Solutions
Product
Pricing
Resources
Start free trial

School Communication RFP Questions: 12 Requirements to Score

School Communication RFP Questions: 12 Requirements to Score

If you’re drafting school communication RFP questions, the short answer is: stop scoring features and start scoring contract clauses. A feature checklist — does it send messages, does it have an app, does it have a calendar — produces near-identical vendor demos, because almost every school communication platform on the market can check those boxes. What actually separates vendors, based on the procurement frameworks now circulating for the 2026 buying cycle, is whether they can produce verifiable evidence on data residency, breach notification, export rights, and exit terms. Below are 12 clauses built for exactly that, each with a concrete ask and a pass/fail signal you can drop straight into a scoring matrix — or a French cahier des charges.

School communication RFP questions: the 12 clauses to score

Score each clause 0 (no or vague answer), 1 (partial, roadmapped), or 2 (documented and verifiable — a certificate, a contract clause, or a named DPA). Anything below 2 on clauses 1–6 is worth pausing on regardless of how polished the messaging demo was.

#ClauseWhat to ask the vendorFail signal
1Data residencyWhere exactly is our data hosted, and can you guarantee EU/France hosting?”US-based, GDPR-compliant” with no location named
2Standard DPAWill you sign the NDPA (or your state/national equivalent) without modification?Vendor insists on its own non-standard DPA template
3SOC 2 Type II + ISO 27001Can you provide the current audit report, not an “in progress” status?Certification listed as “in progress” or unspecified type
4Breach notificationWhat is your contractual notification window?No specific number, or anything slower than 72 hours
5Data export formatWhat exact format do you export — content, metadata, audit logs, workflows?”We can send a CSV” with no metadata or audit trail
6No exit feesAre there egress, extraction, or professional-services fees to leave?Any named fee to retrieve your own data
7Per-family language coverageWhich languages does the platform support per family, not per school?Only the school’s primary language, or machine-translation-only
8SMS fallbackWhat happens for families without a smartphone or the app installed?”They can use the web portal” as the only fallback
9SIS/SSO interoperabilityDoes it integrate with our SIS via API/SSO, not manual CSV upload?Integration is “on the roadmap,” not shipped
10Onboarding-fee capIs there a contractual ceiling on setup and onboarding fees?Open-ended “implementation services” line item
11Price-lockIs the per-family or per-seat rate locked for the full contract term?”Subject to annual review” with no stated cap
12Exit/continuity termsWhat happens to our data and workflows if you’re acquired or the product is sunset?No contractual continuity clause at all

None of the 12 clauses above are things a live demo shows you. A vendor can walk through messaging, calendars, and attendance and still leave every one of these questions unanswered — which is exactly why they belong in the written RFP, not the sales call. The gap between a polished demo and a documented answer shows up fast on clause 3: ParentSquare documents current SOC 2 Type II and ISO 27001 certification, while publicly available pages describe ClassDojo’s SOC 2 as still “in progress” as of August 2026 — not yet Type II. Clause 11 works the same way before a demo is even booked: whether a vendor publishes its pricing or requires a sales call for a quote is itself one of these twelve signals, not just a convenience.

What actually separates the best school communication software

The best school communication software candidates aren’t distinguished by messaging features anymore — nearly every vendor in the category can send an announcement or push a calendar invite. What differs is procurement-grade evidence. Career Clutch’s 2026 procurement checklist reports that 78% of district CTOs now require SOC 2 Type II certification before signing, rising to 94% among large districts, and that the average district manages 2,700+ digital tools a year with a sales cycle running 6 to 18 months from first contact to signed contract.

On the French side, MyScol’s 2026 market analysis frames the same shift around three dimensions: native AI integration, contractually verifiable RGPD compliance rather than a generic compliance claim, and documented interoperability. Its warning is blunt: “Un logiciel qui ne communique pas avec les autres outils de l’établissement crée des silos de données” — software that doesn’t talk to the school’s other tools creates data silos. That’s a functional argument for clause 9 above, not just a security one.

Where vendors most often fail: four clauses in practice

Clauses on a page are easy to nod along to. Here’s what four of the harder ones actually look like when a platform gets them right.

SMS fallback

A platform that can’t reach families by SMS defaults to “email everyone and hope,” which quietly excludes exactly the families ParentSquare’s own RFP framework calls out when it argues for reaching every family “without app or login” barriers. A passing answer names the trigger and the channel, not just the feature — for example, an SMS that auto-sends when a message is flagged urgent and no in-app read receipt registers within a set window, rather than “they can also use the web portal.”

Per-family language coverage

In a francophone or Gulf-region school with a mixed parent population, a platform that only offers school-wide language switching — not per-recipient — forces staff to send duplicate messages or leave one language group behind entirely. A passing implementation stores a language preference on each guardian’s contact record, so one announcement sent once reaches an Arabic-speaking parent in Arabic and a French-speaking parent in French automatically, instead of staff drafting two versions or the school defaulting to a single language for everyone.

Exit and continuity terms

Without a written export clause covering message history, attendance records, and configuration data, a school has no contractual leverage if a vendor is acquired or a product line is sunset — a scenario the industry has already lived through: Remind’s K-12 messaging business was absorbed into ParentSquare after a 2023 acquisition, and Remind Hub is reported not to be renewing past the 2026-27 school year for districts still on it.

Standard DPA

For the DPA clause specifically, the reference point is the National Data Privacy Agreement — a standard template built by 28 U.S. state alliances, over 222,000 copies of which have already been executed, that exists precisely so schools don’t have to negotiate privacy terms vendor by vendor. France and the EU don’t use the NDPA itself, but the same logic applies wherever your school is: ask for a standard, pre-negotiated DPA template rather than accepting the vendor’s bespoke wording unread.

Cahier des charges logiciel communication parents: the France-specific clauses

A French cahier des charges logiciel communication parents needs everything above, plus two additions tied to the regulatory environment (bringing the region-specific total to 14). First, residency: the CNIL’s 2026 work programme confirms continued regulatory attention to AI oversight and the education sector specifically, and sector observers note that hosting within the EU is now treated as a baseline expectation, with hosting in France itself preferred where maximum data-sovereignty guarantees matter — CNIL enforcement activity aimed at education has reportedly intensified over 2024-2026, given the sensitivity of what schools hold: minors’ identity, health, custody, and financial data. Second, portability: the EU Data Act’s export and no-exit-fee provisions took effect September 12, 2025, directly supporting clauses 5 and 6 above for any vendor operating in the EU. Historically, the same analysis notes, “egress charges, inflated ‘extraction’ projects, and bundled professional services” were exactly what deterred customers from switching providers even when they wanted to — the kind of lock-in these provisions are designed to close for any EU-based vendor, schools included.

Who actually passes today: named vendor evidence

Worth flagging clearly: the comparison below comes from vendor-published pages, not an independent audit, so treat it as a starting point to verify directly in RFP responses, not a certified verdict — a current certification is one differentiator among several, not a full picture of a vendor’s practices on its own, so always ask for the certificate itself, with its scope and date, rather than accepting a marketing claim.

ParentSquare

ParentSquare documents holding both SOC 2 Type 2 — “for security, availability, and confidentiality” — and ISO 27001 certification, with AES-256 encryption and infrastructure meeting SOC 2, ISO 27001, PCI DSS Level 1, and NIST 800-53 standards. That’s a concrete pass example for clause 3.

ClassDojo

Publicly available pages describe ClassDojo’s SOC 2 certification as still in progress as of August 2026 — not yet Type II — while the platform separately states FERPA and COPPA compliance.

How to score the responses

Once responses are in, the scoring matrix from clause 1 does the real work: total the 0/1/2 scores across all 12 rows, but treat clauses 1–6 (residency, DPA, certification, breach window, export format, exit fees) as a gate rather than an average — a vendor that scores 2s on messaging features and 0s on data-handling clauses shouldn’t advance on total score alone. TeachTools’ DPA checklist puts it plainly: if a vendor refuses to sign a DPA or negotiate reasonable privacy terms, that refusal is itself the answer. The same checklist notes schools now use over 2,500 different EdTech products a year and expects a contractual breach-notification window of 72 hours — both useful benchmarks to write directly into your scoring sheet.

Once scored this way, what’s left isn’t a feature preference — it’s an operational requirement: a platform that can prove data residency, sign a standard DPA, produce a current SOC 2/ISO 27001 report, export everything without a fee, reach every family regardless of language or device, and commit contractually to what happens if it’s ever acquired or sunset.

Purpose-built platforms exist to answer exactly that list. Most vendors in the category can address some of these clauses; fewer can document all twelve on request. BeeNet is one such option — its security and compliance practices, SMS fallback, and multilingual messaging were built around this same clause list rather than added after the fact, and its pricing is published rather than quoted per district. If you’re drafting an RFP for your school, a live walkthrough is a fast way to see how a vendor actually answers these questions, not just how it writes about them.

The EU Data Act’s remaining deadlines are already on the calendar: switching fees become fully prohibited on January 12, 2027, and unfair contract terms apply retroactively from September 12, 2027. The question for most schools isn’t whether these twelve clauses will matter — it’s whether they’re in your next contract before those deadlines arrive, or after.

References

  1. ParentSquare. “Creating an RFP for School-Home Communications: 7 Questions to Ask in 2026.” 2026. https://www.parentsquare.com/blog/creating-an-rfp-for-school-communications-solution/
  2. MyScol (Tiqtec). “Logiciel De Gestion Scolaire 2026-2027 : IA, RGPD Et Interopérabilité.” July 6, 2026. https://myscol.com/logiciel-de-gestion-scolaire-2026-2027/
  3. Career Clutch. “Procurement Checklist for District EdTech Contracts: 2026.” 2026. https://careerclutch.ai/blog/procurement-checklist-for-district-edtech-contracts.html
  4. Student Data Privacy Consortium (SDPC), Access 4 Learning (A4L). “National Data Privacy Agreement (NDPA).” v2.2, November 19, 2025. https://privacy.a4l.org/national-dpa/
  5. CNIL (Commission Nationale de l’Informatique et des Libertés). “Accompagnement des professionnels : le programme de travail de la CNIL pour 2026.” April 7, 2026. https://www.cnil.fr/fr/accompagnement-des-professionnels-le-programme-de-travail-de-la-cnil-pour-2026
  6. Sutker, Yael (Shield). “The EU Data Act: From Exit Fees to Export Rights, and What to Do Next.” January 8, 2026. https://www.shieldfc.com/resources/blog/eu-data-act-what-to-do-next/
  7. TeachTools. “2026 Vendor Data Processing Agreement Checklist for Schools.” March 23, 2026. https://teachtools.co/blog/vendor-data-processing-agreement-checklist-for-schools
  8. ParentSquare, Inc. “School Data Security and Compliance | SOC 2, ISO 27001.” 2026. https://www.parentsquare.com/platform/security-and-compliance/

Continue reading

Ready to Transform Your School Communication?

Start saving time and increasing parent engagement with BeeNet.

Request Demo