Since we are starting a new school year, I thought it’d be a great time to share some student data privacy FAQs and general information.
- Dual Enrollment information per TEC:
- If a student enrolled in LEA #1 (MO district) transfers to, or is dually enrolled in, LEA #2 (community college), parental consent and/or a DPA would not be required for the district to share the student’s data with the community college, as the disclosure is permitted under FERPA’s school-to-school transfer provisions.
If LEA #2 (the community college) subsequently shares the student’s data with a third-party ed tech provider, it is the community college’s responsibility to ensure that the disclosure is permissible under FERPA, including obtaining a DPA or parental/eligible student consent when required. The community college would have the contractual service agreement with the vendor; the district would have no direct relationship with the third-party provider.
- If a student enrolled in LEA #1 (MO district) transfers to, or is dually enrolled in, LEA #2 (community college), parental consent and/or a DPA would not be required for the district to share the student’s data with the community college, as the disclosure is permitted under FERPA’s school-to-school transfer provisions.
- Does a school resource officer qualify to be a school official?
- Due to the complexity of this question, please refer to this document from the U.S. Department of Education.
- Does a parent have FERPA rights for a 17-year-old that is taking dual-credit courses?
- If the student record is maintained by the college, FERPA rights are transferred to the eligible student for those courses. An eligible student is defined as a student that is over 18 years of age or attending a post-secondary education institution.
- What applications should I consider obtaining a data privacy agreement for?
- If student PII is transferred to the third party, the district should pursue a data privacy agreement or obtain parental consent. Note: Applications will state in their privacy policies if they do not collect student PII.
- Can schools grant COPPA consent?
- Yes, if the tool is used solely for an educational purpose.
- The information collected must be “for the use and benefit of the school, and for no other commercial purpose.”
- Can the Directory Information (DI) Exception be used for vetting educational technology applications?
- FERPA defines directory information as a subset of information within a student’s education record that would generally be considered harmless if disclosed.
- When you combine the limited amount of directory information with non-directory information (which most ed tech will do), none of it can be considered DI anymore.
- What should be included in the Annual Notice to Parents for the School Official Exception?
- You must include a specification of the criteria you use to determine who constitutes a school official.
- Example Criteria
- Legitimate educational interest
- Be under direct control for the use and maintenance of records,
- And be subject to FERPA redisclosure limits
- Example Criteria
- A school’s annual notice should reference ed tech vendors as school officials, otherwise a district cannot share student data under the school official exception.
- You must include a specification of the criteria you use to determine who constitutes a school official.
- Data privacy agreements and school policies
- Compare your DPA and your school policy to confirm they are consistent.
- The privacy policy states the application is not approved for use under 13 years of age. Can I obtain parental consent for this application?
- If the privacy policy/terms of service prohibits the intended age group from using the application, a data privacy agreement or parental consent cannot override this – the application cannot be used for that age group.
- Can we use a “blanket” parental permission form for all applications requiring parental consent?
- Per TEC – Yes, but it should include legal language that removes the liability from the district and parents must be able to opt-in on an individual basis per application. The following information or URL should be included for each application:
- Privacy Policy
- Terms of service
- Data Elements Collected
- Per TEC – Yes, but it should include legal language that removes the liability from the district and parents must be able to opt-in on an individual basis per application. The following information or URL should be included for each application:
- How does AI change the way data is reviewed/vetted?
- Ask the vendor if student PII will be used to train the model and how the outcome will be used for potential future products.
- If the vendor has recently added AI to their tool and have previously signed a data privacy agreement, contact the vendor and ask if the additional tool/implementation complies with the active data privacy agreement.
- AI decision making can create hallucinations, and it’s imperative to understand how the vendor handles hallucinations and ensures they can provide clear explanations of data usage, retention and disposal to meet parental transparency rights.
- Train staff to understand how AI can request input and use that data so they are cognizant of not sharing student PII.
These are guidelines to use when your organization. Please confer with your own legal counsel for specifics for your organization.



