πŸ§™ Wiz Kids
Learn β€Ί EdTech Privacy & Procurement

FERPA basics: the US school-records law, briefly

Scope note: this library serves Australian schools first, and FERPA binds none of them β€” this page exists because the US privacy conversation dominates edtech marketing, so Australian readers keep meeting FERPA claims ("FERPA-compliant!") without a map. For the law that actually governs your school, see the Australian page. US readers: this is orientation, not legal advice.

The Family Educational Rights and Privacy Act (1974) is the grandparent of student-data law: it conditions US federal education funding on schools protecting education records β€” records directly related to a student, maintained by the school or on its behalf. Half a century on, it remains the frame US school privacy hangs from, with strengths and gaps both instructive.

What it grants

The two exceptions that matter for edtech

"School officials with legitimate educational interests" is the doorway through which nearly all edtech enters: schools may treat a vendor as a school official β€” without parental consent β€” where the vendor performs an institutional service, stays under the school's direct control regarding the records, and uses them only for the authorized purpose. That's a genuinely sensible mechanism and the load-bearing joint the whole system leans on: the "direct control" and "authorized purpose" conditions are only as real as the contract terms behind them.

"Directory information" β€” names, photos, activities and similar that a school designates and may disclose after offering parents an opt-out β€” is FERPA's most surprising corner for newcomers: substantial student information can flow with no consent at all unless families act.

Where FERPA falls short

Named plainly, because vendors wave "FERPA-compliant" as a quality seal: FERPA has no private right of action (families can't sue under it; enforcement is complaints to the Department of Education, whose remedy β€” funding withdrawal β€” has never been fully used); it binds schools, reaching vendors only via the school-official conditions; metadata and de-identified data sit largely outside it (the pseudonymous reality applies); and it predates by decades the SDK-and-tracker economy it now supervises. The gaps are why the US layer cake exists β€” COPPA for under-13 operators (our page), state laws like California's SOPIPA imposing duties on edtech directly β€” and why "FERPA-compliant" alone tells you a vendor meets a 1974 floor, not that their data practices are good.

For Australian readers, the translation

FERPA β‰ˆ a narrower, records-focused cousin of the Privacy Act's scheme: inspection/amendment map roughly to APPs 12–13, the school-official exception does the work that contractual data-handling terms do here, and the enforcement gap is the instructive contrast β€” the OAIC route is more direct than FERPA's. When US-market vendors cite FERPA at you, run the same checks as always: the law they name matters less than the inventory, the flows, and the contract.

References


Β© Glu IO Pty. Ltd. β€” Wiz Kids (wiz.kids). Link freely; republication requires permission β€” see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.