Educational institutions hold detailed records on minors while relying heavily on third-party edtech vendors, which is where most student privacy incidents originate. This hub covers both.
FERPA
September 1, 2026
Directory information is the one category of student record a school may release without consent, and the trade is a public notice plus a window to opt out. The PPRA is a separate statute covering surveys, physical examinations and the collection of student information for marketing, with its own annual notice and its own opt-out.
Read more →
FERPA
September 1, 2026
FERPA's default is written parental consent before a school discloses personally identifiable information from education records. The school official exception displaces that default for outsourced vendors, but only where four conditions in 34 CFR 99.31(a)(1) and 99.33 are all met — including a direct control requirement the Department added in 2008 to reach IT and web services.
Read more →
FERPA
August 24, 2026
FERPA is a spending condition rather than a privacy statute in the ordinary sense, and almost everything distinctive about it follows from that. It binds schools that take Department of Education funds, is enforced by withholding them rather than by lawsuits, and its central exception is broad enough to carry an industry of software vendors.
Read more →
COPPA
August 12, 2026
COPPA turns on two questions that decide everything downstream: whether a service is directed to children under 13, and whether the operator has actual knowledge it is collecting from one. This guide covers the multi-factor test, what counts as personal information, the approved consent methods, and the state laws now layered on top.
Read more →