The Family Educational Rights and Privacy Act Applied to AI in K-12
FERPA was enacted in 1974 to protect the privacy of student education records. AI is now generating, transmitting, and processing education records inside K-12 districts daily. The FERPA compliance question for AI is real and answerable, but requires districts to do explicit work that most have not yet completed.
FERPA’s Core Protection and the School Official Exception
FERPA’s core protections require that personally identifiable information from education records not be disclosed without parental consent or under specific permitted exceptions. The “school official” exception permits disclosure to a contractor or vendor performing institutional services if the contractor is under district control and meets specific requirements — legitimate educational interest, FERPA-equivalent use restrictions, and redisclosure controls.
Is Your AI Vendor a School Official Under FERPA?
When an AI tool processes student education records, is the tool’s vendor a “school official” under FERPA? In most cases the answer can be yes — if the district’s contract with the vendor explicitly addresses the FERPA elements. But many AI vendors are not on this kind of contract because the AI feature was added after the original vendor relationship was established.
Some AI vendors process student data under terms that do not meet FERPA’s school official requirements, creating compliance exposure the district may not have evaluated. Identifying which of a district’s AI vendor relationships fall into that gap is foundational governance work — and it is the starting point for the Pillar 4 governance work inside Armorstack’s AI Adoption Security Framework for K-12.
Frequently Asked Questions — FERPA AI Compliance
Can students consent to AI processing of their own records under FERPA?
FERPA assigns rights to parents until the student turns 18 or attends postsecondary education. K-12 student consent has limited effect; parental consent is what FERPA requires. The framework’s Pillar 4 governance produces parent notification and consent procedures appropriate for AI processing scenarios.
How do we ensure an AI vendor qualifies as a school official under FERPA?
Pillar 4 governance produces vendor contract language explicitly addressing the school official requirements: legitimate educational interest, FERPA-equivalent use restrictions, redisclosure controls, and the district’s authority over the contractor’s data handling. The framework also identifies vendors whose current contracts do not meet these requirements and prioritizes them for contract amendment.
How does the framework address the directory information exception?
Districts may designate certain student information as directory information that can be disclosed without consent unless parents opt out. Pillar 4 governance addresses the interaction between AI processing of directory information and FERPA requirements, including the parent opt-out tracking that must be maintained.
What about AI-generated content based on student work?
AI-generated content based on student work raises distinct questions: ownership, FERPA classification, and use rights. Pillar 4 governance addresses district policy on student work used as AI input or AI training data, including parent notification and consent procedures.
How does the framework handle FERPA breach response?
Pillar 4 includes an incident response playbook addressing FERPA breach scenarios with state notification, parent notification, and Department of Education considerations. The framework’s documentation supports the district’s response posture for AI-mediated FERPA exposure events.