What Is FERPA Compliance? 2026 K–12 AI Classroom Guide

TL;DR
FERPA compliance refers to the obligations schools must follow under the Family Educational Rights and Privacy Act, a 1974 federal law protecting student education records. It applies to every school that receives federal funding, not to vendors or software products. In the AI era, understanding FERPA compliance is critical because teachers using consumer AI tools with student data can create violations without realizing it. This guide breaks down what the law actually says, who it applies to, and how to stay on the right side of it when using technology in the classroom.
The question “what is FERPA compliance” used to come up mainly during back-to-school training sessions, sandwiched between fire drill procedures and attendance policies. That’s changed. With AI tools flooding into classrooms and data breaches making national headlines, FERPA has become one of the most searched privacy terms among educators, administrators, and parents alike.
This guide covers everything you need to know: what the law protects, who bears responsibility, how enforcement actually works, and why AI tools have made FERPA compliance more complicated (and more important) than ever before.
Explore FERPA-supportive AI tools built with K–12 privacy in mind.
FERPA at a Glance
The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law enacted in 1974 to protect the privacy of student education records. Sometimes called the “Buckley Amendment” after its sponsor, Senator James Buckley, FERPA is codified at 20 U.S.C. § 1232g.
Here are the basics:
| Detail | Fact |
|---|---|
| Full name | Family Educational Rights and Privacy Act |
| Enacted | 1974 |
| Enforced by | U.S. Department of Education |
| Applies to | All educational institutions receiving federal funding |
| Core purpose | Protect student education records and grant parents/students specific rights |
| Maximum penalty | Withdrawal of all federal funding (never imposed) |
FERPA applies to virtually every public school district in the country, along with most colleges and universities. If your institution receives any federal education funding, FERPA compliance is not optional.
What Does FERPA Protect?
Education Records
FERPA defines education records as records directly related to a student that are maintained by an educational agency or institution. This includes:
- Transcripts and grades
- Class schedules and course work (papers, exams, evaluations)
- Disciplinary records
- Student financial records
- IEPs and 504 plans
- Counselor and advisor case notes (with narrow exceptions)
- Internship program records
In 2026, education records also include digital artifacts: chat logs, AI tool transcripts, and any platform-generated data that contains student information.
What Is NOT an Education Record
Not everything a school maintains qualifies. The following are excluded:
- Sole possession records: Private notes kept by a teacher or staff member, not shared with anyone else
- Campus law enforcement records
- Medical treatment records (governed by HIPAA instead)
- Aggregate statistical data that contains no personally identifiable information
Understanding what counts matters because it determines what falls under student data privacy protections and what doesn’t.
Personally Identifiable Information (PII) Under FERPA
Under FERPA, PII includes a student’s name, address, parent’s names, date of birth, Social Security number, or student ID number. It also covers any other information that, alone or in combination, could be used to identify a specific student.
This broad definition is what catches many teachers off guard. Even entering a student’s name alongside behavioral observations into an AI tool can constitute handling PII.
The Directory Information Exception
Schools may disclose certain “directory information” without consent. This can include names, addresses, phone numbers, dates of attendance, participation in activities, photographs, and email addresses. However, schools must first give public notice of what categories they classify as directory information. And they are never required to release it; it’s simply permitted if proper notice has been given.
What Rights Does FERPA Give Parents and Students?
FERPA grants four core rights:
1. Right to inspect records. Parents and eligible students can access and view education records at any time, free of charge.
2. Right to request amendments. If records are inaccurate or misleading, parents and eligible students can request corrections.
3. Right to consent before disclosure. Written consent must be obtained before the school discloses PII from education records, with specific exceptions (like the school official exception, covered below).
4. Annual notification. Schools must notify parents and eligible students of their FERPA rights every year.
The Age-18 Transition
When a student turns 18 or enrolls in a postsecondary institution, they become an “eligible student.” At that point, all FERPA rights transfer from the parent to the student. For high school teachers with mixed-age classrooms, this creates a practical wrinkle: you may need parental consent for one student and direct student consent for another, depending on birthdays.
The School Official Exception: How EdTech Tools Fit Under FERPA
This is the single most important concept for teachers evaluating AI tools. It’s also the most misunderstood.
Schools can share student PII with a vendor without parental consent under FERPA’s “school official exception,” but only if all four conditions are met:
- The vendor performs an institutional service or function
- The vendor has a legitimate educational interest in the records
- The vendor is under the direct control of the school regarding use and maintenance of records
- The vendor uses records only for authorized purposes
These conditions are formalized through a Data Processing Agreement (DPA). Without a signed DPA, a vendor has no legal basis to receive student education records under FERPA.
Here’s the nuance most content gets wrong: FERPA regulates schools, not vendors. A product cannot technically be “FERPA-compliant” because the compliance obligation falls on the institution. The accurate terms are “FERPA-aligned” or “FERPA-supportive,” meaning the vendor’s design and policies make it possible for schools to use the tool without violating their own obligations. The Future of Privacy Forum, the #1-ranking resource on this topic, makes this distinction explicitly.
If a vendor won’t provide a DPA or can’t explain how it handles student data, that’s a red flag. You can dig deeper into this topic in our FERPA-compliant EdTech checklist.
FERPA Violations and Penalties
The Maximum Penalty (That’s Never Been Used)
On paper, the penalty for violating FERPA is severe: total withdrawal of federal education funding. In practice, this has never happened. Not once. CDT Director Elizabeth Laird put it bluntly to Axios: “Penalty for violating FERPA is that your federal funding is withheld. And that has been enforced exactly zero times. Literally never.”
The Department of Education primarily works through voluntary compliance agreements, helping schools fix problems rather than punishing them financially.
The Real Consequences
The absence of funding penalties doesn’t mean violations are harmless. Practical consequences include:
- Lawsuits: Individuals whose privacy rights were violated may file suit and seek damages.
- Employee discipline: Teachers and staff can face reprimands, suspensions, or termination. In at least one documented case, a school district terminated a teacher’s contract after the teacher emailed testing rosters containing nearly 700 students’ names and personal information to someone with no educational need for the data.
- Reputational damage: Districts that mishandle student data face public scrutiny and erosion of community trust.
Common Violations
Many FERPA violations happen accidentally:
- Posting grades publicly with student names visible
- Emailing student PII to the wrong recipient
- Using consumer AI tools (like free ChatGPT) with student names, grades, or IEP details
- Sharing student records with a vendor that lacks a DPA
The PowerSchool Breach: A Cautionary Tale
In December 2024, the PowerSchool breach compromised over 62 million student records and nearly 10 million teacher records, making it the largest known breach of children’s data in the country. The eventual class action settlement required PowerSchool and the Chicago Public Schools to pay $17.25 million.
Educational institutions now face an average of 2,507 cyberattack attempts per week, and breaches have impacted over 1.8 million students in the U.S. since 2020. These aren’t abstract statistics. They’re the reason understanding what FERPA compliance means has become urgent.
FERPA and AI Tools in the Classroom
Explore 26 free AI tools for teachers
Browse All Tools →This is where FERPA compliance gets complicated fast.
The Scale of AI Adoption
According to RAND’s 2025 survey, 54% of students and 53% of teachers used AI for school that year, both up more than 15 percentage points from the prior year. Yet only 45% of principals reported having a school or district AI policy, and just 34% of teachers said their district had a policy addressing AI and academic integrity. Roughly two-thirds of teachers who used AI received no privacy training from their schools.
Teachers are caught in a bind. They want to use AI for lesson prep, grading, and report writing. But they worry (correctly) about accidentally violating FERPA when they input student information into these tools.
Consumer AI Tools Are the Biggest Risk
Using the free, public version of a consumer chatbot with student PII would almost certainly violate FERPA. These tools were not designed for educational use. OpenAI’s free tier, for instance, uses conversation data to train future models unless a DPA explicitly prohibits it. When a teacher signs up for a free consumer AI account and inputs student names, grades, or IEP details, the district has likely created an unauthorized disclosure of education records.
The distinction between consumer-grade and education-grade AI matters enormously. For practical guidance, see our walkthrough on using AI in the classroom without violating FERPA.
What FERPA-Aligned AI Use Looks Like
Compliant AI use in K–12 requires one of three approaches:
- Contracted enterprise tiers with education-specific terms and a signed DPA
- Redaction at the source so no education record ever leaves the device
- Dedicated EdTech platforms built with FERPA, COPPA, and state-law alignment from the ground up
Platforms designed for education should not require student PII as input, should not train models on user content, and should offer encryption both in transit and at rest.
See how TeachTools approaches AI and data privacy.
FERPA vs. COPPA: What’s the Difference?
Every conversation about what FERPA compliance means eventually leads to COPPA. The two laws overlap but are not interchangeable, and complying with one doesn’t excuse violating the other.
| Dimension | FERPA | COPPA |
|---|---|---|
| Enacted | 1974 | 1998 |
| Enforced by | U.S. Dept. of Education | Federal Trade Commission (FTC) |
| Applies to | Schools receiving federal funding | Operators of commercial websites/services |
| Protects | Student education records (all ages) | Online data of children under 13 |
| Penalty | Loss of federal funding (never imposed) | FTC fines up to $51,744 per violation |
FERPA covers the records schools create. COPPA kicks in the moment students interact with third-party platforms. For K–12 students under 13 using online tools, both laws apply simultaneously. We cover this in more depth in our COPPA compliance guide for AI tools in the classroom.
State Laws Beyond FERPA
FERPA sets a federal floor, not a ceiling. States have been building on it aggressively.
California’s SOPIPA, New York’s Education Law 2-d, and Colorado’s SB 16-068 all impose additional obligations on EdTech vendors beyond what FERPA requires. As of 2026, 21 states have enacted consumer data privacy laws, many with specific provisions for children’s and student data.
Ohio became the first state to require every public school district to adopt a formal AI policy, under a deadline set by House Bill 96: July 1, 2026. This trend will likely accelerate. If you’re a teacher or administrator, your state may require protections that go well beyond the federal baseline.
How to Evaluate an AI Tool for FERPA Alignment
Before adopting any AI tool, run through this checklist:
- Is a Data Processing Agreement (DPA) available? If the vendor can’t or won’t provide one, stop here.
- Does the tool require student PII as input? Tools that function without student names, IDs, or other identifying information are inherently lower risk.
- What is the data training policy? Does the vendor use inputs to train its models? If yes, student data could end up in the model.
- How is data encrypted? Look for AES-256 encryption at rest and TLS 1.2+ in transit.
- What are the data retention periods? How long does the vendor store your inputs, and can you delete them?
- Does the vendor have third-party security certifications? SOC 2 Type II is the current standard for EdTech infrastructure.
- Does the vendor address both FERPA and COPPA? For elementary and middle school use, both apply.
For more detailed procurement questions, our guide on EdTech security questions for district procurement walks through what to ask vendors.
Red Flags
- The vendor markets itself as “FERPA-compliant” but can’t produce a DPA
- The tool is a consumer product without an education-specific tier
- Privacy documentation is vague or outdated
- No clear explanation of where data is stored or who can access it
Compare TeachTools pricing and plans to see a FERPA-supportive approach in practice.
Frequently Asked Questions
Does FERPA only apply to K–12 schools?
No. FERPA applies to all educational institutions that receive federal funding, including colleges, universities, and vocational schools. The rights simply shift from parents to students once a student turns 18 or enters postsecondary education.
Can a product be “FERPA-certified”?
No formal FERPA certification exists. There is no government body that certifies products as FERPA-compliant. When vendors use this language, they typically mean their product is designed to help schools meet their FERPA obligations. The more accurate term is “FERPA-supportive” or “FERPA-aligned.”
What should I do if my school doesn’t have an AI policy?
Proceed cautiously. Avoid entering any student PII into AI tools that lack a signed DPA with your district. Use tools that don’t require student-identifying information as input. And advocate internally for a formal policy. Our guide on using AI without school approval covers this in detail.
Do state laws add requirements beyond FERPA?
Yes. As of 2026, 21 states have consumer data privacy laws on the books, and several (California, New York, Colorado, Ohio) have education-specific provisions that go further than FERPA. Always check your state’s requirements in addition to federal law.
Is typing a student’s name into ChatGPT a FERPA violation?
It depends on the context. If you’re using the free consumer version of ChatGPT (which may use inputs for model training) and you enter student PII, your district has likely created an unauthorized disclosure of education records. Enterprise education tiers with a DPA and no-training clauses are a different story.
What is the most common FERPA violation teachers make?
Sharing student information with someone who has no legitimate educational need for it. This includes emailing records to the wrong person, posting grades with names visible, and entering student data into consumer software without a DPA.
Has a school ever lost federal funding for a FERPA violation?
No. The Department of Education has never imposed this penalty. Enforcement has been entirely corrective, through voluntary compliance agreements. However, individual employees have been terminated, and institutions have faced lawsuits and expensive settlements.
How does FERPA compliance relate to cybersecurity?
FERPA currently lacks explicit cybersecurity requirements, which experts increasingly view as a gap in the law. Schools rely on hundreds of EdTech tools, but FERPA doesn’t mandate specific technical safeguards like encryption standards or breach notification timelines. Many states have begun filling this gap with their own legislation.