately.
GCC Privacy Overview
The platform is designed for schools in Saudi Arabia, the UAE, Qatar, Bahrain, Oman and Kuwait, each of which has its own data-protection requirements. We describe design objectives common to these regimes rather than claiming country-specific compliance. Arabic and English interfaces, multi-campus groups and role-based access support organisations operating across the region.
- 🇸🇦 Saudi Arabia
- 🇦🇪 United Arab Emirates
- 🇶🇦 Qatar
- 🇧🇭 Bahrain
- 🇴🇲 Oman
- 🇰🇼 Kuwait
United States — FERPA, COPPA, CCPA/CPRA
For US schools, Spark-Ed is designed to support FERPA-style controls over education records, school-managed accounts for children under 13 (COPPA), and California privacy request handling (CCPA/CPRA). State student-privacy laws vary; schools should confirm their own requirements. We do not claim FERPA or COPPA compliance on behalf of customers.
European Union — GDPR
Spark-Ed is designed to help organisations handling EU personal data apply GDPR principles such as lawfulness, minimisation, purpose limitation, data-subject rights and security. See our GDPR page. Data-processing terms and a sub-processor list are being formalised.
International Privacy
Beyond the regions above, the same design objectives apply: collect only what is needed, give schools control over access, and keep records of who did what. Customers outside the listed regions should confirm local requirements with their advisers.
Education Data Standards
Spark-Ed offers an open API today. 1EdTech, OneRoster, LTI, Common Cartridge, CASE, Ed-Fi, CEDS, SCORM and xAPI are labelled Planned / Integration Roadmap — they are not currently implemented.
Security by Design
Security is part of the design: role-based portals, separation of student, parent and staff access, and secure web practices. We publish only controls we have verified; see the Security page. Encryption, audit-log coverage, backup and penetration-test details will be added once independently confirmed.
Responsible AI & Education Data
AI features are on the product roadmap and are not live. When introduced, student data will not be used to train third-party models without explicit customer agreement, and AI features will be optional for schools. See AI & Privacy.
Child & Student Safety
Student accounts are managed by the school. Access to student data is limited by role, and parents see only their own children. See Child Safety.
Data Residency
Regional data residency options are part of the deployment roadmap. We do not currently claim in-country hosting in Saudi Arabia or the GCC.
Identity & Access
Role-based access is available. SSO and OAuth 2.0 / OpenID Connect are on the roadmap.
Data Governance
Schools decide who can see which records. Retention periods, export and deletion requests are handled with the customer under the agreement; see Data Retention.
Compliance Roadmap
Planned work: regional data residency options, SSO/OIDC, formal data-processing agreement and sub-processor list, independent security testing, and evaluation of ISO/IEC 27001 and SOC 2 audits. Timing is not committed.
Frequently asked questions
Is Spark-Ed certified or fully compliant with PDPL, GDPR or FERPA?
No. Spark-Ed is designed to support organisations working toward these obligations. Compliance depends on how each school configures and uses the platform.
Does Spark-Ed host data in Saudi Arabia?
Regional data residency options are part of the deployment roadmap.
Does Spark-Ed hold ISO 27001 or SOC 2 certification?
Not at this time. We follow aligned practices and will update this page if certification is independently verified.
Privacy & security documents
Compliance Notice
The information presented on this page describes technical and organizational features and design objectives of Spark-Ed. It does not constitute legal advice, certification, or a guarantee of compliance with any law or regulatory framework.
Applicable requirements vary according to jurisdiction, organization, deployment model, contracts, data processing activities and configuration. Schools and organizations are responsible for determining their own legal and regulatory obligations and obtaining appropriate professional advice.
Where Spark-Ed references a third-party framework, standard or regulation, the reference does not imply certification unless explicitly stated and independently verifiable.