Student Data Statement

Overview

Last Updated: September 15, 2026

ID123 Inc does not use student data for any purpose other than to provide our Services, in accordance with our Terms of Service, and our Privacy Policy. ID123 does not own or control student data, which belongs to the student and/or the institution that contracts with ID123 to provide the digital ID cards to students. Our customers have full access and complete control of all of the student data in their ID Management System (IDMS) account. We keep information collected on behalf of our customers only as long as necessary to perform our Services, pursuant to contractual terms or as otherwise required by applicable law. We do not sell personal data. We may share data with a third party where expressly authorized in writing by the relevant customer or data subject – for example, to enable an integration the customer has requested. We delete information that is not held pursuant to contractual terms in accordance with our data destruction policy or at the request of a customer. We have implemented robust security controls, policies and procedures in order to keep student data safe as well as a documented incident response procedure that includes timely breach notifications.

The Family Educational Rights and Privacy Act (FERPA).

ID123 Services and policies are designed to meet our responsibilities to protect each student’s personal information and educational records under FERPA. We agree to work with our customers to jointly ensure compliance with the FERPA regulations. A school may disclose personally identifiable information from a student’s education records to ID123 with either written consent of the parent or by meeting one of the exemptions set forth in FERPA (“FERPA Exemption(s)”), including the exemption for “Directory Information” or “School Official”.

Children’s Online Privacy Protection Act (COPPA).

The ID123 Service is not directed to children under 13 and does not knowingly collect any information from children under the age of 13. We do not permit a child under 13 to register for the Service, unless an institutional customer represents that it has the authority to provide all necessary consents for ID123 to collect and use such student’s personal information in the manner permitted by COPPA. Please contact us immediately if you believe we have inadvertently collected personal information of a child under 13 without proper consent so that we may delete such data as soon as possible.

Students Online Personal Information Protection Act (“SOPIPA”).

The ID123 Service and policies are designed to comply with SOPIPA, and with substantially equivalent statutes in other states. Our business does not generate revenue from advertising. We do not display ads within the Service at all. We do not use or sell any student data for targeted advertising purposes. We do not use or sell collected information to create a profile of a student except for the functionality of the Service. Other state student privacy laws with substantially equivalent requirements that we are designed to align with include New York Education Law §2-d and the Illinois Student Online Personal Protection Act (“SOPPA”).

India’s Digital Personal Data Protection Act (“DPDPA”).

Where a customer issues digital ID cards or credentials to students located in India, or otherwise directs us to process the personal data of students in connection with the offer of our Services to individuals in India, we process that data solely as a service provider to, and under the instruction of, the institution. The institution remains responsible for determining the purposes and means of that processing and, where the student is a child — defined under the DPDPA as an individual under the age of 18 — for obtaining any parental or lawful guardian consent required under the DPDPA and its rules. Consistent with our practices under COPPA and SOPIPA described above, we do not use student data to undertake tracking, behavioral monitoring, or targeted advertising directed at children, and our business does not generate revenue from advertising of any kind. Please contact us immediately at privacy@id123.io if you believe we have processed a child’s personal data in India without the consent required under the DPDPA, so that we may investigate and, where appropriate, delete such data.

European Union — General Data Protection Regulation (GDPR).

Where a customer issues digital ID cards or credentials to students located in the European Union, or otherwise directs us to process the personal data of students in connection with the offer of our Services to individuals in the EU, we process that data solely as a processor to, and under the instruction of, the institution (as data controller). The institution remains responsible for determining the purposes and means of that processing and, where the student is a child, for obtaining any parental or guardian consent required under Article 8 of the GDPR. EU member states each set their own minimum age at which a child may consent directly to information society services, ranging from 13 to 16 depending on the country. Consistent with our practices described elsewhere in this Statement, we do not use student data to undertake tracking, behavioral monitoring, or targeted advertising directed at children, and our business does not generate revenue from advertising of any kind. ID123 has appointed an Article 27 GDPR representative in the EU; see our Privacy Policy for details. Please contact us immediately at privacy@id123.io if you believe we have processed a child’s personal data in the EU without the consent required under the GDPR, so that we may investigate and, where appropriate, delete such data.

United Kingdom — UK GDPR and the Children’s Code.

Where a customer issues digital ID cards or credentials to students located in the United Kingdom, we process that data solely as a processor to, and under the instruction of, the institution, in accordance with the UK GDPR and the Data Protection Act 2018. The Information Commissioner’s Office’s Age Appropriate Design Code (the “Children’s Code”) requires online services likely to be accessed by anyone under the age of 18 to be designed with the best interests of the child as a primary consideration, including data minimization, high-privacy default settings, and restrictions on using children’s data for purposes beyond delivering the service. ID123’s Services are built around these same principles: we collect only the student data necessary to issue and manage a digital ID card, apply privacy-protective defaults, and do not use student data for tracking, behavioral profiling, or targeted advertising of any kind. Please contact us immediately at privacy@id123.io if you have concerns about how we process a UK student’s personal data.

Switzerland — Federal Act on Data Protection (FADP).

Where a customer issues digital ID cards or credentials to students located in Switzerland, we process that data solely as a processor to, and under the instruction of, the institution, in accordance with the revised Federal Act on Data Protection (FADP). The FADP does not impose a separate parental-consent regime for children’s data in the way COPPA or Article 8 of the GDPR do, but it treats a breach involving children’s data as inherently high-risk, which triggers the incident notification obligations described in our Security page. Consistent with our practices described elsewhere in this Statement, we do not use student data for tracking, behavioral profiling, or targeted advertising.

Australia — Privacy Act 1988 and the Children’s Online Privacy Code.

Where a customer issues digital ID cards or credentials to students located in Australia, including public sector entities such as New South Wales government schools, we process that data solely as a processor to, and under the instruction of, the institution, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. The Privacy Act also provides for a Children’s Online Privacy Code, issued by the Office of the Australian Information Commissioner (OAIC), which sets additional design, transparency, and privacy-impact-assessment requirements for online services likely to be accessed by children — including school management systems that monitor student activity. ID123’s practices are designed to align with the Code’s requirements. Consistent with our practices described elsewhere in this Statement, we do not use student data for tracking, behavioral profiling, or targeted advertising.

Canada — PIPEDA and Provincial Privacy Legislation.

Where a customer issues digital ID cards or credentials to students located in Canada, the personal information of students at public schools is generally governed by provincial legislation — typically a freedom of information and protection of privacy statute — rather than the federal Personal Information Protection and Electronic Documents Act (PIPEDA), which principally applies to private-sector commercial activity. Regardless of which regime applies to a given institution, we process student data solely as a processor or service provider to, and under the instruction of, the institution, and we align our practices with the heightened requirements in force in provinces such as Quebec (Law 25), Alberta, and British Columbia. Consistent with our practices described elsewhere in this Statement, we do not use student data for tracking, behavioral profiling, or targeted advertising, and we maintain the incident response and breach notification procedures described in our Security page.

Other Jurisdictions.

If your institution is located in a jurisdiction not addressed above, please contact us at privacy@id123.io. We work with customers to address the data protection requirements applicable to their jurisdiction, including through jurisdiction-specific contract terms where appropriate.