US Federal Law United States

FERPA and State Student Privacy Laws: The Stricter Layer

How state student privacy laws (SOPIPA, New York Ed 2-d, and 100+ others) exceed FERPA: direct vendor liability, ad bans, security mandates, and building to the strictest state.

Regulation

FERPA (20 USC 1232g) as the federal floor; state statutes including California SOPIPA, New York Education Law 2-d, Illinois SOPPA, Colorado Student Data Transparency and Security Act, Connecticut PA 16-189

Max Penalty

State regimes add real teeth: statutory penalties, AG enforcement, contract-invalidity consequences, and in New York, per-student breach penalties against vendors

Enforcing Authority

Department of Education (FERPA); state attorneys general and state education departments (state laws)

Official Source

studentprivacy.ed.gov

Executive Summary

  • FERPA is a floor, not a ceiling: it regulates schools through funding conditions and leaves vendors, advertising, and security largely unaddressed, gaps every populous state has now filled.
  • California's SOPIPA (2014) set the template: direct statutory duties on edtech operators, banning targeted advertising, profiling, and sale of student data, with reasonable-security and deletion obligations, no contract required to be bound.
  • New York Education Law 2-d goes furthest on process: a parents' bill of rights, mandatory contract terms, NIST CSF alignment, data protection officers, and per-student penalties against vendors for breaches.
  • Over 40 states have student privacy statutes; most follow SOPIPA's operator-duty model, with variations in age scope, de-identified data rules, and enforcement.
  • Because vendors sell nationally, the strictest-state build (SOPIPA prohibitions + 2-d process + Illinois SOPPA's breach and contract rules) is the only scalable posture.

FERPA turned fifty as a law about filing cabinets, and the states spent the last decade writing the law about everything else. The modern student-privacy regime is not federal: it is SOPIPA’s flat bans on ads, profiling, and sale, copied across half the country; New York’s process machine of published disclosures, NIST alignment, and per-student breach penalties; and forty-plus statutes a national vendor must satisfy simultaneously. The practical insight is that the composite is buildable, one strictest-state product posture, one DPA framework with state exhibits, one breach playbook tuned to the shortest clock, and that districts’ procurement checklists enforce it more reliably than any regulator. In this sector, the states are not the overlay; they are the law.

Federal floorFERPA: school-directed, no vendor duties, no security standard
SOPIPA modelDirect operator bans: ads, profiling, sale (~2 dozen states)
NY Ed 2-dContract terms, NIST CSF, DPO, 7-day breach, per-student penalties
De-identified dataRestricted; small-cohort claims scrutinized
StrategyOne composite-ceiling build + SDPC state exhibits

Building the multi-state posture

Hard-code the SOPIPA bans. No ads, no profiling, no sale as product invariants, not policy toggles; they satisfy two dozen states at once, alongside your FERPA vendor obligations.

Adopt 2-d’s artifacts nationally. NIST-mapped security documentation and 7-day breach capability superset most states’ demands.

Treat de-identification as a claim to defend. Documented methodology and downstream re-identification bans; small cohorts need special handling, as with HIPAA de-identification.

Keep the federal stack in view. State law layers onto FERPA, COPPA, and CIPA; under-13 products answer to COPPA’s 2025 rules regardless of state.

State laws judge your actual data flows, not your policy: verify what student-facing pages transmit with a free scan.

Frequently Asked Questions

What does FERPA leave unregulated that states stepped into?

Four gaps. Vendors: FERPA binds schools; vendors feel it only through contracts, and only the five-year data ban reaches them directly, states imposed statutory duties on operators themselves. Commercial use: FERPA says nothing explicit about advertising or profiling built on lawfully received data, SOPIPA-style laws prohibit targeted ads, profiling for non-educational purposes, and sale outright. Security: FERPA contains no security standard at all, states mandate reasonable security, and New York requires NIST Cybersecurity Framework alignment. Breach: FERPA has no breach-notification provision, state student laws and general breach statutes fill it, some with education-specific clocks and, in New York, vendor-paid per-student penalties. Add enforcement reality (no private FERPA suit after Gonzaga, versus state AG actions), and the state layer is where modern student-privacy liability actually lives.

What does SOPIPA require, and who copied it?

California's Student Online Personal Information Protection Act (effective 2016) binds operators of sites and apps designed and marketed for K-12 purposes, no contract, no consent framework, direct statutory duties: no targeted advertising on the service or using data acquired from it; no profiling students except for K-12 purposes; no selling student information; no disclosure except enumerated purposes; reasonable security; and deletion of a student's data at district request. It also expressly permits legitimate uses: adaptive learning, maintaining the service, and improvement within K-12 purposes. Roughly two dozen states copied it nearly verbatim (Delaware, Maryland, Georgia, Kansas, Oregon, Washington and more), making the SOPIPA prohibition set the national baseline for edtech operators regardless of where they incorporate. Its enforcement runs through state UDAP/AG authority, no private right of action, but the prohibitions also become FTC Section 5 hooks when stated in privacy policies.

What makes New York Education Law 2-d the hardest to satisfy?

Process depth. 2-d (2014, with 2020 implementing regulations, Part 121) requires each educational agency to publish a Parents' Bill of Rights and attach supplemental information for every third-party contractor contract; mandates specific contract terms (exclusive purposes, subcontractor flow-down, expiration and data return/deletion, challenge rights, security protections including encryption); requires agencies and vendors to align with the NIST Cybersecurity Framework; obliges districts to appoint a Data Protection Officer; and requires annual employee training. Vendor breach consequences are concrete: report to the district within 7 days, and the state can impose penalties on vendors up to $10 per student affected (statutory maximums apply), plus disqualification exposure. For vendors, 2-d compliance means a New York-specific rider on the national DPA, published data-security disclosures per contract, and NIST-mapped security documentation, the most paperwork-intensive state regime in the sector.

How do states treat de-identified and aggregate student data?

Less permissively than vendors assume. SOPIPA allows de-identified data use within the service and for demonstrating effectiveness, and aggregated de-identified data for development and improvement, but the de-identification must actually hold, small-cohort education data (a rural district's eighth grade) re-identifies easily, and regulators evaluate the claim, not the label. New York's Part 121 requires de-identification consistent with FERPA standards and bars re-identification attempts. Several states restrict even de-identified data sale or require contractual re-identification bans downstream. Colorado's Student Data Transparency Act adds publication duties: districts must post what data goes to which vendors, making quiet de-identified-data commerce visible. The safe architecture: de-identify to a documented standard (expert-style justification, k-anonymity thresholds for small cohorts), bind every recipient against re-identification, and treat 'we might sell aggregate insights someday' as a decision requiring counsel, not a default.

How should a national edtech vendor structure multi-state compliance?

Build once to the composite ceiling. Prohibitions: adopt SOPIPA's bans (no targeted ads, no non-educational profiling, no sale) as absolute product rules, they recur in two dozen states and align with the FTC's posture anyway. Process: build the New York 2-d artifact set (published security disclosures, NIST CSF mapping, parents' bill of rights supplements, 7-day breach clocks) as your national capability, since it supersets most states' process demands. Contracts: negotiate from the SDPC national DPA with state-specific exhibits rather than bespoke agreements, the consortium maintains state versions tracking local requirements. Registries: several states (Utah, Connecticut practice) maintain vendor registries or standard-contract regimes, get listed. Monitoring: assign ownership for tracking new statutes and amendments each legislative season; the count still grows yearly. The alternative, fifty postures, fails commercially: district procurement officers reject vendors whose paperwork does not already match their state's checklist.

Regulatory Crosswalk

SDPC national DPACOPPAState breach notification laws

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.