How an EdTech Vendor Becomes a School Official Under FERPA
Key Takeaways
- An outside vendor qualifies as a school official only if it performs a function the school would otherwise use employees for, meets the criteria in the school's annual FERPA notification, is under the school's direct control as to use and maintenance of records, and complies with the redisclosure limits of 34 CFR 99.33(a)
- The annual notification under 34 CFR 99.7(a)(3)(iii) must specify the criteria for who is a school official and what a legitimate educational interest is; a vendor that falls outside those published criteria is not covered
- Direct control means the school can control the vendor's maintenance, use and redisclosure; the 2008 rulemaking says it does not make the vendor an employee or affect independent contractor status
- Records disclosed under the exception may be used only for the purpose of the disclosure, and may not be redisclosed without consent absent a further FERPA basis
- The FTC declined in 2025 to codify a COPPA school authorization exception, so a service directed to children still answers to COPPA on its own terms
Consent Is the Default
FERPA operates as a funding condition rather than a direct prohibition. 20 U.S.C. 1232g(b)(1) provides that no funds shall be made available under any applicable program to an educational agency or institution that has a policy or practice of permitting the release of education records — or personally identifiable information in them, other than directory information — without the written consent of parents, subject to a list of exceptions.
The regulations at 34 CFR Part 99 carry that structure forward. Section 99.30 sets the written consent requirement, and 99.31 opens with the operative framing: an agency or institution "may disclose personally identifiable information from an education record of a student without the consent required by § 99.30 if the disclosure meets one or more of the following conditions." Everything below is a description of the first of those conditions.
The School Official Exception
The statutory exception at 1232g(b)(1)(A) covers "other school officials, including teachers within the educational institution or local educational agency, who have been determined by such agency or institution to have legitimate educational interests." Read alone, that language is about people inside the institution.
The regulation extends it. Section 99.31(a)(1)(i)(B) provides that "[a] contractor, consultant, volunteer, or other party to whom an agency or institution has outsourced institutional services or functions may be considered a school official under this paragraph" provided the outside party meets three conditions:
- Performs an institutional service or function for which the agency or institution would otherwise use employees
- Is under the direct control of the agency or institution with respect to the use and maintenance of education records
- Is subject to the requirements of § 99.33(a) governing the use and redisclosure of personally identifiable information from education records
The Department's Student Privacy Policy Office states the same test as four elements in its guidance on online educational services, adding the annual-notification condition described below and spelling out the use limitation: the provider "[u]ses education records only for authorized purposes and may not re-disclose PII from education records to other parties (unless the provider has specific authorization from the school or district to do so and it is otherwise permitted by FERPA)."
Legitimate Educational Interest
Neither the statute nor the regulation defines the phrase. Instead, 34 CFR 99.7(a)(3)(iii) shifts the definitional work onto each school: if the agency or institution has a policy of disclosing education records under 99.31(a)(1), its annual notification of FERPA rights must include "a specification of criteria for determining who constitutes a school official and what constitutes a legitimate educational interest."
That makes the annual notice load-bearing rather than ceremonial. The Department's guidance puts the point directly: the provider receiving the information "must have been determined to meet the criteria for being a school official with a 'legitimate educational interest' as set forth in the school's or district's annual FERPA notification." Where the published criteria do not reach a category of vendor, the exception does not reach it either.
A second constraint sits at 99.31(a)(1)(ii). An agency or institution "must use reasonable methods to ensure that school officials obtain access to only those education records in which they have legitimate educational interests," and one that relies on administrative policy rather than physical or technological access controls must ensure that policy is effective. The interest is per-record, not per-relationship.
Direct Control Over the Vendor
The direct control requirement entered the regulation in the December 2008 FERPA rulemaking, published at 73 FR 74806. The preamble explains the object: the term "is intended to ensure that an educational agency or institution does not disclose education records to an outside service provider unless it can control that party's maintenance, use, and redisclosure of education records. This could mean, for example, requiring a contractor to maintain education records in a particular manner and to make them available to parents upon request."
The same discussion sets three limits that are easy to overstate in either direction. Direct control "is intended to apply only to the outside party's provision of specific institutional services or functions that have been outsourced and the education records provided to that outside party." It "is not intended to affect an outside service provider's status as an independent contractor or render that party an employee under State or Federal law." And the Department declined to require that schools verify a vendor's security resources, noting that neither the statute nor the regulations specifically require that verification — while restating that the school remains responsible for not having a policy or practice of releasing records except in accordance with FERPA.
On form, the 2008 preamble observes that one way schools can ensure outside parties understand their responsibilities "is to clearly describe those responsibilities in a written agreement or contract," and singles out IT outsourcing: schools outsourcing web-based and email services "should make clear in their service agreements or contracts that the outside party may not use or allow access to personally identifiable information from education records, except in accordance with the requirements established by the educational agency or institution that discloses the information." The Student Privacy Policy Office is explicit that a written agreement is not itself a regulatory requirement for this exception, while noting that in practice a signed contract, or in some cases terms of service accepted by the district, is how direct control gets established.
Redisclosure Limits
Section 99.33(a)(1) states the baseline: an agency or institution may disclose personally identifiable information from an education record "only on the condition that the party to whom the information is disclosed will not disclose the information to any other party without the prior consent of the parent or eligible student." Paragraph (a)(2) adds a use limitation — the officers, employees and agents of the receiving party "may use the information, but only for the purposes for which the disclosure was made."
Two mechanics follow. Section 99.33(b) permits onward disclosure by the recipient on behalf of the school where the further disclosure itself meets 99.31 and the recordation requirements of 99.32(b) are met. And 99.33(d) requires the school to inform the receiving party of the paragraph (a) restrictions, except for a listed set of disclosures that does not include the school official exception. The Department's guidance draws the practical consequence with an example: a cafeteria account vendor receiving records under the exception "cannot sell the student roster to a third party, nor can it use PII from education records to target students for advertisements."
The guidance also flags a boundary that cuts the other way. Information properly de-identified, or shared under the directory information exception, is not FERPA-protected and is therefore not subject to these use and redisclosure limits — which is part of why the directory route and the school official route lead to materially different vendor obligations.
Where COPPA Applies Alongside FERPA
FERPA binds the school. COPPA binds the operator of a commercial website or online service. Meeting the school official exception resolves the first question and not the second.
The Department's guidance says as much, advising schools and districts to "be aware of and consider the requirements of the Children's Online Privacy and Protection Act (COPPA) before using online educational services for children under age 13," and noting that the FTC "has interpreted COPPA to allow schools to exercise consent on behalf of parents in certain, limited circumstances."
That interpretation remains guidance rather than rule text. In the 2024 notice of proposed rulemaking the FTC had proposed definitions of School and School-authorized education purpose, provisions on collection in schools, and a codified school authorization exception to verifiable parental consent. In the final rule at 90 FR 16918 the Commission dropped all of it, explaining that the Department of Education had affirmed an intention to propose FERPA rule amendments that "may be relevant" to those provisions and that it was declining to finalize them "[t]o avoid making amendments to the COPPA Rule that may conflict with potential amendments to DOE's FERPA regulations." It added that it would keep enforcing COPPA in the ed tech context consistent with existing guidance. As of this writing no proposed or final rule amending 34 CFR Part 99 has been published in the Federal Register since that statement, so the guidance-based position is what remains in place on both sides.
What the Exception Does Not Cover
Several things sit outside it by the terms of the regulation. The exception does not supply a basis for the vendor's own products: records received under it may be used only for the outsourced service. It does not reach functions the school would not otherwise perform with employees, since that is the first condition. It does not survive a vendor that falls outside the criteria published in the annual notification. And it does not displace the access right — the Department's guidance notes that where a provider maintains a student's education records, the school must still be able to give a requesting parent or eligible student access to them within the period set by 34 CFR 99.10, which is not more than 45 days after the request.
Nor does the exception answer the enforcement question. The statute directs the Secretary to take appropriate actions to enforce it, with termination of assistance available only after a finding of non-compliance that cannot be secured by voluntary means (20 U.S.C. 1232g(f)), and to designate an office and review board to investigate and adjudicate complaints (1232g(g)). The obligation the statute writes runs to the funding recipient, so a vendor arrangement is measured through the school's compliance rather than through a duty the statute places on the vendor. The Department's guidance frames FERPA as "a minimum set of requirements," leaving state student-privacy statutes and contract terms to do whatever additional work a district wants done.
Background
For the underlying law rather than this development: Education privacy law, Technology & SaaS privacy law.
Frequently Asked Questions
Can a school designate any vendor as a school official?
Does FERPA require a written contract with an edtech vendor?
What does direct control mean in practice?
May a vendor use student records received under the exception to improve its own product?
Does qualifying as a school official under FERPA satisfy COPPA?
Is directory information a substitute route for setting up vendor accounts?
Sources
Everything above is reported from these documents. Follow them to verify.
- 20 U.S.C. 1232g, Family educational and privacy rights statute
- 34 CFR Part 99, Family Educational Rights and Privacy (current text) regulation
- Protecting Student Privacy While Using Online Educational Services: Requirements and Best Practices (February 1, 2014) agency guidance
- Family Educational Rights and Privacy, Final Rule, 73 FR 74806 (December 9, 2008) regulation
- Children's Online Privacy Protection Rule, Final Rule Amendments, 90 FR 16918 (April 22, 2025) regulation
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.