Skip to content
Sunday, August 23, 2026
REGD NewsENTERTAINMENT & CELEBRITY STYLE
People · Screens · Culture Now
Entertainment

What FERPA actually lets edtech vendors do with student data

The law doesn't ban vendor access to school records. It makes the district the gatekeeper — and most of what happens next depends on a contract clause few people read.

By Omar Rivera · 7 min read
What FERPA actually lets edtech vendors do with student data

FERPA doesn't stop edtech vendors from touching student records — it makes the school the gatekeeper. Under the Department of Education's "school official" exception, a vendor can access student data without individual parental consent only if the district keeps what the Department calls "direct control" over how that data is used, per guidance from the Department's Student Privacy Policy Office for education-technology vendors.

That single exception is the mechanism behind almost every edtech tool a school signs up for, from a reading app to an AI writing assistant. Understanding what it requires — and what it doesn't excuse — is more useful to a teacher or a tech director than reading any individual vendor's privacy policy.

Yes, under FERPA's school official exception, but only if the arrangement meets four conditions the Department's guidance for third-party service providers lays out: the vendor performs a service the school would otherwise handle with its own employees, meets the district's definition of a "school official" with legitimate educational interest, operates under the school's direct control over how it uses and maintains the records, and doesn't use the data for anything beyond the contracted purpose or re-disclose it without authorization.

Miss any one of those four, and the school can't rely on this exception to skip parental consent.

What counts as a "school official" under FERPA?

It's a label the district assigns, not one a vendor claims for itself. The Department's guidance is explicit that a company only qualifies if the school's own policies define "school official" broadly enough to include outside contractors, and if the district actually exercises oversight rather than rubber-stamping the vendor's terms.

The guidance singles out one recurring failure mode: a vendor that changes its terms of service without clear notice. That, the Department warns, "makes it difficult for a school or district to demonstrate direct control" — because a district can't be said to control data use under terms it never agreed to.

What has to be in the written agreement?

FERPA doesn't hand districts a single universal contract template, but the Department's written-agreement checklist — issued through its Privacy Technical Assistance Center — sets out the mandatory elements for agreements that rely on FERPA's studies and audit-or-evaluation exceptions, the two provisions most often used to justify sharing data with outside researchers or evaluators. A usable agreement has to specify the purpose of the data disclosure, limit the scope of information shared to what that purpose requires, set a timeline for the work, and require the outside party to destroy or return the data once it's done.

The same logic — narrow purpose, defined scope, an end date, a destruction requirement — is what districts should be asking edtech vendors to put in writing too, even when the contract runs through the school-official exception rather than the studies exception.

Does COPPA add anything FERPA doesn't cover?

Yes, for students under 13. FERPA governs education records regardless of a student's age, but the Children's Online Privacy Protection Act separately requires parental consent before a company collects personal information online from a child under 13. The Federal Trade Commission's guidance for edtech companies and schools spells out the workaround districts use: a school can consent on a parent's behalf, but — in the FTC's words — "only if such information is used for a school-authorized educational purpose and for no other commercial purpose."

The FTC's guidance ties several conditions to that school-consent standing: the vendor has to give the school the COPPA-required notice of what it collects and why, can't use student data to build advertising profiles or target ads, and has to let the school review the data collected and have it deleted on request. A vendor that can't meet those terms can't rely on a school's consent to stand in for a parent's.

Does the mechanism change for AI-branded tools?

No. FERPA and COPPA are technology-neutral — the school-official exception and the COPPA school-consent standing apply to a chatbot or an AI tutor the same way they apply to a gradebook, because both laws regulate what happens to the data, not the label on the product. A vendor calling its tool "AI-powered" doesn't unlock a new legal category or a lighter compliance bar.

That framing matters because AI tools are exactly where districts have recently pushed back. Coverage tracked by Education Week's student-privacy reporting has followed districts raising data-handling concerns about state-required AI assessments and other AI-branded classroom products — friction that traces back to the same direct-control and purpose-limitation questions this piece walks through, not to anything unique about AI as a category.

What can't a vendor do, even with a signed agreement?

The Department's vendor guidance draws a hard line around commercial use. Under the school-official exception, a company may not use student data for targeted advertising to students or their families, may not sell or mine personally identifiable information for marketing, and may not repurpose data beyond what the contract authorizes — carving out only narrow exceptions, such as security functions like malware detection, that serve the service itself rather than a separate business purpose.

Re-disclosure is the other bright line: a vendor that received data under the school-official exception generally can't hand it to a third party without the district's authorization, even if that third party is another edtech company.

What should a teacher or tech lead actually check before adopting a tool?

  1. Confirm the district's own policy defines "school official" broadly enough to cover the vendor — an individual teacher signing a free-tier terms-of-service page usually isn't enough to invoke FERPA's exception at all.
  2. Ask whether the vendor's terms of service can change without direct notice to the district; if they can, direct control is hard to demonstrate later.
  3. Look for a stated purpose limit — data used only for the contracted educational function, not shared or repurposed for the vendor's other products.
  4. For any tool likely to be used by students under 13, check that the vendor names COPPA compliance and describes how a school reviews or deletes collected data.
  5. Check for a deletion or data-return clause tied to the end of the contract, not an indefinite retention default.

None of this requires legal training to check. It requires reading the data-practices section of a contract instead of skipping to the pricing page — and treating a vendor's silence on any of these points as an answer.

The verdict, by reader

For a district weighing a new platform: the school-official exception is permission to move fast, not permission to skip oversight — direct control and a written scope limit are the two things that hold up if a parent or the Department ever asks how a vendor got access to records.

For a single classroom teacher adopting a free tool independently: FERPA's exception is built around the district's oversight, not an individual teacher's account creation, so a tool adopted outside district review may not be covered by it at all — worth raising with a building or district tech lead before rostering a full class.

What the sourced guidance does not establish is a single compliance checklist that guarantees a tool is safe; FERPA and COPPA set conditions and prohibitions, not a certification a vendor can earn once and be done with.

For a related edtech news perspective, read British Royal music featured on Gossip Stone TV reality TV show by Debbie Wingham.

Sources

  1. U.S. Department of Education, Student Privacy Policy Office — Responsibilities of Third-Party Service Providers under FERPA (Vendor FAQ)
  2. U.S. Department of Education, Student Privacy Policy Office — Responsibilities of Third-Party Service Providers under FERPA (Vendor FAQ)
  3. U.S. Department of Education, Privacy Technical Assistance Center — Written Agreement Checklist
  4. U.S. Department of Education — Protecting Student Privacy (studentprivacy.ed.gov)
  5. Federal Trade Commission — COPPA Guidance for Ed Tech Companies and Schools
  6. Education Week — Student Privacy coverage