DATA SHARING ADDENDUM
Last Updated: April 1, 2026
This Data Sharing Addendum (“Addendum”) forms a part of the Civitas Learning, Inc. (“Civitas”) Master Services Agreement (“MSA”) governed the provision of Civitas products and services. By entering into an Order Form subject to the MSA, Customer agrees to be bound by the terms of this Addendum.
The terms used in this Addendum shall have the meanings set forth in this Addendum. Capitalized terms not otherwise defined herein shall have the meaning given to them in the MSA. Except as modified below, the terms of the MSA shall remain in full force and effect.
In consideration of the mutual obligations set out herein, the Parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the MSA. Except where the context requires otherwise, references in this Addendum to the MSA are to the MSA as amended by, and including, this Addendum.
1. DefinitionsIn this Addendum, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
1.1 “Affiliate” means, with respect to a Party, any entity that directly or indirectly controls, is controlled by, or is under common control with such Party, whereby “control” (including, with correlative meaning, the terms “controlled by” and “under common control”) means the possession, directly or indirectly, of the power to direct, or cause the direction of the management and policies of such person, whether through the ownership of voting securities, by contract, or otherwise.
1.2 “Applicable Laws” means to the extent applicable, the laws and regulations of any country relating to the Shared Personal Data, including but not limited to all Data Protection Laws. For the avoidance of doubt, nothing in this Addendum shall be construed as a representation that either Party is subject to any Applicable Law.
1.3 “Business Day” means a day, other than a Saturday, Sunday, or public holiday, on which clearing banks are open for non-automated commercial business in City of Austin, Texas.
1.4 “Data Protection Laws” means any and all privacy, security, and data protection laws and regulations that apply to the Shared Personal Data Processed by Civitas under the MSA, as amended, replaced, or superseded from time to time, which may include, but is not limited to:
1.4.1 The Family Educational Rights and Privacy Act (“FERPA”), including any regulations promulgated thereunder,
1.4.2 The Gramm-Leach-Bliley Act (“GLBA”), including any regulations promulgated thereunder; and
1.4.3 The EU General Data Protection Regulation 2016/679 (“GDPR”), as transposed into domestic legislation of each member state of the EU;
1.4.4 The UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018, including any applicable regulations promulgated thereunder; and
1.4.5 Collectively, all U.S. State omnibus data protection laws, including any applicable regulations promulgated thereunder.
1.5 “Data Subject” means an identified or identifiable natural person.
1.6 “Parties” means the Parties to this Addendum, namely Civitas and Customer.
1.7 “Personal Data” means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to a Data Subject. Personal Data does not include data that has been anonymized, de-identified, or aggregated such that Data Subjects are not individually identifiable.
1.8 “Shared Personal Data” means any Personal Data transferred or made available by Customer to Civitas, including Personal Data collected by Civitas on behalf of Customer from a third-party through that third-party’s use of the Services. For clarity, Shared Personal Data includes, but is not limited to, student education record information subject to FERPA.
1.9 “Personal Data Breach” means a confirmed unauthorized destruction, loss, alteration, disclosure or acquisition of, Shared Personal Data, including any circumstance where Data Protection Laws require either notification to be provided to affected parties or other activity in response to such circumstance, provided that such event materially compromises the security, confidentiality, or integrity of the Shared Personal Data. For clarity, a Personal Data Breach does not include the good faith, unauthorized acquisition of Shared Personal Data by an employee or agent of Civitas for a legitimate business purpose, provided the Shared Personal Data is not subject to further unauthorized use or disclosure.
1.10 “Processing” means any operation or set of operations which is performed on Shared Personal Data or on sets of Shared Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.11 “Processor” means a legal entity that Processes Personal Data solely on behalf of another legal entity and shall be interpreted to include “service provider” or “processor,” as such terms (or analogous variations thereof) are defined under Data Protection Laws.
1.12 “Regulatory Authority” means any public authority, or government agency responsible for exercising authority over the Shared Personal Data, or the Parties’ Processing thereof.
1.13 “Subprocessor” means any Processor appointed by Civitas to Process Shared Personal Data in connection with this Addendum or the MSA.
The word “include” shall be construed to mean include without limitation, and cognate terms shall be construed accordingly.
2. Purposes of this Addendum
2.1 This Addendum sets out the framework for the sharing and Processing of Shared Personal Data by Civitas on behalf of Customer and defines the principles and procedures that the Parties shall adhere to, the rights of the Parties, and the responsibilities the Parties owe to each other.
2.2 The Parties agree that this Addendum formalizes a lawful transfer of Personal Data between the Parties, and that Civitas qualifies under FERPA as a “school official” of Customer whom the Customer has determined has a legitimate educational interest in the Processing of Shared Personal Data.
2.3 The Parties recognize that the sharing of Personal Data is necessary to achieve the purposes of the MSA, and that the Parties shall not process Shared Personal Data in a way that is incompatible with the MSA or this Addendum. Civitas further agrees to abide by the limitations on re-disclosure of education records from the Shared Personal Data set forth in FERPA.
3. Data Processing
3.1 Civitas will Process Customer Data only: (a) in a manner consistent with documented instructions from Customer which will include Processing as authorized or permitted under the MSA, including as specified in this Addendum; and (b) as required by Data Protection Laws, provided that Civitas will inform Customer (unless prohibited by such Data Protection Laws) of the applicable legal requirement before Processing pursuant to such Data Protection Laws.
3.2 In connection with its Processing of any Shared Personal Data, Civitas will comply with all obligations applicable to it as a Processor under Data Protection Laws and provide the same level of privacy protection as is required by Data Protection Laws. Civitas will promptly notify Customer if Civitas determines it can no longer meet its obligations under this Addendum.
4. Permitted Recipients
4.1 Where required by Applicable Law and In the context of Processing Shared Personal Data pursuant to this Addendum, the Shared Personal Data may only be accessed by the Parties to this Addendum, employees and agents of each Party, the Data Subject to which the Shared Personal Data pertains, and any Subprocessor in connection with this Addendum, subject to requirements of this Addendum.
4.2 Civitas shall implement procedures designed to ensure that any third party it authorizes to have access to the Shared Personal Data, including Subprocessors, will respect and maintain the confidentiality and security of the Shared Personal Data. Any person acting under the authority of the Civitas, including a Subprocessor, shall be obligated to process the Shared Personal Data only on instructions from Civitas. This provision does not apply to persons authorized or required by Applicable Laws to have access to the Shared Personal Data.
4.3 Civitas will not “sell” or “share” (each as defined in Data Protection Laws) any Shared Personal Data, except as explicitly authorized by Customer.
5. Shared Personal Data
5.1 The Parties recognize that while the Civitas requires certain types of Personal Data to effectively deliver the Services under the MSA, Customer shall have ultimate control over which types of Personal Data are transferred to or accessed by Civitas. The types of Personal Data shared by Customer to Civitas may include but is not limited to:
5.1.1 Students and Faculty Data: First and last name, contact information (email, phone, physical business address), identification data (ID numbers, usernames, aliases, etc.), and device data (connection data, location data, etc.).
5.1.2 Student Only Data: Physical characteristics data (ethnicity, gender, religion, sex), family data (family member information, socioeconomic status, etc.), and educational data (class schedules, academic records, etc.).
5.1.3 Faculty and Staff Only Data: Professional data (employer, title, etc.).
6. Data Quality
6.1 Customer shall use its best efforts to ensure that Shared Personal Data provided to Civitas is accurate and current. Where Customer becomes aware of inaccuracies in Shared Personal Data, Customer shall promptly notify Civitas in writing of such inaccuracies.
7. Data Subject Rights
7.1 The Parties acknowledge student Data Subjects’ may have rights to inspect and review their academic records under FERPA and shall endeavor to provide access to such educational records within the Shared Personal Data if properly requested by a student Data Subject in compliance with, and where required by, FERPA.
7.2 The Parties agree that the responsibility for responding to a request from a Data Subject regarding Shared Personal Data under any Data Protection Law falls to Customer.
7.3 Taking into account the nature of the Processing and where required by Data Protection Laws, Civitas shall assist Customer by implementing appropriate technical and organizational measures, insofar as this is possible, to enable the fulfillment of Customer’s obligations, as reasonably understood by Customer, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
7.4 Civitas shall:
7.4.1 notify Customer within five (5) Business Days after Civitas receives a request from a Data Subject that specifically identifies Customer and Civitas has validated that such Data Subject relates to Customer, either directly or from a Subprocessor, under any Data Protection Law regarding Shared Personal Data;
7.4.2 not respond to any such Data Subject request that specifically identifies Customer, except as required by Applicable Laws to which the Civitas is subject, in which case Civitas shall to the extent permitted by Applicable Laws inform Customer of that legal requirement before responding to the request.
7.5 Customer shall:
7.5.1 obtain all necessary consents from Data Subjects, in writing, to the extent consent is required by Applicable Laws in order to authorize Civitas (through the Services) to communicate with Data Subjects on behalf of Customer, including but not limited to communications made via telephone, SMS message, email, push notifications, or similar means, with or without the use of automated dialing technology; and
7.5.2 promptly notify Civitas of changes to or revocations of any Data Subject consents.
8. Security
8.1 The Parties agree to implement appropriate administrative, physical, and technical safeguards designed to protect Shared Personal Data from unauthorized access, acquisition, disclosure, destruction, alteration, accidental loss, misuse, or damage that are no less rigorous than applicable industry standards for information security, and shall ensure that all such safeguards, including the manner in which Shared Personal Data is created, collected, accessed, received, used, stored, processed, disposed of, and disclosed, comply with Applicable Laws, as well as the terms and conditions of this Addendum.
8.2 Civitas’s safeguards for the protection of the Shared Personal Data shall include administrative, physical, and technical safeguards designed to: (i) limit access of Shared Personal Data to persons authorized to access such data; (ii) secure business facilities, data centers, paper files, servers, backup systems, and computing equipment, including, but not limited to, all mobile devices and other equipment with information storage capability; (iii) implement network, application, database, and platform security; (iv) secure information transmission, storage, and disposal; (v) implement authentication and access controls within media, applications, operating systems, and equipment; (vi) conduct risk assessments, penetration testing, and vulnerability scans; (vii) implement appropriate personnel security and integrity procedures and practices, including, but not limited to, conducting background checks consistent with applicable law; and (viii) provide appropriate privacy and information security training to employees.
8.3 Audit Rights. Civitas shall make available to Customer, upon reasonable written request and no more than once per twelve (12) month period, information reasonably necessary to demonstrate Civitas’s compliance with its obligations under this Addendum. Such requests shall be submitted with at least thirty (30) Business Days’ prior written notice and shall be conducted during normal business hours in a manner that does not unreasonably disrupt Civitas’s operations. Customer may, at its sole cost and expense, engage a qualified, independent third-party auditor (subject to Civitas’s reasonable approval, not to be unreasonably withheld) to conduct an on-site or remote audit of Civitas’s Processing activities relevant to the Shared Personal Data. The auditor shall be bound by confidentiality obligations no less protective than those set forth in the MSA. Civitas may satisfy its obligations under this Section by providing Customer with a current SOC 2 Type II report, or substantially equivalent third-party audit report covering the systems and processes used to Process Shared Personal Data. Customer shall accept such report and vendor’s completed HECVAT report in lieu of an on-site audit or Customer security questionnaires unless Customer can demonstrate, in good faith, a specific concern not addressed by these documents. All audit findings and reports shall be treated as Civitas Confidential Information.
9. Personal Data Breach
9.1 In the event of a Personal Data Breach, responsibility for reporting the breach to Regulatory Authorities falls to the Party suffering the breach of security leading to the Personal Data Breach, unless Applicable Laws require otherwise.
9.2 Civitas shall notify Customer within 72 hours of identification and verification by Civitas of a Personal Data Breach affecting Shared Personal Data, and at that time shall provide Customer with reasonably available information to allow Customer to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws, to the extent such information is available. Such notification shall (to the extent available):
9.2.1 describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned;
9.2.2 communicate the name and contact details of Civitas’s data protection officer or other relevant contact from whom more information may be obtained;
9.2.3 describe the likely consequences of the Personal Data Breach; and
9.2.4 describe the measures taken or proposed to be taken to address the Personal Data Breach,
provided that, (without prejudice to the above obligations) if Civitas cannot provide all these details within the timeframes set out in this Section, it shall (before the end of such timeframes) provide Customer with the reasons for the delay, and when it expects to be able to provide the relevant details (which may be provided in phases), and give Customer regular updates on these matters.
9.3 Customer shall promptly notify Civitas upon Customer becoming aware of a breach of security, including a Personal Data Breach affecting or resulting in actual or suspected compromise of Civitas’s information technology assets, resources, services, or systems.The Parties agree to provide reasonable assistance as is necessary to each other to facilitate the handling of any Personal Data Breach in an expeditious and compliant manner.
10. Data Protection Cooperation
10.1 The Parties agree to provide one another with reasonable cooperation and assistance as requested by either Party in relation to any compliance measure which the Parties reasonably consider to be required by Data Protection Laws in relation to the Processing of the Shared Personal Data.
10.2 A Party may provide notice to the other Party of any variations to this Addendum which a Party reasonably considers to be necessary to address the requirements of any Data Protection Law.
10.3 If a Party gives notice under the foregoing Section, the Parties shall promptly discuss the proposed variations and negotiate in good faith with a view to agreeing and implementing those or alternative variations designed to address the requirements identified in the proposing Party’s notice as soon as is reasonably practicable.
11. Indemnification
11.1 The limitations on liability, liability caps, and/or exclusions of certain types of damages as set forth in the Agreement shall apply to the subject matter of this DSA and the Parties’ related rights and obligations hereunder.
12. General Terms
12.1 Governing law and jurisdiction. The Parties to this Addendum hereby submit to the choice of jurisdiction stipulated in the MSA with respect to any disputes or claims howsoever arising under this Addendum, including disputes regarding its existence, validity or termination or the consequences of its nullity.This Addendum and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the MSA.
12.2 Order of precedence. The order of precedence governing the relationship between this Addendum, the MSA, and any Order Form is set forth in Section 21 of the MSA.
12.3 Severance. Should any provision of this Addendum be invalid or unenforceable, then the remainder of this Addendum shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.
By entering into an Order Form, Customer agrees that this Addendum is entered into and becomes a binding part of the MSA as of the MSA Effective Date, thereafter terminating upon the cessation of Processing under this Addendum.
Bring your questions. Leave with an estimate you can defend.
A 45-minute working session: we start from your public IPEDS figures, show what the platform found at institutions like yours, and size the outcome — before anyone touches your data.