The Family Educational Rights and Privacy Act (FERPA) protects the personally identifiable information in student education records, and private K-12 schools that receive U.S. Department of Education (DOE) funding must comply.
FERPA-related offenses can cost tens of thousands of dollars in fines, court fees, and settlements, but schools with strong data security and retention policies are better positioned to prevent improper disclosure.
This guide explains what FERPA covers, who qualifies as an eligible student, notable disclosure exceptions, how to handle breaches, and how FERPA intersects with AI tools and state privacy laws. You will also find a practical, step-by-step approach to building a FERPA-compliant admissions and records workflow that registrars and admissions teams can put to work right away.
RELATED: From Aid Award to LMS Class Roster: Closing the Enrollment Gap
Table of Contents:
- Key Takeaways
- What is FERPA and how does it apply to private K-12 schools?
- What counts as an education record under FERPA?
- Who is an eligible student under FERPA?
- What is the FERPA redisclosure rule under 34 CFR §99.33?
- How does FERPA help protect student data?
- What are the most common FERPA violations?
- How to build a FERPA-compliant records workflow at your school
- How does Ravenna Solutions help schools stay FERPA compliant?
- Frequently asked questions
- Does FERPA apply to private and independent schools?
- How long must schools retain student education records under FERPA?
- Can FERPA rights be waived?
- Does FERPA apply to videos?
- How does the FERPA breach response process work?
- How do you file a FERPA complaint?
- What happens if a FERPA complaint is lodged against my school?
Key Takeaways
- FERPA applies to any public or private K-12 school that receives funding from the U.S. Department of Education.
- Rights transfer to the “eligible student” at age 18 or upon enrollment in postsecondary education.
- 34 CFR §99.31(a) lists 16 specific exceptions that let schools disclose records without consent, including the school-official, studies, and health-or-safety-emergency exceptions.
- Uploading student data to AI tools and chatbots may count as a FERPA disclosure unless a qualifying written agreement is in place.
- Secure third-party software supports FERPA compliance through encryption, role-based access, and audit-ready reporting. Ravenna® offers exactly this for private K-12 schools.
What is FERPA and how does it apply to private K-12 schools?
FERPA is a federal law that protects student education records and gives families control over who can access them (20 U.S.C. §1232g and 34 CFR Part 99). It applies to any K-12 or postsecondary public or private school that receives funds from the U.S. Department of Education. Private, independent, and parochial schools that accept no federal funding are not subject to FERPA.
Signed into law in 1974, FERPA grants parents and caregivers three core rights:
- The right to access their child’s education records
- The right to request corrections to inaccurate or misleading records
- The right to control who accesses those records, with specific exceptions.
When a student turns 18 or enrolls in postsecondary education, these rights transfer from the parent or caregiver to the student. Following 2021 guidance from the DOE, written consent may now be provided electronically when proper authentication is in place, a helpful update for modern record keeping practices.
What counts as an education record under FERPA?
Education recordsDefinitionEducation RecordsInformation, whether online or on paper, a school keeps which relate directly to a student. Education records cover personal, behavioral, and classroom information.are any files or documents maintained by a school relating directly to a student. FERPA protects these records whether they exist in printed, handwritten, visual, audio, or digital format. Protected records include:
- Personal details such as a student’s race, gender, citizenship, address, and Social Security number.
- Attendance records, enrollment records, discipline records, class schedules, and grades.
- Notes from a teacher or administrator that have been shared or discussed with other staff.
Some items fall outside the definition. Personal notes kept private by a single staff member, law enforcement records created solely for law enforcement, designated directory information, and a student’s private health records are generally not considered education records.
For Parents
You have a right to request your child’s information and to keep it out of school directories. If you have any questions about your children’s rights to data privacy, contact your school’s registrar.
Who is an eligible student under FERPA?
An eligible studentDefinitioneligible studenta student who as either turned 18 years old or enrolled at a college or university. Once a student becomes "eligible," their rights to FERPA protections pass from parent to student. is one who has turned 18 years old or enrolled in a postsecondary institution. FERPA defines this transition of data protections as the point where rights previously belonging to the parent transfer to the student (34 CFR § 99.5). For example, a 17-year-old attending college is already an eligible student.
One key nuance: some postsecondary institutions may still permit parents to access records without student consent if the student is claimed as a dependent on federal taxes. For K-12 schools, the parent or guardian holds these rights until the student reaches 18.
For Eligible Students
Once you turn 18 or enter college, you become responsible for your own data. If you wish to view your data, schools have 45 days to respond to a formal request. Understand in which scenarios schools are allowed to share your personal information with outside parties.
What are all the exceptions to FERPA consent under §99.31?
FERPA generally requires written consent before a school discloses education records, but 34 CFR §99.31(a) provides a number of specific exceptions to that consent rule. The 16 exceptions for sharing protected student data are:
- Disclosure to faculty or staff to assist day-to-day operations:
-
- To other teachers or staff of the same school or district, as long as there is an educational interest at play.
- To an outsourced party (e.g., volunteer, contractor) operating in an official school capacity and within the confines of school policy.
- Schools must ensure staff and outside parties only have access to information on a need-to-know basis, as it pertains to the educational interest of each student.
-
- Disclosure to officials at another school or college for the purposes of a student transferring, applying, or enrolling at that institution. This includes disciplinary records.
- Disclosure to a state or federal authority.
- Disclosure in connection with financial aid the student has applied for.
- Disclosure to state or local officials, especially if these records concern the juvenile justice system.
- Disclosure for organizations conducting studies on behalf of the school.
- Disclosure to accrediting organizations.
- Disclosure to parents of a student they claim as a dependent.
- Disclosure to comply with a lawful subpoena or court order.
- Disclosure to appropriate parties in a health or safety emergency.
- Disclosure designated as directory information.
- Disclosure to the parent of a student who is not an eligible student or directly to the student.
- Disclosure of a disciplinary investigation’s final results to the victim of a violent crime or non-forcible sex offense.
- Only applying to colleges and universities, the disclosure of a disciplinary investigation’s final results of a student’s violent crime or non-forcible sex offense that violates school policies.
- Disclosure of drug- or alcohol-related disciplinary violations to the parents of college students under 21 years of age.
- Disclosure of information related to sex offenders.
When sharing sensitive information, documenting which exception applies to each disclosure protects your school during an audit.
What is directory information, and how can parents opt out?
Directory information is basic demographic data a school may disclose without consent, provided it gives public notice and allows families to opt out. Examples include a student’s name, address, telephone number, date of birth, participation in school sports, and honors or awards.
To use this exception correctly, a school must publicly define what it treats as directory information and give parents and eligible students a genuine chance to keep that information private.
Note one specific obligation: under the Elementary and Secondary Education Act, FERPA-eligible high schools must share student names, addresses, and telephone listings with military recruiters, unless a family has opted out or the school holds a verifiable religious objection.
Rights holders also have the option to request their own education records. Upon receiving a request, schools have 45 days to provide either a parent or eligible student with the information requested. Failing to do so constitutes a FERPA violationDefinitionFERPA violationSchools sharing education records with the wrong party, or denying education records to an eligible party, are in violation of FERPA and may be subject to to investigation, fines, or fund withholding from the Department of Education..
What is the FERPA redisclosure rule under 34 CFR §99.33?
The redisclosure rule of §99.33 prohibits anyone who receives FERPA-protected records from sharing them further without the original school’s consent or a new qualifying exception. In practice, this means a vendor, contractor, or partner organization cannot pass student data down the line on its own authority.
This rule matters most when your school works with third-party software providers. Confirm that every vendor understands the redisclosure restriction and agrees to honor it in writing. A clear redisclosure clause protects your school from downstream data sharing that was never authorized.
How does FERPA apply to AI tools and chatbots in schools?
Uploading student data to a generative AI tool or chatbot may constitute a FERPA disclosure unless your school has a qualifying written agreement in place. Pasting student names, grades, or behavioral notes into a public platform like ChatGPT can expose protected information without consent, creating a compliance risk that many schools have not yet addressed.
Many schools have already established guidelines for combining protected student data with AI tools. In general, staff should take these precautions:
- Update the existing FERPA release form to request permission for staff usage of student data in AI tools.
- Treat AI platforms like any other third-party vendor and require a written data-sharing agreement.
- Confirm the tool does not use your inputs to train its public models. This often means avoiding the free plan and purchasing a business plan for users.
- Develop a written internal policy that clearly defines which AI tools are approved and which categories of student data may never be entered.
This is a fast-emerging area with limited published guidance, so a clear internal policy gives your team confidence and keeps student data protected.
What is a FERPA-compliant data-sharing agreement with a vendor?
A FERPA-compliant data-sharing agreement (DSA) is a written contract that defines how a third-party vendor may handle, store, and destroy student data, and it specifies that the vendor will not redisclose records without authorization. Many schools rely on informal terms-of-service review, but a formal DSA provides far stronger protection.
When evaluating a vendor, look for a DSA that:
- Limits data access to the vendor’s personnel with a legitimate need.
- Specifies encryption and security standards for data in transit and at rest.
- Requires destruction of student data once it is no longer needed.
- Names the school as the controlling authority over any redisclosure.
These provisions align with FERPA’s contractor exceptions, which require a written agreement whenever an outside organization handles education records on the school’s behalf (34 CFR §99.31).
How does FERPA help protect student data?
FERPA protects students by safeguarding the personal details and academic information that could affect their reputation and future opportunities. Schools collect an enormous volume of sensitive data, and families trust that this information stays secure. Three pressures make that protection especially urgent today.
Rising cyberthreats against K-12 schools
Education is a frequent target for cyberattacks. Recent reporting from educational outlets finds 82 percent of schools experienced a noteworthy cyber threat, and one-third endured a significant attack over a similar period.
Because schools hold deep stores of personal data, they remain attractive targets. It’s incumbent upon schools to develop strategies to combat phishing and ransomware attempts and collaborate with cybersecure vendors.
Student safety in emergencies
FERPA permits schools to disclose protected information of student(s) during a genuine medical or safety emergency (34 CFR § 99.36). Sharing the right information quickly helps ensure students receive proper medical treatment when it matters most.
Protecting students with disabilities
While a student’s education record should not contain specific medical records, it may include notes or messages that reveal a child’s disability or medical condition. Exposing that information could lead to discrimination or harassment.
Records tied to the education plans of special needs students sit at the intersection of FERPA, the Individuals with Disabilities Education Act (IDEA), and HIPAA, each governing a different aspect of student health and education data. Families have the right to decide who can access this sensitive information.
What are the most common FERPA violations?
Most FERPA violations stem from honest mistakes rather than intentional wrongdoing. Knowing the common pitfalls helps your team prevent them. Ravenna’s compliance team notes that the most common FERPA violations include:
- Releasing information without consent: Emailing student information to the wrong recipient, sharing an athlete’s academic status, or including a Social Security number on an unprotected document all count as violations.
- Failing to secure records properly. Allowing unauthorized staff or outside parties to access records, or failing to dispose of records securely, violates FERPA’s protection requirements. This doesn’t always mean a cyberattack or negligence — it can be as simple as a teacher meeting with parents privately and leaving student information on-screen from the previous meeting.
- Denying authorized access. Refusing the parent of an under-18 student, or an eligible student, access to records they are entitled to see is a FERPA violation.
- Failing to inform families of their rights. Schools must notify parents and eligible students of their FERPA rights at least once a year and announce any policy changes.
What are the consequences and penalties for a FERPA violation?
The most severe penalty for misusing or improperly disclosing student records is the loss of DOE funding (34 CFR 99.67(a)). In practice, reaching that point would require a major, intentional refusal to comply.
The DOE’s Student Privacy Policy Office (SPPO) resolves FERPA violations, and its mission centers on helping schools return to compliance rather than punishing them. When a violation is reported, the SPPO works with the school to adjust its operations. Schools that refuse to cooperate may face escalating consequences:
- An order to cease and desist
- Required payment of fines
- Paused payments from the Department of Education
- Loss of eligibility for future federal funding
- Loss of accreditation.
Keep in mind these are only consequences as far as the federal government is concerned. Misuse of student data often damages a school’s reputation, opens it up to lawsuits, and may result in action from state-level regulators.
How does FERPA compare to state student privacy laws?
FERPA sets a federal floor for student privacy, but many schools must also meet additional state and federal obligations. Depending on location and the ages of students served, your school may be subject to overlapping frameworks beyond FERPA. In addition, it’s important to understand how vendors and key partners are also responsible for data protection.
| Law | Scope | What it adds beyond FERPA |
|---|---|---|
| FERPA | Federal: all funded schools | Baseline access, consent, and disclosure rules for education records |
| COPPA | Federal: children under 13 online | Consent rules for collecting children’s data through online services |
| PPRA | Federal: all funded schools | Guides how schools conduct surveys or collect sensitive behavioral data |
| SOPIPA | State: California edtech vendors | Restricts how edtech providers use and sell student data |
| NY Education Law 2-d | State: New York schools and vendors | Adds data security and breach-notification duties for student data |
Because state laws change frequently, registrars benefit from a system that adapts to evolving compliance requirements rather than one that locks them into a single rule set.
How to build a FERPA-compliant records workflow at your school
Building strong workflows protects student data and keeps your school audit-ready.
- Assess strengths and weaknesses. Periodically evaluate current record-keeping practices, including the security policies of any third-party software, to identify and prioritize gaps.
- Implement clear data privacy policies. Establish straightforward rules for collecting and sharing student data so staff handle records consistently. Ensure compliance as policies evolve by updating FERPA disclosure forms each year to help families fully understand their rights.
- Destroy outdated files securely. Assign an administrator to regularly dispose of unused digital and physical records, shredding paper files that contain personal information.
- Encrypt sensitive data. Encrypt information as it rests in your system and when sending it to a recipient. Ensure software vendors abide by this principle.
- Provide staff training. Accidental leaks often originate with staff. Improper designation of directory information, for example, is one of the most common FERPA violations, with a repeat offense rate of 31 percent. As such, it’s important to teach employees what FERPA requires using regular compliance and cybersecurity trainings.
- Monitor cybersecurity threats. Invest in technology and IT support to detect threats and test your defenses before a breach occurs. Have a plan for immediate response and notification should a breach occur.
- Limit access to records. Grant access only when staff have a legitimate educational need. Teachers should see records for their own students, and only the nurse should view vaccination records. Vendors, too, should only have access to student data when processing workflows, so have a written agreement on when sensitive data will be deleted.
- Review third-party tools carefully. Examine the terms, privacy policies, and data-sharing agreements of every external tool, with special attention to AI platforms and their redisclosure obligations.
For Schools
Schools have the responsibility of safeguarding student data and ensuring parents or eligible students have access to the personal data they request. Ensure staff only have access to the data they have an educational interest in, and train them to properly handle and disclose education records.
How does Ravenna Solutions help schools stay FERPA compliant?
Ravenna Solutions is an admissions and financial aid management platform built exclusively for K-12 private and independent schools. Serving more than 5,000 independent and private schools, supporting over 1 million students, and processing more than 300,000 applications annually, Ravenna pairs admissions-specific functionality with the security features needed to protect student data.
Ravenna Admissions and Ravenna Financial Aid support FERPA compliance through built-in encryption, role-based access controls that limit record access to staff or trusted partners with a legitimate need, and audit-ready reporting tools. Ravenna acts as a FERPA School Official with a legitimate educational interest, encrypting all data in use, whether processed, stored, or sent through secure transmissions.
These security protocols give schools and families peace of mind, but Ravenna offers more than just data protection. Schools using Ravenna report 67% fewer administrative hours spent on admissions workflows and process admissions data up to five times faster than manual methods, freeing your team to focus on mission-critical work while keeping sensitive information secure.
Frequently asked questions
Does FERPA apply to private and independent schools?
FERPA applies only to private or independent schools that receive funds from the U.S. Department of Education. Private, independent, and parochial schools that do not accept federal funding are not subject to FERPA, though they may still be bound by federal and state privacy laws.
How long must schools retain student education records under FERPA?
FERPA does not set a federal retention timeline. Instead, schools should follow their state’s record retention schedule, which varies by jurisdiction, and destroy records lawfully once they are no longer needed. Paper records with personal information should be shredded.
Can FERPA rights be waived?
Yes. Under 34 CFR §99.37, an eligible student may voluntarily waive the right to inspect confidential letters of recommendation. A valid waiver must be made in writing, and the school cannot require it as a condition of admission or any other service.
Does FERPA apply to videos?
Yes. A video that contains information directly related to a student and is maintained by a qualifying school is protected under FERPA. Routine footage that does not focus on a specific student, such as general hallway security video, is generally not protected unless it captures an incident involving a particular student.
How does the FERPA breach response process work?
While FERPA does not mandate a specific breach-notification procedure, a strong response follows clear steps: contain the incident, identify what data was exposed, notify affected families and the SPPO as appropriate, document every action taken, and review the workflow to prevent a recurrence.
How do you file a FERPA complaint?
If a parent or eligible student (18 years old or enrolled in college) believes a school violated their privacy, they can file a complaint with the U.S. Department of Education’s Family Policy Compliance Office (SPPO). The petitioner must submit an online form available on the SPPO website, detailing the specific allegations and how they violate FERPA policies.
Complaints must be submitted within 180 days of the data exposure or 180 days of knowledge of the event. The SPPO recommends first seeking to resolve your complaint with the offending school.
What happens if a FERPA complaint is lodged against my school?
If a complaint is filed against your institution, the SPPO will request documentation of your records practices, consent procedures, and disclosure logs. Schools with well-maintained audit trails and documented exception justifications are far better positioned to demonstrate compliance and resolve complaints efficiently.



