US Federal Law United States

FERPA, COPPA, and CIPA Together: The School Privacy Stack

How FERPA, COPPA, and CIPA interact in K-12: school consent on parents' behalf, filtering and monitoring duties, and building one compliance posture for schools and their vendors.

Regulation

FERPA (20 USC 1232g); COPPA (15 USC 6501-6506, 16 CFR Part 312); CIPA (47 USC 254(h)); PPRA for surveys

Max Penalty

FERPA: funding conditions and vendor data bans; COPPA: per-child civil penalties; CIPA: loss of E-Rate discounts and potential recovery of funds

Enforcing Authority

Department of Education SPPO (FERPA/PPRA); FTC (COPPA); FCC via E-Rate conditions (CIPA)

Official Source

studentprivacy.ed.gov

Executive Summary

  • Three federal regimes govern K-12 data and access: FERPA (education records and disclosure), COPPA (under-13 online data collection), and CIPA (internet filtering and monitoring tied to E-Rate funding), each with a different regulator and trigger.
  • Schools may consent to COPPA collection on parents' behalf, but only where data is collected for the use and benefit of the school and no other commercial purpose, the load-bearing limit in every classroom app deployment.
  • CIPA requires filtering of obscene and harmful-to-minors content, an internet safety policy with monitoring, and educating minors on online safety, as conditions of E-Rate discounts.
  • The regimes interlock at the vendor contract: a classroom app must simultaneously satisfy FERPA's school official exception, COPPA's limits on school consent, and district monitoring policies under CIPA.
  • State student-privacy laws (SOPIPA and 100+ successors) sit on top, generally stricter than all three federal statutes on commercial use.

School privacy law is three statutes from three eras solving three problems: FERPA (1974) guards the records, COPPA (1998) guards young children’s data from commerce, CIPA (2000) trades funding for filters. None was designed for a classroom where every worksheet is an app and every app is a data flow, so the regimes meet, awkwardly, in the district’s vendor contracts and the FTC’s school-consent doctrine. The load-bearing rule is the education-only limit: schools can stand in for parents exactly as far as the data serves the school, and not one ad impression further. Districts that govern app adoption centrally, and vendors that paper all three regimes plus state law in one DPA, handle this fine; everyone else is one teacher’s click-wrap away from an incident with four regulators’ names on it.

FERPAEducation records, disclosure consent, school official exception
COPPAUnder-13 collection; school consent OK if education-only
CIPAFiltering + safety policy + monitoring, tied to E-Rate
Age linesCOPPA <13, CIPA <17, FERPA to 18 (eligible student)
OverlayState student-privacy laws, stricter than all three
Meeting pointThe district-vendor DPA

Making the stack work

Centralize app approval. District-level review is the only structure that satisfies FERPA direct control and valid school COPPA consent simultaneously.

Scope school consent honestly. Education-only collection is the whole permission; COPPA’s 2025 rules add retention and ad-consent unbundling on top.

Right-size CIPA monitoring. Filter and monitor to the statute, then treat the monitoring output as protected records; over-surveillance is its own liability.

Layer in state law last and strictest. State student and minors’ laws usually decide the hardest clause; age-assurance choices follow from them.

Classroom platforms load third-party code like any website: see what a student’s browser actually contacts with a free scan.

Frequently Asked Questions

Which law applies to what in a school context?

Sort by trigger. FERPA: any disclosure of personally identifiable information from education records by a federally funded school, grades, rosters, IDs, behavioral data, to anyone including vendors; governs through consent requirements and exceptions. COPPA: online collection of personal information from children under 13 by commercial operators, the edtech app itself, not the school (COPPA does not bind schools); governs notice and verifiable parental consent. CIPA: schools and libraries taking E-Rate discounts for internet access; governs technology protection measures (filtering), an internet safety policy adopted after a public hearing, monitoring of minors' online activities, and, per the Protecting Children in the 21st Century Act amendment, educating minors about appropriate online behavior. PPRA adds survey consent rules for sensitive topics. One classroom Chromebook session can implicate all four.

When can a school consent to COPPA on parents' behalf?

FTC guidance (longstanding, reaffirmed in the 2025 amendment process) permits schools to authorize collection in loco parentis where the operator collects children's personal information solely for the use and benefit of the school and for no other commercial purpose. The conditions carry weight: the operator must give the school full COPPA-style notice; data cannot feed targeted advertising, non-educational profiling, or unrelated product development; and the school should make notices available to parents. Where collection serves the operator's own commercial ends beyond the educational service, school consent fails and actual parental consent is required. Operationally, districts centralize this: an approved-app process where the district reviews the vendor's practices and signs the consent, because teacher-by-teacher click-wrap adoption creates both a COPPA gap and a FERPA direct-control failure at once.

What does CIPA actually require, and what does it not?

For E-Rate internet/internal-connections discounts: a technology protection measure (filter) on all internet-connected devices blocking visual depictions that are obscene, child sexual abuse material, or harmful to minors (for minor-accessible devices); an internet safety policy addressing minors' online safety, adopted with reasonable public notice and at least one public hearing; monitoring of minors' online activity; and online-safety education for minors. Adults may have filters disabled for bona fide research or lawful use. What CIPA does not require: tracking individual students' every click, retaining browsing histories indefinitely, or surveilling personal devices off-network, districts routinely exceed CIPA in the name of CIPA, and the over-collection becomes a FERPA and state-law problem of its own. Filtering vendors' monitoring dashboards generate education records; treat their retention and access accordingly.

Where do the three regimes conflict or gap?

Age boundaries gap: COPPA stops at 13, FERPA runs to the eligible student at 18, CIPA's 'minor' is under 17, so a 14-year-old's app data is FERPA-and-state-law territory with no COPPA hook. Consent authority differs: FERPA consent belongs to parents then eligible students; COPPA consent can be the school's within limits; CIPA needs no individual consent at all. Monitoring tension: CIPA-driven monitoring creates records FERPA then protects, and state laws may restrict, the surveillance mandate and the privacy mandate share a filing cabinet. Vendor obligations diverge: a vendor can be FERPA-compliant (school official, direct control) while violating COPPA (ad SDK on under-13 users), or COPPA-clean while breaching state law (de-identified data resale). The gaps close only at the contract layer: districts and vendors papering all regimes at once, which is why the consolidated DPA became the industry's central artifact.

What should districts and vendors each own in the stack?

Districts: the approved-app governance process (no ungoverned adoption); the FERPA annual notice designating school officials; the COPPA consent decision per app with documentation that collection is education-only; the CIPA policy, hearing record, filter, and education program; PPRA notices for surveys; parent communication channels; and retention schedules for the monitoring data their own tools generate. Vendors: a signed DPA meeting FERPA direct control; COPPA-compliant under-13 handling (or honest audience exclusions), including the 2025 rule's retention and unbundled-consent requirements; no ads, sale, or out-of-scope use per state law; security programs with breach notice; and transparent subprocessor chains. Shared: incident response (the district owns parent notification, the vendor owes the district speed and facts) and annual re-review, because app updates change data practices faster than contracts do. The failure mode in nearly every K-12 incident is an owner gap, each side assuming the other had it.

Regulatory Crosswalk

State student privacy lawsCOPPA safe harborsState minors' design codes

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.