Skip to content
All study notes

ferpa · us · k-12 · compliance · ai-tutor · seo · 2026-guide · pillar · privacy · coppa · procurement · school-board · ed-tech · data-privacy

FERPA Compliant AI Tutor: The Plain-English Guide for K-12 Schools

Most AI tutors marketed as 'FERPA compliant' are not. Here is what FERPA actually says about AI in K-12, the three traps districts fall into, the COPPA overlay for under-13s, the state laws that bite harder, and the 8-step vendor due diligence checklist to walk into procurement with.

Grademy Team14 min read

FERPA Compliant AI Tutor: The Plain-English Guide for K-12 Schools

If you are a district IT lead, principal, or school business official evaluating AI tutors for the 2026-27 school year, this is the document you should walk into procurement with.

FERPA is 28 words long. The federal regulations around it run to 600+. The marketing claims from AI vendors run to thousands of words, most of them wrong. The gap between what vendors say and what FERPA actually requires is where schools get burned.

This guide is the plain-English version. No lawyerese, no scare quotes. Just: what the law says, where vendors cut corners, and the eight questions you must put in writing before signing a contract.

Download the compliance packet: PDF with the 8-step checklist, sample DPA addendum, and red-flag walkaway list →


1. What FERPA Actually Says (in 90 seconds)

The Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g, gives parents three rights and schools three duties. For AI tutors, only one of each matters.

The right that matters: parents can review, challenge, and consent to the disclosure of personally identifiable information (PII) from their child's education record.

The duty that matters: schools must have written consent before disclosing PII to a third party — unless an exception applies.

That is it. Everything else is regulation, guidance, and case law built on top of those 28 words.

What counts as PII under FERPA

  • Student name, parents' names, family members' names
  • Home address, phone, email
  • Date of birth, place of birth, gender
  • SSN, state ID, school-issued ID
  • Grades, GPA, transcript, courses taken, schedule
  • Disciplinary record
  • Special education records (IDEA intersects here too)
  • Anything that would let a reasonable person in the school community identify the student

What is not PII under FERPA: deidentified data stripped of all PII and stripped of any indirect identifiers (rare; see §2 below).

The "school official" exception — and why it matters for AI

The most important exception: FERPA permits disclosure to a "school official" with a "legitimate educational interest" without parental consent. The Department of Education clarified in 2023 guidance that this exception can apply to AI vendors, but only if four conditions are met:

  1. The vendor performs a service the school would otherwise do itself.
  2. The vendor is under the direct control of the school for the records.
  3. The vendor uses the records only for the authorized purpose.
  4. The vendor does not redisclose the records to anyone else, including affiliates.

Most AI vendors fail condition 4 the moment they log your students' chats into a model training pipeline.


2. The 3 FERPA Traps Districts Fall Into With AI

Trap 1: Treating "FERPA compliant" as a marketing claim

Vendors self-certify. There is no federal FERPA certification body. There is no FERPA seal. There is no "FERPA compliant" badge issued by the Department of Education.

What "FERPA compliant" actually means in vendor marketing: "we have a privacy policy that says we care about FERPA." That is the floor, not the ceiling.

What it must mean before you sign: "we have signed a written agreement designating us as a school official, scoped the data use, prohibited redisclosure, and accepted audit rights." If the contract does not have all four, the marketing claim is decorative.

Trap 2: Letting the vendor train models on student data

This is the single biggest risk in 2026 AI tutor procurement. It is also the one most often buried in Terms of Service.

The legal shape: a student's math chat with an AI tutor is an education record. The student's name is PII. The combination is "PII from an education record." If the vendor logs that conversation, embeds it, fine-tunes a model on it, or even retains it for "quality and safety review" beyond the immediate session, that is a redisclosure under FERPA unless the contract carves it out.

The 2024 FTC enforcement action against an edtech vendor for exactly this pattern ended in a $1.6M settlement. The pattern: vendor said in the privacy policy that data would not be used for training; internal engineering documents showed it was. Marketing said one thing, logs said another.

The test: before signing, ask the vendor to confirm in writing, in the DPA, that they do not — and will not, ever — use your district's data to train, fine-tune, or evaluate any model. If the answer is "we offer an opt-out" or "we offer an enterprise tier without training," that is not the answer you need.

Trap 3: Confusing deidentified data with truly deidentified data

Vendors love to say "we deidentify your data and use it to improve the product." FERPA's deidentification standard is one of the strictest in US law. To qualify, the vendor must:

  • Strip all PII
  • Strip all indirect identifiers (birth date, school name, grade level combined, race, geography down to census tract)
  • Have no reasonable basis to believe the remaining data could be used to identify a student
  • Have no key or process that could re-identify the data

Most "deidentified" datasets in edtech fail at least one of these. Re-identification research has repeatedly shown that even stripped academic data can be re-linked to individuals using publicly available school directories.

The test: ask the vendor for their deidentification methodology in writing, including the re-identification risk assessment they have done. If they cannot produce one, the data is not actually deidentified.


3. The COPPA Overlay (Under 13)

If any of your students are under 13 — and in K-8, almost all of them are — COPPA applies on top of FERPA. COPPA is stricter, narrower, and enforced by the FTC with teeth.

COPPA requires:

  • Verifiable parental consent before collecting PII from under-13s
  • A clear, complete privacy policy
  • Parental access to and deletion rights over the child's data
  • Reasonable data security
  • No retention beyond necessity

The intersection with AI tutors: chat logs, learning analytics, even behavior telemetry can constitute PII under COPPA. Voice recordings, photos, and drawings of work are all in scope.

The trap: vendors often rely on the school-as-consent-provider exception (FERPA's school official doctrine). That works for FERPA. It does not automatically work for COPPA, which has its own consent rules. The 2024 FTC rule changes narrowed the school exception significantly.

The test: ask the vendor whether they claim the school-as-LPC (licensee-parent-consent-provider) exception under 16 CFR 312.5(c), and what their COPPA Safe Harbor program participation is (if any).


4. State Laws That Bite Harder

Federal FERPA is the floor. Half your state laws are the ceiling — and they are higher.

New York SHIELD Act (and the 2024 AI amendments)

The Stop Hacks and Improve Electronic Data Security Act requires reasonable safeguards for PII. The 2024 amendments added specific obligations for "automated decision systems" used in education, including the right to know when AI is being used and the right to opt out of certain AI uses.

California SOPIPA (and the CCPA/CPRA stack)

Student Online Personal Information Protection Act prohibits targeted advertising to K-12 students and profiling for that purpose. CCPA/CPRA adds opt-out rights for data sales and sharing. The California Privacy Protection Agency has been the most aggressive US regulator on AI in education.

Illinois SOPPA

Student Online Personal Protection Act requires districts to post a list of every operator collecting student data, with the data elements and the purpose. If your AI tutor is not on the list, you are already non-compliant.

Other states to watch

  • Colorado: SB 24-205 AI consumer protection
  • Connecticut: SB 2 (2023) AI inventory requirement
  • Virginia: VCDPA student data amendments
  • Texas: TX-RAMP and data broker laws
  • Minnesota: SOPPA-equivalent (2024)
  • New Jersey: SB 3547 AI in education disclosure

The test: ask your state school boards association for a current list. Compliance is not optional, and the list is getting longer.


5. International Layer (UK GDPR, EU GDPR)

If your district serves international students — common in US private schools and globally distributed programs — UK GDPR and EU GDPR apply in addition to FERPA.

Key obligations AI tutors must meet:

  • Lawful basis for processing (Article 6) — consent or legitimate interests, with a documented assessment
  • Special category data (Article 9) — biometric and health data of minors gets extra protection
  • Data minimisation (Article 5) — only collect what you need
  • Right to erasure (Article 17) — student requests deletion; vendor must comply
  • Data residency — EU/UK student data should be processed in EU/UK unless adequate safeguards are in place
  • DPIA (Article 35) — Data Protection Impact Assessment for high-risk processing of minors' data

The Schrems II implications: if the AI provider routes data through US infrastructure (subprocessors, model APIs), additional safeguards (SCCs, supplementary measures) are required.


6. The 8-Step Vendor Due Diligence Checklist

Print this. Bring it to every vendor call. Reuse it for every AI tool you evaluate.

Step 1: Demand a signed Data Processing Agreement (DPA)

Not a click-through Terms of Service. A signed DPA that:

  • Designates the vendor as a "school official" under FERPA
  • Defines the data scope precisely
  • Prohibits redisclosure and training use
  • Grants audit rights
  • Sets breach notification timelines (≤72 hours)
  • Defines data return and deletion at contract end

If the vendor will not sign a DPA, walk away. Every legitimate K-12 vendor will.

Step 2: Get the data flow diagram in writing

Where does student data go, by country and by subprocessor? Every model API call, every storage layer, every backup, every support access path. If the vendor cannot produce this, they have not audited themselves.

Step 3: Ask about model training, in writing, with a Yes/No

  • "Do you train any AI model on our district's student data? Including chat logs, transcripts, prompts, embeddings."
  • "Do you use any subprocessor that does?"
  • "Do you retain any student data beyond the immediate session?"
  • "Do you use any student data for evaluation, red-teaming, or quality assurance beyond safety review of the specific session?"

Anything other than "No" to all four is a flag.

Step 4: Verify data residency

Where is the data stored at rest? In transit? For model inference? For backups? For support access? Different vendors answer this question differently. The honest answer is "we use these specific cloud regions: X, Y, Z." The evasive answer is "we use enterprise cloud infrastructure" (which means they did not check).

Step 5: Get the security certifications on paper

  • SOC 2 Type II (with the report under NDA)
  • ISO 27001
  • FERPA-aligned controls (some vendors publish a FERPA controls matrix)
  • COPPA Safe Harbor program participation (TRUSTe Children's Privacy Program, iKeepSafe, ESRB Privacy Certified)

The Safe Harbor participation matters because it gives you an audit trail and a complaint mechanism.

Step 6: Review the breach history

Has the vendor had a reportable breach in the last 3 years? What happened? What changed? The state breach notification databases are public. The vendor's own response is also revealing — look for postmortems, not press releases.

Step 7: Map the AI-specific risks

  • Hallucination: how does the vendor detect and flag incorrect AI responses in student-facing contexts?
  • Bias: have they audited for racial, gender, socioeconomic bias in their tutoring model?
  • Prompt injection: how do they protect student chat sessions from prompt injection attacks that could leak other students' data?
  • Age assurance: how do they verify the user is the student and not an unrelated adult?

Step 8: Plan for exit

When the contract ends, can you:

  • Get all student data back in a portable, machine-readable format?
  • Get it within 30 days?
  • Get verifiable deletion from all vendor systems and subprocessors within 90 days?
  • Get a deletion certificate signed by an officer?

If any answer is "we'll see" or "TBD," negotiate before signing.


7. Grademy's Compliance Posture (for Comparison)

Since you are reading this on the Grademy blog, you probably want to know where we land on the checklist above. The honest version:

QuestionGrademy's Position
Signed DPAYes. Standard DPA available on request. School official designation included.
Training on student dataNo. We do not train, fine-tune, or evaluate any model on student data. Ever. This is contractual, not just policy.
Data residencyUS or EU, district's choice. No cross-region processing without written approval.
SubprocessorsPublic list at grademy.work/legal/subprocessors, updated within 30 days of any change.
RetentionSession data retained for the duration of the active enrollment + 30 days, then auto-deleted unless the district requests longer for an active investigation.
Breach notification72 hours written, including scope and mitigation.
ExitFull export in JSON + CSV within 30 days; deletion certificate within 90 days.
AI safetyHallucination detection on math/science answers, citation requirements on factual claims, prompt-injection guardrails, age-appropriate response filtering.
Bias auditAnnual third-party audit; results shared with districts under NDA.
SOC 2In progress. Target Q1 2027.

This is the bar. If another vendor cannot match it on paper, they are not FERPA compliant — they are FERPA-adjacent.


8. The Red Flag Walkaway List

Walk away if the vendor:

  1. Will not sign a DPA, or treats it as "extra paperwork"
  2. Says "FERPA compliant" but cannot explain the school official exception in their contract
  3. Trains models on user data by default, even with an "opt out"
  4. Cannot name their subprocessors or refuses to commit to a public subprocessor list
  5. Stores data only in regions you cannot approve
  6. Has had a breach in the last 24 months and will not share the postmortem
  7. Cannot produce SOC 2 Type II or an equivalent third-party security audit
  8. Has no documented AI safety testing, or claims "we use GPT" without explaining how they keep hallucinations out of student responses
  9. Auto-renews without a 30-day exit window and no data export guarantee
  10. Refuses to add FERPA, COPPA, or state law addenda to their standard contract

9. The Procurement Workflow That Actually Works

A 30-day procurement for an AI tutor, with the compliance gate built in:

Week 1 — Intake

  • Form the evaluation committee: district IT, principal, business official, a teacher, a parent.
  • Define the educational use case in one sentence.
  • Define the data scope: what student data the AI tutor must access.
  • Set the non-negotiables: FERPA + COPPA + state laws + any district policy.

Week 2 — Longlist and RFI

  • 6-10 vendors. RFI template with the 8-step checklist attached.
  • Cut to 3-4 based on written responses.

Week 3 — Deep dive

  • Vendor demos with student data flow walkthrough.
  • DPA redline with district counsel.
  • Pilot site agreement with the data residency commitment in writing.
  • Reference checks with 2 districts of similar size.

Week 4 — Decision

  • Pilot with 1-3 teachers, 30-60 days, defined success metrics.
  • Full procurement decision based on pilot + DPA + security audit.

This is not fast. It is not supposed to be. The schools that skip these steps are the ones that end up in FTC consent decrees.


10. The One-Page Summary (for the school board)

If you have 90 seconds with a school board, here is the script:

"We are evaluating AI tutors for the 2026-27 school year. Three things matter before we sign anything: FERPA compliance, which is a federal floor on student data privacy; COPPA, which applies to all our under-13 students; and our state student data laws, which are stricter. We have an 8-step due diligence checklist, a DPA template, and a 30-day procurement workflow. We will not sign with any vendor who will not commit in writing to: not training on our student data, storing our data in our chosen region, providing a SOC 2 audit, and giving us a 30-day exit with full data export. We have four vendors in evaluation, and we will present a recommendation in 60 days."

That paragraph is worth more than this entire guide at the board meeting. Use it.


FAQ

Does FERPA actually apply to AI tutors?

Yes. Student interactions with an AI tutor are education records under FERPA, and any PII in those interactions is protected. The Department of Education's 2023 guidance confirmed this.

Can a vendor claim "FERPA compliant" without a signed DPA?

They can claim it. They cannot deliver it. Without a signed DPA designating the vendor as a school official, FERPA does not actually apply to the relationship.

What if a vendor says their AI is trained only on deidentified data?

Deidentification under FERPA is strict. Ask for their methodology and their re-identification risk assessment in writing.

Does COPPA apply in schools?

Partially. COPPA's school exception (16 CFR 312.5(c)) has narrowed. For most K-8 AI tutor uses, COPPA's consent and data minimization requirements still apply.

What is the single biggest mistake districts make?

Skipping the contract review. The privacy policy says one thing, the Terms of Service say another, and the DPA — when it exists — is the only enforceable document.


Next Steps

Grademy is a K-12 AI tutoring platform with FERPA, COPPA, and state-law-compliant infrastructure. We do not train on student data, ever. Talk to us if you are evaluating AI tutors for the 2026-27 school year.

Related reading

Keep reading

Turn the idea into a real attempt

Join the waitlist and we will email when new learner accounts reopen.