PGCPS reviews all technologies, services, and hardware to make sure they are safe, accessible, and compatible with our systems. We also check that they follow federal, state, and local rules. To be considered, vendors must meet the criteria listed below. Please review these expectations carefully before submitting your product for review. These requirements are in addition to and in conjunction with vendor approval via iSupplier.
In PGCPS, a digital tool meets at least one of the criteria below:
Digital tools include online platforms, courses, digital content, and mobile apps. Md. Code, Educ. § 7-910.
The above also applies to services that include the use of digital tools as part of their delivery.
Requests to review a product must be initiated internally, by a school administrator or office supervisor. PGCPS will not review a product based on a vendor’s request.
When evaluating a digital tool or platform, PGCPS considers each of the following criteria.
Artificial Intelligence (AI) |
PGCPS has a roadmap for how and when artificial intelligence may be incorporated to support operational, professional and/or instructional activities. All vendors are expected to complete the Artificial Intelligence Declaration Agreement (AIDA) to confirm whether or not their platform or product incorporates AI features, for any user group. If AI is present, additional information is required and will be reviewed by the AI team. When AI is not present, vendors must also agree to inform PGCPS if it is added in the future. Required File: Artificial Intelligence Declaration Agreement (AIDA) |
Data Privacy |
A signed Data Privacy and Security Agreement (DPSA) must be executed when student, staff or operational data is shared with a third party. A key requirement is the vendor's completion of Exhibit A - Institution Data Schedule and Security Practices. The Data Schedule tab details all data fields (required, optional, or not used) that the platform will store, process, access, or use. For every required or optional field, the vendor must provide a detailed explanation of its purpose. In accordance with Maryland Code, Education § 4-131, PGCPS will not approve any vendor that engages in targeted advertising if the advertising is based on information that the vendor has acquired because of the use of the vendor's site, service, or application. Instructions for PGCPS Data Privacy and Sharing Agreement (DPSA) Required File: Data Privacy and Security Agreement (DPSA) Required File: Exhibit A - Part 1 - Institution Data Schedule and Security Practices |
Information Security |
Third Party Security Verification All vendors must indicate which third party security verifications apply to their product in on the Vendor Security Practices tab of Exhibit A. A recent SOC 2 Type 2 Audit Report and/or ISO 27001 Certificate with Scope of Applicability (SoA) will be required when the Data Schedule indicates that a platform will store, process, access, or use sensitive data fields. An NDA can be signed, if needed. If an independent review is not available, vendors must provide complete the remainder of the Vendor Security Practices tab to provide detailed responses to describe their organization's security practices regarding:
Required File: Exhibit A - Part 2 - Vendor Security Practices (same file as above) Exhibit A - Data Schedule and Vendor Security Practices is made available as a spreadsheet for easier editing. The finalized version will be incorporated into DPSA prior to final signatures. |
Interoperability |
Prince George's County Public Schools (PGCPS) prioritizes seamless and secure access to digital resources and therefore requires Vendors to implement automated roster management and Single Sign-On (“SSO”) for all Students, Teachers and Administrators using one of the following approved options, unless a waiver is granted by the Chief Technology Officer in writing. Agreed upon methods will be documented in the Interoperability Agreement (IA). Authentication/Single Sign-On (SSO)Acceptable Methods
Unacceptable Methods
Rostering/Automated File TransferAcceptable Methods
Unacceptable Methods
Required File: Interoperability Agreement (IA). |
Accessibility |
Annually, vendors must submit the following to PGCPS at ACR.VPAT@PGCPS.ORG. Filename conventions must be followed.
|
PGCPS will email vendors to request their participation in this process, based on internal requests for review. While vendors must not submit unsolicited documentation, all relevant documents are available below for easier planning.
If I have a question about one of the contract addenda, who should I contact?
Please send an email to pgcps.digitaltoolrev@pgcps.org and include “[YEAR - Vendor Name - Product Name] - Contract Addenda Question” in the subject line.