United States · Applies by law
FERPA compliance
Family Educational Rights and Privacy Act
Edtech vendors handling student education records on behalf of US schools and districts.
The context
What it actually asks of you
FERPA governs student education records held by US schools, districts and institutions that receive Department of Education funding. Edtech vendors are not directly regulated by it, but you inherit the obligations contractually, and a district that believes you have caused a FERPA violation will terminate rather than negotiate.
Most vendors operate under the 'school official' exception, which permits access without separate parental consent. It carries hard conditions: the institution must maintain direct control over your use of the data, you must have a legitimate educational interest, and you may not repurpose the data for anything else, including product improvement or marketing, unless the contract allows it.
In practice FERPA rarely arrives alone. State student-privacy statutes such as California's SOPIPA, and COPPA for younger users, usually apply to the same product at the same time, and the strictest of them sets your actual requirement.
The common mistake
What teams get wrong.
You'll usually operate under the 'school official' exception, which carries hard constraints: direct institutional control, a legitimate educational interest, and no secondary use of the data. Ever.
Our scope
What we do for FERPA.
- 01School official exception analysis and contract terms
- 02Student data inventory and retention schedule
- 03Directory information handling and parental rights
- 04State student-privacy law overlay (SOPIPA and equivalents)
- 05Vendor and sub-processor review
innsecs provides security and compliance services, not legal advice, and we are not a law firm. We build the technical and organisational measures, evidence and processes these obligations require, and work alongside your counsel on legal interpretation.
Questions
FERPA FAQ
Only if the contract with the institution permits it, and many explicitly forbid it. Aggregate, properly de-identified analytics are usually acceptable; training models on identifiable student records generally is not. Get this written into the agreement rather than inferring permission.
FERPA does not set a single retention period, your contract and the institution's own policy do. The practical answer is a documented retention schedule with deletion on contract termination, which is what districts increasingly require in procurement.
Neither overrides the other; they apply in parallel. A K-8 product will typically face both, plus state law. We map them together so you build one control set rather than three.
Find out whether FERPA binds you.
Bring your product, your users and your markets. We will tell you what applies, what does not, and what it takes to close the gap.
No sales sequence. A scoping call and a written proposal cost nothing.