FERPA basics: the US school-records law, briefly
The Family Educational Rights and Privacy Act (1974) is the grandparent of student-data law: it conditions US federal education funding on schools protecting education records β records directly related to a student, maintained by the school or on its behalf. Half a century on, it remains the frame US school privacy hangs from, with strengths and gaps both instructive.
What it grants
- Inspection and review: parents may see their child's education records (schools have up to 45 days to comply); the rights transfer to the student at 18 or on entering post-secondary study (the general rights map).
- Amendment: parents may request correction of inaccurate or misleading records, with a hearing process if refused.
- Consent over disclosure β the default rule: schools need written consent to disclose education recordsβ¦ subject to the exceptions that do most of the real work.
The two exceptions that matter for edtech
"School officials with legitimate educational interests" is the doorway through which nearly all edtech enters: schools may treat a vendor as a school official β without parental consent β where the vendor performs an institutional service, stays under the school's direct control regarding the records, and uses them only for the authorized purpose. That's a genuinely sensible mechanism and the load-bearing joint the whole system leans on: the "direct control" and "authorized purpose" conditions are only as real as the contract terms behind them.
"Directory information" β names, photos, activities and similar that a school designates and may disclose after offering parents an opt-out β is FERPA's most surprising corner for newcomers: substantial student information can flow with no consent at all unless families act.
Where FERPA falls short
Named plainly, because vendors wave "FERPA-compliant" as a quality seal: FERPA has no private right of action (families can't sue under it; enforcement is complaints to the Department of Education, whose remedy β funding withdrawal β has never been fully used); it binds schools, reaching vendors only via the school-official conditions; metadata and de-identified data sit largely outside it (the pseudonymous reality applies); and it predates by decades the SDK-and-tracker economy it now supervises. The gaps are why the US layer cake exists β COPPA for under-13 operators (our page), state laws like California's SOPIPA imposing duties on edtech directly β and why "FERPA-compliant" alone tells you a vendor meets a 1974 floor, not that their data practices are good.
For Australian readers, the translation
FERPA β a narrower, records-focused cousin of the Privacy Act's scheme: inspection/amendment map roughly to APPs 12β13, the school-official exception does the work that contractual data-handling terms do here, and the enforcement gap is the instructive contrast β the OAIC route is more direct than FERPA's. When US-market vendors cite FERPA at you, run the same checks as always: the law they name matters less than the inventory, the flows, and the contract.
References
- 20 U.S.C. Β§1232g; 34 CFR Part 99 β the statute and regulations.
- US Department of Education, Privacy Technical Assistance Center (PTAC) β Protecting Student Privacy While Using Online Educational Services and the school-officials guidance.
- Zeide, E. (2016). Student privacy principles for the age of big data. Drexel Law Review, 8 β the scholarly account of FERPA's modern gaps.
Β© Glu IO Pty. Ltd. β Wiz Kids (wiz.kids). Link freely; republication requires permission β see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.