Uniqcli

What Is FERPA? Student Data Privacy for District IT Teams

Education records, the school-official exception that governs vendor access, and where the obligations land on disposal, backups, logging and endpoint security.

By Uniqcli Team

FERPA is the Family Educational Rights and Privacy Act, a federal law codified at 20 U.S.C. § 1232g with implementing regulations at 34 CFR Part 99. It protects personally identifiable information contained in student education records by restricting unauthorized disclosure, and it gives parents three rights: access to their children's education records, the ability to seek to have those records amended, and some control over the disclosure of personally identifiable information from them.

Those rights do not stay with parents forever. Per the U.S. Department of Education, once a student reaches 18 years old or attends a postsecondary institution at any age, the student becomes an eligible student and the rights under FERPA transfer to that student. Education records themselves are defined by two tests: records directly related to a student, and maintained by an educational agency or institution or by a party acting for the agency or institution.

That second test — maintained by a party acting for the institution — is why FERPA is a district IT topic and not only a registrar's topic. Every system a district contracts for that touches student information is a party acting for the district, and the conditions under which that is permitted are specific. This page is written for the IT and procurement audience: what FERPA is, how the school-official exception governs vendor access, and where the obligations land on device disposal, backup retention, network logging and endpoint controls. It is background, not legal advice — take actual compliance questions to your district's counsel and records officer.

What counts as an education record

The regulatory standard is broad and deliberately so: a record is an education record if it is directly related to a student and maintained by the educational agency or institution or by a party acting for it. Nothing in that test mentions a student information system, a filing cabinet or a particular format, which is why the boundary tends to be wider than an IT team's first instinct.

In a modern district the obvious inhabitants of that boundary are the student information system, the learning management system, assessment platforms, special-education case management, health office records and transportation routing. The less obvious ones are the interesting part: a rostering integration's synchronized data, an export sitting in a shared drive because someone was building a report, a device-management inventory that maps named students to assigned assets, and backup copies of any of the above.

The practical consequence for IT is that a data inventory is the foundation of everything else. A district that cannot say which systems hold student information, which integrations move it, and where copies land cannot meaningfully answer a records request, evaluate a vendor, or scope an incident. That inventory is unglamorous work and it is the single highest-value FERPA task an IT team owns.

The school-official exception: how vendors get access at all

FERPA generally requires consent before personally identifiable information from education records is disclosed, but it permits schools to outsource institutional services or functions involving such disclosure to contractors, consultants, volunteers and other third parties under what is commonly called the school-official exception. The Department of Education sets four conditions, and all of them have to hold.

The outside party must perform an institutional service or function for which the agency or institution would otherwise use employees. It must be under the direct control of the agency or institution with respect to the use and maintenance of education records. It must be subject to the requirement that personally identifiable information from education records may be used only for the purposes for which the disclosure was made. And it must meet the criteria specified in the school or local educational agency's annual notification of FERPA rights for being a school official with a legitimate educational interest in the education records.

Read as a procurement instruction, that list is unusually concrete. Direct control is a contract term, not a feeling about a vendor's reputation — it means the district dictates how the vendor uses and maintains the records. The use limitation is the clause that makes secondary use, product improvement on identifiable data and onward disclosure a contractual matter rather than a vendor policy matter. And the annual-notification criterion means a district's own FERPA notice has to define school official in a way that actually covers the contractors it uses — a gap that is invisible until someone checks.

The Department is also explicit that the responsibility does not transfer. When personally identifiable information from education records is disclosed to a provider, FERPA still governs its use, and the school or district is responsible for its protection. A vendor's compliance posture is evidence, not a transfer of accountability.

Directory information and the opt-out that has to reach your systems

FERPA carves out a category called directory information that may be disclosed without consent under conditions. It typically includes items such as a student's name, address, telephone listing, date and place of birth, participation in officially recognized activities and sports, and dates of attendance.

The conditions are procedural. A school may disclose directory information only if it has given public notice of the types of information it has designated as directory information, of the parent's or eligible student's right to restrict disclosure of that information, and of the period within which they must notify the school in writing that they do not want some or all of it designated as directory information. The Department notes several acceptable notice channels, including a registration package sent home, a notice in the local newspaper, the annual school handbook, or a posting on the school system's website. An opt-out made while the student was in attendance must be honored even after the student leaves, unless the student rescinds it.

For IT, directory information is a data-plumbing problem rather than a policy one. The opt-out flag lives in the student information system, and it has to reach every downstream consumer — the yearbook vendor's export, the athletics roster, the photo service, the district website's honors list, the family-directory application. A rostering integration that faithfully synchronizes names and does not carry the suppression flag is the mechanism by which a correctly honored opt-out becomes a published one.

Where FERPA lands on device disposal

Retired devices are the most physical FERPA exposure a district has. Student laptops, staff machines from the counselling office, imaging servers, spare drives pulled during repairs and the storage inside multifunction printers can all hold data that meets the education-record test, and a device leaving district control with that data intact is a disclosure waiting to be discovered.

The controls are well understood and mostly a matter of doing them consistently: verified sanitization or physical destruction of every storage device, an asset-level record of what was processed and what happened to it, chain-of-custody documentation from the moment a device leaves a building until it is destroyed or resold, and certificates that are matched back against the asset list rather than filed unread. A disposal program without a reconciliation step — comparing the devices that left against the certificates that came back — is a program that cannot detect a gap.

The device-management inventory matters here too, because it is what tells you which student was assigned which asset tag. That mapping is exactly what makes an incident scopeable, and it is also, itself, information directly related to students that should be handled accordingly. Our IT asset disposition explainer and chain-of-custody standard cover the mechanics; the FERPA angle is simply that the records on those devices are not ordinary corporate data.

Backups, logs and the questions IT should escalate

Two areas routinely generate questions IT should not answer alone. The first is backup retention against the amendment right. FERPA gives parents and eligible students the ability to seek to have records amended; districts also, increasingly, run immutable or write-once backups precisely so that ransomware cannot alter them. Those two facts sit in tension, and how a district reconciles them — what an amendment obligation means for historical backup sets, and how long those sets are kept — is a question for counsel and the records officer, decided once and written down, not improvised during a request.

The second is logging. Web-filtering logs, monitoring alerts, device-management telemetry and network authentication records can tie a named student to activity, and whether a given log meets the education-record test depends on how it is maintained and used rather than on what system produced it. The practical posture is to set retention deliberately with input from counsel rather than leaving appliances at their factory defaults, and to treat access to those logs as a controlled function with a defined list of who may query them and why.

A third, quieter question is the exported spreadsheet. Most districts' real student-data sprawl is not in a system of record but in extracts — rosters, intervention lists, testing files — that staff pulled for a legitimate reason and left in a shared drive or a personal cloud folder. Data-loss-prevention tooling and sensible sharing defaults help; a periodic sweep and a clear rule about where extracts may live helps more.

The endpoint controls worth standardizing

The endpoint side of student-data protection is unremarkable and effective. Full-disk encryption on every staff device, backed by a hardware root of trust — a TPM holds the keys so an encrypted drive removed from a laptop is inert — turns a stolen machine from a disclosure event into a property loss. Enforced screen lock, current patching, and a management platform that can verify encryption status across the fleet make that claim provable rather than assumed.

Remote wipe and device retirement should be tested rather than assumed. A district that has never actually run a wipe against a lost device does not know how long it takes, whether the device has to check in first, or what happens when it never does. Those answers matter on the day a counsellor's laptop goes missing with a caseload export on it.

What we can help with is the hardware side of that list: endpoints that ship with TPM 2.0 and support full-disk encryption, and a documented disposal path for the machines coming out of service. We do not certify FERPA compliance and nothing here is legal advice — the obligations, the contracts and the annual notification are the district's, and your counsel and records officer own them. Send us the requirement and we will quote the equipment against it.

Key takeaways

  • FERPA (20 U.S.C. § 1232g, 34 CFR Part 99) protects personally identifiable information in education records and gives parents rights of access, amendment and some control over disclosure.
  • Rights transfer to the student — who becomes an eligible student — at age 18 or on attending a postsecondary institution at any age.
  • An education record is one directly related to a student and maintained by the institution or by a party acting for it, which is why vendor systems are in scope.
  • The school-official exception permits vendor access only where all four Department of Education conditions hold, including direct control over use and maintenance of records and a strict use limitation.
  • Responsibility does not transfer to the vendor: FERPA still governs the information, and the district remains responsible for its protection.
  • Directory information may be disclosed without consent only after public notice, a stated opt-out right and a stated response window — and the opt-out flag has to propagate to every downstream system.
  • IT owns the physical and technical edges: verified device sanitization with chain of custody, deliberate backup and log retention decided with counsel, and encrypted endpoints anchored to a TPM.

Shop it at Uniqcli

Frequently asked

What does FERPA protect?
FERPA protects personally identifiable information contained in student education records by restricting unauthorized disclosure. It affords parents the right to access their children's education records, to seek to have those records amended, and to have some control over the disclosure of personally identifiable information from them. An education record is one that is directly related to a student and maintained by an educational agency or institution or by a party acting for it.
Can a district share student data with a software vendor without parental consent?
It can, under the school-official exception, but only if all four Department of Education conditions are met. The vendor must perform an institutional service or function the district would otherwise use employees for; be under the district's direct control with respect to the use and maintenance of education records; be subject to the requirement that the information is used only for the purposes for which it was disclosed; and meet the criteria for a school official with a legitimate educational interest as set out in the district's own annual FERPA notification. Those are contract and policy conditions, not vendor assurances.
Who is responsible if a vendor mishandles student data?
The district remains responsible. The Department of Education is explicit that when personally identifiable information from education records is disclosed to a provider, FERPA still governs its use, and the school or district is responsible for its protection. A vendor's certifications and audit reports are useful evidence when selecting a provider, but they do not shift the accountability.
Does FERPA apply to the data on a retired student laptop?
If the device holds records directly related to students that the district maintains, then those records are education records regardless of the medium they sit on. That is why disposal is a privacy control rather than a logistics task: verified sanitization or destruction of every storage device, chain-of-custody documentation from collection to destruction, and reconciliation of the certificates you get back against the asset list you sent out. A disposal process with no reconciliation step cannot detect a gap.
Are web-filtering logs student records under FERPA?
It depends on how they are maintained and used rather than on which appliance produced them, and it is a question to put to your counsel and records officer rather than to decide in the network team. The practical posture is to set retention deliberately instead of leaving factory defaults in place, restrict who can query logs that identify named students, and document both decisions. Districts frequently discover the answer matters only when a request or an incident arrives.
Is FERPA the same as CIPA?
No — they solve different problems. FERPA governs the privacy of student education records and who may see them. CIPA conditions certain federal discounts on a school adopting an internet safety policy with a technology protection measure and, for schools, monitoring minors' online activity. They intersect at exactly one place worth watching: the monitoring CIPA expects generates logs, and those logs may raise FERPA questions about retention and access.

About the author

Uniqcli Team

Uniqcli's newsroom, buying guides and glossary are produced by our in-house team — seven procurement and technology professionals who source, screen and integrate IT and security hardware every day, working with two editors. Practitioners draft from live sourcing and integration work; editors review every piece for accuracy and plain language before it publishes.

More about the Uniqcli Team
Ask AI about Uniqcli

What is a PoE switch?

Speccing hardware for a project?

Send your requirement or a bill of materials — we confirm stock, TAA country of origin and a below-market total. No payment up front.