The Data Quality Campaign, a nonprofit that has published widely used guidance on responsible student-data use, has repeatedly found that districts entering partnerships with outside organizations — nonprofits providing tutoring, mentoring, college-access services, or wraparound supports — often move ahead on the strength of a relationship and a general sense of shared mission before the data-sharing terms are formally documented, which creates exposure under FERPA that surfaces only when something goes wrong: a data breach, a partner organization's closure, or a parent complaint about how information was used.
This is a verification checklist, not legal advice; FERPA compliance details depend on a district's specific state law overlay and should be reviewed by counsel before any partnership agreement is signed.
What Does FERPA Actually Require of a District Sharing Data With a Nonprofit?
Under FERPA's school-official exception, a district can share otherwise-protected student records with an outside organization without individual parental consent only if the organization is performing an institutional service or function the district would otherwise perform itself, remains under the district's direct control regarding the use and maintenance of the records, and is subject to the same use-and-redisclosure limitations that would apply to a district employee. A partnership that does not meet all three conditions requires either individual parental consent for each disclosure or a narrower data-sharing approach that avoids personally identifiable information altogether.
Districts that treat a partner's general nonprofit mission as sufficient justification, without verifying these three specific conditions in a written agreement, are relying on an interpretation of the exception that would not hold up if formally challenged.
What Should Be in the Written Data-Sharing Agreement?
A defensible agreement specifies, in writing, before any data flows: the exact data elements being shared, rather than a general reference to "student records," since specificity is what makes the school-official exception's control and limitation requirements enforceable; the specific permitted uses of the data, with an explicit prohibition on any use beyond the stated service; a data-retention and destruction schedule, so the partner organization is not indefinitely holding student records after the service relationship ends; and a breach-notification clause specifying the district's and the partner's respective obligations if data is compromised.
What Should a District Verify About the Partner Organization Itself?
Beyond the written agreement's terms, a district should verify the partner's actual data-security practices before, not after, records begin flowing: whether the organization has a documented data-security policy and staff training program, what happens to the data if the organization merges, is acquired, or closes, and whether any of the partner's own vendors or subcontractors will have access to the shared data, since a district's agreement with the primary partner does not automatically bind that partner's downstream vendors unless the agreement specifically addresses it.
What Happens If a Partner Organization Closes or Changes Mission?
Nonprofit partners, unlike large commercial vendors, can close, merge, or pivot their mission with comparatively little warning, and a data-sharing agreement that does not specify what happens to previously shared student records in that scenario leaves the district with no enforceable claim over data it originally shared under conditions that assumed an ongoing relationship. A clause requiring return or verified destruction of all shared records upon partnership termination, regardless of the reason for termination, closes this specific gap.
How Should a District Structure Ongoing Oversight?
A signed agreement at the start of a partnership is necessary but not sufficient; districts that have managed these relationships well generally build in an annual review confirming the partner organization's continued compliance with the agreement's terms, rather than treating the initial signature as the end of the district's diligence obligation. That periodic check is what catches a partner's data practices drifting from the original agreement before a problem, rather than a district's own routine compliance failure, becomes the reason a partnership ends badly.




