Student Privacy

FERPA, COPPA, and state privacy laws: who reviews what when schools buy AI?

School AI review fails when everybody assumes another department handled the law. FERPA, COPPA, state rules, contracts, security, and instruction answer different questions.

By HonorlyAI Team · 2026-07-23 · 11 min read

Quick answer

FERPA, COPPA, and state student-privacy laws overlap but do not do the same job. FERPA governs education records and the conditions under which schools disclose personally identifiable information. COPPA places duties on covered online-service operators collecting personal information from children under 13 and limits when schools may consent on a parent's behalf. State laws and contracts can add use, disclosure, advertising, deletion, security, and transparency requirements. A district needs coordinated legal, privacy, security, procurement, and instructional review.

Why the acronym checklist breaks down

Districts often ask a vendor whether it is "FERPA and COPPA compliant" as though two yes-or-no labels settle the review. They do not. Applicability depends on the data, users, purpose, relationship, contracts, and actual product behavior. A vendor's marketing statement cannot decide whether the district's planned use fits an exception or whether local obligations have been met.

The more useful question is: which rule governs which decision, who owns that decision, and what evidence will the district keep? That turns compliance from a badge into a workflow.

FERPA: education records, disclosure, and school control

FERPA protects personally identifiable information from education records maintained by an educational agency or institution. A district may sometimes disclose that information to a contractor under the school-official exception, but the relationship must satisfy specific conditions. Federal guidance emphasizes that the provider performs an institutional service or function, remains under the school's direct control regarding use and maintenance of the records, uses the information only for the authorized purpose, and meets the district's stated criteria for a school official with legitimate educational interest.

For an AI service, the district should map every input and output that may become part of an education record: prompts, uploaded assignments, feedback, teacher notes, analytics, classifications, summaries, and support logs. It should then connect each data flow to purpose, access, retention, redisclosure, and deletion.

COPPA: duties on operators serving children under 13

COPPA generally applies to covered commercial websites and online services that collect personal information online from children under 13. In an educational context, the FTC explains that a school may sometimes act as the parent's agent and consent to collection, but only when the information is used for the benefit of the school and for no other commercial purpose.

The operator must provide the school with the required notice of its collection, use, and disclosure practices. The FTC also recommends that schools or districts, rather than individual teachers, decide whether a service's information practices are appropriate. If the provider intends to use children's information for unrelated commercial purposes, school consent is not a magic permission slip.

State law may add another layer

Many states regulate operators of K-12 online services beyond federal baselines. Depending on the jurisdiction, those laws may restrict targeted advertising, profiling, sale, unrelated commercial use, disclosure, retention, or changes in control. They may create security duties, deletion rights, contract terms, or enforcement mechanisms.

New Jersey, for example, enacted a law concerning online education services and covered student information in 2020. A multi-state district, charter network, or vendor cannot assume that one federal analysis covers every deployment. The review should identify the states connected to the students and schools, then verify current statutory and contractual requirements with counsel.

The contract is where promises become enforceable

A privacy policy describes the provider's public position. The district agreement determines obligations between the parties. The contract should address authorized purpose, ownership, access, security, breach notification, subprocessors, model training, product improvement, human review, retention, deletion, export, audit rights, legal requests, changes to terms, and what happens when the relationship ends.

AI-specific review should ask whether prompts or outputs are used to train or evaluate models, whether humans may inspect content, whether safety systems create additional copies, and whether data moves across model providers or infrastructure subprocessors. "We do not sell student data" leaves most of those questions unanswered.

  • List every subprocessor that can receive student or school content.
  • Separate service delivery from product improvement and model training.
  • Specify deletion timing for primary systems, backups, logs, and derived data.
  • Require notice before material changes to data use or subprocessors.
  • Define the district's rights to export records and verify deletion.

Security and instruction are separate reviews

A legally permissible data flow can still be insecure. A secure product can still be instructionally harmful. Security teams should review authentication, authorization, encryption, logging, vulnerability management, incident response, isolation, and administrative controls. Curriculum and classroom leaders should review accuracy, age appropriateness, accessibility, student agency, teacher control, and the consequences of incorrect output.

NIST's AI Risk Management Framework offers a useful cross-functional structure through Govern, Map, Measure, and Manage. It does not certify a school tool. It helps the district document context, risk, measurement, ownership, and response throughout the lifecycle.

A review table that prevents dropped handoffs

Assign each question to a named owner and require a documented disposition. Privacy may own data purpose and rights; security may own technical controls; procurement may own enforceable terms; curriculum may own instructional fit; special services may own accessibility and accommodations; communications may own family notice; and leadership may own risk acceptance.

No department should approve "its part" in isolation and assume the whole product is approved. The final decision should state the permitted users, grades, purposes, settings, data types, and review date.

1. Legal and privacy

Identify applicable laws, authority for disclosure or consent, records obligations, and prohibited uses.

2. Security

Verify identity, access, encryption, logging, incident response, and vulnerability practices.

3. Procurement

Turn promises into contract duties, remedies, notice requirements, and exit rights.

4. Instruction

Determine whether the tool supports the learning objective and preserves teacher judgment.

5. Accessibility and equity

Test accommodations, language access, device assumptions, and equivalent alternatives.

6. Governance

Define approved scope, owner, monitoring, renewal, and the conditions for suspension.

The conclusion should name a scope, not award a badge

A defensible approval sounds like this: "Approved for grades 9-12, for teacher-created tutoring activities, using district accounts, with uploads limited to assigned course materials, under the attached retention and access settings, through June 2027." It does not sound like "FERPA approved."

Specific scope makes later auditing possible and prevents a narrow review from silently expanding into unrelated uses. This article is general educational information, not legal advice or a compliance determination.

Frequently asked questions

Does FERPA certify school AI vendors?

No. FERPA does not operate as a vendor certification program. Districts must analyze their planned disclosure and use, the provider relationship, direct control, authorized purpose, redisclosure, and other requirements.

Can a school consent under COPPA for every use of a child's data?

No. FTC guidance limits school consent to the educational context, for the use and benefit of the school and not for unrelated commercial purposes. The operator still has notice and other COPPA duties.

Who should approve an AI tool for classroom use?

A cross-functional district process should combine legal/privacy, security, procurement, curriculum, accessibility, operations, and leadership review. Individual teachers should not be expected to perform a full vendor privacy assessment alone.