US Federal Law United States

FERPA for EdTech: School Official Exception, Vendor Duties

How FERPA governs edtech vendors: the school official exception, direct control requirements, metadata and product-improvement limits, and contract terms districts demand.

Regulation

Family Educational Rights and Privacy Act, 20 USC 1232g; 34 CFR Part 99; PPRA for surveys; enforced guidance from the Student Privacy Policy Office

Max Penalty

Ultimate sanction is loss of federal education funding for the institution; vendors risk the five-year ban on access to PII from education records plus contract loss and state-law penalties

Enforcing Authority

US Department of Education, Student Privacy Policy Office (SPPO); no private right of action (Gonzaga v. Doe)

Official Source

studentprivacy.ed.gov

Executive Summary

  • FERPA binds educational agencies and institutions receiving federal funds; edtech vendors are regulated indirectly, through the conditions schools must impose when sharing education records without parental consent.
  • The school official exception is edtech's main lane: a vendor may receive PII from education records if it performs an institutional service, is under the school's direct control regarding the data, and uses it only for the contracted purpose.
  • Product improvement, advertising, and building non-educational profiles from student data fall outside the exception; metadata and de-identified data have carefully bounded uses.
  • Enforcement runs through the Department of Education against schools (funding conditions) with a five-year data-access ban available against misbehaving vendors; there is no private lawsuit under FERPA (Gonzaga v. Doe), but state student-privacy laws add direct vendor liability.
  • Practical compliance is contractual: data privacy agreements (often the SDPC national template) defining purpose limits, deletion, security, breach notice, and no-ad-use terms.

FERPA is the rare privacy law that regulates its subjects by regulating their customers. No edtech company answers to the Department of Education directly; every serious one lives inside contracts written to keep school districts on the right side of the school official exception, direct control, purpose limits, no ads, delete on exit. The federal enforcement record looks toothless (no funding termination, ever; no private suits, per Gonzaga) until you notice where the teeth actually are: state statutes like SOPIPA with real prohibitions, FTC jurisdiction over the same conduct, five-year data bans, and procurement lists that quietly end companies. In edtech, the DPA is the product spec, and privacy diligence is the sales cycle.

StatuteFERPA, 20 USC 1232g; 34 CFR Part 99
Vendor laneSchool official exception: service + direct control + use limits
ForbiddenAds, profiling, sale, out-of-scope product development
Federal teeth5-year PII ban; funding conditions (schools)
Real teethState laws (SOPIPA+), FTC, DPAs, procurement lists
Standard paperSDPC national DPA template

Becoming district-procurable

Build to the DPA, not your ToS. The SDPC template’s terms are the market’s requirements document; FERPA’s interaction with state laws determines the strictest clause set.

Scope product improvement honestly. Improving the contracted service is defensible; training general models on student data is not, and state law says so explicitly.

Control the SDK layer. Analytics and ad SDKs in a school product are the standard incident; under-13 users add COPPA exposure on top, and FERPA/COPPA/CIPA interplay governs the school context.

Prepare the parents’ rights machinery. Districts must produce and amend records on request; your platform’s export and correction functions are FERPA infrastructure.

Student-facing pages with third-party trackers are how edtech incidents start: audit yours with a free scan.

Frequently Asked Questions

How does FERPA reach a private edtech company at all?

Indirectly but effectively. FERPA regulates schools: PII from education records may not be disclosed without written parental consent (or the eligible student's, at 18) unless an exception applies. The school official exception (34 CFR 99.31(a)(1)) lets schools treat contractors as school officials when the vendor performs a service the school would otherwise use employees for, meets the criteria in the school's annual FERPA notice, is under the school's 'direct control' with respect to use and maintenance of the records, and complies with 99.33's use restrictions, use only for the authorized purpose, no re-disclosure. Those conditions must land in your contract, which is how federal education law becomes vendor obligations. Violate them and the school has a FERPA problem, you lose the customer, and the Department can bar the school from providing you PII access for up to five years, a commercial death sentence in the sector.

What can and can't we do with student data under the exception?

Permitted: exactly what the contract authorizes in service of the school's educational purpose, deliver the platform, generate the analytics the school ordered, maintain security. Prohibited without separate consent: targeted advertising to students or parents; selling data; building profiles for non-educational purposes; using PII to develop or improve products beyond the contracted service (the contested middle ground, Department guidance permits improvement of the specific service being provided but not mining student data to build new products, and state laws like SOPIPA draw the line harder); re-disclosure to third parties, including your own subprocessors unless the contract and direct-control conditions extend to them. De-identified data (99.31(b)) may be used more freely if re-identification is not reasonably possible, but weak de-identification of small cohorts fails that test, and several state laws restrict even de-identified commercial use.

What does 'direct control' require in practice?

The Department has not exhaustively defined it, but guidance and district practice converge on contractual and operational elements: the school dictates permitted uses and the vendor may not exceed them; the school can audit or obtain attestations of compliance; data is returned or deleted at contract end on the school's instruction; subprocessors are disclosed and bound to the same terms; security incidents are reported to the school promptly; and the vendor makes no unilateral changes to data practices (quietly amended terms of service defeat direct control). Click-wrap consumer terms where the teacher 'agrees' on behalf of the district are the classic failure, districts increasingly prohibit app adoption outside vetted lists precisely because a teacher accepting consumer ToS creates an uncontrolled disclosure. Vendors should sell against this: a signed DPA with direct-control terms is what makes you procurable.

Who enforces, and what is the realistic exposure?

The Student Privacy Policy Office investigates complaints against educational agencies; the nuclear sanction, terminating federal funding, has never been imposed, and Gonzaga University v. Doe (2002) forecloses private FERPA suits. So the direct federal exposure is modest, which misleads vendors into complacency. The real enforcement web: the five-year PII ban against third parties that improperly re-disclose (34 CFR 99.67); the FTC, which treats student-data misuse as a Section 5 issue and enforces COPPA where under-13 users are involved; state attorneys general under student-privacy statutes (California's SOPIPA bans ads, profiling, and sale outright, with 100-plus state laws following); contractual liability to districts, including breach-notification costs; and procurement consequences, state vetting registries and district approved-lists exclude vendors with incidents. The pattern in practice: a researcher or journalist finds an exposed bucket or an SDK oversharing, and the vendor's business unravels through channels FERPA never mentions.

What should a district-ready data privacy agreement contain?

The Student Data Privacy Consortium's national DPA template is the de facto standard, negotiate from it rather than your consumer ToS. Core terms: designation as school official under direct control; enumerated data elements collected (exhibit-based, kept current); purpose limitation to the contracted service; prohibition on ads, profiling, and sale; product-improvement language scoped to the provided service; subprocessor lists with flow-down obligations; security program commitments (encryption, access controls, and increasingly SOC 2 or state-specific frameworks); breach notification to the district on a defined clock (some states set 30 days or less); data return/deletion at termination with certification; audit or attestation rights; and survival of restrictions post-contract. Add parents' rights mechanics: the district owns inspection and amendment requests, and your platform must be able to produce a student's records when the district asks. One well-built DPA exhibit set serves hundreds of districts; artisanal per-district terms do not scale.

Regulatory Crosswalk

COPPAState student privacy laws (SOPIPA and progeny)CIPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.