US Education & Children’s Privacy

FERPA

Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99)

The US federal law protecting student education records, explained as it applies to AI: chatbots, AI graders, tutoring tools, and the teacher who pastes a student's file into a consumer chatbot.

United States (all schools and postsecondary institutions receiving federal education funds)In force since 1974; US Department of Education AI guidance issued 2023-2025Verified 2026-08-31

What it means for AI and data privacy

FERPA was written in 1974, but it governs AI use in US schools today because it controls one thing AI tools consume in bulk: personally identifiable information from education records. A school cannot disclose that information to an AI vendor without consent unless an exception applies, and the workhorse exception, the school-official exception, only covers vendors under the school's direct control that use the data solely for the authorized educational purpose. A consumer chatbot on a teacher's personal account meets none of those conditions, so pasting a student's grades, IEP details, or disciplinary history into it is functionally an unauthorized disclosure. The Department of Education's 2023-2025 AI guidance repeats the same theme: the law did not change, but the number of unvetted tools sitting one paste away from student records did. The practical compliance problem is therefore at the point of entry, before the prompt is submitted.

Who it applies to

  • K-12 school districts and public schools receiving US Department of Education funds
  • Colleges and universities receiving federal student aid or other ED program funds
  • Ed-tech and AI vendors handling education records on a school's behalf under the school-official exception
  • Teachers, professors, and staff whose everyday AI use can create disclosures the institution is accountable for
  • State and local education agencies sharing student data with AI-powered systems

Enforcement and penalties

FERPA's formal penalty is dramatic and never used: the Department of Education can withhold all federal education funding from an institution that has a policy or practice of violating the law, a sanction it has never actually imposed. Real enforcement runs through the Student Privacy Policy Office, which investigates complaints, requires corrective action, and can bar an institution from sharing data with an offending third party for at least five years. There is no private right of action (the Supreme Court confirmed this in Gonzaga v. Doe, 2002), but FERPA findings feed state ed-tech laws, contract claims, and reputational damage, and an AI-related student-data incident invites all three at once.

Key provisions for AI and data privacy

34 CFR § 99.3 (definitions of education records and PII)

What counts as an education record and personally identifiable information

Education records are records directly related to a student and maintained by the school or a party acting for it. PII includes names, family member names, ID numbers, birth dates, and, importantly, any information that would let a reasonable person in the school community identify the student with reasonable certainty.

This definition is why AI prompts are a FERPA problem: a prompt describing a specific student's grades, disability, or discipline can be PII from an education record even with the name removed, because indirect identifiers plus context can identify the student. An organization using AI on student data needs to treat prompt content, not just exported files, as potential education-record disclosures, and needs de-identification that actually survives the reasonable-certainty test.

34 CFR § 99.30

Prior written consent required before disclosure

The default rule: a school must obtain signed, dated written consent from the parent or eligible student before disclosing PII from education records, specifying the records, the purpose, and the recipient.

Any AI tool that receives student PII is a recipient under this rule. No school collects consent forms naming a teacher's personal chatbot account, so consumer AI use with student data almost never has a consent basis. Compliance means either keeping student PII out of prompts to unapproved tools entirely, or routing AI work through vendors covered by a valid exception.

34 CFR § 99.31(a)(1)

The school-official exception, and when an AI vendor qualifies

Schools may disclose PII without consent to school officials with a legitimate educational interest, including contractors and vendors, but only if the vendor performs a service the school would otherwise use employees for, is under the school's direct control regarding the records, and uses the PII only for the authorized purpose, subject to the redisclosure limits of § 99.33.

This is the test an AI grader, chatbot, or tutoring platform must pass. Direct control means a contract governing the data, not consumer terms of service the school never negotiated. Only for the authorized purpose means the vendor cannot reuse student data to train its models or improve its products for other customers unless the data is properly de-identified. A free consumer tool accessed on a personal account fails every element, so the same underlying model can be permissible through a contracted enterprise deployment and impermissible through a browser tab.

34 CFR § 99.33

Limits on redisclosure and re-use

A party that receives education records under an exception may not redisclose them or use them for other purposes without meeting FERPA's conditions, and schools must be able to demonstrate compliance down the chain.

For AI vendors this is the anti-training clause in regulatory form: student data received to power a tutoring or grading feature cannot flow onward into model training, product analytics, or advertising. Organizations should demand contract language mirroring this section and verify what the vendor's retention and training defaults actually are, because a vendor's breach lands on the school as the disclosing party.

US Department of Education AI guidance (2023-2025)

AI reports and toolkits applying FERPA to modern tools

The Department's 2023 report Artificial Intelligence and the Future of Teaching and Learning, its 2024 leader toolkit for safe and equitable AI integration, and ongoing Student Privacy Policy Office materials apply existing FERPA rules to AI, stressing vetting, contracts, human oversight, and staff training rather than new obligations.

The guidance signals what enforcement will look for: an institution that vetted its AI tools, contracted for data protection, trained staff on what may not enter a prompt, and can show it. Drafting IEPs, student feedback, or recommendation letters in consumer AI tools is exactly the everyday practice the guidance flags, because those documents are dense with education-record PII and the disclosure happens the moment the prompt is sent.

Practical compliance steps

  1. 1Inventory which AI tools staff actually use with student information, including personal-account chatbots, not just district-procured platforms
  2. 2Vet and contract AI vendors under the school-official exception: direct control, defined educational purpose, no training on student data, deletion on request
  3. 3Publish a plain-language rule for staff on what may never enter an unapproved AI tool: student names, ID numbers, grades, IEP and 504 content, discipline, health information
  4. 4Put a technical control in the browser that catches student identifiers in prompts before submission, since policy alone does not stop a paste
  5. 5Train teachers on the specific high-risk workflows: IEP drafting, feedback on named student work, and recommendation letters
  6. 6Update annual FERPA notifications and school-official criteria to reflect approved AI tools
  7. 7Review vendor terms yearly and after any product change, checking retention and model-training language against § 99.31 and § 99.33

How Sanitized AI maps to this

34 CFR § 99.30 (consent before disclosure)

Student names, ID numbers, and other identifiers are caught and redacted in prompts before a teacher submits them to a consumer chatbot, stopping the unauthorized disclosure at the moment it would otherwise happen.

34 CFR § 99.31(a)(1) (school-official exception)

Administrators can see which AI tools staff actually use in the browser, so the district knows which tools need vetting and contracts and which unapproved tools are receiving prompts today.

US Department of Education AI guidance

Interception reporting gives the district documented evidence of staff training gaps and of controls actually operating, the demonstrable safeguards the 2023-2025 guidance expects institutions to show.

34 CFR § 99.33 (redisclosure and re-use limits)

When student PII never reaches an external tool in the first place, there is nothing for that tool to retain, redisclose, or train on, which shrinks the surface the redisclosure rules have to police.

Frequently asked questions

Can teachers use ChatGPT under FERPA?

Teachers can use consumer AI tools for lesson planning, general drafting, and other work that contains no student PII. The line is crossed when a prompt includes personally identifiable information from education records: a named student's grades, behavior, disability, or anything that identifies a student with reasonable certainty. Sending that to a consumer tool on a personal account is a disclosure with no consent and no exception, so districts either need approved, contracted tools or a control that keeps student PII out of prompts.

Is it a FERPA violation to put student data into an AI grading or tutoring tool?

Not automatically. If the school has contracted the tool under the school-official exception, with direct control over the data, a legitimate educational interest, and no re-use or model training on student data, the disclosure is permitted. The same data entered into an unvetted tool, or a tool whose terms allow training on inputs, is an unauthorized disclosure. The vendor contract, not the technology, decides the answer.

Can I use AI to write an IEP or a recommendation letter?

Only with care. IEPs and recommendation letters are built from education-record PII: evaluations, grades, diagnoses, and identifiable details. Drafting them in a consumer AI tool discloses that PII to the vendor. Safer patterns are district-approved tools covered by contract, or drafting from fully de-identified inputs, remembering that a detailed description of one student in one class is often identifiable even without the name.

What are the penalties for a FERPA violation involving AI?

The statutory penalty is loss of federal education funding, which the Department of Education has never actually imposed. In practice the Student Privacy Policy Office investigates, requires corrective action, and can cut off data sharing with the offending vendor for five years. There is no private right of action under FERPA itself, but state student-privacy laws, contracts, and public trust all impose their own costs after an incident.

Can an AI vendor train its models on student data?

Not on identifiable student data received under the school-official exception. FERPA limits use to the authorized educational purpose and § 99.33 blocks re-use and redisclosure, which the Department of Education reads as excluding model training on identifiable records. Vendors can generally use properly de-identified data, so the contract questions that matter are what the vendor's training defaults are and how de-identification is done and verified.

Does FERPA apply to AI tools students use on their own?

FERPA binds schools and their agents, not students or parents acting privately. A student pasting their own essay into a chatbot is not a FERPA event. It becomes the school's problem when the school requires, supplies, or integrates the tool, or when staff feed other students' information into it, and for children under 13 COPPA adds its own obligations on the tool's operator.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards