US Privacy Law United States (Federal)

FERPA: Student Privacy Rules for Schools and Ed-Tech

FERPA's education-records rules: who is covered, directory information, the school-official exception ed-tech relies on, PPRA and state student-privacy laws, and enforcement.

Regulation

Family Educational Rights and Privacy Act (20 U.S.C. 1232g; 34 CFR Part 99), 1974

Max Penalty

Loss of federal education funding (never yet imposed); no private right of action; state student-privacy laws and FTC/COPPA fill the penalty gap

Enforcing Authority

US Department of Education, Student Privacy Policy Office (SPPO)

Official Source

studentprivacy.ed.gov

Executive Summary

  • FERPA gives parents (and students at 18 or in postsecondary education, 'eligible students') rights to inspect, seek amendment of, and control disclosure of education records at schools receiving federal education funds.
  • Disclosure of personally identifiable information from education records requires written consent unless an exception applies; the 'school official' exception is how districts lawfully share data with ed-tech vendors, under direct control and legitimate-educational-interest conditions.
  • 'Directory information' (name, email, honors, dates of attendance) may be disclosed without consent only if the institution publishes its designation and offers an opt-out.
  • Enforcement runs through the Department of Education's SPPO on a complaint-and-compliance model; the nuclear remedy (funding loss) has never been used, so practical accountability comes from state student-privacy statutes, COPPA, and FTC actions against ed-tech vendors.
  • The modern pressure points are digital: ed-tech contracts, analytics and advertising trackers on school and university sites, online proctoring, and data breaches (the Illuminate Education incident exposed data of over a million students and triggered multi-state AG action in 2022-2024).

FERPA is a 1974 records statute doing 2026 work. Written for filing cabinets, it now governs cloud learning platforms, analytics pipelines, and the terabytes of behavioral data that follow every student, through a single load-bearing mechanism: the school-official exception and the contracts that implement it. Its own enforcement is famously toothless, but the surrounding ecosystem, state SOPIPA laws, COPPA, AGs, and breach litigation, supplies the teeth FERPA lacks.

LawFERPA, 20 U.S.C. 1232g; 34 CFR Part 99
CoversInstitutions receiving federal education funds
RightsInspect, amend, control disclosure of education records
EnforcementED complaint process; state laws + COPPA supply penalties
Key exceptionSchool official (ed-tech’s legal basis)

The compliance program for institutions and vendors

Institutions: govern the vendor fleet. Inventory every ed-tech tool touching student data (including teacher-adopted free tools, the classic gap), and paper each under school-official terms: purpose limitation, direct control, no ads, deletion, security, breach notice. Publish the annual FERPA notice and directory-information designation with a working opt-out.

Vendors: build to the contract you’ll be asked to sign. No advertising or product-improvement use beyond the educational purpose, no re-disclosure, deletion on request or term end, and security proportionate to holding an entire district’s records, Illuminate’s breach and the AG actions that followed price the failure. Under-13 products layer COPPA’s 2025 requirements on top.

Both: watch the web layer. Analytics and advertising trackers on portals, LMS pages, and enrollment flows can transmit identifiable student context to third parties outside any exception, the same architecture problem as health-site tracking, and increasingly cited in state enforcement.

Map the state overlay. SOPIPA-model statutes ban targeted advertising and profiles from student data; comprehensive state privacy laws generally exempt FERPA-covered records but not the institution’s other data (employees, alumni, marketing), which lands in the state-law framework; minors’ data outside education records answers to the children’s privacy stack.

School and university websites are the most public slice of the program: verify what yours collect and transmit with a free scan.

Frequently Asked Questions

What is an 'education record,' and what isn't?

Records directly related to a student and maintained by the institution or a party acting for it: grades, transcripts, discipline files, class schedules, special-education records, and student data held in ed-tech systems under the school-official exception. Not covered: sole-possession notes, law-enforcement unit records, employment records, alumni records, and peer-graded work before collection. Metadata and behavioral data in learning platforms are education records when linked to identifiable students.

How does the school-official exception cover ed-tech vendors?

A district may treat a vendor as a 'school official' with a legitimate educational interest if the vendor performs a service the school would otherwise use employees for, is under the school's direct control regarding the records, uses the data only for the authorized purpose, and does not re-disclose. The contract carries the compliance: purpose limits, no advertising use, deletion at term end, security requirements, and re-disclosure bans. Vendor marketing built on student data breaks the exception and, in many states, SOPIPA-style statutes.

What are the rules for directory information?

Institutions must give public notice of which categories they designate (name, address, email, photo, honors, sports participation, dates of attendance), and honor opt-outs before non-consensual disclosure. Even designated directory information cannot be released if the disclosure would reveal something protected in context, and institutions may adopt limited-directory policies restricting recipients. Publishing student lists to data brokers has drawn both FERPA complaints and state AG attention.

Who actually enforces student privacy, if FERPA has no fines?

Four channels: (1) SPPO investigations ordering corrective action, with funding conditions as leverage; (2) state student-privacy laws, over 40 states have them, California's SOPIPA prohibiting ed-tech advertising uses being the model, enforced by state AGs; (3) COPPA and the FTC for under-13 services, including the 2023 Edmodo order barring a platform from conditioning participation on excessive data collection; (4) breach litigation and multi-state AG actions like the Illuminate Education matter. Schools also enforce privately through contract termination.

How do FERPA, COPPA, and PPRA divide a K-12 compliance program?

FERPA governs records the school maintains and disclosure out of them (obligation holder: the institution). COPPA governs online collection from children under 13 (obligation holder: the operator, though schools may consent for educational-context collection). PPRA restricts surveys touching protected topics and requires parental notice/opt-outs, including for marketing-purpose data collection. Ed-tech vendors face all three simultaneously: FERPA via contract, COPPA directly, PPRA through the survey and marketing provisions.

Regulatory Crosswalk

COPPAPPRAState student privacy laws (SOPIPA)

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.