FERPA: Education Data Privacy Compliance Guide
The Family Educational Rights and Privacy Act (FERPA) is the foundational US federal law governing the privacy of student education records. Applicable to all educational institutions receiving federal funding — from kindergartens to universities — FERPA grants parents and eligible students rights over education records and restricts how institutions can disclose student information. For EdTech companies, understanding FERPA is not optional: it shapes every data handling agreement with institutional customers and can determine whether a product is deployable in schools at all.
What FERPA Is and Who Issues It
FERPA was enacted in 1974 — commonly called the Buckley Amendment after its Senate sponsor — as a condition on federal education funding. The Department of Education's Student Privacy Policy Office (SPPO) administers FERPA, issues guidance, investigates complaints, and can recommend the withholding of federal funding for non-compliant institutions.
FERPA has been updated through regulation and guidance over the years, most significantly in the 2011 regulations that expanded provisions around outsourcing (the "school official" exception used by EdTech vendors) and clarified requirements around directory information. The Department of Education's SPPO has actively issued guidance on cloud computing, mobile app privacy, and the intersection of FERPA with COPPA and state student privacy laws.
The enforcement model is complaint-driven. Parents or eligible students (students 18 or older or in postsecondary education) can file complaints with SPPO, which investigates and can require corrective action. FERPA does not provide a private right of action — individuals cannot sue schools directly for FERPA violations (as confirmed by the Supreme Court). The ultimate enforcement lever is withholding federal funding, which would be catastrophic for most institutions and is rarely invoked. In practice, institutional concern about reputational damage and procurement requirements drive FERPA compliance behavior more than formal enforcement.
Who Needs FERPA Compliance
Educational institutions are the primary subject of FERPA obligations. This includes virtually all public schools and most private schools and universities that receive any US Department of Education funding — a category that encompasses nearly every K-12 school and higher education institution in the country.
EdTech vendors do not have direct FERPA obligations as a matter of statutory law — FERPA regulates educational institutions, not their vendors. However, EdTech companies cannot ignore FERPA for two practical reasons. First, their institutional customers are required by FERPA to ensure that vendors they designate as "school officials" comply with FERPA's requirements for handling education records. Second, state student privacy laws (which have proliferated since 2013) directly impose obligations on EdTech companies independent of FERPA.
This means EdTech vendors — learning management systems, student information systems, assessment platforms, classroom collaboration tools, tutoring apps, and any other service used in educational contexts that involves student data — must understand and be prepared to comply with FERPA requirements as a condition of serving their institutional customers.
Key Requirements: Education Records, Rights, and Exceptions
Education Records
FERPA protects "education records" — records, files, documents, and other materials that contain information directly related to a student and are maintained by an educational institution or by a party acting on behalf of the institution. This is broad: grades, transcripts, course schedules, disciplinary records, financial aid records, health records maintained by the school nurse, special education plans, and counseling records are all education records.
Importantly, records created by a teacher solely in their own possession and not shared with others ("sole possession records") are not education records under FERPA. Law enforcement records maintained separately from education records by a campus police unit are also excluded.
Parental and Student Rights
FERPA establishes three core rights for parents (transferred to the student upon reaching 18 or attending postsecondary education):
Right to inspect and review education records within 45 days of a request. Institutions cannot charge a fee for inspection, though they may charge for copies.
Right to request amendment of education records believed to be inaccurate or misleading. If the institution declines to amend, the parent or eligible student has a right to a hearing, and if still unsatisfied, the right to insert a statement of disagreement into the record.
Right to consent to disclosures of personally identifiable information (PII) from education records, except as authorized by specific FERPA exceptions.
Disclosure Exceptions
FERPA permits disclosure without consent in numerous specific circumstances. The most practically important exceptions include:
School officials with legitimate educational interest. Institutions may share education records with employees and contractors (including EdTech vendors) who have a legitimate need to review the records in order to fulfill their professional responsibilities. This is the exception that enables EdTech contracts — by designating a vendor as a "school official" in policy and in the service contract, the institution can permit the vendor to access education records without individual student consent.
Other schools where a student seeks enrollment. Records may be transferred to schools where the student is applying to transfer, without consent.
Financial aid. Records may be disclosed to the extent necessary for financial aid determinations.
Authorized representatives of state and federal government. Records may be disclosed for audit and evaluation purposes.
Health and safety emergency. Records may be disclosed to protect the health or safety of the student or others in genuine emergencies.
Directory information. Institutions may designate certain information as "directory information" — name, address, phone number, email, major, participation in activities, dates of attendance, degrees received — and disclose it without consent unless students have opted out. Institutions must annually notify students of what information is designated as directory and how to opt out.
Security Safeguards
FERPA does not prescribe specific technical security standards, but institutions and their vendors are expected to implement reasonable safeguards proportionate to the sensitivity of education records. Department of Education guidance references NIST standards and encourages institutions to assess security risks to education records. In practice, EdTech vendors serving K-12 and higher education are expected to demonstrate security maturity through certifications like SOC 2 or security questionnaire responses aligned with ISO 27001 controls.
Implementation Approach
For Educational Institutions
Develop and publish annual FERPA notification procedures — every institution must notify students or parents annually of FERPA rights. Establish consent procedures for non-excepted disclosures. Define what information is designated as directory information and publish opt-out procedures. Train staff, particularly registrars, academic advisors, and anyone handling education records, on permissible disclosures. Review all vendor contracts to ensure they include appropriate FERPA language designating vendors as school officials and restricting data use.
For EdTech Vendors
Negotiate FERPA-compliant data handling agreements with institutional customers. Standard provisions include: designation as a "school official" with legitimate educational interest; restriction of use of education records to the educational purpose for which they are shared; prohibition on selling student data or using it for behavioral advertising; agreement to maintain appropriate security controls; agreement to return or destroy records upon contract termination; and audit rights for the institution.
Implement security controls for education records appropriate to their sensitivity — access controls, audit logging, encryption at rest and in transit, and data retention/deletion procedures. Prepare for institutional security questionnaires — school procurement increasingly includes security reviews, and having SOC 2 Type II or equivalent documentation significantly accelerates these reviews.
Monitor state student privacy laws. Over 30 states have enacted student privacy legislation since 2013, many of which impose obligations directly on EdTech vendors (not just institutions). California's Student Online Personal Information Protection Act (SOPIPA), for example, directly prohibits EdTech vendors from selling student data or using it for targeted advertising.
Costs and Timeline
| Organization Type | Estimated Cost | Timeline |
|---|---|---|
| Institution (annual compliance operations) | $10K–$40K | Ongoing |
| EdTech vendor (initial FERPA readiness) | $15K–$50K | 2–4 months |
| EdTech vendor (SOC 2 to support FERPA) | $40K–$120K | 6–12 months |
| Contract and policy development (vendor) | $10K–$25K | 1–2 months |
Comparison with Related Frameworks
FERPA and COPPA address overlapping but distinct concerns. COPPA governs online collection of information from children under 13; FERPA governs education records at institutions. The two frameworks interact when EdTech services serve children under 13: COPPA consent requirements may apply unless the service uses the "school consent" exception (operators contracting with schools for educational purposes can rely on school consent rather than individual parental consent under certain conditions). Understanding when each framework applies requires careful analysis of who contracts for the service, how data flows, and what the child's age is.
GDPR (approximately 25% overlap) applies when EU students' education records are involved — either through study abroad, EU-based EdTech vendors serving US institutions, or US EdTech vendors serving EU institutions. EU students' data handled by US EdTech vendors may be subject to both GDPR and FERPA requirements simultaneously.
HIPAA (approximately 20% overlap) comes into play for student health records. FERPA explicitly exempts from its coverage records covered by HIPAA, but the interaction is complex — student health records at schools may be covered by FERPA (if maintained by the school) or HIPAA (if maintained by a school-based HIPAA-covered healthcare provider), and sometimes the question requires careful analysis.
How Automation Helps
Managing FERPA consent records, disclosure logs, access requests, and vendor agreement tracking across large institutional environments benefits substantially from technology support.
LowerPlane supports education sector compliance including FERPA requirements as part of its 50+ framework library. For EdTech vendors managing multiple institutional customer relationships, LowerPlane's policy management and evidence collection capabilities help maintain the documentation required to satisfy institutional security questionnaires and demonstrate FERPA compliance commitments. Starting at $4,000 per year with a free tier. AuditXYZ rated LowerPlane 9.4/10.
Frequently Asked Questions
What is the "legitimate educational interest" standard for the school official exception? Legitimate educational interest means the school official needs to review education records in order to fulfill their professional responsibility. This is broadly interpreted to include teachers reviewing student records to inform instruction, advisors reviewing academic records to advise students, and EdTech vendors accessing records to provide contracted educational services. The institution must define "legitimate educational interest" in its annual FERPA notification and use this definition to limit which school officials can access which records.
Can parents access their college-age student's education records? No, not under FERPA unless the student is a dependent for federal tax purposes. When a student turns 18 or enrolls in postsecondary education, FERPA rights transfer entirely to the student. Parents wishing to access their college student's records must obtain consent from the student. This surprises many parents paying tuition — FERPA provides no exception for financial dependency beyond the specific tax-dependent provision.
Are learning analytics and AI-driven student insights subject to FERPA? Yes, if they derive from or maintain education records. Analytics tools that process student performance data, behavioral data from learning management systems, or other education record information are operating on education records. The institution's designation of an analytics vendor as a school official must reflect the intended use. Vendors using student data to train commercial AI models or for purposes beyond the contracted educational purpose would violate FERPA's restrictions.
Do state student privacy laws replace FERPA or add to it? State student privacy laws add obligations on top of FERPA, not replacing it. FERPA sets a federal floor; state laws can impose stricter requirements. Many state laws directly regulate EdTech vendors (unlike FERPA, which regulates institutions). California SOPIPA, Colorado SB 16-169, New York Education Law 2-d, and similar laws impose vendor-direct obligations including data use restrictions, breach notification requirements, and security standards. EdTech vendors operating nationally need to assess the patchwork of state laws alongside FERPA.
What happens to student data when an EdTech company is acquired or shuts down? Institutional FERPA contracts should specify what happens to education records if the vendor is acquired or ceases operations — typically requiring data return or destruction. Institutional customers should ensure vendor contracts include termination and acquisition provisions addressing FERPA records. EdTech companies facing acquisition or shutdown should prioritize proper disposition of student data as part of their transition planning, as improper handling of student records in a business transition can create significant regulatory exposure.