Picture a parent asking to see everything your school has ever recorded about their child. Every grade, every email, every health record, and every disciplinary note needs to be ready and accounted for. That single request is the real test of FERPA compliance, and it reaches far past a rule about grades.
FERPA is the federal law that shapes student data privacy in schools across the country. It governs how records get collected, stored, shared, and disclosed.
This guide walks through what FERPA protects and who it applies to. It also covers common school compliance gaps and includes a FERPA checklist you can use before your next audit or accreditation review.
What FERPA Actually Protects
FERPA protects what the law calls “education records,” meaning any record tied to a student and kept by a school or a party acting on its behalf. That definition covers far more than most people expect.
Many people think FERPA only covers grades. It also protects health notes, disciplinary files, enrollment forms, and financial aid records, whether they sit in a filing cabinet or a cloud-based platform.
Parents generally hold these rights until a student turns 18 or starts college, at which point the rights transfer directly to the student as an “eligible student.” Schools can share limited “directory information,” like a student’s name or grade level, without consent, after giving families annual notice and a real chance to opt out.
For the full regulatory text, visit the official FERPA website.
Who FERPA Applies To
FERPA applies directly to schools that receive funding through a U.S. Department of Education program, which covers most public school districts and some private and independent schools depending on their funding.
Schools outside that direct scope often follow FERPA-aligned practices anyway, since families and accreditors expect the same student data privacy standards.
School compliance under FERPA depends on far more than administrators. Day-to-day responsibility includes:
- Teachers handling records tied to student behavior
- Coaches tracking eligibility and health details
- IT staff managing the student information system
- Vendors and apps that store or process student data
Any vendor granted access to student records needs a written agreement defining how that data gets used. Learning management systems and other classroom apps schools rely on daily fall under this same rule.
Regulators are watching this closely. In May 2026, the U.S. Department of Education sent a letter to the CEO of Instructure Holdings, the company behind the Canvas learning management system, requesting information on its FERPA compliance.
It’s a clear sign that federal scrutiny around student data privacy now reaches the vendors schools use every day, according to the U.S. Department of Education’s Student Privacy Policy Office.
The Three Most Common Compliance Gaps Schools Don’t Realize They Have
Outdated or Missing Vendor Agreements
Apps and platforms added mid-year rarely get the same vendor agreement review as core systems. Over time, that leaves several tools holding student data without a current agreement behind them.
Access Logs That Aren’t Consistently Kept
FERPA requires a record of who has accessed a student’s education records and why. Most schools keep this in memory rather than in a real log, so a parent or auditor request means reconstructing history instead of producing one.
Directory Information Notices That Haven’t Kept Pace
Many directory information notices are years old and don’t reflect how schools now share photos or use student information in marketing. That gap between what families were told and current practice is easy to miss.
What a FERPA Audit or Review Looks Like in Practice
A FERPA-focused review typically starts with a full inventory of every system and vendor that touches personally identifiable student information, mapped in one place instead of scattered across departments.
From there, a vCISO checks vendor agreements against what’s currently in use and tests whether access logs and disclosure records exist. The directory information notice gets checked against current practice too.
The output is a prioritized list tied to what matters for your board and your next accreditation cycle, showing which gaps carry risk and which are simple to close right away.
The more involved fixes are flagged with a realistic timeline and a budget line attached. Good reviews finish with a plan you can act on before your next visit from an accreditor, a board member, a grant funder, or a family’s attorney.
A Practical FERPA Checklist
Use this checklist to get a quick read on where your school stands before your next audit or accreditation review.
- Every vendor or platform touching student data has a current, signed agreement defining how that data can be used.
- Parents and eligible students receive an annual notice about directory information, with a real opportunity to opt out.
- Access to student records is limited to staff with a legitimate educational interest, and that access is documented.
- A log exists showing who has requested or received access to education records, along with the reason for that access.
- Staff across the school understand which records count as protected under FERPA.
- A written policy covers how long student records are retained and how they’re securely disposed of.
- Your school has a documented process for responding to a parent or eligible student’s request to review their records within the required timeframe.
- A response plan exists for a potential data breach involving student information, and someone on staff knows how to activate it.
Ready to Find Out Where Your School Stands on FERPA?
A FERPA review doesn’t need to feel like exam week. Most schools we work with start from a good-faith effort built up over time, with a few gaps nobody’s had the chance to track down.
Our team reviews your systems and vendor agreements, then delivers a plain-English report ranked by what matters most to your board.
Get in touch with our team to schedule a review.
FAQs
- What does FERPA compliance require from schools?
FERPA compliance requires schools to protect education records and limit access to staff with a legitimate interest. Parents also get annual notice of their rights. - Does FERPA apply to independent and private schools?
FERPA applies directly to schools that receive U.S. Department of Education funding. Many independent schools still follow the same student data privacy standards. - What counts as student data privacy under FERPA?
Student data privacy under FERPA covers any education record tied to a student, including grades and health records. - What should be on a FERPA checklist for schools?
A useful FERPA checklist covers vendor agreements, access logs, directory notices, and a data retention policy. - Who is responsible for school compliance with FERPA?
School compliance with FERPA is shared between school staff and any vendor touching student data. - What happens if a school violates FERPA?
A FERPA violation can lead to corrective action or loss of federal funding.
