OMNIA Inclusion Ltd — the document a US school's business office, IT
director, or board-level procurement committee typically asks for before
signing, covering data residency, the US privacy-law landscape as it
actually applies to a private school, and the two federal special-education
baselines (IDEA, ADA Title III) OMNIA's own /us page already frames
honestly.
Version: 1.0 Last updated: 25 September 2026
Status note. Unlike the UAE and Qatar packs, this document has not been reviewed by US counsel. It is accurate to the best of OMNIA's understanding of publicly available statutory text, but US student-data and privacy law varies by state and changes often. Do not present this as a legal opinion. Before this pack is used with a real, contract-track prospect, have US counsel (ideally one familiar with independent-school data-privacy questions) review §2 and §3 specifically. Flag this status to the prospect's own counsel too — an honest "here's our understanding, please have your own counsel confirm" is a stronger position than an unreviewed guarantee.
1. Data hosting and residency
All pupil, parent, and staff personal data entered into OMNIA is stored in
AWS Europe (Ireland), region eu-west-1, on managed PostgreSQL provided
through Lovable Cloud (Supabase) — the same infrastructure documented in
the Data Residency One-Pager. The
application runs on Cloudflare Workers at the edge; request bodies are
processed in memory only and are not persisted at the edge.
There is no US hosting region today. No US state currently has a general law requiring K-12 student data to be hosted within the United States, so EU hosting is not, by itself, a compliance blocker for a US private school. It is nonetheless a question a US IT director or board member may reasonably ask, since "where does the data live" is a normal procurement question regardless of whether a specific statute compels a particular answer. Be ready to say plainly: Ireland, EU, not the US, and to point to encryption-in-transit (TLS 1.2+) and at-rest (AES-256) as the controls that matter more than the data's physical location for a school with no in-state hosting requirement.
If a specific prospect's counsel identifies a state or contractual requirement for in-region hosting, treat that as a genuine commercial question to escalate — not something to argue around.
2. The US privacy-law landscape for a private school
This section is deliberately narrower than "you have zero obligations." The honest position is: most of the general-purpose and student-specific privacy statutes US schools hear about are written to reach entities this platform's typical customer — a single private or international school, not a public school district — usually does not meet.
2.1 State comprehensive consumer-privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, and similar)
The wave of state privacy laws that followed California's CCPA/CPRA generally apply to a "business" or "controller" that meets a revenue or data-volume threshold (for example, CCPA's ~$25M annual revenue, or processing the personal data of 100,000+ consumers/households in a calendar year), and several of them (Virginia, Colorado, Connecticut, Utah, and others) explicitly exclude nonprofit organizations from the definition of a covered entity altogether. A single independent school — almost always a nonprofit, and almost never meeting the volume/revenue thresholds even where no nonprofit exclusion applies — is very unlikely to be a covered entity under any of these statutes in its own right. This is a genuine, defensible position, not a loophole being stretched.
2.2 State student-data-privacy statutes (SOPIPA-style laws, NY Education Law §2-d, and similar)
Most state student-data-privacy statutes (modelled, directly or loosely, on California's SOPIPA) are written to govern operators contracting with a "local education agency" — a public school district, BOCES, charter school, or state education department. New York's Education Law §2-d is a clear example: its obligations (and the NIST-aligned Data Privacy and Security Policy it requires of contracting vendors) attach to "educational agencies" as that term is defined in the statute, which does not reach a general private school. Where a state's statute is scoped this way, a private school contracting with OMNIA directly — rather than a public school district doing so — is outside the statute's own definition of what it regulates, on the statute's own terms.
This is not universal, and a small number of states are a genuine exception worth a caveat rather than a blanket claim. OMNIA's understanding is that Vermont, and possibly Nebraska, New Hampshire, and Georgia, have either broader statutory language or ed-tech/student records provisions not as clearly limited to public LEAs as the SOPIPA/2-d model. Where a prospective school is based in one of these states, flag it explicitly and recommend the school's own counsel confirm applicability — do not extend the "private schools are generally outside scope" framing to these states without that confirmation.
2.3 FERPA
The Family Educational Rights and Privacy Act applies to "educational agencies or institutions" that receive funds under a program administered by the US Department of Education. A private school with no such federal funding is, in the ordinary case, not a FERPA-covered institution at all. Some private schools do participate in narrow federal programs (E-Rate, IDEA Part B "proportionate share" equitable services arranged through the local public school district for parentally-placed children — see §4 — or occasional Title I equitable-services arrangements); where that's true for a specific prospect, note it and avoid a flat "FERPA doesn't apply to you" statement without checking what federal programs, if any, that particular school participates in.
2.4 The general-purpose law that DOES apply regardless of state: breach notification
Every US state has some form of data-breach notification statute requiring notice to affected residents (and, above certain thresholds in many states, to the state Attorney General) following unauthorized access to specified categories of personal information. Unlike the sector-specific statutes above, these laws are not limited to public schools, LEAs, or entities meeting a revenue threshold — they generally apply to any entity holding the covered data categories of that state's residents. This is the baseline that actually reaches every school, public or private, regardless of size.
OMNIA's own breach response is documented in the Breach Notification SOP: detection and containment within the first four hours, a structured assessment of what data and how many data subjects were affected, School (controller) notification within 24 hours of OMNIA's own awareness, and pre-drafted notice templates the School can use for its own state-law notifications to affected families. The specific notice deadline and content requirements vary by the affected data subjects' state of residence — the SOP's templates are built to be adapted per state rather than assuming a single regulator, since a US school's breach response, unlike the UAE/Qatar packs' single-regulator workflow, may touch multiple states' AG offices depending on where enrolled families live.
3. Federal special-education baselines
OMNIA's /us marketing page already states this distinction plainly, and
this pack restates it for a procurement audience rather than a prospective
buyer reading the product page:
3.1 IDEA — and its proportionate-share rule for private schools
The Individuals with Disabilities Education Act's full procedural machinery (eligibility determinations, FAPE, IEPs, due process) binds public schools and school districts that receive IDEA Part B federal funds. A private school itself is not an IDEA grant recipient and is not directly bound by IDEA's procedural requirements.
IDEA does reach private schools indirectly through the "proportionate share" / equitable-services provision (34 CFR §§300.130–300.144): where parents unilaterally enroll a child with a disability in a private school (rather than the child being placed there by the public agency), the local school district in which the private school is located must spend a proportionate amount of its IDEA Part B funds to provide equitable services to parentally-placed private-school children with disabilities within its jurisdiction. This is a service obligation on the district, administered through a "services plan" the district develops (typically in consultation with the private school and parents) — it is not a right to FAPE, and it is not enforceable through the same due-process route as a public-school IEP. A pupil at a private school may therefore have both a services plan of this kind and a separate, informally-held plan the school itself maintains (exactly the shape OMNIA's Beacon Hill demo models with a pupil whose previous public-school-issued IEP is voluntarily honoured by a private school that isn't itself IDEA-bound).
3.2 ADA Title III — reasonable modifications, with a religious-institution exemption
Title III of the Americans with Disabilities Act (42 U.S.C. §12181 et seq.) treats private schools as places of public accommodation and requires reasonable modifications to policies, practices, and procedures for students with disabilities, unless doing so would fundamentally alter the nature of the school's services — plus removal of architectural barriers where readily achievable, and provision of auxiliary aids and services. Religious organizations, and entities controlled by religious organizations, are exempt from Title III entirely (42 U.S.C. §12187). For a prospective school affiliated with or controlled by a religious organization, this exemption is worth surfacing directly rather than assuming Title III applies by default the way it would for a secular independent school.
4. Paperwork available on request
- Data Processing Agreement (master DPA) — within the Terms of Service.
- Data residency one-pager.
- Security posture overview.
- Breach-notification SOP.
- DPIA.
- Sub-processors list.
- A US-specific jurisdiction addendum does not yet exist (unlike the UAE and Qatar addenda) — see §5.
5. Open items — do not overclaim past this pack
- No US counsel review yet. §2 and §3 above are OMNIA's own understanding of public statutory text, not a legal opinion. Route to counsel before this pack is relied on in a live procurement process.
- No US jurisdiction addendum. The UAE and Qatar packs each have a signed jurisdiction addendum layering local requirements onto the master DPA. Nothing equivalent exists for the US yet — if a prospect's counsel asks for one, that's a real gap, not a formality to wave past.
- State-by-state variation is real. §2.2's Vermont/Nebraska/New Hampshire/Georgia caveat is based on OMNIA's own (unreviewed) reading — treat it as "ask counsel," not as a settled list of every state where the general private-school-is-out-of-scope framing might not hold.
- A school that participates in federal programs changes §2.3 and §3.1. If a specific prospect receives Title I funds, E-Rate discounts, or otherwise touches federal education funding, do not use the flat "private schools generally aren't FERPA/IDEA-bound" framing without checking what that school's actual funding picture is.
