Skip to content
All study notes

ferpa · compliance · k-12 · data-privacy · ai-tutor · procurement · seo

FERPA + AI Tutors: What Every K–12 School Needs to Know Before Buying

AI tutors process millions of student interactions. Before you sign a contract, here's the FERPA checklist no vendor will hand you.

Grademy Team8 min read

FERPA + AI Tutors: What Every K–12 School Needs to Know Before Buying

Audience: K–12 district IT directors, compliance officers, school board members, principals handling procurement Hook: AI tutors process millions of student interactions. Before you sign a contract, here's the FERPA checklist no vendor will hand you. Tone: Professional, careful, builds authority. Not fear-mongering. Practical. Word count target: 1,600–2,000 SEO keywords: FERPA AI tutor, FERPA compliance EdTech, AI tutor student data privacy, COPPA AI tutor, K-12 data privacy


Why This Matters

A teacher types a student's name into an AI tutor. The student practices math for 20 minutes. The AI grades their work. The teacher sees a summary. The student sees feedback.

In that 20 minutes, personally identifiable information (PII) about a minor flowed through a third-party AI system. That's a FERPA event.

If your district signs with the wrong vendor, you could be on the hook for a data breach, an OCR investigation, or a parent lawsuit. And "we didn't know" isn't a defense — OCR has made that clear in recent enforcement actions.

This guide gives you the 9 FERPA questions to ask any AI tutor vendor, the 3 contract clauses that protect your district, and the 5 red flags that mean walk away.


The 9 FERPA Questions

1. "Are you a 'school official' under FERPA?"

Under FERPA, a vendor can receive student PII only if it:

  • Performs a service the school would otherwise do
  • Is under direct control of the school for the use of the records
  • Uses the records only for the authorized purpose

If the vendor can't explain how they qualify as a "school official" with "legitimate educational interest," they're not compliant. Period.

2. "Where is student data stored?"

You need:

  • Geographic location of data centers (US-only is safest for K-12)
  • Encryption at rest and in transit (AES-256 + TLS 1.3 minimum)
  • Tenant isolation (your students' data not commingled with other districts)

If they say "we use AWS" without specifying region, push back.

3. "Do you train your models on student work?"

This is the make-or-break question. If they say yes:

  • Student work is being used to improve a commercial product
  • That work is leaving your district's control
  • Parents can (and will) object

If they say yes, walk away. There's no compliant way to train on K-12 student data without explicit, documented consent for every student.

4. "What happens if we leave?"

You need:

  • Data export in standard format (CSV, JSON, or SIS-compatible)
  • 30-90 day data return window after contract ends
  • Certified deletion (not just "marked for deletion")
  • No data retention for vendor's own purposes

If they keep your data after you leave, that's a FERPA violation waiting to happen.

5. "Can parents request their child's data?"

Under FERPA, parents have the right to:

  • Inspect and review their child's education records
  • Request correction of inaccurate records
  • Opt out of certain disclosures

The vendor must have a process to handle parent requests within your district's standard timeline (usually 30-45 days). If they say "talk to the school," that's a process gap.

6. "What's your breach notification timeline?"

You need:

  • Notification within 24-48 hours of confirmed breach
  • Specific contact at the vendor (not a generic support email)
  • Documented incident response plan you've reviewed

Most state laws now require faster notification than FERPA itself. Make sure the vendor contract reflects your state's timeline.

7. "Do you sub-contract any processing?"

A lot of vendors say "we use AWS / GCP / Azure" — that's sub-processing. You need:

  • List of all sub-processors
  • Notification when sub-processors change
  • Same FERPA standards flowing down

If they won't name sub-processors, they don't have control over them.

8. "What's your AI training data source?"

If the AI tutor uses a foundation model, that model was trained on something. You need to know:

  • Was the foundation model trained on student data?
  • Was your students' data used to fine-tune or improve the model?
  • Can you get a written attestation?

This is where most vendors get evasive. Push.

9. "Can we audit you?"

Under FERPA, your district has the right to audit any "school official" handling student records. The vendor contract must:

  • Allow on-site or remote audits
  • Provide audit logs on request
  • Cooperate with OCR investigations

If the vendor says "we have a SOC 2 report" — that's not the same thing. SOC 2 ≠ FERPA audit rights.


The 3 Contract Clauses That Protect Your District

Clause 1: Data Processing Agreement (DPA)

Not a generic privacy policy. A specific DPA that:

  • Names your district as the data controller
  • Names the vendor as the data processor
  • Specifies purpose limitation (the AI tutor is the only purpose)
  • Includes sub-processor restrictions
  • Includes breach notification timeline
  • Includes audit rights

Template: Many districts use the Student Data Privacy Consortium (SDPC) or iKeepSafe template as a starting point.

Clause 2: Data Deletion + Return

At contract end:

  • 30-day window for data return in standard format
  • 90-day window for certified deletion
  • Written attestation of deletion
  • No data retention for vendor's own purposes (training, analytics, etc.)

Clause 3: Indemnification + Insurance

If the vendor causes a breach:

  • They pay for credit monitoring for affected families
  • They cover your legal costs
  • They carry cyber liability insurance ($5M+ minimum)

If they won't indemnify, your district is on the hook.


The 5 Red Flags

🚩 "We train our models on student work to improve the product." Run. This is the #1 deal-breaker.

🚩 "We use a BAA, not a DPA." A Business Associate Agreement (BAA) is for HIPAA, not FERPA. They don't understand K-12 privacy law.

🚩 "We're COPPA compliant, that's enough." COPPA covers under-13. FERPA covers all K-12. Different laws, different requirements. You need both.

🚩 "We can't tell you our sub-processors." They don't know their own infrastructure. Or they're hiding something.

🚩 "FERPA doesn't apply because we're an ed tool, not a school." They don't understand the law. The "school official" exception requires a direct service relationship with the school.


What Grademy Does

Grademy is built for K–12 FERPA + COPPA compliance from day one:

  • US-only data storage (AWS us-east-1, us-west-2)
  • AES-256 encryption at rest, TLS 1.3 in transit
  • No model training on student work (written attestation in every contract)
  • 30-day data export window, 90-day certified deletion
  • 24-hour breach notification
  • Sub-processor list maintained + change notifications
  • Parent data request portal (coming Q4 2026)
  • SOC 2 Type II + annual FERPA audit available
  • Standard SDPC DPA template

Want our compliance packet? Email compliance@grademy.work for the full data sheet, sub-processor list, and DPA template.


FAQ

Q: Is FERPA or COPPA more important? A: You need both. COPPA covers under-13 (parental consent for data collection). FERPA covers all K-12 (educational records). They overlap but aren't the same.

Q: What if our state has stricter laws? A: Many states do (CA SOPIPA, NY Shield, etc.). Your contract should specify "comply with all applicable state laws" and the vendor should be familiar with your state.

Q: Can we use a vendor that won't sign a DPA? A: Technically yes, but then YOU become liable for any privacy issue. Most districts won't sign without a DPA.

Q: How often should we audit? A: At least annually. Many districts do a privacy review every 6 months for AI/ML tools specifically.

Q: What about AI tutors that are free? A: "Free" usually means they monetize student data. Run.


The Bottom Line

FERPA isn't optional. It's federal law. And OCR is actively enforcing against school districts that didn't do their due diligence on EdTech vendors.

The 9 questions, 3 clauses, and 5 red flags above will protect your district. Use them with every AI tutor vendor — including us.

Grademy welcomes your scrutiny. Email compliance@grademy.work.

Related reading

Related reading

Related reading

Related reading

  • FERPA + AI tutor K-12 schools buying guide — for AP Chemistry: the 9 units, 6 science practices, 4 FRQ types, 16 required labs, 5 math routines, and 22-week workflow that lifts a 3 to a 5 on the May 2027 exam

Related reading

  • FERPA + AI tutor K-12 schools buying guide — for AP Calculus AB: the 8 units, 6 FRQ types, 3 calculator-active + 3 calculator-inactive question types, 21 theorems and definitions, and 22-week workflow that lifts a 3 to a 5 on the May 2027 exam

Related reading

  • AP Statistics AI tutor playbook 2026 — for AP Statistics: the 9 units, 6 FRQ types, 3 calculator-active + 3 calculator-inactive question types, 24 inference procedures, and 22-week workflow that lifts a 3 to a 5 on the May 2027 exam

Keep reading

Turn the idea into a real attempt

Join the waitlist and we will email when new learner accounts reopen.