Skip to content
Saturday, August 29, 2026
Education FameEducation · EdTech
Research · Learning · Evidence
EdTech

How FERPA and COPPA Protect Student Data in the Digital Classroom

A working guide to the two federal laws that govern student data privacy, and what schools and vendors each must do under them.

Privacy compliance certification marks displayed on device screens

Every time a student logs into a learning app, two federal laws quietly shape what may happen to their data. FERPA, the Family Educational Rights and Privacy Act of 1974, governs education records held by schools, while COPPA, the Children's Online Privacy Protection Act of 1998, imposes consent and data-handling duties on commercial online services directed at children under 13. Together they form the legal floor for student data privacy in the United States, and both schools and edtech vendors are expected to understand where one ends and the other begins. Requirements on top of these vary by state, and more than a hundred state student privacy laws have been enacted since 2013.

What does FERPA actually require?

FERPA gives parents, and students after they turn 18 or enter postsecondary education, the right to inspect and request correction of education records and to control their disclosure. A school generally may not release personally identifiable information from education records without written consent, subject to specific exceptions: directory information, school officials with legitimate educational interests, transfers to another enrolled school, and certain audit or legal purposes. The U.S. Department of Education, which enforces the law against schools, publishes plain-language guidance through its Student Privacy Policy Office. Penalties are rare but real: institutions can lose federal funding, and enforcement actions have produced required corrective training.

How can schools share data with vendors at all?

The exception most edtech runs on is the school official exception. A vendor qualifies as a school official when it performs a function the school would otherwise perform, is under the school's direct control, and uses the data only for that authorized purpose. In practice this means the contract matters enormously: the agreement must specify that the vendor may not re-disclose or use student data for any other purpose, such as advertising or building commercial profiles. The Department of Education's guidance and model terms of service checklist, built around the standards and reporting requirements of the Privacy Technical Assistance Center, give districts concrete language to demand. A vendor that refuses to sign a district's data privacy agreement is, in effect, declining the exception that lets it hold the data legally.

What does COPPA require of vendors?

COPPA is enforced by the Federal Trade Commission against companies, not schools, and it applies to online services directed at children under 13 or that knowingly collect their data. Covered companies must post clear privacy notices, limit collection to what is necessary, obtain verifiable parental consent before collecting personal information, and allow parents to review and delete data. The 2013 amendments and subsequent FTC guidance added restrictions on behavioral advertising to children and on conditioning participation in activities on disclosing more data than necessary. In 2025 the FTC finalized a stronger COPPA rule updating its requirements, including tighter limits on how long companies may retain children's data.

When does COPPA apply in a school context?

The FTC has long said that schools can provide consent on behalf of parents for educational-purpose-only collection, which is how districts legally adopt apps for young children without collecting millions of signatures. But that school consent is narrow: it covers data collected for the educational purpose the school authorized, not for a vendor's commercial benefit. The FTC's 2022 policy statement put companies on notice that using school data for non-educational purposes, such as training unrelated commercial products or marketing, violates COPPA. Districts should therefore ask vendors two direct questions: what data do you collect, and what do you do with it beyond delivering the service we are paying for?

Who is responsible for what?

ObligationSchool under FERPAVendor under COPPA
Notice to parentsAnnual FERPA notification of rightsClear online privacy notice
ConsentWritten consent before disclosure, with exceptionsVerifiable parental or school consent for under-13 collection
Data limitsDirect vendors through contract termsCollect only what is necessary for the service
Retention and deletionSet return-and-delete terms in contractDelete children's data when no longer needed
EnforcementU.S. Department of EducationFederal Trade Commission

What are the most common failure points districts see?

Privacy officers describe a recurring short list. Free consumer apps get used in classrooms without any district review, so no contract and no FERPA basis exists. Vendor contracts auto-renew with privacy terms that quietly worsened in an updated terms-of-service page. Third-party trackers and advertising cookies run on login pages intended for seven-year-olds. And breach notification obligations are missing from the contract, leaving the district legally responsible for telling families about an incident it learns about late. All four are fixable with an approved-software list, annual terms review, and standard breach clauses.

What should a strong district data privacy agreement contain?

Experienced district privacy officers converge on the same core clauses: purpose limitation tied to the educational service; a ban on selling data and on targeted advertising; subcontractor disclosure and flow-down of the same obligations; defined security standards and a breach notification window, commonly expressed in days rather than weeks; parental access and correction procedures; and return or deletion of data at contract end in a documented, machine-readable format. Vendors that serve many districts increasingly maintain public security and privacy certifications to avoid negotiating hundreds of bespoke agreements, which has made the market more standardized than it was a decade ago.

What happens after a data breach?

Breach response is where paper compliance meets reality. Nearly all states have enacted data breach notification laws covering education records, with varying deadlines and definitions, and district insurance requirements increasingly mandate a written incident response plan. The sequence that works: contain and preserve evidence, determine what data was actually exposed, meet the contract's notification window to the district, then notify affected families in the manner state law requires. Vendors sometimes prefer quiet remediation, which is why the breach clause — who notifies whom, in how many days, and who pays for monitoring or legal costs — belongs in the signed agreement rather than in goodwill.

How do state laws layer on top?

State statutes add real obligations that district staff must track. Some states, including New York with its education law provisions on third-party contractors, impose statutory contract terms; California's student privacy law extends duties to online services used for K-12 purposes; and many states maintain registries or model agreements districts are encouraged or required to use. The practical consequence for vendors is a compliance map with dozens of variations, and for districts a reason to check what their own state requires before borrowing another district's agreement. The federal floor stays FERPA and COPPA; the ceiling depends on the state capital.

What can parents do under these laws?

Parents can request their child's education records, ask what software the district has approved, and expect the annual FERPA notice. If a concern involves a commercial app's handling of a young child's data, the complaint route is the FTC. For school-side disclosure problems, the route is the U.S. Department of Education's Family Policy Compliance Office. Teachers and parents who understand these boundaries are, in practice, the most effective early-warning system a district has — most privacy incidents begin with an enthusiastic app adoption nobody reviewed.

Frequently Asked Questions

Does FERPA apply to edtech vendors?
Directly, no — FERPA binds schools. But vendors receiving student data must qualify under the school official exception, which requires contract terms restricting their use of the data.
Can schools consent to data collection on behalf of parents under COPPA?
Yes, the FTC allows schools to consent for educational-purpose-only collection by online services for children under 13, but that consent does not cover commercial uses like advertising.
Who enforces FERPA and COPPA?
The U.S. Department of Education enforces FERPA against schools; the Federal Trade Commission enforces COPPA against companies.
What should a district data privacy agreement include?
Purpose limitation, a ban on selling data and targeted advertising, subcontractor controls, security and breach notification terms, parental access procedures, and data return or deletion at contract end.