What Is FERPA and Why It Matters

FERPA is often filed under "registrar problems." That is a mistake. FERPA compliance lives and dies in IT systems: access controls, cloud platforms, identity management, data sharing, and vendor oversight.

If your organization handles student data - as a school or as one of its vendors - FERPA is a security and risk management obligation, not just an administrative one.

What It Is

The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law that protects the privacy of student education records - it governs how educational institutions, and the vendors acting for them, collect, use, store, and disclose student information (U.S. Department of Education; regulations at 34 CFR Part 99).

FERPA exists to grant three core rights. Parents and eligible students may:

1. Inspect and review the student's education records 2. Seek amendment of records that are inaccurate, misleading, or in violation of the student's privacy rights 3. Consent to disclosures of personally identifiable information, subject to the law's enumerated exceptions

These rights belong to parents until the student turns 18 or enters a postsecondary institution - then they transfer to the student, who becomes an "eligible student" under the law.

Every one of those rights is an IT capability in disguise. Inspection requires retrieval. Amendment requires change control. Consent requires disclosure tracking. Systems that cannot do these things cannot support compliance, whatever the policy binder says.

Who It Applies To

FERPA applies to educational agencies and institutions that receive funds under any program administered by the U.S. Department of Education (34 CFR § 99.1). The funding condition is the gate - it is what makes FERPA nearly universal in public education and conditional everywhere else.

Educational Institutions

  • Public K-12 schools and school districts: effectively always covered
  • Charter schools: covered as public schools
  • Colleges and universities: covered through federal student aid and other ED programs
  • Postsecondary institutions generally: including trade and technical schools receiving Title IV aid

The exception that surprises people: private and religious K-12 schools that accept no Department of Education funds are not covered by FERPA. Coverage follows the funding, not the word "school."

Vendors and Service Providers

FERPA reaches vendors differently than laws like HIPAA - there is no FERPA equivalent of a business associate. Instead, an outside party handles education records as a "school official" when it performs an institutional service the school would otherwise use employees for, is under the institution's direct control regarding the records, and uses them only for authorized purposes (34 CFR § 99.31(a)(1); ED student privacy FAQ).

That framing matters for:

  • EdTech and SaaS providers
  • LMS and student information system vendors
  • Cloud service providers
  • MSPs and IT providers
  • Assessment, testing, and analytics platforms
  • Consultants and contractors with student data access

The compliance obligation stays with the institution. FERPA binds the schools you serve - vendors handle education records as school officials under the institution's direct control, and institutions remain accountable for what their vendors do. If you sell into education, your customers' FERPA exposure is your contract requirement.

What Information Is Regulated

FERPA protects education records: records that are directly related to a student and maintained by an educational agency or institution, or by a party acting for it (34 CFR Part 99).

Examples include:

  • Student names, IDs, and contact information: when held in education records
  • Grades, transcripts, and academic records: the classic case
  • Attendance and disciplinary records: often the most sensitive
  • Financial aid information: family finances included
  • Special education records: layered with additional protections
  • Student schedules and class enrollment
  • Digital records in LMS, SIS, email, or cloud platforms: the format does not matter; the relationship to the student does

The directory information exception: properly designated directory information - such as name, address, email, or photograph, but never Social Security numbers - may be disclosed without consent after the institution gives public notice and an opportunity to opt out (34 CFR § 99.37). IT systems must honor those opt-outs record by record, which makes this an access-control problem, not a policy footnote.

In our experience, most student data stored electronically at a covered institution ends up FERPA-regulated - which is why data mapping comes before everything else.

Relation to Other Frameworks

FERPA often overlaps with:

  • COPPA: for children under 13 using online services, the FTC's rule adds its own consent requirements (FTC)
  • State privacy laws: including CCPA/CPRA in some contexts, plus state-specific student privacy statutes
  • GLBA and the FTC Safeguards Rule: higher-ed institutions participating in federal student aid carry financial data obligations alongside FERPA
  • Cybersecurity frameworks and contractual requirements: NIST CSF, ISO 27001, and SOC 2 supply the control structure FERPA assumes but does not specify

FERPA is not optional and cannot be bypassed by internal policy. Institutions are accountable for how vendors handle student data, not just how staff do.

IT Requirements

FERPA does not prescribe specific technologies. It requires "reasonable methods" to protect student records from unauthorized access or disclosure (34 CFR § 99.31(a)(1)(ii)) - and in practice, reasonable methods means the controls below.

Access Controls & Identity Management

  • Role-based access to student records: teachers see their students, not the district
  • Least-privilege permissions: access matched to job function
  • Strong authentication: MFA where possible
  • Immediate access removal when roles change: the departed employee's account is the classic failure

Data Protection & Secure Storage

  • Secure cloud and on-prem systems: hardened configurations either way
  • Encryption of sensitive data: at rest and in transit
  • Secure backups and recovery: protected copies, tested restores
  • Protection of data in transit: between campus, cloud, and vendors

Auditability & Monitoring

  • Logging of access to student records: who saw what, when
  • Ability to investigate unauthorized access: logs you can actually query
  • Documentation of access reviews: evidence that oversight happened

Controlled Disclosure & Data Sharing

FERPA strictly limits when and how student records may be disclosed. IT systems must support:

  • Controlled data sharing: approved paths, nothing ad hoc
  • Vendor restrictions: school-official access scoped to the authorized purpose
  • Purpose-based access: the reason for access built into the permission
  • Prevention of unauthorized exports or sharing: the bulk download is the breach
  • Directory-information opt-outs: enforced per student, automatically

Vendor & Third-Party Risk Management

Schools and institutions remain responsible for:

  • How vendors access student data: direct control is a FERPA condition, not a courtesy
  • Ensuring vendors use data only for authorized purposes: the school-official criteria in practice
  • Contractual safeguards and oversight: agreements that say it, and reviews that check it

Why It Matters

FERPA violations can lead to:

  • Loss of federal funding: the Department of Education's enforcement path runs from investigation to withholding payments, cease-and-desist orders, or termination of funding eligibility (34 CFR § 99.67) /* ⚖️ counsel-flagged penalty statement */
  • Regulatory investigations: complaint-driven, document-heavy, public
  • Legal exposure: state law and contract claims ride alongside federal enforcement
  • Reputational damage: parents do not forgive schools that leak their children's records
  • Loss of trust from students and parents: the asset no remediation restores quickly

In our experience, FERPA incidents commonly trace to overly broad system access, misconfigured cloud platforms, inadequate vendor controls, poor identity and access management, and missing monitoring or documentation. None of these require a sophisticated attacker. Most are self-inflicted.

How It Fits Into Cyber Risk Management

FERPA aligns closely with the NIST Cybersecurity Framework, ISO 27001, SOC 2, and general data protection practice - the same controls, aimed at student records.

That overlap is the efficiency: institutions that manage FERPA well typically have strong overall security posture, because access governance, monitoring, and vendor oversight protect every other data type too.

Our Cyber Risk Management service treats FERPA as one obligation inside one program - not a standalone project competing for the same budget.

How We Help With FERPA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps where student records actually live, tests whether access matches roles, and reviews your vendor relationships against FERPA's school-official conditions - direct control included.

How to Prepare

  1. 01Identify where student data lives

    Document the systems storing education records, cloud platforms and SaaS tools, who has access, and every vendor and integration touching the data. You cannot control disclosure of records you have not located.

  2. 02Review access controls

    Ensure access is role-based, permissions match job responsibilities, administrative access is limited, and access reviews happen on a schedule - with evidence. Include directory-information opt-outs in the review.

  3. 03Secure systems handling student data

    Implement MFA where feasible, encryption of data and backups, endpoint and email security, and secure remote access. The controls are ordinary; applying them everywhere student data lives is the work.

  4. 04Evaluate vendor and third-party risk

    Confirm contracts define data use restrictions, vendors meet the school-official conditions - institutional service, direct control, authorized purposes only - and access is limited and monitored. The institution answers for the vendor either way.

  5. 05Train staff

    Employees must understand what counts as an education record, how student data should be handled, how to recognize and report incidents, and why FERPA violations are serious. Most exposure starts with a well-meaning shortcut.

Frequently Asked Questions

Does FERPA apply to my business if we're not a school?

Not directly - FERPA binds the educational institutions you serve. Vendors handle education records as "school officials" under the institution's direct control, using data only for authorized purposes. The institution holds the legal obligation, which is why your education customers put FERPA terms in your contract.

Do private schools have to comply with FERPA?

Only if they receive funds under a program administered by the U.S. Department of Education. Private and religious K-12 schools that accept no ED funds are not covered. Most public schools and nearly all colleges participating in federal student aid are.

What counts as an education record under FERPA?

Any record directly related to a student and maintained by the institution or a party acting for it - grades, transcripts, attendance, discipline, financial aid, special education records, schedules, and the digital versions in your SIS, LMS, email, and cloud platforms.

What is directory information, and can we share it?

Directory information is data the institution designates as generally not harmful if disclosed - name, address, email, photograph, and similar, never Social Security numbers. It may be shared without consent only after public notice and an opt-out opportunity, and your systems must honor each opt-out.

What rights do parents and students actually have?

Three: inspect and review the student's education records, seek amendment of inaccurate or misleading records, and consent to disclosures outside FERPA's exceptions. Those rights transfer from parent to student at 18 or upon entering a postsecondary institution.

What happens if we violate FERPA?

The Department of Education's enforcement runs from investigation and required corrective action up to withholding federal payments or terminating funding eligibility. Alongside that: regulatory scrutiny, legal exposure, and the trust damage that follows any student data incident.

What does FERPA compliance cost?

It depends on how many systems and vendors touch student records. We don't publish pricing - you get a firm quote after the assessment, and the conversation costs nothing.

Where do we start?

Start with a data map: every system, platform, and vendor holding student records, and who can access each. Our Cyber Risk & Compliance Gap Assessment builds that map and turns it into a prioritized FERPA roadmap.

FERPA in Florida

Florida schools and colleges carry a state-law layer alongside FERPA. The Florida Information Protection Act (F.S. 501.171) covers commercial and governmental entities alike - school districts, public colleges, and the vendors serving them included - and its definition of personal information reaches much of what a student information system holds: names paired with ID numbers, medical information, health insurance details, and biometric data.

When that data is breached, FIPA's deadlines run regardless of FERPA: affected individuals must be notified within 30 days of determining the breach, the Florida Department of Legal Affairs within 30 days when 500 or more Floridians are affected, and consumer reporting agencies when more than 1,000 are. Vendors holding the data as third-party agents must notify the institution within 10 days.

Late notice carries penalties of up to $1,000 per day for the first 30 days, then $50,000 per subsequent 30-day period, capped at $500,000. /* ⚖️ counsel-flagged penalty figures - verified against F.S. 501.171(9) 2026-07-25 */

For Treasure Coast school districts, private schools, and colleges, the practical takeaway: a student-data incident starts two clocks at once - the Department of Education's FERPA expectations and Florida's 30-day notification deadlines.

Official source

Official source: U.S. Department of Education, Student Privacy Policy Office

Secondary source: eCFR — 34 CFR Part 99

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25