Newsela Data Processing Addendum

Last Updated: September 1, 2026

Please note: This DPA was updated September 1, 2026. If you are an existing Newsela Customer, please contact your Newsela representative for the prior version.

This Data Processing Addendum ("DPA") forms part of the Master Services Agreement (“MSA”), Terms of Use, and Order Form (collectively “Agreement”) between Newsela, Inc., its wholly owned subsidiaries including Formative, Generation Genius, Schoolytics, and EveryDay Labs (“Newsela”) and the Customer. The term of this DPA shall follow the term of the Agreement. Capitalized terms not defined herein shall have the meaning as set forth in the Agreement.

In the course of providing the Services to Customer pursuant to the Agreement, Newsela may process Personal Data on behalf of Customer. The Parties agree to comply with the following provisions with respect to any Personal Data and/or Customer Data submitted by or on behalf of Customer to Newsela in connection with the Services.

1. DEFINITIONS

1.1. Unless otherwise defined herein, capitalized terms and expressions used in this DPA shall have the following meaning:

1.1.1. "Applicable Data Protection Laws" means the data protection laws of applicable U.S., and global data protection laws including but not limited to EU Data Protection Laws, UK GDPR, the Family Educational Rights and Privacy Act (“FERPA”) Children's Online Privacy Protection Act (“COPPA”), California Consumer Privacy Act and its subsequent amendments (“CCPA”), applicable state student data privacy laws (including but not limited to the Student Online Personal Information Protection Act and state equivalents), Canadian provincial Freedom of Information and Protection of Privacy laws, the British Columbia Personal Information Protection Act, the Alberta Personal Information Protection Act, and the Quebec Act (“Canadian Privacy Laws”);

1.1.2. "Customer Data" means any Personal Data, student data, and/or business data processed by Newsela on Customer's behalf pursuant to or in connection with the Agreement and the DPA, and as defined by Applicable Data Protection Laws. Customer Data includes, without limitation, data received by Newsela through direct uploads, automated integrations with Customer's student information systems, learning management systems, assessment platforms, or other third-party educational technology systems ("Integrated Platforms");

1.1.3. Customer SCCs” means (i) where the EU GDPR applies, the contractual clauses annexes the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council; and (ii) where the UK GDPR applies, standard data protection clauses adopted pursuant to or permitted under Article 46 of the UK GDPR located at https://newsela.com/legal/scc. Please note, Customer SCCs are primarily entered into with Customers based outside the U.S., and in the EU or UK. 

1.1.4. "Derivative Data" means data that is collected, compiled, aggregated, or generated by Newsela through the operation of the Services and the processing of Customer Data, from which all personally identifiable information has been permanently removed such that the data cannot reasonably be used to identify an individual student, parent, guardian, or end user. Derivative Data may include aggregated usage statistics, performance trends, benchmark metrics, and other de-identified analytical outputs. For the avoidance of doubt, Derivative Data does not include Customer Data, Sensitive Student Data, or any data that remains capable of identifying or being linked to a specific data subject.

1.1.5. "EU Data Protection Laws" means EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time; the European Union General Data Protection Regulation 2016/679 (“EU GDPR”) and laws implementing or supplementing the EU GDPR;

1.1.6. Personal Data” shall have the same meaning as defined and recognized under Applicable Data Protection Laws;

1.1.7. Sensitive Student Data” means any Customer Data that includes health information, special education status, socioeconomic or homeless status indicators, behavioral or discipline records, or other data classified as sensitive under Applicable Data Protection Laws. Newsela shall apply protections to Sensitive Student Data that are no less stringent than the protections afforded to Customer Data generally under this DPA.

1.1.8. Service Provider” shall have the same meaning as defined in Section 1798.140(v) of the California Consumer Privacy Act of 2018 (“CCPA”). For the purposes of this DPA, Newsela agrees it is a Service Provider as that term is defined under the CCPA.

1.1.9. "Subprocessor" means any person appointed by or on behalf of Newsela to process Personal Data on behalf of Customer in connection with the DPA;

1.1.10. Third Country” means a country outside the European Economic Area not recognized by the European Commission as providing an adequate level of protection for personal data (as described in the EU GDPR); and

1.1.11. UK GDPR” means as defined in Section 3 of the Data Protection Act 2018.

1.2. If you are a Customer for whom the EU GDPR and/or the UK GDPR qualify as Applicable Data Protection Laws, please note that the terms "Commission," "Controller," "Data Subject," “Processor,” "Member State," and "Supervisory Authority" shall have the same meaning as in the EU GDPR or UK GDPR, and their cognate terms shall be construed accordingly.

2. RESPONSIBILITIES OF THE PARTIES

2.1. Roles of the Parties. 

For purposes of this DPA, the Parties acknowledge and agree, when applicable, with the following:

2.1.1. To the extent that this DPA is entered into by a Customer based in the EU or UK, or a Customer for whom the EU GDPR or the UK GDPR qualify as Applicable Data Protection Laws, you, the Customer, are the Data Controller and Newsela is a Data Processor as defined by EU Data Protection Laws or UK GDPR. 

2.1.2. To the extent that this DPA is entered into by a Customer based in the US, Newsela is a “school official” under FERPA and has a legitimate educational interest in personally identifiable information from education records received from the Customer pursuant to the DPA. For purposes of the Agreement and this DPA, Newsela: (a) provides a service or function for which Customer would otherwise use employees; (b) is under the direct control of the Customer with respect to the use and maintenance of education records; and (3) is subject to the requirements of FERPA governing the use and redisclosure of personally identifiable information from the education records received from Customer; and

2.1.3. Newsela is a “Service Provider,” “Third Party” or “Operator” as used in Applicable Data Protection Laws.

2.2. Permitted Uses. 

Newsela provides digital educational software or services, including cloud-based services, for the digital storage, management, retrieval, and use of Customer Data. Depending on the Products used by Customer, Newsela's services (such as Schoolytics and EveryDay Labs) may also include: (a) collecting and aggregating Customer Data from Integrated Platforms as configured and authorized by Customer; (b) creating student-level profiles, dashboards, reports, and alerts to help Customer identify trends, patterns, and indicators related to attendance, academic performance, behavior, and student well-being; (c) generating and transmitting automated communications (including letters, emails, and text messages) to parents and guardians on Customer's behalf regarding attendance or academic matters; and (d) providing predictive analytics, risk indicators, and benchmark reporting for educational purposes. Newsela will only process Customer Data in accordance with Customer’s instructions per the Agreement. Customer permits Newsela to process Customer Data to provide Newsela’s products, services and related technical support as stated in the Agreement and Newsela’s Privacy Policy. Customer is responsible for ensuring it has the authority to share Customer Data from Integrated Platforms with Newsela and for obtaining any required consents from parents, guardians, or other data subjects in connection with the foregoing processing activities.

2.3. Intra-Group Data Sharing. Customer acknowledges and agrees that Customer Data may be shared amongst Newsela and its wholly owned subsidiaries identified in this DPA (currently Formative, Generation Genius, Schoolytics, and EveryDay Labs) to the extent necessary to provide the Products and Services under the Agreement. Each such group entity receiving Customer Data shall process such data solely in accordance with this DPA, the Agreement, and Applicable Data Protection Laws, and shall be bound by obligations of confidentiality, security, and use limitations no less protective than those set forth herein. Newsela shall remain fully responsible and liable to Customer for the acts and omissions of its subsidiaries with respect to Customer Data. 

2.4. Compliance with Laws. 

The Parties agree to comply with all Applicable Data Protection Laws, rules and regulations in the performance of this DPA. Nothing in this DPA may be construed to allow either party to maintain, use, disclose, or share Customer Data in a manner not allowed under the Applicable Data Protection Laws.

2.5. Details of Data Processing.

2.5.1. Subject matter. The subject matter of the data processing under this DPA is Customer Data.

2.5.2. Duration. As stated in the Agreement. 

2.5.3. Purpose. The purpose is to provide Customers with Products agreed to under the Agreement.

2.5.4. Nature of the processing. Providing Product(s) described in the Agreement and this DPA.

2.5.5. Type of Customer Data. Customer Data uploaded to, received by, or processed through the Services under Customer's Newsela accounts, including through Integrated Platforms. 

For Customers using Schoolytics and EveryDay Labs and as authorized and directed by Customer, Customer Data may include: (a) student identification numbers and contact information (including mailing addresses, email addresses, and phone numbers); (b) demographic data (e.g., age, ethnicity, gender, home language); (c) attendance and absenteeism records (including daily and period-level attendance codes, chronic absenteeism classifications, and truancy status); (d) academic performance and transcript data (e.g., grades, assessment scores, assignment completion rates); (e) behavioral and discipline records (including incident reports and intervention tracking); (f) special education status; (g) socioeconomic and homeless status indicators; (h) health information; (i) social-emotional learning survey responses; (j) digital learning platform engagement data; and (k) barrier-to-attendance assessments and intervention records. The specific categories of Customer Data processed will depend on the Products and integrations configured by Customer.

2.5.6. Categories of data subjects. The data subjects include Customer's Authorized Users, end users, students (including students who may not directly access the Services), parents or guardians of students, and school personnel whose data is submitted to or processed through the Services.

2.5.7. Scope of Covered Products. This DPA governs Newsela's processing of Customer Data through our Digital Products and Print Products, through the data-collecting features of any Digital Product, including core curriculum and instructional materials made available in digital form. Printed instructional materials that do not transmit, collect, or otherwise cause Newsela to process Customer Data are not subject to this DPA.

2.6. Ownership. All Customer Data transmitted to Newsela pursuant to the Agreement and DPA is and will continue to be the property of and under the control of Customer. Customer acknowledges and agrees that it has the legal authority and consent to disclose, share, and transfer all Customer Data and User Data to Newsela for the purposes agreed to under the Agreement and this DPA. Newsela further acknowledges and agrees that all copies of Customer Data transmitted to the Customer, including any modifications or additions or any portion thereof from any source, are subject to the provisions of this DPA in the same manner as the original Customer Data. The Parties agree that as between them, all rights, including all intellectual property rights in and to Customer Data contemplated per the Agreement and DPA, shall remain the exclusive property of the Customer. Customer grants to Newsela a non-exclusive, royalty-free, worldwide license to use, transmit, distribute, modify, reproduce, display and store Customer Data transferred under the Agreement or this DPA solely for the purposes permitted by Customer. Notwithstanding the foregoing, Newsela retains all right, title, and interest in and to Derivative Data, provided that Derivative Data shall consist solely of de-identified and aggregated data from which all personally identifiable information has been permanently removed. Nothing in this section shall be construed to transfer to Customer any intellectual property rights in Newsela's pre-existing technology, platform, or services.

2.7. No Re-Identification. If Newsela receives de-identified Customer Data, or de-identifies Customer Data from which identifying information has been removed, aggregated, and/or anonymized (“De-identified Data”), Newsela agrees to make no attempt to re-identify De-identified Data. De-Identified Data may be used by Newsela for purposes permitted under Applicable Data Protection Laws. Specifically, Newsela may use De-identified Data for the following purposes: (a) assisting Customer or other governmental agencies in conducting research and other studies; (b) developing and updating Newsela’s services and products, including educational sites, applications, and experimental features; (c) adaptive learning and customized student learning; (d) attendance intervention modeling, student outcome prediction, and risk indicator development using De-identified Data; (e) generating benchmark reports and aggregate analyses for educational research and program evaluation; and (f) improving automated communication algorithms and behavioral nudge methodologies, provided such improvements rely solely on De-identified Data. Newsela's use of De-Identified Data shall survive termination of this DPA or any request by Customer to return or destroy Customer Data. Except for Subprocessors, Newsela agrees not to transfer De-identified Data to any party unless (a) that party agrees in writing not to re-identify or attempt to re-identify the data, and (b) prior written notice has been given to the Customer who has provided prior written consent for such transfer.

2.8. Analytics. In addition to the permitted uses described in Section 2.2, Newsela is permitted to use Customer Data for the purpose of: (a) generating analyses, metrics and reports based on Customer Data in whole or in part (“Analytics”); (b) providing Analytics and reports based on such Analytics to Customer and others as permitted by this DPA and Applicable Data Protection Laws; (c) maintaining, supporting, evaluating, improving, and developing educational sites, services or applications, (d) for Schoolytics customers, creating student-level profiles, risk indicators, and trend analyses to assist Customer in identifying attendance patterns, academic performance trends, behavioral indicators, and student well-being metrics, solely for educational purposes as directed by Customer; and (e) for EveryDay Labs customers, generating and transmitting communications to parents and guardians on Customer's behalf, including attendance notifications, intervention letters, and related outreach, using Customer Data as directed by Customer. 

2.9.  AI Data Processing. To the extent Customer or its Authorized Users interact with AI-powered features within the Services, including Newsela's AI assistant ("Luna") (collectively, "AI Tools"), any Customer Data submitted to such AI Tools ("AI Inputs") shall be treated as Customer Data for all purposes under this DPA. Newsela shall process AI Inputs solely to generate content in response to AI Inputs ("AI Outputs") and deliver our Services, and shall not use AI Inputs or AI Outputs to train any machine-learning model or AI system, whether owned by Newsela or a third party. We shall not retain AI Inputs or AI Outputs longer than necessary to deliver the Services, and shall ensure that all third-party providers of large language models are listed as Subprocessors under Section 3 and bound by data processing obligations no less protective than this DPA. Newsela's processing of Customer Data through AI Tools shall comply with all Applicable Data Protection Laws, including FERPA, COPPA, and applicable state student data privacy laws.

3. SUBPROCESSORS

Newsela shall enter into written agreements with all Subprocessors performing functions for Newsela in order for Newsela to provide the Products pursuant to the Agreement, whereby the Subprocessors agree to protect Customer Data in a manner no less stringent than the terms of this DPA. A list of Newsela’s subprocessors are available here at any time: https://newsela.com/legal/subprocessors.

4. DATA SECURITY

Taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons; Newsela shall, in relation to the Customer Data, implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as required under Applicable Data Protection Laws.

Newsela shall ensure that its personnel engaged in processing Customer Data (i) have received appropriate training regarding their responsibilities with respect to the access, use and treatment of Customer Data; and (ii) have committed themselves to confidentiality through executed written confidentiality agreements.

5. DATA SUBJECT RIGHTS

5.1 Data Subject Requests. Newsela shall not respond to requests received from an end user (“Data Subject Request”) without Customer’s prior written consent. Newsela shall comply with any reasonable request by Customer, or any request mandated by Applicable Data Protection Laws and regulations applicable to Customer and made by Customer. This includes the Customer’s right to access, amend, opt-out of processing, block or delete Customer Data.

5.2 Data Subject Request Assistance. Newsela shall give prompt and reasonable attention, co-operation and assistance to Customer in order to assist Customer in complying with any Data Subject Request and comply with reasonable instructions and timetables of Customer in relation to the provision of details of Customer Data to the relevant individual.

5.3 Complaints or Requests. Newsela shall notify Customer promptly upon receipt of any complaint or request relating to: (a) Customer obligations under Applicable Data Protection Laws; (b) Personal Data; or (c) any breach of this DPA, and shall provide reasonable and prompt cooperation and assistance in relation to such complaint, request or breach reasonably requested by Customer.

6. SECURITY BREACH

6.1 Security Incident. In the event of an unauthorized release, disclosure or acquisition of Customer Data that compromises the security, confidentiality or integrity of the Data maintained by Newsela (“Security Incident”), Newsela shall provide notification to the Customer within seventy-two (72) hours of confirmation of the incident, unless notification within this time limit would disrupt investigation of the incident by law enforcement. In such an event, notification shall be made within a reasonable time after the Security Incident.

6.2 Data Breach Notification. The security breach notification described above shall include, at a minimum, the following information to the extent known by Newsela and as it becomes available:

  • The name and contact information of the individual reporting a breach subject to this section;
  • The specific Digital Product(s) affected (e.g., Newsela, Formative, Generation Genius, Schoolytics, or EveryDay Labs);
  • A list of the categories of personal information that were or are reasonably believed to have been the subject of the Security Incident;
  • If the information is possible to determine at the time the notice is provided, then either (1) the date of the Security Incident, (2) the estimated date of the Security Incident, or (3) the date range within which the Security Incident occurred. The notification shall also include the date of the notice;
  • Whether the notification was delayed as a result of a law enforcement investigation, if that information is possible to determine at the time the notice is provided; and
  • A general description of the Security Incident, if that information is possible to determine at the time the notice is provided.

6.3 Security Laws. Newsela agrees to adhere to all requirements under the Applicable Data Privacy Laws with respect to a Security Incident related to Customer Data, including, when appropriate or required, the required responsibilities and procedures for notification and mitigation of any such Security Incident. In the event of a Security Incident originating from the Customer’s use of the Products, Newsela shall cooperate with the Customer to the extent necessary to expeditiously secure Customer Data.

7. DISPOSITION OF DATA

Upon termination of this DPA for whatever reason, or upon written request from Customer at any time, Newsela shall cease to use or process any Customer Data received from or on behalf of Customer under this DPA, and return to Customer, or destroy (at Customer's direction), any Customer Data in Newsela's possession or control in accordance with Newsela’s data retention policy (unless Applicable Data Protection Laws require the continued storage of such Customer Data).

8. INTERNATIONAL DATA TRANSFER

Customers subject to the EU GDPR and UK GDPR, please note that the Customer is the Controller and Newsela is the Processor. The Customer SCCs (Controller-to-Processor Clauses available at https://newsela.com/legal/scc) will apply and govern the relationship between the Parties directly and as it relates to onward transfer, to any Third Country.

As stated above, To the extent that this DPA is entered into by a Customer based in the EU or UK, or a Customer for whom the EU GDPR and/or the UK GDPR qualify as Applicable Data Protection Laws, the Customer, is the Data Controller and Newsela is a Data Processor as defined by EU Data Protection Laws or UK GDPR. 

9. AUDIT RIGHTS

No more than once a year, or following a Security Incident, upon receipt of a written request from the Customer with at least ten (10) business days’ notice and upon the execution of an appropriate confidentiality agreement, Newsela will allow the Customer to audit the security and privacy measures that are in place to ensure protection of Customer Personal Data or any portion thereof as it pertains to the delivery of Products to the Customer.

10. LIABILITY

The Parties agree that all indemnification obligations and liabilities between them under this DPA are as stated in the MSA between the Parties (including as to limitation of liability).

11. GENERAL TERMS

11.1 Confidentiality. Each Party must keep confidential any Confidential Information it receives about the other Party and its business in connection with this DPA and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that: (a) disclosure is required by Applicable Data Protection Laws, or; (b) the relevant information is already in the public domain. Each Party agrees to comply with all confidentiality obligations under Section 6 of the MSA.

11.2 Notices. All notices and communications given under this DPA must be in writing and will be sent in accordance with Section 11 of the MSA.

11.3 Governing Law. Unless agreed to otherwise, this DPA and all claims relating to this DPA shall be interpreted, construed and enforced in accordance with the laws of the State of New York without giving effect to its conflicts of laws rules.