Student Records, EdTech Vendors, and the School Official Exception
The one-paragraph answer
FERPA AI compliance turns on a single provision. The Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99) prohibits schools that receive federal funds from disclosing personally identifiable information from a student’s education records without written parental consent. AI systems that process education records disclose them, in FERPA terms. The only workable path for most EdTech AI is the school official exception under 34 CFR 99.31(a)(1), which lets a school treat a vendor as an internal school official if the contract puts the vendor under the school’s direct control, if the vendor has a legitimate educational interest, and if the school stays responsible for the vendor’s use of the records. The exception exists. It is legally usable. And most EdTech AI contracts do not actually satisfy it, because they lack direct-control clauses, they allow the vendor to use the data to train models on other schools’ behalf, and they do not restrict re-disclosure. The Department of Education’s 2024 Toolkit for AI in Education said this in polite language; the exam findings are less polite.
A K-12 district signs an AI tutoring platform. The platform is genuinely good: adaptive practice, standards-aligned, teacher dashboards. It also ingests every student’s work product, and its terms grant the vendor a licence to use aggregated and de-identified data to improve its models. Six months later, a parent files a FERPA complaint with the Department of Education’s Student Privacy Policy Office. The complaint alleges that the district disclosed education records to a vendor whose use of those records exceeded the school official exception. The district cannot produce a contract that meets 34 CFR 99.31(a)(1)’s direct-control requirement. That is the exam finding.
A university deploys a generative-AI research assistant. Students paste draft essays and instructor feedback into it. The instructor feedback is an education record under FERPA. The vendor’s terms include a training-data licence and route content through a large-language-model API operated by a subprocessor in another jurisdiction. The university’s general counsel realises this after the deployment is already live. The choices are: withdraw the tool, renegotiate the contract to satisfy the school official exception, or obtain written consent from every affected student. None of those is free.
FERPA applies to every educational agency or institution that receives federal funds from a programme administered by the US Department of Education. That reaches essentially every public K-12 district and public college, plus private institutions that participate in Title IV, plus a wide range of state agencies. The rule is straightforward: no disclosure of personally identifiable information from a student’s education records without prior written consent, subject to a defined set of exceptions.
“Education records” is broader than most operators think. It includes any record maintained by the school that is directly related to a student, in any medium. Grades, transcripts, disciplinary records, health records held by the school, teacher comments, assessment results, and the outputs of AI systems that are stored and directly related to a student all qualify. “Personally identifiable information” includes name, address, personal identifiers, indirect identifiers that would let a reasonable person identify the student, and information requested by someone the school believes knows the student’s identity.
The consent path is real but operationally impossible for most AI deployments. Written parental consent (or eligible-student consent, once the student turns 18 or enters postsecondary education) has to name the records, the purpose, and the recipient. A generic terms-of-service click does not satisfy it. That leaves the exceptions, and for AI vendors the only workable one is the school official exception.
34 CFR 99.31(a)(1) allows disclosure of education records without consent to “a school official, including a teacher, within the agency or institution whom the agency or institution has determined to have a legitimate educational interest.” The regulation lets a school treat an outside party (a contractor, consultant, volunteer, or other party) as a school official for this purpose only if the party meets four cumulative criteria:
The Family Policy Compliance Office (which enforces FERPA) has said repeatedly that “direct control” is the piece that most vendor contracts miss. Direct control means the school can dictate what the vendor does with the records, can require the vendor to stop, and can require destruction on termination. A licence that lets the vendor use the records for its own purposes, including improving its own models on other customers’ behalf, is not direct control.
Three failure patterns show up in almost every EdTech AI contract we review:
Training-data licences. The vendor grants itself a right to use the customer’s data (sometimes framed as “anonymized” or “aggregated”) to train or improve its models. That is not direct control. The school cannot make the vendor stop using data that has already been ingested into a model, and the vendor benefits commercially from the data across its whole customer base.
Subprocessor chains. The vendor routes education records through a large-language-model API operated by a third party. Sometimes several third parties. The contract discloses the subprocessor list but does not flow FERPA’s restrictions down. The subprocessors are not under the school’s direct control. Re-disclosure is uncontrolled by construction.
No destruction clause. The contract does not require the vendor to return or destroy education records on termination. The school has no way to reach the model weights or the retrieval index that were built from the records. The obligation to safeguard the records, which persists after the vendor relationship ends, cannot actually be discharged.
“Effective data governance is important for minimizing data breach activity and mitigating bias, and educational institutions face particular challenges because student records touch multiple legal regimes simultaneously.”
That layered exposure is why the school official exception matters so much: a single contract has to satisfy FERPA, and often state laws like SOPIPA (California’s Student Online Personal Information Protection Act) or Illinois SOPPA, and COPPA where the students are under 13. A failure at the FERPA layer typically produces failures at the others.
“Global data privacy laws differ substantially in their approach to consent, purpose limitation, and re-disclosure, and technology-driven intrusions expose gaps between what statutes say and what platforms actually do with the data they collect.”
No. FERPA consent must be written, must specify the records to be disclosed, must state the purpose, and must identify the recipient. A boilerplate terms-of-service acceptance does not meet any of those requirements. The school official exception is the practical path.
De-identification under FERPA has a specific standard (34 CFR 99.31(b)) that is stricter than the marketing meaning of “anonymised.” A vendor claim that data has been anonymised does not, on its own, remove the data from FERPA’s reach. The disclosure has already occurred.
Not directly. FERPA reaches the recipient of federal education funds, which is the school. A non-US school is not a FERPA-covered institution. Vendors selling into US schools inherit FERPA obligations through the school official contract; selling into non-US schools involves different regimes (GDPR, national data protection laws) but not FERPA.
The AI Vendor Tier Map, the AI Vendor Security Review, and the AI Data Flow Map from Volume V produce exactly the artefacts a school needs to defend a school-official-exception determination: which vendor holds which records, under what direct-control terms, with what subprocessor chain, on what destruction commitment.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including FERPA and AI, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →