FERPA, COPPA, and State Privacy Laws for K-12: A Combined Compliance Guide
TL;DR — The three layers at a glance:
- FERPA protects education records with PII at all grade levels — schools must sign formal vendor contracts (school official agreements) and cannot rely on teacher click-wrap agreements.
- COPPA applies to children under 13 — the 2025 FTC Rule expanded “personal information” to include biometric data (facial recognition, fingerprints, voiceprints) with a compliance deadline of April 2026.
- State privacy laws exceed FERPA in stringency — California, Illinois, New York, and Texas mandate 72-hour breach notifications, advertising bans, public vendor lists, and mandatory contract clauses that federal law doesn’t require.
If you’re selecting an EdTech vendor — whether it’s a screen recording and monitoring tool, a plagiarism check solution, or something else entirely — you need to understand how these three laws interact. They don’t operate in isolation. A single proctoring tool that collects webcam footage, screen recording, and keystroke logs triggers obligations under FERPA, COPPA, and whichever state laws apply to your district. Most articles cover just one or two layers. This guide shows how they work together and what you actually need to do.
The Three-Layer Compliance Framework
The K-12 student privacy landscape isn’t a single federal law. It’s three overlapping frameworks that apply simultaneously, creating compliance gaps most guides don’t address.
| Scenario | FERPA | COPPA | State Law |
|---|---|---|---|
| Proctoring tool for grades 9–12 | Yes — education records | No (students 13+) | Depends on state |
| Proctoring tool for grades K–5 | Yes — education records | Yes — personal information | Depends on state |
| Vendor uses student data for marketing | Violates school official criteria | Violates COPPA | Violates CA, IL, TX, etc. |
| Vendor trains AI on student data | May violate if not de-identified | Violates COPPA (under 13) | Violates CA AB 1159 |
| Data breach | 3–9 months notification | Vendor obligation | 72 hours (CA, IL) |
| Which law takes precedence? | Federal baseline | Federal baseline (under 13) | Strictest standard applies |
The principle is straightforward: EdTech vendors must comply with the strictest applicable standard. If your district serves students in California, Illinois, and New York, vendors need to implement California and Illinois requirements as baseline — 72-hour breach notifications, advertising bans, public vendor lists — to ensure compliance across all jurisdictions. You can’t pick and choose.
FERPA: What It Actually Means for K-12 Districts
FERPA protects “education records” with personally identifiable information (PII) about students at any grade level — K-12 through higher education. It’s administered by the U.S. Department of Education’s Student Privacy Policy Office. You already know it covers grades, transcripts, and disciplinary actions. But the definition extends to indirect identifiers like birthdate combinations, unique metadata, or any information that could identify a specific student when combined with publicly available data.
For proctoring and monitoring tools, the scope is even broader. Continuous webcam feeds, recorded behavior patterns, exam videos, screen recordings, and keystroke logs are all legally categorized as education records under FERPA. This means typing activity monitoring, screen recording, and even AI behavioral flags all fall under FERPA protection when they’re tied to an identifiable student.
The “School Official” Exception
Under the FERPA “school official” exception, schools can share education records with EdTech vendors without parental consent — but only if four mandatory criteria are met:
- Performance of institutional services: The vendor performs services school employees would normally perform (test proctoring, safety monitoring, data management).
- Legitimate educational interest: The vendor needs for data is strictly limited to records required for the service.
- School control via contract: The vendor operates under the school’s direct control.
- Prohibition on further disclosure: The vendor cannot share PII with third parties without authorization.
Schools can’t skip this formal process. Individual teachers cannot sign vendor Terms of Service with a “click-wrap” agreement — formal district-level contracts are required. Districts must also include “school official” criteria and “legitimate educational interest” in their mandatory annual FERPA notification to parents.
Vendor Management Under FERPA
FERPA compliance isn’t a one-time checkbox. Schools need ongoing oversight: formal procedures for who holds legal authority to sign vendor contracts, annual FERPA training for all staff, and a directory opt-out process that’s accessible to parents. The penalty for non-compliance isn’t a fine — it’s loss of federal funding, the most severe enforcement mechanism available.
COPPA and the 2025–2026 Rule Changes
COPPA applies to online data collection from children under age 13. It’s enforced by the Federal Trade Commission and applies to operators of commercial websites and online services — including EdTech vendors. It doesn’t impose obligations directly on schools, but schools are deeply involved in the consent process.
The Expanded “Personal Information” Definition
The FTC’s 2025 COPPA Rule update — with a compliance deadline of April 2026 — significantly expanded what counts as “personal information.” It now includes:
- Biometric data: Facial patterns, fingerprints, voiceprints — this is where proctoring webcams capturing facial data hit the strictest restrictions.
- Persistent identifiers: Device IDs, cookies, advertising IDs
- Precise geolocation data
- Photos, videos, and image-derived data
- Online contact info: Usernames, passwords
- Government IDs
For AI content detection tools or any platform that collects biometric data from under-13 students, this expanded definition changes everything. Webcam facial data alone now triggers COPPA’s strictest biometric restrictions.
Data Retention Limits and Annual Assessments
The 2025 Rule also introduced two critical requirements: prohibition on indefinite data retention and mandatory annual cybersecurity assessments. Schools must obtain documented consent — either school consent (for educational purposes) or verifiable parental consent — and COPPA notice must be available to parents.
School Consent vs. Parental Consent
This is where most districts get tripped up.
| Aspect | School Consent | Verifiable Parental Consent (VPC) |
|---|---|---|
| Who can provide | School/district on behalf of parents | Parent/guardian directly |
| Scope | Educational purposes only | Any purpose (vendor must justify each use) |
| Documentation | Should be documented policy reviewed with district counsel | Must include clear notice + reliable verification method |
| Risk if vendor misuses data | School may be liable for failing to oversee | Vendor directly liable under FTC enforcement |
The FTC explicitly states that schools can provide consent for educational purposes, but if a vendor uses data for non-educational purposes — marketing, targeted advertising, behavioral ads — the school cannot consent. The vendor independently needs parental consent. This is the #1 way EdTech vendors violate COPPA.
Our recommendation: Schools should treat school consent under COPPA as a documented decision reviewed with district counsel, not a casual assumption or informal practice.
State Privacy Laws: SOPIPA Model and Key Statutes
Since 2014, nearly 400 student privacy bills have been introduced across 49 states. State laws now often exceed FERPA in stringency, adding requirements that federal law doesn’t mandate. The SOPIPA (Student Online Personal Information Protection Act) model — first pioneered by California — has become the template that most states follow.
California — The Strictest Standard
California’s AB 1584 mandates 9 specific contract clauses in all school-vendor agreements and pairs it with SOPIPA (SB 22584), which prohibits EdTech vendors from using, sharing, or disclosing student information for any purpose other than educational purpose. The state also requires public vendor lists and mandates a 72-hour breach notification. In November 2025, California AG Rob Bonta secured a $5.1 million settlement with Illuminate Education for alleged failure to protect students’ data.
AB 1159 extends these protections further by banning student data for AI training — not just direct EdTech vendors but the entire data supply chain, with a private right of action.
New York — Education Law 2-d
New York requires all EdTech contracts to include a “Parents’ Bill of Rights” document — a plain-language explanation of what data vendors collect, how they use it, who else receives access, and how parents can review or challenge records. The state also mandates NIST Cybersecurity Framework alignment and requires a designated data protection officer.
Texas — SCOPE Act
Texas’ SCOPE Act applies broadly to digital service providers and prohibits sharing, disclosing, or selling a minor’s (under 18) personal identifying information without parental consent. Texas AG Ken Paxton filed a lawsuit against PowerSchool in September 2025 after a data breach exposed more than 880,000 Texas school-aged children’s data.
Ohio — SB 29
Ohio’s student privacy law requires school districts to develop policies governing student information collected by third-party operators and mandates parent notification when student data is collected for commercial purposes. The state has also enacted age verification requirements for material harmful to juveniles on the internet.
State Law Comparison
| Requirement | Federal (FERPA/COPPA) | California | Illinois | New York |
|---|---|---|---|---|
| Breach Notification | 3–9 months | 72 hours | 72 hours | Reasonable time |
| Advertising Ban | No | Yes | Yes | No |
| Public Vendor List | No | Required | Required | Required |
| Parents’ Bill of Rights | No | No (AB 1584 equivalent) | No | Mandatory |
| Data Deletion | Not specified | On request | On request | On request |
Key takeaway: EdTech vendors must comply with the strictest standard. If you serve students in California, Illinois, and New York, vendors need to implement CA and IL requirements as baseline to ensure compliance across all jurisdictions.
2026 AI Education Legislation: New Compliance Obligations
The privacy landscape is evolving faster than ever. In 2026, 134 AI bills have been introduced across 31 states, creating entirely new compliance obligations that didn’t exist two years ago.
Idaho — SB 1227
Idaho’s bill requires a statewide AI framework for K-12 education, including data privacy requirements for AI tools used in schools. It explicitly prohibits AI from replacing human teachers and mandates transparency in AI decision-making.
Oklahoma — SB 1734
Oklahoma requires all AI decisions affecting students to be made under human educator oversight. High-stakes AI decisions — those affecting enrollment, discipline, or academic placement — are explicitly prohibited without human review. This is critical for AI content detection tools and any platform making automated judgments about student behavior.
What This Means for Your District
If your district uses AI-powered proctoring tools, plagiarism detection, or behavioral analysis platforms, you need to verify that vendors are complying with state AI legislation. Tools that use AI behavioral analysis now face mounting state-level restrictions. California’s AB 1159 already bans student data for AI training with a private right of action — meaning parents can sue if their child’s data trains an AI model.
30-60-90 Day Privacy Compliance Roadmap
This is the practical asset most guides lack. Here’s a phased implementation framework you can actually follow.
Days 1–30: Inventory and Assess
- Data inventory: Catalog every EdTech tool in use, what data each collects, and which laws apply (FERPA, COPPA, state statutes).
- Vendor contract review: Check existing contracts for the 9 mandatory clauses; flag any missing clauses.
- FERPA notification check: Confirm your annual FERPA notification includes “school official” criteria and an accessible opt-out process.
- COPPA assessment: Identify which tools serve under-13 students and whether school consent or parental consent applies.
Days 31–60: Build the Framework
- Vendor application approval process: Establish a formal workflow requiring IT, legal, and procurement review before any new tool deploys.
- DPA negotiation: Require all new vendors to sign FERPA-compliant Data Processing Agreements with the 9 mandatory contract clauses.
- Parent communication: Draft a parent notification about EdTech tools in use, data collected, and privacy protections in place.
- Breach response plan: Document incident response procedures including 72-hour notification timelines per state law.
Days 61–90: Implement and Sustain
- Annual compliance review: Schedule yearly vendor compliance audits, SOC 2 Type II verification, and security questionnaire updates.
- Staff training: Implement annual FERPA/COPPA compliance training for all staff with quarterly phishing simulations.
- Data retention schedule: Establish and enforce data retention and deletion policies across all vendor tools.
- State law alignment: Ensure contracts satisfy applicable state-specific requirements (CA AB 1584, NY Ed Law 2-d, TX SCOPE Act, etc.).
Vendor Contract Requirements
When evaluating an EdTech vendor — whether it’s a classroom management software platform or an plagiarism check service — you need to demand these 9 mandatory contract clauses:
- Data Ownership: The school district retains 100% ownership of student data. The vendor is a data custodian, not a controller.
- Usage Limitations: Strict prohibitions on using student data for advertising, commercial profiling, behavioral ads, or any purpose beyond the contracted service.
- AI Training Prohibition: Explicit ban on using student data (video feeds, keystrokes, essays) to train vendor AI models unless data is fully de-identified.
- Sub-processor Transparency: Vendor must disclose all sub-processors (cloud hosting, analytics platforms, AI model vendors) and bind them to the same privacy terms.
- Data Deletion Timelines: Clear procedures and firm deadlines for purging student data upon contract termination or parent request — 30–90 days maximum.
- Breach Notification: Specific timelines (typically 72 hours of discovery) for notifying schools of security incidents.
- Indemnification: Liability assignment for compliance failures. Vendor responsibility for data protection failures under their control.
- Audit Rights: School authority to conduct security audits, compliance reviews, and data inventory inspections.
- Regulatory Updates: Vendor commitment to maintain compliance as regulations evolve. Contract terms automatically update to meet new requirements.
If a vendor resists negotiating these clauses, that’s a red flag. A vendor unwilling to modify their contract to include your district’s mandatory clauses shows they may not prioritize student privacy.
What to Avoid: Common Compliance Mistakes
Before you sign a vendor agreement, check your district against these common pitfalls:
- Assuming FERPA covers everything: It doesn’t. COPPA and state laws govern data FERPA doesn’t touch — especially biometric data, persistent identifiers, and online contact info. This is the single most common mistake we see.
- Using click-wrap agreements: Individual teachers cannot sign vendor Terms of Service. Formal district-level contracts are required.
- Allowing indefinite data retention: COPPA requires deletion of children’s information as soon as the exam window terminates. School contracts should specify deletion timelines.
- Vague vendor policies: “We may use data to improve our services” without specifics is a red flag.
- Ignoring state law differences: Compliance with FERPA alone is insufficient — state laws (especially CA, IL, NY, TX) impose additional requirements.
- Letting vendors use student data for marketing: This violates all three law layers simultaneously and triggers FTC and state AG enforcement.
- Assuming school consent covers everything: School consent only covers educational purposes. If the vendor has commercial intent, school consent is invalid.
- Ignoring AI training risks: Student data entering AI model training datasets creates irreversible compliance exposure.
The tradeoff to weigh: Comprehensive data protection (maximum security) versus practical usability for teachers (minimal friction). The best vendors you select will find the balance — they’ll encrypt data, restrict access, and minimize collection without making classroom tools so cumbersome that teachers abandon them. Ask vendors how they operationalize compliance in practice, not just on paper.
Summary + Next Steps
The K-12 student privacy compliance landscape is three layers deep — FERPA (federal, all grades), COPPA (under 13, FTC-enforced), and state laws (varies, 400+ bills since 2014). The 2025 COPPA Rule changes create urgency with an April 2026 compliance deadline. State laws like California AB 1159, New York Ed Law 2-d, and Texas SCOPE Act impose requirements that far exceed federal law. And with 134 AI bills across 31 states in 2026, the landscape only grows more complex.
If you’re evaluating EdTech vendors right now — whether for classroom management, monitoring, or content detection — use the 30-60-90 day roadmap above as your framework. Demand the 9 mandatory contract clauses. Treat COPPA school consent as a documented decision with district counsel. And verify that vendors are complying with the strictest applicable standard across all jurisdictions they serve.
Need help navigating these requirements? We can help. Whether you’re evaluating proctoring tools, selecting a screen recording and monitoring platform, or reviewing vendor contracts, our team understands the intersection of FERPA, COPPA, and state privacy laws. Contact us to discuss your district’s specific compliance needs.
Related Guides
- Classroom Management Software — How to evaluate tools that keep students organized and on task.
- AI Content Detection for Educators — Choosing the right tool for detecting AI-written assignments.
- Screen Recording and Monitoring — Selecting monitoring tools that respect student privacy.
- Plagiarism Check Solutions — Academic integrity tools compared for classroom use.
- Typing Activity Monitor — Understanding keystroke logging and what it means for student privacy.
Online Proctoring Cost Breakdown: Per-Student vs. Per-Exam Pricing Models Explained
Online proctoring typically uses two pricing models: per-exam (pay-as-you-go, starting at about $3–$45 per exam depending on security tier) and […]
Student Mental Health and Online Testing: Supporting Students During Proctored Exams
You’ve just opened the exam. The timer starts. The webcam locks. Your room is being recorded. Every keystroke is tracked. […]
AI Policy Implementation Guide: From Draft to Rollout in School Districts
Step-by-step guide to drafting, implementing, and maintaining AI acceptance policies in K-12 school districts. Includes templates, case studies, and state compliance requirements.