Student Data Privacy and AI: FERPA in Practice
Student data privacy under AI means controlling how artificial intelligence tools collect, store, and process education records protected by the Family Educational Rights and Privacy Act (FERPA). FERPA, a U.S. federal law enacted in 1974, gives parents and eligible students rights over education records and limits how schools and their vendors disclose personally identifiable information (PII). When a school adopts an AI tutor, an essay grader, or a predictive analytics platform, that tool becomes a FERPA-covered service the moment it touches student records, and the school stays legally responsible for how the vendor handles the data.
This is the practical problem facing every district, college, and edtech buyer in 2026. AI systems collect large volumes of data by design, and FERPA was written 50 years before large language models existed. The law still applies, but applying it correctly to AI requires translating old definitions into new technical realities.
What does FERPA actually protect, and how does AI change the calculation?
FERPA protects education records: records directly related to a student and maintained by an educational agency or institution that receives U.S. Department of Education funds. This covers grades, transcripts, disciplinary files, special education records, and increasingly the detailed activity data students generate inside learning platforms.
The core FERPA rule is consent. A school generally cannot disclose PII from education records without written consent from a parent or an eligible student (a student 18 or older, or attending a postsecondary institution). AI changes the calculation in three concrete ways:
Volume and granularity. AI platforms ingest keystroke logs, time-on-task data, draft revisions, and interaction patterns that traditional gradebooks never captured. More data means more PII to protect and more exposure in a breach.
Secondary use. Many AI vendors want to use student inputs to train or improve their models. FERPA limits using education records for purposes beyond the service the school contracted for.
Opacity. When an AI model makes or informs a decision about a student, the record of that decision, and the inputs behind it, can become part of the education record, which means parents have a right to inspect it.
Is data that trains an AI model covered by FERPA?
Often, yes. If a vendor uses identifiable student records to train a model, that is a disclosure and use of education records. FERPA permits sharing records with a vendor only under specific exceptions, and any use must stay inside the scope of those exceptions. Using student work to improve a commercial product, beyond serving the school, generally falls outside what FERPA allows without consent.
The cleaner path is de-identification. FERPA permits disclosure of de-identified records, but the standard is strict: a record is de-identified only when the school has made a reasonable determination that a student's identity is not personally identifiable, accounting for other reasonably available information that could re-identify the student. Stripping a name is not enough. Free-text student writing is hard to de-identify because the content itself can be identifying.
How do FERPA exceptions apply to AI vendors?
Two FERPA exceptions do most of the work when a school hands student data to an AI tool: the school official exception and the directory information rule.
The school official exception lets a school disclose education records, without consent, to a third party performing an institutional service or function the school would otherwise do itself. To qualify, the arrangement must meet four conditions:
Legitimate educational interest. The vendor needs the data to perform the contracted service.
Direct control. The school maintains direct control over the vendor's use and maintenance of the records.
Use limitation. The vendor uses the records only for the authorized purpose and does not redisclose them.
Annual notification. The school's annual FERPA notice defines who counts as a school official, including contractors and vendors.
An AI vendor that wants to reuse student data to train models for other customers breaks condition 2 and condition 3. That is the most common point of FERPA failure in AI contracts.
What is the school official exception in plain terms?
It means a school can treat an AI vendor like an in-house employee for data-access purposes, but only if the contract keeps the vendor tightly restricted: the vendor uses the data solely for the school's purpose, holds it under the school's control, and deletes or returns it when the engagement ends. If the contract lets the vendor do anything else with the data, the exception no longer covers it.
Does directory information let schools share student data freely?
No. Directory information is a narrow category (name, grade level, participation in activities, and similar items) that a school may designate and disclose without consent, after giving parents notice and a chance to opt out. Directory information does not include grades, behavioral data, biometric identifiers, or the detailed interaction data AI tools collect. Treating that interaction data as covered by directory information is a misreading of the rule.
What does FERPA-compliant AI procurement look like in practice?
FERPA compliance for AI is mostly a contracting and configuration exercise. The law sets the obligations; the data protection addendum (DPA) and the product settings make them real. Below is a side-by-side view of the high-risk default versus the compliant configuration.
FERPA concern: Model training on student data.
High-risk default: The AI vendor trains its models on customer inputs by default.
Compliant configuration: The contract explicitly prohibits training on student data, and model training is disabled.
FERPA concern: Data ownership.
High-risk default: Ownership of student records or AI-generated outputs is unclear or claimed by the vendor.
Compliant configuration: The school retains ownership of all student records and AI-generated outputs.
FERPA concern: Redisclosure.
High-risk default: The vendor may share student data with subcontractors without clear restrictions.
Compliant configuration: All subprocessors are identified, bound by the same contractual protections, and prohibited from further disclosure or sale.
FERPA concern: Data retention.
High-risk default: Student data is retained indefinitely.
Compliant configuration: The contract specifies retention limits and requires deletion or return of all data when the agreement ends.
FERPA concern: Re-identification.
High-risk default: There are no restrictions on re-identifying de-identified student data.
Compliant configuration: The contract expressly prohibits any attempt to re-identify de-identified data.
FERPA concern: Breach response.
High-risk default: Data breach obligations are vague or missing.
Compliant configuration: The agreement defines breach notification timelines and the vendor's cooperation responsibilities.
FERPA concern: Data location and access.
High-risk default: Data storage locations and access controls are not specified.
Compliant configuration: The contract clearly defines where data is stored and documents the encryption, access controls, and other security measures used to protect student information.
The pattern is consistent: every row turns a vague vendor promise into a written, enforceable term. A school that signs an AI vendor's standard terms of service without a FERPA-specific addendum has usually not met its direct control obligation.
What contract terms should a school require from an AI vendor?
Require these terms before any student data flows to the tool:
No training on student data without separate, specific consent.
School ownership of all education records and derived outputs.
Purpose limitation restricting use to the contracted service.
Subprocessor disclosure with flow-down of identical FERPA obligations.
Defined retention and deletion, with certified deletion at termination.
Re-identification prohibition on any de-identified data.
Breach notification within a stated number of days, plus cooperation in any investigation.
Audit rights allowing the school to verify compliance.
How should schools handle parental consent and notice for AI tools?
For uses that fall outside the school official exception, the school needs written consent that identifies the records to be disclosed, the purpose, and the party receiving them. For uses inside the exception, the school still must list vendors as school officials in its annual FERPA notification and honor inspection and correction rights. Districts adopting classroom AI broadly should fold these requirements into a written governance policy. A practical model for that policy lives in our guide to AI policy for schools.
How does FERPA interact with state laws and other AI regulations?
FERPA sets a baseline, and other laws build on it. State policymakers have passed more than 100 student-privacy laws since 2014, and several are stricter than the federal standard.
State student-privacy statutes. Many states have laws modeled on California's Student Online Personal Information Protection Act (SOPIPA), which directly binds edtech operators (not just schools) and prohibits using covered student data for targeted advertising or building non-educational profiles. These laws reach AI vendors directly.
Children's online privacy. The federal Children's Online Privacy Protection Act (COPPA) governs collection of data from children under 13 and overlaps with school use of edtech, including AI tools used by younger students.
Special education records. The Individuals with Disabilities Education Act (IDEA) adds confidentiality requirements for special education data, a category AI tools touch when they personalize instruction.
State AI statutes. Colorado's SB 24-205 was the first comprehensive U.S. state AI law, imposing duties on developers and deployers of high-risk AI systems used in consequential decisions, a category that can reach AI used in education. The original statute has faced legal challenge and legislative revision, so schools should track its current status rather than assume a fixed set of obligations.
The compliance reality is layered: a single AI tutoring contract can trigger FERPA, a state SOPIPA-style law, COPPA for younger students, and IDEA for students with disabilities, all at once.
What can hiring-AI enforcement teach schools about AI risk?
Education has fewer AI-specific enforcement actions than employment does, but the employment cases show the legal logic schools will face. Regulators and courts have already treated AI decision systems as accountable to existing law:
NYC Local Law 144 requires a bias audit of automated employment decision tools, with enforcement that began on July 5, 2023.
The iTutorGroup EEOC settlement (2023) resolved claims that hiring software automatically rejected older applicants. iTutorGroup agreed to pay $365,000.
Mobley v. Workday allowed an AI-screening bias suit to proceed, signaling that AI vendors themselves can face liability under an agent theory.
The EU AI Act classifies employment and recruitment AI as high-risk under Annex III, point 4, with documentation and oversight duties.
The transferable lesson is that blaming the algorithm is not a defense. When AI informs decisions about students (placement, intervention, discipline, admissions), the institution stays accountable for accuracy, bias, and the records the system creates. A predictive tool that flags students for intervention based on protected-class proxies invites the same scrutiny that hiring tools now face.
What are the most common FERPA-AI compliance failures?
Schools and vendors repeat a short list of mistakes:
Signing clickwrap terms. Accepting a vendor's standard terms of service, which often grant broad data-use rights, instead of a FERPA-specific addendum.
Allowing default model training. Leaving the "improve our service" setting on, which routes student inputs into model training.
Treating de-identification as a name-strip. Removing names while leaving identifying free-text or rare attributes intact.
Ignoring shadow AI. Teachers pasting student work into consumer chatbots that have no school agreement and no FERPA terms.
No retention limit. Letting vendors hold student data indefinitely with no deletion obligation.
Skipping the annual notice update. Failing to list AI vendors as school officials, which weakens the school official exception.
Shadow AI deserves separate attention. When a teacher pastes identifiable student writing into a free consumer AI tool, the school has disclosed education records to a third party with no FERPA terms, no control, and no deletion guarantee. That is a disclosure the school cannot account for, and it is now one of the most frequent real-world FERPA exposures in K-12 and higher education.
Next steps: a FERPA-AI compliance checklist
Use this checklist before and after adopting any AI tool that touches student records.
Step: 1
Action: Inventory every AI tool that accesses or processes student data, including unofficial or employee-adopted tools.
Owner: IT and Data Governance.
Step: 2
Action: Classify the personally identifiable information (PII) collected by each tool against the FERPA definition of education records.
Owner: Privacy Officer.
Step: 3
Action: Require a FERPA-specific Data Processing Agreement (DPA) before any student data is shared, and reject vendors that rely only on standard click-through terms.
Owner: Procurement and Legal Counsel.
Step: 4
Action: Disable model training and any secondary data use features in each AI product.
Owner: IT Administrator.
Step: 5
Action: Verify that any de-identification process satisfies FERPA's reasonable determination standard.
Owner: Privacy Officer.
Step: 6
Action: Include approved AI vendors as school officials in the institution's annual FERPA notice, where appropriate.
Owner: Registrar and Compliance.
Step: 7
Action: Establish data retention limits and require certified deletion of student data at the end of each vendor contract.
Owner: Procurement.
Step: 8
Action: Publish a policy prohibiting staff from entering student PII into unapproved consumer AI tools.
Owner: Institutional Leadership.
Step: 9
Action: Evaluate compliance with applicable state student privacy laws (such as SOPIPA-style laws), COPPA, and IDEA in addition to FERPA.
Owner: Legal Counsel.
Step: 10
Action: Reassess AI tools annually and whenever a model, vendor, or major system change occurs.
Owner: Data Governance.
Frequently asked questions
Does FERPA apply to AI tools like ChatGPT used in schools?
FERPA applies whenever a school discloses education records to an AI tool. A general consumer tool used without a school agreement and without FERPA terms creates an unaccounted disclosure if a staff member enters identifiable student data. To use such a tool compliantly, a school needs a contract with FERPA-specific terms or must keep all identifiable student records out of the tool entirely.
Can an AI vendor train its models on our students' data?
Only under tight limits. Training a commercial model on identifiable education records is a use that usually falls outside FERPA's school official exception, because it serves the vendor's product rather than the school. Compliant practice is to prohibit training on student data by contract, disable the corresponding product setting, and require separate written consent for any training use.
Is de-identified student data still covered by FERPA?
Properly de-identified data falls outside FERPA's disclosure restrictions, but the standard is demanding. The school must reasonably determine a student cannot be identified, accounting for other available data that could re-identify them. Removing a name is not enough, and free-text student writing is difficult to de-identify. Contracts should also ban any attempt to re-identify the data.
Who is liable if an AI vendor mishandles student records?
The school or district carries primary FERPA accountability, because FERPA obligations run to the educational institution. The school stays responsible for vendor conduct under the school official exception, which is why direct control and contract terms matter. Vendors face exposure under state student-privacy laws, COPPA, and, as the Workday litigation shows, potentially as parties to bias and discrimination claims.