AI and FERPA
Before student information enters an AI tool, schools need to establish what is being shared, why it is needed, and whether the disclosure is permitted.
Teachers often ask whether an AI tool is "FERPA compliant." A vendor's assurance cannot settle that question. The school must evaluate the proposed use, the information involved, and the terms governing the provider's access to it.
The practical question is specific: may this teacher share this information with this provider for this purpose?
What FERPA covers
FERPA protects education records: records directly related to a student and maintained by a school or a party acting on its behalf. These include grades, class lists, student schedules, and disciplinary files. Protection extends to personally identifiable information drawn from those records. U.S. Department of Education: education records
A generic lesson plan or blank rubric ordinarily does not contain protected student information. A completed rubric identifying a student, a gradebook export, or an individualized report presents a different question. The document's contents and use matter more than its label.
Schools should make these distinctions clear so teachers can recognize which activities require additional review.
When a school may share records with a vendor
FERPA generally requires consent from a parent or eligible student before disclosing personally identifiable information from education records, unless an exception applies. One commonly used for educational technology is the school official exception.
Under that exception, a provider must perform a service the school would otherwise use employees to perform, meet the school's published criteria for a school official with a legitimate educational interest, remain under the school's direct control regarding the records, and comply with restrictions on use and redisclosure. Calling a provider a "school official" does not, by itself, satisfy those conditions. Department of Education: school official exception
FERPA does not specifically require a written agreement under this exception, although an agreement is an important means of establishing direct control. State law or local policy may impose additional requirements. Teachers should follow their institution's approval process and should not assume that access to records gives them authority to accept vendor terms or authorize disclosure. Department of Education: online educational services guidance
Distinguish three kinds of use
Work without student information. Creating a generic lesson plan, drafting a blank tracking template, or developing fictional examples ordinarily does not involve disclosure of protected education records. Schools should identify permitted uses clearly, including any tool restrictions.
Work with de-identified information. Removing names is only a first step. The remaining information must not identify a student, either on its own or in combination with other available information. A small group, an unusual service combination, or a distinctive personal account may still reveal identity. Properly de-identified information can be disclosed without consent under FERPA, but schools need a sound basis for determining that it is de-identified. Department of Education: de-identification
Work with identifiable student information. Uploading student assignments, assessment results, or individualized reports requires an established legal basis and approval through the school's designated process. Permission to use a tool for lesson planning should not be treated as permission to upload student records.
Handle special education records carefully
IEPs and related records collected or maintained under IDEA carry additional confidentiality requirements. Section 504 records can also be protected education records under FERPA, but a Section 504 plan does not automatically fall under IDEA's confidentiality provisions. IDEA confidentiality requirements, FERPA regulations
Schools should address these records explicitly in their procedures. Staff need to know which systems are approved, what information may be shared, and who can authorize a proposed use.
Make approval clear and usable
For a use that is not already covered by school guidance, the teacher should describe the tool, the task, and the information involved to the designated administrator, privacy officer, or technology lead.
A written request helps document the decision. It does not itself authorize disclosure or make an otherwise impermissible use acceptable. Approval must come from someone with the appropriate authority and address the actual use proposed.
A workable process also gives teachers a clear answer they can use again. An approved-tools list should specify permitted activities and data types, with a route for reviewing new requests.
Account for Arizona law
Arizona's student data privacy statute, A.R.S. § 15-1046, places restrictions on covered educational service operators, including certain advertising, profiling, sales, and disclosures. It also requires security measures and deletion under specified conditions.
Its scope matters: the statute expressly excludes general-audience websites and applications. Schools should not assume that its operator protections apply to every AI tool a teacher can access. The law also includes local education agency responsibilities concerning technology policies and parent notification, subject to stated exceptions. A.R.S. § 15-1046
Before adopting an AI service that will receive student records, a school should have its authorized reviewers examine the intended use and agreement, with counsel addressing legal questions. Teachers need an approved process they can follow without having to make those determinations themselves.
This overview supports planning and policy discussion; it is not legal advice.
Sorting this out for your school?
We develop AI policy for schools and districts, including the tool-approval and student-information provisions, with a board presentation when the engagement includes one.