FERPA turned fifty as a law about filing cabinets, and the states spent the last decade writing the law about everything else. The modern student-privacy regime is not federal: it is SOPIPA’s flat bans on ads, profiling, and sale, copied across half the country; New York’s process machine of published disclosures, NIST alignment, and per-student breach penalties; and forty-plus statutes a national vendor must satisfy simultaneously. The practical insight is that the composite is buildable, one strictest-state product posture, one DPA framework with state exhibits, one breach playbook tuned to the shortest clock, and that districts’ procurement checklists enforce it more reliably than any regulator. In this sector, the states are not the overlay; they are the law.
| Federal floor | FERPA: school-directed, no vendor duties, no security standard |
|---|---|
| SOPIPA model | Direct operator bans: ads, profiling, sale (~2 dozen states) |
| NY Ed 2-d | Contract terms, NIST CSF, DPO, 7-day breach, per-student penalties |
| De-identified data | Restricted; small-cohort claims scrutinized |
| Strategy | One composite-ceiling build + SDPC state exhibits |
Building the multi-state posture
Hard-code the SOPIPA bans. No ads, no profiling, no sale as product invariants, not policy toggles; they satisfy two dozen states at once, alongside your FERPA vendor obligations.
Adopt 2-d’s artifacts nationally. NIST-mapped security documentation and 7-day breach capability superset most states’ demands.
Treat de-identification as a claim to defend. Documented methodology and downstream re-identification bans; small cohorts need special handling, as with HIPAA de-identification.
Keep the federal stack in view. State law layers onto FERPA, COPPA, and CIPA; under-13 products answer to COPPA’s 2025 rules regardless of state.
State laws judge your actual data flows, not your policy: verify what student-facing pages transmit with a free scan.