Skip to content
Saturday, August 22, 2026
MamagerahEducation & media
Research · Learning · Evidence
teachers

What FERPA actually permits before a new app touches student data

The 'school official' exception is why a class can start using an app without a permission slip for every family — but only when a vendor clears three specific conditions written into federal regulation, not its own privacy page.

What FERPA actually permits before a new app touches student data

FERPA's "school official" exception, as the Department of Education's Student Privacy Policy Office describes it, is why a teacher can assign a new app to a class without collecting a signed permission slip from every parent — but only when the vendor clears three conditions written into federal regulation: a defined service role, direct school control, and no redisclosure of student data.

What FERPA covers, and why the exception exists

FERPA — the Family Educational Rights and Privacy Act — protects a student's "education records," defined by the Student Privacy Policy Office's FERPA guidance as records that are directly related to a student and maintained by a school or by a party acting for the school. The default rule is that a school needs a parent's (or, after age 18, the student's) consent before disclosing those records to an outside party. That default is the reason permission slips exist at all for field trips, photo releases, and research studies.

The school-official exception, codified at 34 CFR §99.31(a)(1), is a carve-out to that default. It lets a school disclose records without separate consent to "school officials" who have a legitimate educational interest — and the regulation, as the Student Privacy Policy Office quotes it, explicitly extends that label to outside vendors: "A contractor, consultant, volunteer, or other party to whom an agency or institution has outsourced institutional services or functions may be considered a school official." That single sentence is the legal basis for almost every ed-tech tool a teacher assigns without an individual consent process, from a spelling app to a whole-class writing platform.

It is worth being precise about what that sentence does not say. It does not say any vendor is automatically a school official. It does not say a free sign-up form substitutes for a contract. It sets a test, and the test has three parts.

What are the three conditions a vendor actually has to meet?

The exception only applies when a vendor satisfies all three tests the Student Privacy Policy Office lays out from the regulation — miss one, and the vendor is just an outside party like any other, back under the general consent requirement.

ConditionWhat the regulation requiresWhat breaks it
Defined service roleThe vendor must "perform an institutional service or function for which the agency or institution would otherwise use employees."The tool isn't doing a job the school would otherwise staff — it's a general consumer product a student happens to use.
Direct controlThe vendor must be "under the direct control of the agency or institution with respect to the use and maintenance of education records."There's no district contract or data agreement — just a teacher or student's individual account, governed by the vendor's own terms.
No redisclosureThe vendor is bound by §99.33(a), barring it from disclosing information "to any other party without the prior consent of the parent or eligible student."The vendor sells, shares, or otherwise redistributes student data to a fourth party.

Does clicking "I agree" on a vendor's terms satisfy FERPA?

Not by itself. The Student Privacy Policy Office's guidance on privacy and education technology points schools toward a specific evaluation step before signup, not after: a "Model Terms of Service" framework built to help a school or district read "how a given online service or app will collect, use and/or transmit user information" and decide whether to sign up in the first place.

That framing matters because "direct control" is a school-side obligation, not something a vendor's standard consumer terms of service establishes on their own. A district's actual FERPA position rests on what its contract or data-sharing agreement with the vendor says — not on the vendor's own marketing language about privacy, and not on a teacher's individual click-through acceptance of a free tier's terms. A teacher accepting a browser pop-up is not the same act, legally, as a district signing a data-sharing agreement — even when the app looks identical on screen either way.

What happens if a vendor doesn't meet the three conditions?

The Student Privacy Policy Office presents the school-official exception as one of the carve-outs FERPA allows before a school needs a parent's consent for disclosure — which means a vendor that fails any of the three conditions simply falls outside the exception. At that point the tool is legally just another outside party, and the school's normal FERPA consent obligations apply to whatever student data the tool collects. In practice, that's the dividing line between a tool a district has vetted and contracted with, and a free consumer app an individual teacher or student signs up for independently — the second category is common in classrooms, and it's exactly the category the exception doesn't cover.

Does COPPA add anything on top of FERPA?

Separately from FERPA, the Federal Trade Commission's Children's Online Privacy Protection Act rules apply whenever an online service collects personal information from children under 13. The FTC's compliance FAQ, current as of a July 2026 update, notes that when a service collects a parent's or child's name or contact information for consent purposes, "the sole purpose of collecting the name or online contact information of the parent or child is to provide notice to the parent and obtain parental consent." The same FAQ document sets aside an entire dedicated section specifically addressing how COPPA interacts with schools — a signal that the FTC treats classroom deployment differently from a public consumer app, though the specific school-consent mechanics laid out in that section weren't confirmed for this piece and shouldn't be assumed from the heading alone. For any tool used with students under 13, treat COPPA as a second, separate compliance question from FERPA rather than something the school-official exception already resolves.

What should a teacher actually check before assigning a new tool?

Based on the Department's own guidance, a few concrete checks are within a teacher's reach even without becoming the district's privacy officer:

  1. Ask whether the tool is on the district's approved or contracted list — that contract, not the vendor's public terms of service, is what establishes "direct control" under FERPA.
  2. If it isn't on that list, treat it as outside the school-official exception by default, and check with a building or district administrator before assigning it for anything beyond optional, non-graded use.
  3. For any tool that does collect student data, ask specifically how it's collected, used, and transmitted — the same three questions the Student Privacy Policy Office's Model Terms of Service framework is built around.
  4. For students under 13, assume COPPA's separate consent framework is in play alongside FERPA, and confirm with an administrator how the district is satisfying it rather than assuming a vendor's sign-up flow has already handled it.
  5. Keep the question narrow and practical: not "is this tool good," but "has anyone with authority to sign for the school actually agreed to how this vendor handles student data."

None of this requires a teacher to become a lawyer. It requires knowing which question to route to someone who already is one — and knowing that a vendor's own reassurances aren't the same evidence as a signed agreement.

What the sourcing here doesn't settle: how individual states layer additional student-data-privacy statutes on top of FERPA and COPPA, and the full substance of the FTC's schools-specific COPPA guidance beyond its heading. Both are worth a district's data privacy officer weighing in on directly — this piece covers the federal floor, not every layer above it.

For a related edtech news perspective, read What FERPA actually lets edtech vendors do with student data.

Sources

  1. U.S. Dept. of Education, Student Privacy Policy Office — "FERPA | Protecting Student Privacy"
  2. U.S. Dept. of Education, Student Privacy Policy Office — "FERPA | Protecting Student Privacy"
  3. U.S. Dept. of Education, Student Privacy Policy Office — "Privacy and Education Technology"
  4. Federal Trade Commission — "Complying with COPPA: Frequently Asked Questions"