10.1 FERPA and Education-Technology Risk
Key Takeaways
- FERPA (20 U.S.C. § 1232g; 34 C.F.R. Part 99) protects personally identifiable information in education records at schools that receive U.S. Department of Education funds and is enforced by ED's Student Privacy Policy Office.
- An eligible student is 18 or older or attends a postsecondary institution; FERPA rights transfer from the parent to that student.
- A contractor is a school official only if it performs an institutional function, is under the school's direct control as to use and maintenance of the records, and is bound by FERPA's redisclosure limits.
- Directory information may be disclosed without consent after public notice and an opt-out; a Social Security number may not be designated as directory information.
- Gonzaga University v. Doe (2002) holds FERPA's nondisclosure provisions do not create a private right of action under 42 U.S.C. § 1983; Illinois SOPPA and similar state edtech statutes are supplements, not FERPA.
10.1 FERPA and Education-Technology Risk
Domain II.D performance indicators 1 and 2 ask you to apply the Family Educational Rights and Privacy Act of 1974 (FERPA), 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99, and then to spot the extra risk when a school hands student data to an education-technology vendor. Official primary materials live at studentprivacy.ed.gov/ferpa. FERPA is a conditions-on-federal-funds statute. It applies to educational agencies and institutions that receive funds under a program administered by the U.S. Department of Education. It is not a general children's-privacy statute, not COPPA, and not a private damages code.
Education records and personally identifiable information
Education records are records that are (1) directly related to a student and (2) maintained by an educational agency or institution, or by a party acting for the agency or institution. The exam fact pattern is a transcript, a gradebook, a disciplinary file, an individualized education program, a class roster with student numbers, or a learning-management-system log the school keeps. FERPA does not cover everything a school touches. The regulations exclude:
- Sole-possession notes used only as a personal memory aid and not shared with others (except a temporary substitute).
- Records of a law-enforcement unit of the institution, created and maintained for a law-enforcement purpose.
- Employment records of a person who is employed by the school, if those records relate only to employment and the person is not employed as a result of student status.
- Treatment records of an eligible student that are made or maintained by a physician, psychiatrist, psychologist, or other recognized professional and used only in connection with treatment.
- Records created or received after a person is no longer a student and that are not directly related to the individual's attendance (alumni records).
Personally identifiable information (PII) from education records includes the student's name; the names of parents or other family members; the student's or family's address; a personal identifier such as a Social Security number, student number, or biometric record; and other information that, alone or in combination, is linked or linkable to a specific student and would allow a reasonable person in the school community to identify the student with reasonable certainty. De-identified data that cannot reasonably be re-identified is outside the PII definition. A hashed student identifier that the vendor can still match back to the student is still PII.
Eligible student and parent rights
FERPA rights belong first to the parent. They transfer to the eligible student when the student turns 18 or attends a postsecondary institution at any age. After the transfer, the school generally deals with the student, not the parent. Two traps sit next to that rule. First, a postsecondary institution may disclose education records to a parent without the eligible student's consent if the student is a dependent for federal income-tax purposes. That is a permitted disclosure, not a parent-owned right. Second, FERPA does not stop a school from communicating with parents about a health or safety emergency.
The core rights are the same whether they sit with the parent or the eligible student:
- Inspect and review education records within a reasonable period, not more than 45 days after the request.
- Request amendment of records that are inaccurate, misleading, or in violation of privacy rights, and obtain a hearing if the school refuses.
- Consent in writing before the school discloses PII from education records, unless an exception applies.
- File a complaint with the Department of Education.
Consent must be signed and dated, specify the records, state the purpose, and identify the party to whom disclosure may be made. A blanket "we can share with anyone for any reason" form is not FERPA consent.
School-official exception and directory information
Two exceptions dominate the exam.
The school-official exception, 34 C.F.R. § 99.31(a)(1), lets the school disclose PII without consent to officials who have a legitimate educational interest. The annual FERPA notice must say how the school decides who is a school official and what a legitimate educational interest is. Faculty, registrars, and counselors are the easy cases. Contractors, consultants, volunteers, and other outside parties can qualify only if they:
- Perform an institutional service or function the school would otherwise use employees to perform.
- Are under the school's direct control with respect to the use and maintenance of education records.
- Are subject to FERPA's § 99.33 use and redisclosure limits — they may use the PII only for the purpose for which the disclosure was made and may not redisclose it except as FERPA allows.
Direct control is a contract-and-oversight fact, not a logo on a vendor slide. If the vendor may use student data for its own product training, sell it, or target ads, the school is not in direct control and the exception does not save the disclosure.
Directory information is PII that would not generally be considered harmful or an invasion of privacy if disclosed. The regulatory list includes name, address, telephone listing, email address, photograph, date and place of birth, major, grade level, enrollment status, dates of attendance, participation in officially recognized activities and sports, weight and height of athletes, degrees, honors, awards, and the most recent school attended. Directory information does not include a Social Security number. A student ID may be directory information only if it cannot, by itself, be used to gain access to education records. The school may disclose designated directory information without consent only after it gives public notice of the categories and a reasonable period to opt out. Opt-out is not a right to attend class anonymously; the Department's FAQs say a student may not use directory opt-out to block the school from identifying the student in the classroom.
Other frequently tested exceptions include disclosure to officials of another school where the student seeks or intends to enroll, financial-aid disclosures, studies under a written agreement, accrediting organizations, judicial orders and subpoenas, and the health-or-safety emergency exception. Those are permissions, not mandates. FERPA rarely requires a disclosure.
No private right of action — Gonzaga
Gonzaga University v. Doe, 536 U.S. 273 (2002), is the required citation. The Supreme Court held that FERPA's nondisclosure provisions do not create individually enforceable rights under 42 U.S.C. § 1983. There is no general FERPA private right of action. A student who wants FERPA relief files with the Student Privacy Policy Office (SPPO). The Department can withhold funds or impose conditions. It does not write the student a damages check. When a fact pattern adds a damages claim, look for a state student-records statute, a contract, or an unfair-or-deceptive-practices theory — not FERPA itself.
Education-technology risk and state supplements
The live FERPA problem is the learning platform that stores assignments, messages, and analytics off-campus. To use the school-official exception the school must keep direct control: a written agreement that names the authorized uses, bans unrelated commercial use and unauthorized redisclosure, requires security consistent with the school's duties, and requires return or destruction when the relationship ends. FERPA does not itself require that written agreement for the school-official exception, but without one the school usually cannot show direct control. If the vendor rediscloses PII in violation of § 99.33, the originating school may be barred from giving that vendor access to education records for at least five years.
State student-edtech statutes sit on top of FERPA. They are not FERPA and they do not preempt it. Name them as state supplements:
| State overlay | Core extra duty (not a FERPA substitute) |
|---|---|
| Illinois Student Online Personal Protection Act (SOPPA), 105 ILCS 85 (rewrite effective 1 July 2021) | Written operator contracts, public listing of operators, breach notice, no targeted advertising based on covered information acquired because the site or app was used for K–12 school purposes, no sale of covered information |
| California Student Online Personal Information Protection Act (SOPIPA) | Operator ban on targeted ads, profiling, and sale of K–12 student data collected through a school site or app |
| New York Education Law § 2-d | Parents' bill of rights, contracts with third-party contractors, breach notification, and data-security standards for student, teacher, and principal data |
SOPPA's targeted-advertising definition is exam-useful: ads selected from the student's online behavior, app usage, or covered information, not contextual ads based on the current page visit without retaining that activity to target later ads. A national vendor that treats FERPA as the only rule and then runs retargeting from a homework app in Illinois has a SOPPA problem, not a "FERPA private right of action" problem.
COPPA versus FERPA when a site is used in schools
The Children's Online Privacy Protection Act of 1998 (COPPA) regulates operators of child-directed sites or services, and operators with actual knowledge they collect personal information from children under 13. FERPA regulates schools that maintain education records. The same classroom tool can trigger both.
The Federal Trade Commission's COPPA FAQs allow a school to act as the parent's agent and provide consent when the operator collects personal information for the use and benefit of the school and not for the operator's own commercial purpose. The operator must still give the school the COPPA notices. If the operator wants to use the same identifiers for advertising networks, sell student lists, or build a commercial profile, school-consent does not cover that use. The operator needs verifiable parental consent, and after the 22 April 2026 COPPA Rule compliance date a separate verifiable consent is required for most third-party disclosures. FERPA still applies to the education records in the school's hands even when COPPA also applies to the operator.
Worked scenario. A middle school adopts a math app. Students submit homework under their district ID. The contract says the vendor is a school official, may use data only to deliver the app, and must delete accounts at year-end. That is the FERPA school-official path, and the school may provide COPPA consent for children under 13. In month four the vendor turns on "engagement insights" that send persistent identifiers and homework metadata to an advertising network. Direct control is gone, the school-official exception fails, SOPPA-style state law is independently triggered in Illinois, and COPPA school-consent no longer covers the commercial disclosure.
The exam trap is collapsing these regimes. FERPA is education records plus Department of Education process. COPPA is operator collection from children under 13 plus FTC process. SOPPA and its cousins are state operator-and-district duties. Gonzaga means the injured student does not enforce FERPA in a private federal damages suit.
A graduate sues her university under 42 U.S.C. § 1983, alleging the registrar sent her transcript grades to a prospective employer without consent. Which statement is the exam-correct rule?
A district wants a homework platform to qualify as a FERPA school official. Which condition is required for that exception to cover the vendor?
A child-directed math site is used in a fifth-grade classroom and also wants to send students' persistent identifiers to an advertising network. How do FERPA and COPPA interact?