Skip to content
Saturday, August 22, 2026
MamagerahEducation & media
Research · Learning · Evidence
business-news

Why FERPA's vendor exception decides what ed-tech can access

Federal law never says a classroom app can have student data by default. A narrow exception does the work, and a wave of new state laws is now building stricter rules on top of it.

Why FERPA's vendor exception decides what ed-tech can access

Almost every classroom app that touches a student record runs through one legal mechanism: FERPA's "school official" exception. The U.S. Department of Education says a vendor may see personally identifiable information only if it performs a function the school would otherwise handle itself, stays under the school's direct control, and never re-discloses that data without specific authorization. That single exception is the hinge the entire ed-tech data economy swings on, and states are now writing tighter law around it.

What does FERPA's school-official exception actually allow?

The federal Family Educational Rights and Privacy Act does not name apps or vendors at all. Schools may treat a contractor as a "school official" only if four conditions hold, per Department of Education guidance: the vendor performs a service the school would otherwise staff itself, it operates under the institution's direct control over data use, it uses the data solely for the purposes named in the contract, and it does not re-disclose personally identifiable information to other parties without specific authorization. The Department's vendor-facing guidance is explicit that data mining student records for purposes such as targeted advertising "likely violates" federal or state law, and that any use outside the contract's stated purpose falls outside the exception entirely.

Why does the exception, not a specific law, set the real limits?

FERPA does not require a particular data-security standard or a specific contract clause; it requires that whatever a vendor does trace back to a school's own authority. That is a lower bar than many teachers assume, and a 2021 study in the BYU Education & Law Journal found the gap shows up in practice: by 2017, more than half of K-12 students were using Google's education apps, and over 95% of U.S. K-8 schools were using ClassDojo, yet an earlier study the paper cites found most school technology contracts "failed to list the type of student information collected or did not stop vendors from selling personal student data." Only about a quarter of districts in that same research had told parents which cloud services were in use, despite regulatory expectations that they do so.

What data ends up in scope beyond grades and attendance?

The BYU review lists categories well past the traditional education record: names and contact details, web-browsing histories and IP addresses, geolocation, biometric and behavioral data, and disciplinary or medical information collected incidentally through classroom software. None of that is exotic — it is the ordinary telemetry of a login-based app — but FERPA's school-official exception covers it only to the extent a school's own contract says so. The Department of Education's vendor FAQ states that schools should require vendors to disclose data-security plans, publish contracts listing what data elements are shared, and provide certification of data destruction once a contract ends. None of that is a federal mandate; it is best practice the Department recommends schools build into procurement.

How does Utah's 2026 law tighten what FERPA leaves open?

States are increasingly not waiting on federal rulemaking to close those gaps. A bill amended in Utah's 2026 legislative session, H.B. 55, requires the state board's student data privacy team to audit new contracts and data-privacy agreement revisions with third-party contractors within six months, bars vendors from selling student data except in specified circumstances, and requires vendors to return or delete all personally identifiable student data at contract's end unless a parent or adult student gives written permission to keep it. Utah lawmakers built the bill directly on top of FERPA's contract-based framework rather than replacing it — the audit and deletion requirements attach to the same vendor contracts FERPA already governs, they just add state-level enforcement teeth.

Where does FERPA's authority stop?

FERPA governs education records held by schools that take federal funding, which is why the school-official exception is the mechanism vendors rely on in the first place — it is the legal bridge that lets a school's own data obligations extend to a third-party app at all. The Department of Education's guidance for vendors sits inside that same framework: it addresses cybersecurity practices, breach response, and data retention and destruction as things a school-official contract should specify, not as separate federal mandates. That is also why state law has become the layer doing more of the specific work. Utah's H.B. 55 does not attempt to redefine what a school official is; it adds an audit requirement, a sale ban, and a deletion mandate on top of the contracts FERPA already recognizes. The Department of Education's own guidance frames this as consistent with its broader posture: the Department describes itself as having moved toward more efficient, risk-based enforcement rather than prescribing a single national data-handling standard, which is part of why individual states have room to legislate ahead of any federal rule change.

What does the audit requirement mean for vendor sales cycles?

Utah's 2026 legislation puts a concrete clock on vendor compliance: the state board's student data privacy team must audit a new contract or a revised data-privacy agreement within six months of it taking effect, according to the bill text. For an ed-tech company selling into Utah districts, that converts what used to be a one-time contract negotiation into a recurring compliance checkpoint tied to the state board rather than the individual school. The bill also requires state board staff to produce educational materials to help vendors understand the requirements — an acknowledgment, built into the law itself, that many vendors are not currently structured to track state-by-state data rules on top of federal ones. Companies selling into multiple states now have to reconcile FERPA's baseline with a growing patchwork of state-specific audit, sale, and deletion rules rather than a single national standard.

What does the school-official exception not cover?

The school-official exception has real edges. The Department of Education's vendor FAQ is explicit that PII use must stay limited to the purposes named in the contract, and that data mining for something like targeted advertising to students "likely violates" federal or state law — meaning a vendor operating inside the exception for one function (say, assignment grading) is not automatically covered for another (say, building an advertising profile) even under the same login. Utah's law adds a parallel boundary at the back end: a vendor cannot simply keep data indefinitely once a contract ends, and cannot sell it, absent written parental or adult-student permission. Neither rule requires a school to catch the violation itself in real time; both rely on contract terms and, in Utah's case, a state audit process to surface problems after the fact.

What should a district ask before buying software?

For a purchasing committee, the practical upshot is that FERPA compliance and a signed vendor contract are not the same thing. A vendor can be fully within FERPA's school-official exception and still be operating under a contract that never specifies what data it collects, whether it can be sold, or what happens when the contract ends — the exact gaps the BYU research found common as of 2021. States moving to require contract audits, sale bans, and mandatory deletion are effectively writing the specificity FERPA's exception assumes districts will negotiate for themselves but does not require. A district evaluating any new classroom tool should expect to see, in writing and dated, what data is collected, whether it can be resold, and what happens to it if the contract lapses — because federal law leaves those terms to the contract, not the statute.

For a related edtech news perspective, read What FERPA actually lets edtech vendors do with student data.

Sources

  1. U.S. Department of Education, Protecting Student Privacy — Vendor FAQ
  2. U.S. Department of Education, Protecting Student Privacy — Education Technology Vendors
  3. Susan G. Archambault, "Student Privacy in the Digital Age," BYU Education & Law Journal (2021)
  4. Utah State Legislature, H.B. 55 (2026 General Session, amended)