FormGuard guide for schools

Student data privacy for Google Forms add-ons: what school IT should check

California Education Code 49073.1 requires a data privacy agreement (DPA) before schools procure educational technology. Use this checklist before turning on any Google Forms add-on for classrooms, enrollment, or staff workflows.

Quick answer

The rule

CA schools need a signed DPA.

Before procurement, LEAs must execute a data privacy agreement such as the CA-NDPA v1.5, in compliance with Education Code 49073.1.

Ask where data lives

Check storage and egress.

Ask the vendor: where is student data stored, is it outside your Google Workspace, and does the add-on make external requests?

Ask what is collected

Get the data exhibit in writing.

The DPA's Schedule of Data should list every data element the tool collects. "No student data collected" should be explicit, not implied.

FormGuard status

CA-NDPA executed with a CA district.

FormGuard's provider agreement was fully executed with San Bernardino City Unified School District through the CITE Privacy Services program.

The school IT checklist for a Forms add-on

  1. Locate the privacy agreement. Look for a signed CA-NDPA (California) or the SDPC national DPA. Districts signed through CITE Privacy Services can piggyback an existing provider agreement instead of drafting one.
  2. Verify the data schedule. The agreement's Exhibit B should enumerate collected data elements. Tools that only count responses and never store names, emails, or scores should say so plainly.
  3. Confirm where data is stored. The lowest-risk pattern for Google Forms add-ons is configuration stored inside the district's own Google Workspace, with no external server and no external HTTP calls.
  4. Check prohibited uses. The agreement should prohibit selling student data, targeted advertising, and training AI models on student data.
  5. Note the incident commitment. CA-NDPA requires notification to the district within 72 hours of a confirmed breach, plus a written incident response plan.

How FormGuard handles this today

Questions to send any Forms add-on vendor

  1. Do you have a signed CA-NDPA or SDPC DPA an LEA can piggyback?
  2. Which data elements appear in your Schedule of Data exhibit?
  3. Is any student data stored outside our Google Workspace tenant?
  4. Do you operate external servers, analytics, or telemetry endpoints?
  5. What is your breach notification commitment and security framework?

If a vendor cannot answer these in one email, treat that as the answer.

Next steps