School leaders operating under FERPA, PPRA, COPPA, and CIPA have one core duty: protect education records, notify affected parties when required, and document every disclosure. Here is the five-step compliance checklist every district should have in place now.
Five-step compliance checklist:
- Policy review. Confirm your district's student data privacy policy references current federal statutes and any applicable state law.
- Vendor agreements. Audit every active edtech contract for written data-use limitations, redisclosure restrictions, and breach-notification timelines.
- Access controls. Implement role-based access and least-privilege permissions for all systems that store education records.
- Annual notice. Send parents and eligible students the required annual FERPA notification before the school year begins.
- Incident response plan. Maintain a written, tested plan that assigns roles and specifies notification steps.
If you suspect a breach right now:
- Isolate affected systems within the first hour.
- Preserve logs before any remediation changes overwrite them.
- Notify your superintendent, legal counsel, and IT director immediately.
- Open a written incident record and timestamp every action.
The U.S. Department of Education's Student Privacy Policy Office (SPPO) publishes model notices, FAQs, and training materials that should anchor every district's compliance program.
Pro Tip: Print this checklist and post it in your IT director's office and your privacy officer's workspace. Compliance gaps surface fastest when the list is visible, not buried in a policy binder.
Key Takeaways
Federal law (FERPA, PPRA, COPPA, CIPA) sets the compliance floor for student data privacy, but state laws, vendor agreements, and technical controls determine whether that floor actually holds in practice.
| Point | Details |
|---|---|
| Federal law is the baseline | FERPA, PPRA, COPPA, and CIPA each cover different scopes; districts must satisfy all that apply. |
| Vendor contracts are compliance documents | Every edtech vendor receiving student PII needs a written agreement with data-use limits, breach-notification timelines, and deletion requirements. |
| Access controls prevent most violations | Role-based access, least privilege, MFA, and audit logging address the majority of FERPA exposure points. |
| Annual notice is a legal obligation | Parents and eligible students must receive FERPA notification annually; model notices are available from DOE/SPPO. |
| Jonathanjboone offers direct advisory support | Policy audits, contract review, executive workshops, and tabletop exercises are available for district and higher education leaders. |
Table of Contents
- Which federal student data privacy laws apply to your school?
- How state student-privacy laws differ and how to track them
- What to require of vendors and third parties
- How to map FERPA principles to technical and administrative controls
- What parental and eligible-student rights require operationally
- What to do in the first 72 hours after a suspected breach
- A 6-month implementation timeline with roles and milestones
- Where to find model notices, templates, and authoritative resources
- Compliance without culture is just paperwork
- How Jonathanjboone supports district leaders on student data privacy
- Sources
Which federal student data privacy laws apply to your school?
Four federal statutes form the baseline for protecting student data in U.S. schools. Each covers a different scope, and knowing where they overlap prevents both gaps and redundant effort.
FERPA
The Family Educational Rights and Privacy Act, codified at 20 U.S.C. § 1232g, applies to any educational institution that receives federal funding. It gives parents the right to inspect, amend, and control disclosure of their child's education records. Those rights transfer to the student at age 18 or upon enrollment in a postsecondary institution. The implementing regulations at 34 CFR Part 99 detail recordkeeping requirements (§99.32), redisclosure limits (§99.33), and conditions for sharing records with other education agencies (§99.34). Enforcement sits with the DOE; noncompliance can result in loss of federal funding.
PPRA
The Protection of Pupil Rights Amendment governs surveys, analyses, and evaluations funded by the DOE that ask students about sensitive topics including political affiliations, mental health, sexual behavior, and family income. Schools must provide parents advance notice and an opportunity to opt out. PPRA also applies to marketing surveys conducted by third parties. The DOE administers and enforces PPRA alongside FERPA.
COPPA
The Children's Online Privacy Protection Act applies to commercial operators of websites and online services directed at children under 13. For schools, COPPA is most relevant when deploying apps or platforms that collect personal data from students in that age range. Schools can provide consent on behalf of parents for school-authorized educational uses, but that consent does not extend to commercial data collection. The Federal Trade Commission enforces COPPA.
CIPA
The Children's Internet Protection Act requires schools that receive certain federal E-rate funding to implement internet-safety policies and content-filtering technology. FCC guidance specifies that compliant schools must block or filter visual depictions that are obscene, contain child pornography, or are harmful to minors, and must adopt an acceptable-use policy covering minor students' online activity.
| Law | Applies to | Consent / exceptions | Recordkeeping | Enforcement / penalties |
|---|---|---|---|---|
| FERPA | K-12 and higher ed receiving federal funds | Written consent required; exceptions include school officials with legitimate educational interest, judicial orders, health/safety emergencies | Record every request and disclosure; retain with education records | DOE/SPPO; loss of federal funding |
| PPRA | K-12 receiving DOE funds; third-party marketing surveys | Advance notice; opt-out for sensitive surveys; opt-in for certain marketing | Document notice and opt-out records | DOE; complaint-based review |
| COPPA | Commercial operators; schools deploying apps for under-13 students | Verifiable parental consent; school-as-agent exception for educational use only | Operator must retain consent records | FTC; civil penalties per violation |
| CIPA | Schools and libraries receiving E-rate funds | Acceptable-use policy required; public notice and hearing | Policy documentation; certification to E-rate program | FCC; loss of E-rate funding |
Pro Tip: When your procurement team reviews a new edtech platform, map the vendor's data practices to each statute's column above. A platform collecting biometric data from students under 13 triggers COPPA and likely FERPA simultaneously. Catch that overlap before the contract is signed.
How state student-privacy laws differ and how to track them
Federal law sets a floor. States routinely raise it, and the variation across jurisdictions is significant enough that a district near a state border or operating a virtual program across state lines needs a deliberate tracking strategy.
The most common state model is a vendor-focused restriction law modeled on California's Student Online Personal Information Protection Act (SOPIPA). These laws prohibit edtech vendors from using student data for targeted advertising, selling student data, or building profiles for non-educational purposes. Many states have enacted their own SOPIPA-style statutes, and the FPF Policymaker's Guide to Student Privacy notes that rapid edtech adoption has outpaced legacy privacy frameworks, making these vendor-focused laws an increasingly critical layer of protection.
A second common model is the Student DATA Act approach, which places governance obligations directly on districts rather than vendors. These laws require districts to publish data inventories, adopt formal data governance policies, and designate a privacy officer.
Common state requirements administrators should expect:
- A ban on commercial use of student data by vendors, including behavioral advertising.
- Data retention limits specifying how long vendors may retain student records after contract termination.
- Breach notification timelines that are often shorter than the federal baseline (some states require notification within 30 days of discovery).
- Auditing rights allowing districts to inspect vendor data practices on demand.
- Parental access rights that expand on FERPA's baseline, sometimes including the right to request deletion.
- Designation of a district-level student data privacy officer or coordinator.
To track state law changes, subscribe to the Future of Privacy Forum's policy updates, monitor your state education agency's legal bulletins, and check the Parent Coalition for Student Privacy at StudentPrivacyMatters.org, which maintains a state law tracker updated as legislatures act. Your district's legal counsel should also flag relevant bills during each legislative session.
What to require of vendors and third parties
Written agreements are not optional under FERPA. Any vendor that receives personally identifiable information from education records must be designated as a "school official" with a "legitimate educational interest," and that designation must be documented in a written agreement that limits the vendor's use of the data to the contracted educational purpose. State laws often add further requirements on top of this baseline.
The DOE's data security guidance warns that insufficient security controls at the vendor level can produce FERPA violations at the district level. That means your vendor contracts are a direct extension of your compliance posture.
Key principle from DOE guidance: A vendor that receives student PII under a FERPA school-official exception is bound by the same redisclosure limits as the school itself. The vendor cannot share that data with a subprocessor, analytics partner, or parent company without the district's authorization and a compliant written agreement covering that subprocessor.
Vendor inventory template fields every district should maintain:
| Field | What to capture |
|---|---|
| Product / service name | Official product name and version |
| Vendor contact | Name, email, and phone of the vendor's privacy or legal contact |
| Data types collected | Categories of student PII (name, ID, grades, behavioral data, biometrics) |
| Legal basis | FERPA school-official exception, COPPA school-agent consent, or other |
| Retention period | How long vendor retains data; deletion timeline at contract end |
| Subprocessor list | All third parties the vendor shares data with |
| Last security review | Date of most recent SOC 2 report, penetration test, or equivalent |
Sample contract clause categories to include:
- Data-use limitation. Vendor may use student PII only to provide the contracted service and for no other purpose.
- No commercial use. Vendor may not sell, rent, or use student data for advertising or to build commercial profiles.
- Security controls. Vendor must maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data.
- Breach notification. Vendor must notify the district within a specified number of hours (typically 24–72) of discovering a breach or suspected breach.
- Audit rights. District may request documentation of vendor security practices and data handling on reasonable notice.
- Deletion at contract end. Vendor must certify deletion or return of all student PII within a specified period after contract termination.
During procurement, ask vendors for their most recent SOC 2 Type II report or equivalent security attestation. Red flags include vendors who cannot identify their subprocessors, who resist audit-rights clauses, or whose data-retention terms survive contract termination indefinitely. The DOE's SPPO publishes model terms of service for online educational services that districts can adapt directly into their procurement templates.
Pro Tip: Build the vendor questionnaire into your procurement workflow before any pilot program launches. A 30-day pilot with an unvetted vendor can create a FERPA disclosure that is difficult to remediate after the fact.
How to map FERPA principles to technical and administrative controls
FERPA does not prescribe specific technical controls, but the DOE's data security resources make clear that inadequate security can itself constitute a FERPA violation. The practical translation is straightforward: every FERPA concept maps to a modern control.
FERPA concept to control mapping:
| FERPA concept | Technical / administrative control |
|---|---|
| Access (who may view records) | Role-based access control (RBAC); directory services tied to job function |
| Legitimate educational interest | Least-privilege permissions; access requests require documented justification |
| Disclosure control | Data loss prevention (DLP) tools; contractual API restrictions on vendor data pulls |
| Recordkeeping of disclosures | Centralized audit logging; SIEM integration for log retention and alerting |
| Consent and notice | Identity and access management (IAM) workflows; annual notice distribution tracking |
Retention schedule guidance. Education records must be retained as long as the student's file is active and for a period after the student leaves the district, consistent with your state's records-retention schedule. Logs supporting FERPA compliance (access logs, disclosure records) should be retained for at least as long as the underlying education records they document. Deletion should be documented and verifiable.
Logging requirements. Capture login events, record-access events, export or download events, and any administrative changes to access permissions. Retain logs in a tamper-evident format. Logs are your primary evidence in an incident investigation and your documentation of compliance with 34 CFR Part 99 recordkeeping requirements.
District readiness controls checklist:
- Multi-factor authentication (MFA) on all systems storing education records.
- Encryption at rest and in transit for all student PII.
- Quarterly access-rights reviews to remove stale permissions.
- Vendor API access scoped to minimum necessary data fields.
- Written incident response plan tested at least annually.
Pro Tip: Require contractual SIEM log access from your major SIS and LMS vendors. If a breach originates in a vendor environment, your ability to reconstruct the event depends on logs you may not control. Negotiate that access before you sign.
What parental and eligible-student rights require operationally
FERPA grants parents and eligible students three core rights: the right to inspect education records, the right to request amendment of inaccurate records, and the right to consent to disclosure. Districts must notify families of these rights annually.

Annual notice requirements
The annual notice must inform parents and eligible students of their right to inspect and review education records, the procedure for requesting access, the right to request amendment, the conditions under which the district may disclose records without consent, the right to file a complaint with the DOE, and the district's definition of "school officials" and "legitimate educational interest." The DOE's FERPA resources include a model annual notice that districts can adapt.
Access and amendment requests
| Step | Timeline / requirement |
|---|---|
| Receive written access request | Log date received; assign to privacy officer |
| Provide access for inspection | Within the FERPA-mandated timeframe for requests |
| Respond to amendment request | Reasonable time; notify parent/student of decision |
| If amendment denied | Inform parent/student of right to a hearing |
| Record the disclosure | Log in the student's education record per §99.32 |
No fee may be charged for inspection of records. Fees for copies are permissible as long as they do not effectively prevent access. Every disclosure made in response to a request must be recorded and retained with the student's education records.
Directory information and opt-outs
Districts may designate certain data elements (name, address, phone number, enrollment status, participation in activities) as "directory information" and disclose them without consent, provided the district has given annual notice of the categories it designates and allowed a reasonable time for parents to opt out. Operationally, this means maintaining an opt-out list, flagging opted-out students in your SIS, and training front-desk and communications staff to check that flag before releasing any directory data.
For testing accommodations and related consent processes, districts coordinating with external testing organizations should review consent templates such as those used in educational testing contexts to understand how layered consent and notice obligations interact.
What to do in the first 72 hours after a suspected breach
A data breach involving student education records can trigger FERPA review by the DOE/SPPO, state breach-notification obligations, and contractual vendor remedies simultaneously. Speed and documentation matter equally.
First 72-hour incident response checklist:
- Hour 1: Contain. Isolate affected systems or accounts. Revoke compromised credentials. If the breach originates with a vendor, invoke your contract's breach-notification clause and request immediate isolation.
- Hour 2–4: Preserve. Capture and preserve logs before any remediation activity that could overwrite them. Assign a forensic lead or engage outside counsel with forensic capability.
- Hour 4–12: Assess scope. Identify what data was accessed or exfiltrated, how many students are affected, and which records categories are involved.
- Hour 12–24: Notify internally. Brief superintendent, legal counsel, communications, and board leadership. Do not make public statements until legal counsel has reviewed.
- Hour 24–72: Prepare preliminary record. Document every action taken, every person notified, and every system affected. This record becomes the foundation of your FERPA disclosure log and any regulatory filing.
A breach that exposes student PII from education records can prompt a DOE/SPPO review if a complaint is filed. State attorneys general may also open investigations under state breach-notification laws, which often have shorter notification windows than federal law. Typical cost drivers include forensic investigation, legal fees, notification costs, credit monitoring for affected students and families, and potential contract remedies with vendors.
Post-72-hour tasks:
- Complete forensic investigation and finalize scope determination.
- Send required notifications to parents, state agencies, and any contractually required vendor or partner notifications.
- Remediate the vulnerability that enabled the breach.
- Document all remediation steps and retain records.
- Invoke contract remedies against any vendor whose security failure caused or contributed to the breach.
- Conduct a post-incident review and update the incident response plan.
The SPPO's guidance on recordkeeping and disclosure applies directly to breach documentation: every disclosure of student PII made during incident response must be logged and retained.

A 6-month implementation timeline with roles and milestones
Standing up or remediating a student data privacy program in six months is achievable with clear role assignments and measurable milestones. The table below maps tasks to a RACI framework across the district's key roles.
| Month | Milestone | Owner (R) | Accountable (A) | Consulted (C) | Informed (I) |
|---|---|---|---|---|---|
| 1 | Policy gap analysis; inventory all systems holding student PII | Privacy Officer | Superintendent | Legal, IT | Board |
| 1–2 | Vendor inventory complete; contracts flagged for update | Procurement | Privacy Officer | Legal | IT |
| 2–3 | Contract updates executed for highest-risk vendors | Legal | Superintendent | Procurement, Privacy Officer | IT |
| 3 | Technical controls audit: RBAC, MFA, encryption verified | IT Director | Privacy Officer | Vendors | Legal |
| 3–4 | Annual notice updated and distributed; opt-out process tested | Privacy Officer | Superintendent | Legal, Communications | Principals |
| 4–5 | Staff training completed; training records documented | HR / Privacy Officer | Superintendent | IT | All staff |
| 5–6 | Tabletop incident exercise conducted; plan updated | IT Director | Privacy Officer | Legal, Communications | Superintendent |
| 6 | Compliance audit: percent contracts updated, percent staff trained | Privacy Officer | Superintendent | Legal, IT | Board |
Milestones and metrics to track progress:
- Percent of active vendor contracts updated with compliant data-use terms (target: 100% of high-risk vendors by month 3).
- Percent of staff who have completed privacy training (target: all staff trained before the new school year).
- Number of systems with MFA enabled (target: all systems storing student PII by month 3).
- Tabletop exercise completed and after-action report filed (target: month 5–6).
The FPF Policymaker's Guide recommends treating privacy as a dynamic, ongoing commitment rather than a one-time project. Build a quarterly review cycle into your calendar after the six-month sprint ends.
Pro Tip: Sequence procurement controls before you approve any new edtech deployments. A district that locks down vendor vetting first prevents new compliance debt from accumulating while it remediates existing contracts.
Where to find model notices, templates, and authoritative resources
The resources below are the primary references for district policy work. Bookmark them and share them with your legal counsel and privacy officer.
- DOE Student Privacy Policy Office (SPPO). The central hub for FERPA and PPRA guidance, model notices, FAQs, and webinar recordings. Start here for any compliance question.
- DOE FERPA topic pages. Regulatory excerpts, template annual notices, and examples covering directory information, dual-enrollment records, and photo/video edge cases.
- DOE data security resources. Model Terms of Service for online educational services and best-practice guidance on technical safeguards for K-12 and higher education.
- 34 CFR Part 99 (eCFR). The implementing regulations for FERPA. Bookmark §99.32 (recordkeeping), §99.33 (redisclosure), and §99.34 (disclosure to other education agencies).
- FCC CIPA guidance. Filtering, acceptable-use policy, and E-rate certification requirements.
- FPF Policymaker's Guide to Student Privacy. A practical guide covering state law trends, procurement vetting, and policy frameworks for district leaders.
- Parent Coalition for Student Privacy (StudentPrivacyMatters.org). State law tracker, model policies, and advocacy resources updated as state legislatures act.
- Prepadmit privacy policy. An example of operational privacy policy language for online educational products, useful as a reference when drafting or reviewing vendor privacy disclosures.
Most useful templates for immediate use:
- Model annual notice. Available from DOE/SPPO; adapt to include your district's specific directory information categories and opt-out procedure.
- Directory information template. Lists the categories your district designates and the opt-out deadline.
- Vendor questionnaire. Use the inventory fields from Section 4 above as your baseline; add state-specific requirements.
- Incident response checklist. Adapt the 72-hour checklist from Section 7 into a laminated one-page card for your IT and legal teams.
Compliance without culture is just paperwork
Legal compliance and ethical stewardship of student data are not the same thing, though they are often treated as if they were. A district can check every FERPA box and still erode the trust of the families it serves, if the underlying culture treats privacy as a burden rather than a commitment.
The compliance tasks in this guide are real and necessary. But the districts that do this work well are the ones where privacy is embedded in procurement decisions, staff onboarding, and vendor conversations from the start, not retrofitted after a breach or a regulatory complaint. That shift from reactive to proactive is a leadership choice, not a legal requirement.
The intersection of law, technology, and organizational culture is exactly where the hardest student data decisions live. Getting the contracts right matters. Getting the culture right is what makes the contracts hold.
How Jonathanjboone supports district leaders on student data privacy
Jonathanjboone works directly with higher education institutions and district leadership teams on the policy, legal, and cultural dimensions of student data governance. The work is concrete: policy audits that identify gaps against current federal and state requirements, vendor contract review sessions that translate statutory obligations into enforceable terms, executive workshops that build staff capacity across IT, legal, and administration, and tabletop incident exercises that test your response plan before a real breach does.

This is paid advisory work, not a subscription or a software platform. District leaders who engage Jonathanjboone get direct access to expertise at the intersection of higher education law, responsible technology governance, and organizational strategy. If your district is standing up a privacy program, remediating vendor contracts, or preparing leadership for the governance demands of AI-powered edtech, the next step is a direct conversation. Visit Jonathanjboone to learn about available engagements and request an initial consultation.
Sources
The sources below are the primary references used throughout this guide. Add them to your district's policy resource library.
- | Protecting Student Privacy
- Data Security: K-12 and Higher Education | Protecting Student Privacy
- STUDENT DATA PRIVACY
- eCFR - 34 CFR Part 99
- Childrens Internet Protection Act
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
