Gap assessment
Review your systems and processes against the requirements that apply to you, and prioritize the technical work.
Security
We help schools, agencies and businesses put the technical controls behind FERPA, COPPA, HIPAA, GLBA, GDPR and India’s DPDP Act in place — working alongside your legal counsel.
Our approach
Compliance is a shared effort between your teams, your legal counsel and us. We focus on the systems and software that make it work day to day.
Review your systems and processes against the requirements that apply to you, and prioritize the technical work.
Document what personal data you hold, where it lives, who can reach it and where it flows.
Notices, consent capture, access and deletion requests, and retention rules built into the software we deliver.
Role-based access, encryption in transit and at rest, and multi-factor authentication.
Record who accessed what and when, and alert on unusual activity.
Review how vendors and partners handle your data, and the technical safeguards behind your agreements.
Privacy by design and secure coding practices in every application we build on Nodio.
Policies, system documentation and evidence your auditors and regulators can review.
Regulations
A plain-language overview of each regulation, what it requires and where we can help.
United States
Family Educational Rights and Privacy Act (1974)
FERPA protects the privacy of student education records and gives parents — and students once they become “eligible students” — rights over those records.
Schools, districts and other educational agencies and institutions that receive funds under applicable US Department of Education programs. That includes most public K-12 districts and most colleges and universities. Rights pass from parents to the student at age 18 or when the student attends a postsecondary institution.
Many states add their own student-privacy laws on top of FERPA. We can help map those requirements into your systems too.
United States
Children’s Online Privacy Protection Act (1998) and the FTC’s COPPA Rule
COPPA gives parents control over the personal information that websites, apps and online services collect from children under 13.
Operators of commercial websites and online services, including apps, that are directed to children under 13 — and general-audience services that have actual knowledge they collect personal information from children under 13. It is enforced by the Federal Trade Commission (FTC).
Under FTC guidance, a school may be able to consent in place of parents when an ed-tech service collects student data solely for the school’s educational use and for no other commercial purpose. Confirm the details with your counsel.
United States
Health Insurance Portability and Accountability Act (1996)
HIPAA protects protected health information (PHI). PHI held or sent electronically is electronic PHI, or ePHI.
Covered entities — health plans, health care clearinghouses and health care providers that conduct certain transactions electronically — and their business associates: vendors that create, receive, maintain or transmit PHI on their behalf. It is enforced by the HHS Office for Civil Rights.
Student health records kept by K-12 schools are generally education records under FERPA rather than PHI under HIPAA. School-based health centers, district health plans and healthcare partners may be subject to HIPAA, so confirm which law applies to each system.
United States
Gramm-Leach-Bliley Act (1999)
GLBA protects customers’ nonpublic personal information (NPI) held by financial institutions, through the Financial Privacy Rule and the FTC’s Safeguards Rule.
Companies significantly engaged in providing financial products or services — such as banks, lenders, mortgage brokers and tax preparers — and colleges and universities that participate in federal student financial aid programs.
For colleges and universities, GLBA commonly applies to financial aid, billing and enrollment systems that handle student and family financial information.
European Union
General Data Protection Regulation — Regulation (EU) 2016/679
The GDPR has applied since 25 May 2018 and governs how the personal data of people in the EU is processed.
Organizations in the EU, and organizations outside the EU that offer goods or services to, or monitor the behavior of, people in the EU — including processors acting on behalf of such organizations.
India
Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025
India’s DPDP Act governs digital personal data. It is implemented through the DPDP Rules, 2025, which phase obligations in over time.
Digital personal data processed in India, and processing outside India connected with offering goods or services to people in India. Key roles are the Data Fiduciary (who decides why and how data is processed), the Data Processor, the Data Principal (the individual), Consent Managers and the Data Protection Board of India.
FAQ
No. Vizipp provides technical and operational implementation support. Work with qualified legal counsel to interpret how each law applies to your organization.
It depends on who you serve, what data you hold and where your users are. A K-12 district typically works with FERPA and, through its ed-tech vendors, COPPA; a healthcare partner with HIPAA; a college’s financial aid office with GLBA. Your counsel confirms the list — we map it into your systems.
Yes. We build FERPA- and COPPA-aware features such as role-based access, audit logs, consent flows and data deletion into applications for schools, including those built on our Nodio platform.
Yes. We review existing systems and add access controls, encryption, audit logging, consent and retention features where they are missing.
No. We help you implement controls and prepare documentation and evidence. Compliance decisions rest with you and your counsel, and any formal certification or audit opinion comes from independent auditors.
Tell us which regulations you’re working with and we’ll help you plan the technical work alongside your legal counsel.

We help organizations thrive in the digital age — building custom software, web and mobile applications, and AI-powered tools on our Nodio platform.
hr@vizipp.com
Proud member of TIPS-USA