FERPA is a 1974 records statute doing 2026 work. Written for filing cabinets, it now governs cloud learning platforms, analytics pipelines, and the terabytes of behavioral data that follow every student, through a single load-bearing mechanism: the school-official exception and the contracts that implement it. Its own enforcement is famously toothless, but the surrounding ecosystem, state SOPIPA laws, COPPA, AGs, and breach litigation, supplies the teeth FERPA lacks.
| Law | FERPA, 20 U.S.C. 1232g; 34 CFR Part 99 |
|---|---|
| Covers | Institutions receiving federal education funds |
| Rights | Inspect, amend, control disclosure of education records |
| Enforcement | ED complaint process; state laws + COPPA supply penalties |
| Key exception | School official (ed-tech’s legal basis) |
The compliance program for institutions and vendors
Institutions: govern the vendor fleet. Inventory every ed-tech tool touching student data (including teacher-adopted free tools, the classic gap), and paper each under school-official terms: purpose limitation, direct control, no ads, deletion, security, breach notice. Publish the annual FERPA notice and directory-information designation with a working opt-out.
Vendors: build to the contract you’ll be asked to sign. No advertising or product-improvement use beyond the educational purpose, no re-disclosure, deletion on request or term end, and security proportionate to holding an entire district’s records, Illuminate’s breach and the AG actions that followed price the failure. Under-13 products layer COPPA’s 2025 requirements on top.
Both: watch the web layer. Analytics and advertising trackers on portals, LMS pages, and enrollment flows can transmit identifiable student context to third parties outside any exception, the same architecture problem as health-site tracking, and increasingly cited in state enforcement.
Map the state overlay. SOPIPA-model statutes ban targeted advertising and profiles from student data; comprehensive state privacy laws generally exempt FERPA-covered records but not the institution’s other data (employees, alumni, marketing), which lands in the state-law framework; minors’ data outside education records answers to the children’s privacy stack.
School and university websites are the most public slice of the program: verify what yours collect and transmit with a free scan.