What Is FERPA Compliance? 2026 K–12 AI Classroom Guide

What Is FERPA Compliance? 2026 K–12 AI Classroom Guide

August 14, 2026

What Is FERPA Compliance? 2026 K–12 AI Classroom Guide

what is ferpa compliance

TL;DR

FERPA compliance refers to the obligations schools must follow under the Family Educational Rights and Privacy Act, a 1974 federal law protecting student education records. It applies to every school that receives federal funding, not to vendors or software products. In the AI era, understanding FERPA compliance is critical because teachers using consumer AI tools with student data can create violations without realizing it. This guide breaks down what the law actually says, who it applies to, and how to stay on the right side of it when using technology in the classroom.


The question “what is FERPA compliance” used to come up mainly during back-to-school training sessions, sandwiched between fire drill procedures and attendance policies. That’s changed. With AI tools flooding into classrooms and data breaches making national headlines, FERPA has become one of the most searched privacy terms among educators, administrators, and parents alike.

This guide covers everything you need to know: what the law protects, who bears responsibility, how enforcement actually works, and why AI tools have made FERPA compliance more complicated (and more important) than ever before.

Explore FERPA-supportive AI tools built with K–12 privacy in mind.


FERPA at a Glance

The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law enacted in 1974 to protect the privacy of student education records. Sometimes called the “Buckley Amendment” after its sponsor, Senator James Buckley, FERPA is codified at 20 U.S.C. § 1232g.

Here are the basics:

Detail Fact
Full name Family Educational Rights and Privacy Act
Enacted 1974
Enforced by U.S. Department of Education
Applies to All educational institutions receiving federal funding
Core purpose Protect student education records and grant parents/students specific rights
Maximum penalty Withdrawal of all federal funding (never imposed)

FERPA applies to virtually every public school district in the country, along with most colleges and universities. If your institution receives any federal education funding, FERPA compliance is not optional.


What Does FERPA Protect?

Education Records

FERPA defines education records as records directly related to a student that are maintained by an educational agency or institution. This includes:

In 2026, education records also include digital artifacts: chat logs, AI tool transcripts, and any platform-generated data that contains student information.

What Is NOT an Education Record

Not everything a school maintains qualifies. The following are excluded:

Understanding what counts matters because it determines what falls under student data privacy protections and what doesn’t.

Personally Identifiable Information (PII) Under FERPA

Under FERPA, PII includes a student’s name, address, parent’s names, date of birth, Social Security number, or student ID number. It also covers any other information that, alone or in combination, could be used to identify a specific student.

This broad definition is what catches many teachers off guard. Even entering a student’s name alongside behavioral observations into an AI tool can constitute handling PII.

The Directory Information Exception

Schools may disclose certain “directory information” without consent. This can include names, addresses, phone numbers, dates of attendance, participation in activities, photographs, and email addresses. However, schools must first give public notice of what categories they classify as directory information. And they are never required to release it; it’s simply permitted if proper notice has been given.


What Rights Does FERPA Give Parents and Students?

FERPA grants four core rights:

1. Right to inspect records. Parents and eligible students can access and view education records at any time, free of charge.

2. Right to request amendments. If records are inaccurate or misleading, parents and eligible students can request corrections.

3. Right to consent before disclosure. Written consent must be obtained before the school discloses PII from education records, with specific exceptions (like the school official exception, covered below).

4. Annual notification. Schools must notify parents and eligible students of their FERPA rights every year.

The Age-18 Transition

When a student turns 18 or enrolls in a postsecondary institution, they become an “eligible student.” At that point, all FERPA rights transfer from the parent to the student. For high school teachers with mixed-age classrooms, this creates a practical wrinkle: you may need parental consent for one student and direct student consent for another, depending on birthdays.


The School Official Exception: How EdTech Tools Fit Under FERPA

This is the single most important concept for teachers evaluating AI tools. It’s also the most misunderstood.

Schools can share student PII with a vendor without parental consent under FERPA’s “school official exception,” but only if all four conditions are met:

  1. The vendor performs an institutional service or function
  2. The vendor has a legitimate educational interest in the records
  3. The vendor is under the direct control of the school regarding use and maintenance of records
  4. The vendor uses records only for authorized purposes

These conditions are formalized through a Data Processing Agreement (DPA). Without a signed DPA, a vendor has no legal basis to receive student education records under FERPA.

Here’s the nuance most content gets wrong: FERPA regulates schools, not vendors. A product cannot technically be “FERPA-compliant” because the compliance obligation falls on the institution. The accurate terms are “FERPA-aligned” or “FERPA-supportive,” meaning the vendor’s design and policies make it possible for schools to use the tool without violating their own obligations. The Future of Privacy Forum, the #1-ranking resource on this topic, makes this distinction explicitly.

If a vendor won’t provide a DPA or can’t explain how it handles student data, that’s a red flag. You can dig deeper into this topic in our FERPA-compliant EdTech checklist.


FERPA Violations and Penalties

The Maximum Penalty (That’s Never Been Used)

On paper, the penalty for violating FERPA is severe: total withdrawal of federal education funding. In practice, this has never happened. Not once. CDT Director Elizabeth Laird put it bluntly to Axios: “Penalty for violating FERPA is that your federal funding is withheld. And that has been enforced exactly zero times. Literally never.”

The Department of Education primarily works through voluntary compliance agreements, helping schools fix problems rather than punishing them financially.

The Real Consequences

The absence of funding penalties doesn’t mean violations are harmless. Practical consequences include:

Common Violations

Many FERPA violations happen accidentally:

The PowerSchool Breach: A Cautionary Tale

In December 2024, the PowerSchool breach compromised over 62 million student records and nearly 10 million teacher records, making it the largest known breach of children’s data in the country. The eventual class action settlement required PowerSchool and the Chicago Public Schools to pay $17.25 million.

Educational institutions now face an average of 2,507 cyberattack attempts per week, and breaches have impacted over 1.8 million students in the U.S. since 2020. These aren’t abstract statistics. They’re the reason understanding what FERPA compliance means has become urgent.


FERPA and AI Tools in the Classroom

Explore 26 free AI tools for teachers

Browse All Tools →

This is where FERPA compliance gets complicated fast.

The Scale of AI Adoption

According to RAND’s 2025 survey, 54% of students and 53% of teachers used AI for school that year, both up more than 15 percentage points from the prior year. Yet only 45% of principals reported having a school or district AI policy, and just 34% of teachers said their district had a policy addressing AI and academic integrity. Roughly two-thirds of teachers who used AI received no privacy training from their schools.

Teachers are caught in a bind. They want to use AI for lesson prep, grading, and report writing. But they worry (correctly) about accidentally violating FERPA when they input student information into these tools.

Consumer AI Tools Are the Biggest Risk

Using the free, public version of a consumer chatbot with student PII would almost certainly violate FERPA. These tools were not designed for educational use. OpenAI’s free tier, for instance, uses conversation data to train future models unless a DPA explicitly prohibits it. When a teacher signs up for a free consumer AI account and inputs student names, grades, or IEP details, the district has likely created an unauthorized disclosure of education records.

The distinction between consumer-grade and education-grade AI matters enormously. For practical guidance, see our walkthrough on using AI in the classroom without violating FERPA.

What FERPA-Aligned AI Use Looks Like

Compliant AI use in K–12 requires one of three approaches:

  1. Contracted enterprise tiers with education-specific terms and a signed DPA
  2. Redaction at the source so no education record ever leaves the device
  3. Dedicated EdTech platforms built with FERPA, COPPA, and state-law alignment from the ground up

Platforms designed for education should not require student PII as input, should not train models on user content, and should offer encryption both in transit and at rest.

See how TeachTools approaches AI and data privacy.


FERPA vs. COPPA: What’s the Difference?

Every conversation about what FERPA compliance means eventually leads to COPPA. The two laws overlap but are not interchangeable, and complying with one doesn’t excuse violating the other.

Dimension FERPA COPPA
Enacted 1974 1998
Enforced by U.S. Dept. of Education Federal Trade Commission (FTC)
Applies to Schools receiving federal funding Operators of commercial websites/services
Protects Student education records (all ages) Online data of children under 13
Penalty Loss of federal funding (never imposed) FTC fines up to $51,744 per violation

FERPA covers the records schools create. COPPA kicks in the moment students interact with third-party platforms. For K–12 students under 13 using online tools, both laws apply simultaneously. We cover this in more depth in our COPPA compliance guide for AI tools in the classroom.


State Laws Beyond FERPA

FERPA sets a federal floor, not a ceiling. States have been building on it aggressively.

California’s SOPIPA, New York’s Education Law 2-d, and Colorado’s SB 16-068 all impose additional obligations on EdTech vendors beyond what FERPA requires. As of 2026, 21 states have enacted consumer data privacy laws, many with specific provisions for children’s and student data.

Ohio became the first state to require every public school district to adopt a formal AI policy, under a deadline set by House Bill 96: July 1, 2026. This trend will likely accelerate. If you’re a teacher or administrator, your state may require protections that go well beyond the federal baseline.


How to Evaluate an AI Tool for FERPA Alignment

Before adopting any AI tool, run through this checklist:

  1. Is a Data Processing Agreement (DPA) available? If the vendor can’t or won’t provide one, stop here.
  2. Does the tool require student PII as input? Tools that function without student names, IDs, or other identifying information are inherently lower risk.
  3. What is the data training policy? Does the vendor use inputs to train its models? If yes, student data could end up in the model.
  4. How is data encrypted? Look for AES-256 encryption at rest and TLS 1.2+ in transit.
  5. What are the data retention periods? How long does the vendor store your inputs, and can you delete them?
  6. Does the vendor have third-party security certifications? SOC 2 Type II is the current standard for EdTech infrastructure.
  7. Does the vendor address both FERPA and COPPA? For elementary and middle school use, both apply.

For more detailed procurement questions, our guide on EdTech security questions for district procurement walks through what to ask vendors.

Red Flags

Compare TeachTools pricing and plans to see a FERPA-supportive approach in practice.


Frequently Asked Questions

Does FERPA only apply to K–12 schools?

No. FERPA applies to all educational institutions that receive federal funding, including colleges, universities, and vocational schools. The rights simply shift from parents to students once a student turns 18 or enters postsecondary education.

Can a product be “FERPA-certified”?

No formal FERPA certification exists. There is no government body that certifies products as FERPA-compliant. When vendors use this language, they typically mean their product is designed to help schools meet their FERPA obligations. The more accurate term is “FERPA-supportive” or “FERPA-aligned.”

What should I do if my school doesn’t have an AI policy?

Proceed cautiously. Avoid entering any student PII into AI tools that lack a signed DPA with your district. Use tools that don’t require student-identifying information as input. And advocate internally for a formal policy. Our guide on using AI without school approval covers this in detail.

Do state laws add requirements beyond FERPA?

Yes. As of 2026, 21 states have consumer data privacy laws on the books, and several (California, New York, Colorado, Ohio) have education-specific provisions that go further than FERPA. Always check your state’s requirements in addition to federal law.

Is typing a student’s name into ChatGPT a FERPA violation?

It depends on the context. If you’re using the free consumer version of ChatGPT (which may use inputs for model training) and you enter student PII, your district has likely created an unauthorized disclosure of education records. Enterprise education tiers with a DPA and no-training clauses are a different story.

What is the most common FERPA violation teachers make?

Sharing student information with someone who has no legitimate educational need for it. This includes emailing records to the wrong person, posting grades with names visible, and entering student data into consumer software without a DPA.

Has a school ever lost federal funding for a FERPA violation?

No. The Department of Education has never imposed this penalty. Enforcement has been entirely corrective, through voluntary compliance agreements. However, individual employees have been terminated, and institutions have faced lawsuits and expensive settlements.

How does FERPA compliance relate to cybersecurity?

FERPA currently lacks explicit cybersecurity requirements, which experts increasingly view as a gap in the law. Schools rely on hundreds of EdTech tools, but FERPA doesn’t mandate specific technical safeguards like encryption standards or breach notification timelines. Many states have begun filling this gap with their own legislation.

Free Tool

Explore 26 free AI tools for teachers

Worksheets, quizzes, lesson plans, rubrics — all free, all private, all built for educators.

Browse All Tools →

Try TeachTools Free

Create worksheets, quizzes, and lesson plans in seconds with AI.

Explore All Tools →

Tools Mentioned in This Article

📝
AI Worksheet Generator
Create differentiated worksheets for any subject and grade level in seconds.
Try it free →
AI Quiz Generator
Build formative assessments with multiple question types — auto-graded and printable.
Try it free →
🧰
All 26 Free AI Tools
Explore every generator — worksheets, quizzes, lesson plans, rubrics, and more.
Try it free →

More from the TeachTools Blog

View all articles →

Try TeachTools Free
Browse Tools →