The back to school supply list: Strong passwords, smart policies & safer data
The regulatory and litigation landscape governing student data has grown considerably more complex in recent years. Institutions that once treated compliance as a matter of federal law and internal policy now face a layered set of obligations spanning federal statute, state legislation, and rapidly evolving vendor risks. Two recent vendor incidents have brought these issues into sharp focus for the educational sector and offer instructive lessons for institutions and counsel alike.
During our recent webinar, The Back to School Supply List: Strong passwords, smart policies & safer data, attorneys Meghan Collins and Chery Saniuk-Heinig explored key concepts such as directory vs. non-directory information, FERPA considerations, and everyday best practices to help keep students, parents, and staff informed and protected all year long.
FERPA remains the baseline, not the full picture
The Family Educational Rights and Privacy Act of 1974, 20 U.S.C. § 1232g, (FERPA) continues to serve as the foundational framework for student data protection, but its practical reach is often misunderstood. FERPA’s core rights are the right to access and review one’s own records, the right to seek amendment of those records, and its requirement that consent is obtained before disclosure of a student’s education record, subject to a defined set of exceptions. Those exceptions are where the practical risk really resides.
As a preliminary matter, FERPA does not create a private right of action. This was settled by the United States Supreme Court in Gonzaga University v. Doe, 536 U.S. 273, decided in 2002, which held that FERPA’s nondisclosure provisions create no personal right enforceable by an individual, even under 42 U.S.C. § 1983, a statute that ordinarily provides a fairly broad vehicle for enforcing federal rights. Because of this holding, litigation following an ed-tech incident tends to involve claims under the Electronic Communications Privacy Act, state wiretap statutes, common law torts, or state student-privacy statutes.
Most ed-tech vendors working with FERPA covered institutions receive student data not through direct parental or student consent, but through what is known as the “school official” exception. This provision merits careful attention, because institutions frequently treat the label “school official” as something the contract simply asserts, but the exception requires satisfying four distinct regulatory elements, including institutional control over the vendors use of the data and a genuine legitimate educational interest as defined in the institution's own policies. A vendor contract labeling a party as a “school official” does not, by itself, satisfy this analysis.
State law frequently extends further than institutions expect
A common misconception is that compliance obligations are determined by an institution’s physical location. In practice, most states student privacy statutes are triggered by the state of residence of the affected student. As a result, a single incident involving a national vendor can trigger dozens of separate state notification obligations simultaneously, each governed by its own timeline and substantive requirements. For example, New York’s Education Law § 2-d, imposes a three-tiered notification cascade with deadlines running from 7 to 60 days, depending on the recipient. Institutions and counsel should maintain current state-by-state awareness of these layered obligations well in advance of any incident.
Recent incidents illustrate where exposure may arise
The Canvas/Instructure incident and PowerSchool/Naviance matters, illustrates several recurring principles.
- Vendor due diligence and contract negotiations are most effective before an agreement is signed, when institutions retain meaningful leverage;
- Ransom payment never guarantees that stolen data will be deleted or that further extortion will cease;
- Exposure is not limited to traditional intrusions. Embedded analytic tools operating without adequate oversight can therefore create the same practical risk as a breach, without any unauthorized access ever occurring; and
- No breach does not mean no exposure.
AI requires the same rigor as any vendor relationship
Artificial intelligence tools are already in widespread use across school and university campuses, frequently without a formal governance structure in place. The relevant institutional question is not whether AI is present, but whether its use has been adequately governed through policy, contract terms, and staff training.
Further discussion
These issues and more were discussed during the August 19th webinar, including a walkthrough of the Canvas and PowerSchool incidents and a review of overlapping regimes such as COPPA, PPRA, the GLBA Safeguard Rule, and state biometric privacy laws. A full recording can be found here.