School privacy law is three statutes from three eras solving three problems: FERPA (1974) guards the records, COPPA (1998) guards young children’s data from commerce, CIPA (2000) trades funding for filters. None was designed for a classroom where every worksheet is an app and every app is a data flow, so the regimes meet, awkwardly, in the district’s vendor contracts and the FTC’s school-consent doctrine. The load-bearing rule is the education-only limit: schools can stand in for parents exactly as far as the data serves the school, and not one ad impression further. Districts that govern app adoption centrally, and vendors that paper all three regimes plus state law in one DPA, handle this fine; everyone else is one teacher’s click-wrap away from an incident with four regulators’ names on it.
| FERPA | Education records, disclosure consent, school official exception |
|---|---|
| COPPA | Under-13 collection; school consent OK if education-only |
| CIPA | Filtering + safety policy + monitoring, tied to E-Rate |
| Age lines | COPPA <13, CIPA <17, FERPA to 18 (eligible student) |
| Overlay | State student-privacy laws, stricter than all three |
| Meeting point | The district-vendor DPA |
Making the stack work
Centralize app approval. District-level review is the only structure that satisfies FERPA direct control and valid school COPPA consent simultaneously.
Scope school consent honestly. Education-only collection is the whole permission; COPPA’s 2025 rules add retention and ad-consent unbundling on top.
Right-size CIPA monitoring. Filter and monitor to the statute, then treat the monitoring output as protected records; over-surveillance is its own liability.
Layer in state law last and strictest. State student and minors’ laws usually decide the hardest clause; age-assurance choices follow from them.
Classroom platforms load third-party code like any website: see what a student’s browser actually contacts with a free scan.