FERPA Exemption From State Privacy Laws: The Seven States That Do Not Give Schools a Clean Pass
Last updated August 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
Most comprehensive state privacy laws exempt 501(c) nonprofits outright and separately carve out education records governed by FERPA, which is why the majority of colleges, universities, and school districts have been able to treat the state privacy wave as somebody else's problem. Seven states break that pattern: California, Colorado, Delaware, Maryland, Minnesota, New Jersey, and Oregon. In those seven, nonprofit status is either irrelevant or nearly so, the exemption for educational institutions is narrow or absent, and everything a school holds that is not a FERPA education record carries full access, correction, deletion, and opt-out rights on a 45-day clock.
Two of those states moved recently. Oregon's grace period for nonprofits ended on July 1, 2025, which put most Oregon institutions inside the law for the first time. Maryland's law took effect October 1, 2025 and reaches processing from April 1, 2026. If your privacy posture still rests on the sentence "we are a nonprofit school, so this does not apply to us," it is now wrong in seven states, and it was never right for your vendors anywhere.
Which states exempt schools from their privacy laws and which do not
The table covers the seven states where an educational institution does not get a clean entity-level pass. The other thirteen comprehensive-law states, including Texas, Virginia, Connecticut, Utah, Iowa, Montana, and Tennessee, exempt 501(c) organizations at the entity level, which puts nonprofit schools outside the law entirely. Exemption language is amended more often than any other part of these statutes, so confirm a row against the current text before you rely on it.
| State | Does the law reach the institution itself? | Nonprofits | FERPA records | Key dates |
|---|---|---|---|---|
| California CCPA and CPRA | For-profit only. Nonprofit institutions fall outside the "business" test. For-profit colleges and edtech vendors are fully in. | Exempt (not a business) | Deletion is constrained where federal law requires retention | Jan 1, 2020 |
| Colorado CPA | Narrow. Only state institutions, and only for noncommercial use. The controller must prove the exemption. | No nonprofit exemption at all | Carved out at the data level | Jul 1, 2023 |
| Delaware DPDPA | No. Section 12D-103 exempts government bodies but writes higher education out of that exemption. | Only insurance-fraud nonprofits exempt | Carved out at the data level | Jan 1, 2025 |
| Maryland MODPA | No. No entity-level exemption for higher education. | Only insurance-related nonprofits exempt | Carved out at the data level | Effective Oct 1, 2025; reaches processing from Apr 1, 2026 |
| Minnesota MCDPA | Deferred, not exempt. Postsecondary institutions under the Office of Higher Education need not comply until July 31, 2029. | Only insurance-fraud nonprofits exempt | Carved out at the data level | Jul 31, 2025; postsecondary Jul 31, 2029 |
| New Jersey NJDPA | No. Exempts neither nonprofits nor higher education, the broadest reach of any state law here. | Not exempt | Sources differ on the scope of the carve-out; read the current text | Jan 15, 2025; cure period ended Jul 15, 2026 |
| Oregon OCPA | No. No entity-level exemption for higher education. | Covered since Jul 1, 2025, when the grace period ended | Carved out at the data level | Jul 1, 2024; nonprofits Jul 1, 2025 |
One row deserves a second look. New Jersey is the outlier in both directions: it declines to exempt nonprofits and it declines to exempt institutions of higher education, which makes it the state where a private university has the least room to argue it is out of scope. Published analyses disagree about exactly how far its FERPA carve-out extends, and rather than guess, we have left that cell describing the disagreement. Read the statute, or have counsel read it, before you build a process on either answer.
Why the nonprofit exemption is the one that actually matters
Schools tend to reach for FERPA when they think about privacy exposure, but FERPA is not what keeps most institutions out of these laws. The nonprofit exemption is. FERPA only ever carves out education records, which is a specific and surprisingly narrow category, while a nonprofit exemption removes the entire organization. Lose the second one and the first one protects a small fraction of what you hold.
Consider what a mid-sized university has in its systems that is not an education record. Alumni records, which FERPA explicitly excludes once a person is no longer a student in attendance. Donor and prospect files, including wealth screening data bought from a vendor. Ticket buyers for athletics and performing arts. Summer camp and community program registrants, many of them minors with no enrollment relationship. Continuing education students who never matriculated. Applicants who were admitted and went elsewhere, and applicants who were rejected. Everyone on the mailing list. Every visitor to the public website, along with whatever the advertising pixels recorded. Employees, contractors, and job applicants, who have carried full rights in California since January 1, 2023. In a covered state, each of those people can send a request, and none of them are behind the FERPA wall.
Does the CCPA apply to universities?
To nonprofit universities, generally no, because the CCPA applies to a "business," which the statute defines as a for-profit legal entity. To for-profit institutions, yes. And to the long list of companies a nonprofit university buys from, emphatically yes, which is where the practical exposure sits. Your student information system vendor, learning management provider, admissions CRM, retention analytics platform, proctoring service, and payment processor are almost all for-profit California-covered businesses processing your students' data, and their obligations become your procurement and contracting problem the moment a student sends one of them a request directly.
The trap is assuming the nonprofit answer travels. It does not travel across state lines, since Colorado, Delaware, Maryland, Minnesota, New Jersey, and Oregon do not use the for-profit test at all, and it does not travel down your vendor chain. A useful exercise is to count how many of your enrolled students are residents of those seven states rather than how many are on campus, because these laws follow the resident, not the campus. The threshold guide to which state privacy laws apply to your business walks through the counting rules.
What is the difference between an entity-level and a data-level exemption?
An entity-level exemption removes the organization from the law. If you qualify, you have no consumer rights obligations under that statute, no notice duties, and nothing to build. A data-level exemption removes specific records while leaving the organization fully covered. You still owe rights, notices, and deadlines, and for every incoming request somebody has to decide which records are carved out and which are not.
The operational gap between those two is large, and it is not a question you answer once. It has to be answered per request, per record, per system, because one person is frequently several things at once: a current student, a work-study employee, an alumni donor in waiting, and a season ticket holder. Only the first of those sits behind FERPA. Healthcare and financial institutions hit the same wall from different directions, and the pattern repeats closely enough to be worth reading across: see the HIPAA entity-level versus data-level breakdown by state and the GLBA exemption split across state privacy laws.
Does FERPA give students a right to delete their data?
No. FERPA creates no right to erasure and no right to a portable copy. It gives the right to inspect and review, and under 34 CFR 99.20 the right to seek amendment of a record the parent or eligible student believes is inaccurate, misleading, or in violation of the student's privacy rights. If you decide not to amend, you have to say so and offer a hearing. If the hearing upholds the record, the student may place a statement in the file, and you must keep that statement with the record and disclose it whenever the record is disclosed.
That matters here because it sets up an awkward pairing. In a covered state, the same student can send a deletion request under state law for the non-FERPA data and get one, while the education record itself stays put. Two different answers to what feels to the requester like one question, and the difference has to be explained clearly enough that it does not read as a refusal. The distinction between the two request types is covered in more depth in the guide to DSARs versus deletion requests.
The deadline is 45 days, and you cannot bill for the expensive part
Section 99.10 requires compliance with a request for access within a reasonable period and in no case more than 45 days. There is no extension mechanism, which makes FERPA's 45 days meaningfully tighter than the 45 days in the state consumer laws, since those come with a further 45-day extension on request. Then section 99.11 adds the part that decides how you should resource this: you may charge a fee for copies unless the fee effectively prevents access, but you may not charge a fee to search for or to retrieve a student's education records.
Read those two together and the economics are clear. The deadline is short, the search is the slow step, and the search is the step the regulation says you eat. Institutions that handle real volume respond by shortening the search rather than adding people to it, which is what personal data discovery is for. The record sprawl is the obstacle: student information system, LMS, advising and early-alert tools, disciplinary case management, financial aid, housing, campus card, help desk queues, and department shared drives. Continuing education and staff development frequently run somewhere else again, on a separate platform for onboarding and certifying employees, outside whatever inventory the registrar maintains.
Edtech vendors are covered directly, not just by contract
A vendor can serve as a school official with a legitimate educational interest under 34 CFR 99.31(a)(1) if it performs a function the institution would otherwise use employees for, stays under the institution's direct control with respect to the use and maintenance of education records, and does not redisclose. That relationship is contractual, and it is often the only privacy obligation an edtech company tracks carefully.
It is not the only one that applies. An edtech company is a for-profit business in its own right, which means the California test it fails is the same one its nonprofit customers pass, and the six other states on the list reach it without the for-profit question arising. On top of that sits the amended COPPA Rule, finalized January 16, 2025, effective June 23, 2025, with full compliance required from April 22, 2026. It made biometric identifiers personal information, required separate verifiable parental consent before disclosing children's data to third parties for targeted advertising, and prohibited indefinite retention outright, which means a written retention policy stating how long you keep student data and a real ability to delete on that schedule. A retention policy you cannot execute is a document rather than a control, and executing one requires knowing what you still hold about a specific child and where it sits.
What to do about it
Work out which of the seven states reach you, counting residents rather than campuses, and remember that Minnesota's postsecondary deferral to July 31, 2029 buys time for institutions and nothing at all for the vendors serving them. Then draw the line in writing, per system, between FERPA education records and everything else, before a request arrives rather than during one, because that boundary is the decision every request will turn on and it does not get easier under a 45-day clock.
After that it is intake discipline. The failure mode in this area is not a bad judgment call about record scope. It is a request that arrived in an unwatched mailbox at the registrar's office and sat there for six weeks. Log the date on arrival, start the clock, and keep one record of what was searched and when. The operational side, including discovery, the manifest, and the approval trail, is covered on the FERPA compliance page for schools and edtech. Obtainer helps you comply. It is not legal advice, and the exemption analysis stays with your team.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.