FERPA is often filed under "registrar problems." That is a mistake. FERPA compliance lives and dies in IT systems: access controls, cloud platforms, identity management, data sharing, and vendor oversight.
If your organization handles student data - as a school or as one of its vendors - FERPA is a security and risk management obligation, not just an administrative one.
The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law that protects the privacy of student education records - it governs how educational institutions, and the vendors acting for them, collect, use, store, and disclose student information (U.S. Department of Education; regulations at 34 CFR Part 99).
FERPA exists to grant three core rights. Parents and eligible students may:
1. Inspect and review the student's education records 2. Seek amendment of records that are inaccurate, misleading, or in violation of the student's privacy rights 3. Consent to disclosures of personally identifiable information, subject to the law's enumerated exceptions
These rights belong to parents until the student turns 18 or enters a postsecondary institution - then they transfer to the student, who becomes an "eligible student" under the law.
Every one of those rights is an IT capability in disguise. Inspection requires retrieval. Amendment requires change control. Consent requires disclosure tracking. Systems that cannot do these things cannot support compliance, whatever the policy binder says.
FERPA applies to educational agencies and institutions that receive funds under any program administered by the U.S. Department of Education (34 CFR § 99.1). The funding condition is the gate - it is what makes FERPA nearly universal in public education and conditional everywhere else.
The exception that surprises people: private and religious K-12 schools that accept no Department of Education funds are not covered by FERPA. Coverage follows the funding, not the word "school."
FERPA reaches vendors differently than laws like HIPAA - there is no FERPA equivalent of a business associate. Instead, an outside party handles education records as a "school official" when it performs an institutional service the school would otherwise use employees for, is under the institution's direct control regarding the records, and uses them only for authorized purposes (34 CFR § 99.31(a)(1); ED student privacy FAQ).
That framing matters for:
The compliance obligation stays with the institution. FERPA binds the schools you serve - vendors handle education records as school officials under the institution's direct control, and institutions remain accountable for what their vendors do. If you sell into education, your customers' FERPA exposure is your contract requirement.
FERPA protects education records: records that are directly related to a student and maintained by an educational agency or institution, or by a party acting for it (34 CFR Part 99).
Examples include:
The directory information exception: properly designated directory information - such as name, address, email, or photograph, but never Social Security numbers - may be disclosed without consent after the institution gives public notice and an opportunity to opt out (34 CFR § 99.37). IT systems must honor those opt-outs record by record, which makes this an access-control problem, not a policy footnote.
In our experience, most student data stored electronically at a covered institution ends up FERPA-regulated - which is why data mapping comes before everything else.
FERPA often overlaps with:
FERPA is not optional and cannot be bypassed by internal policy. Institutions are accountable for how vendors handle student data, not just how staff do.
FERPA does not prescribe specific technologies. It requires "reasonable methods" to protect student records from unauthorized access or disclosure (34 CFR § 99.31(a)(1)(ii)) - and in practice, reasonable methods means the controls below.
FERPA strictly limits when and how student records may be disclosed. IT systems must support:
Schools and institutions remain responsible for:
FERPA violations can lead to:
In our experience, FERPA incidents commonly trace to overly broad system access, misconfigured cloud platforms, inadequate vendor controls, poor identity and access management, and missing monitoring or documentation. None of these require a sophisticated attacker. Most are self-inflicted.
FERPA aligns closely with the NIST Cybersecurity Framework, ISO 27001, SOC 2, and general data protection practice - the same controls, aimed at student records.
That overlap is the efficiency: institutions that manage FERPA well typically have strong overall security posture, because access governance, monitoring, and vendor oversight protect every other data type too.
Our Cyber Risk Management service treats FERPA as one obligation inside one program - not a standalone project competing for the same budget.
Here is the simple truth: FERPA compliance is mostly about controlling access and preventing unnecessary exposure.
Strong identity management, secure configurations, and clear accountability prevent the failures we see most often. /* J3 pending - signature claim kept non-numeric per decision */
FERPA doesn't require cutting-edge tools. It requires discipline and visibility - knowing where student records live, who can touch them, and being able to prove both.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment maps where student records actually live, tests whether access matches roles, and reviews your vendor relationships against FERPA's school-official conditions - direct control included.
Document the systems storing education records, cloud platforms and SaaS tools, who has access, and every vendor and integration touching the data. You cannot control disclosure of records you have not located.
Ensure access is role-based, permissions match job responsibilities, administrative access is limited, and access reviews happen on a schedule - with evidence. Include directory-information opt-outs in the review.
Implement MFA where feasible, encryption of data and backups, endpoint and email security, and secure remote access. The controls are ordinary; applying them everywhere student data lives is the work.
Confirm contracts define data use restrictions, vendors meet the school-official conditions - institutional service, direct control, authorized purposes only - and access is limited and monitored. The institution answers for the vendor either way.
Employees must understand what counts as an education record, how student data should be handled, how to recognize and report incidents, and why FERPA violations are serious. Most exposure starts with a well-meaning shortcut.
Not directly - FERPA binds the educational institutions you serve. Vendors handle education records as "school officials" under the institution's direct control, using data only for authorized purposes. The institution holds the legal obligation, which is why your education customers put FERPA terms in your contract.
Only if they receive funds under a program administered by the U.S. Department of Education. Private and religious K-12 schools that accept no ED funds are not covered. Most public schools and nearly all colleges participating in federal student aid are.
Any record directly related to a student and maintained by the institution or a party acting for it - grades, transcripts, attendance, discipline, financial aid, special education records, schedules, and the digital versions in your SIS, LMS, email, and cloud platforms.
Directory information is data the institution designates as generally not harmful if disclosed - name, address, email, photograph, and similar, never Social Security numbers. It may be shared without consent only after public notice and an opt-out opportunity, and your systems must honor each opt-out.
Three: inspect and review the student's education records, seek amendment of inaccurate or misleading records, and consent to disclosures outside FERPA's exceptions. Those rights transfer from parent to student at 18 or upon entering a postsecondary institution.
The Department of Education's enforcement runs from investigation and required corrective action up to withholding federal payments or terminating funding eligibility. Alongside that: regulatory scrutiny, legal exposure, and the trust damage that follows any student data incident.
It depends on how many systems and vendors touch student records. We don't publish pricing - you get a firm quote after the assessment, and the conversation costs nothing.
Start with a data map: every system, platform, and vendor holding student records, and who can access each. Our Cyber Risk & Compliance Gap Assessment builds that map and turns it into a prioritized FERPA roadmap.
Florida schools and colleges carry a state-law layer alongside FERPA. The Florida Information Protection Act (F.S. 501.171) covers commercial and governmental entities alike - school districts, public colleges, and the vendors serving them included - and its definition of personal information reaches much of what a student information system holds: names paired with ID numbers, medical information, health insurance details, and biometric data.
When that data is breached, FIPA's deadlines run regardless of FERPA: affected individuals must be notified within 30 days of determining the breach, the Florida Department of Legal Affairs within 30 days when 500 or more Floridians are affected, and consumer reporting agencies when more than 1,000 are. Vendors holding the data as third-party agents must notify the institution within 10 days.
Late notice carries penalties of up to $1,000 per day for the first 30 days, then $50,000 per subsequent 30-day period, capped at $500,000. /* ⚖️ counsel-flagged penalty figures - verified against F.S. 501.171(9) 2026-07-25 */
For Treasure Coast school districts, private schools, and colleges, the practical takeaway: a student-data incident starts two clocks at once - the Department of Education's FERPA expectations and Florida's 30-day notification deadlines.
Official source: U.S. Department of Education, Student Privacy Policy Office
Secondary source: eCFR — 34 CFR Part 99
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25