FERPA Compliance Software for Student Data Privacy: Education Records Requests and State Privacy Rights
FERPA sets a 45-day clock on a request to inspect and review education records, and 34 CFR 99.11 says you may charge for the copies but not for finding them. The expensive half of the work is the half you cannot bill for. Meanwhile the assumption that a school sits outside state privacy law has stopped holding in seven states, and the amended COPPA Rule came fully into force on April 22, 2026 with a written retention policy requirement that means knowing what student data you still hold. Obtainer finds where a student's records actually live across your systems, compiles one reviewable manifest, and keeps the clock.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
FERPA compliance means meeting the Family Educational Rights and Privacy Act and its regulations at 34 CFR Part 99, which apply to any educational agency or institution receiving federal funding from the Department of Education. The core obligations are narrower than most privacy regimes and sharper in a few specific places. A parent, or an eligible student meaning one who has turned 18 or attends a postsecondary institution, has the right to inspect and review that student's education records, and under 34 CFR 99.10 you must comply within a reasonable period and in no case more than 45 days after receiving the request. Education records are records directly related to a student and maintained by the institution or by a party acting for the institution, which is the clause that pulls your vendors in. The definition excludes sole-possession memory aids, law enforcement unit records, employee records made in the normal course of business, treatment records for students 18 and over, records created after a person is no longer a student in attendance, and peer-graded papers before a teacher collects them. Under 34 CFR 99.11 you may charge a fee for copies unless the fee effectively prevents access, but you may not charge a fee to search for or to retrieve a student's education records. Two things FERPA does not give anyone are worth stating plainly, because teams keep assuming otherwise. There is no right to deletion and no right to a portable copy. What 34 CFR 99.20 through 99.22 give is the right to seek amendment of a record the requester believes is inaccurate, misleading, or in violation of the student's privacy rights, and if you decline you must tell them so and offer a hearing. If the hearing upholds the record, the student may place a statement in the file, and that statement has to be maintained with the record and disclosed whenever the record is disclosed. There is also no private right of action: the Supreme Court settled that in Gonzaga University v. Doe, 536 U.S. 273 (2002), so enforcement runs through the Department of Education's Student Privacy Policy Office rather than through the courts. That combination, a real deadline with no consumer lawsuit behind it, is exactly why FERPA request handling tends to be under-resourced until a state privacy law or an amended COPPA Rule lands on top of it. Obtainer covers the operational half. It intakes the request, verifies the requester, discovers where a student's records actually sit across the student information system and everything around it, separates FERPA education records from data that falls outside the definition, compiles one source-system manifest, drafts a response, and tracks the 45-day clock. Nothing is disclosed automatically. A human reviews, redacts, and approves what goes out, and you keep a timestamped record of what was searched and when. Obtainer helps you comply. It is not legal advice, so the record-scope calls, the amendment decisions, and any denial stay with your registrar, your general counsel, and your privacy office. Self-serve from $49/mo.
Why it fits
Registrars, privacy officers, and general counsel at colleges, universities, and K-12 districts, plus the edtech vendors that operate as school officials under FERPA.
You cannot charge for the part that costs you the most
Section 99.11 is short and consequential. You may charge a fee for a copy of an education record made for the parent or eligible student, provided the fee does not effectively prevent access. You may not charge a fee to search for or to retrieve the records. Copying is the cheap step and it is the only billable one. Searching is the step that occupies a registrar for three days, and the rule says you absorb it. That asymmetry is a straightforward argument for making discovery faster rather than staffing it harder, because every hour saved there is an hour you were never going to recover.
The records are directly related to a student, not filed under Student Records
The definition reaches any record directly related to a student and maintained by the institution or by a party acting for it. In a modern institution that is the student information system plus the learning management system, the advising and early-alert platform, the disciplinary case manager, the financial aid file, the housing and meal system, the campus card, the tutoring and accessibility services tools, the recruiting CRM, the ticketing and help desk queues, and the shared drives where a department keeps its own copies. The exclusions help less than they look like they should. A sole-possession note stops qualifying the moment it is shared with anyone else, and an employee record is only outside the definition if the employment is not a consequence of student status, which means a work-study file usually is an education record.
Seven states stopped giving schools and their vendors a clean pass
The comfortable position, that a school is a nonprofit and nonprofits are exempt, is now wrong in California, Colorado, Delaware, Maryland, Minnesota, New Jersey, and Oregon. Colorado exempts only state institutions of higher education, only where the data is used for noncommercial purposes, and puts the burden of proving the exemption on the controller. Delaware exempts state and local government bodies but writes institutions of higher education out of that exemption. New Jersey exempts neither nonprofits nor institutions of higher education. Oregon's grace period for nonprofits ended July 1, 2025. In every one of those states, FERPA education records are generally carved out at the data level while alumni, donors, ticket buyers, camp registrants, website visitors, applicants who never enrolled, and your own staff are not.
The amended COPPA Rule turned retention into a discovery problem
The FTC finalized its COPPA Rule amendments on January 16, 2025. They took effect June 23, 2025 with full compliance required by April 22, 2026. Two of the changes land directly on anyone building for K-12. Biometric identifiers are now personal information, and indefinite retention of children's data is prohibited outright: you need a written retention policy that states how long you keep student data and why, and you have to actually delete on that schedule. A retention policy you cannot execute is a document, not a control. Executing one means being able to answer what you still hold about a specific child, in which system, and how it got there, which is the same question a FERPA request asks in a different accent.
More use cases
Related features
Questions
Common questions about this
What is FERPA compliance?
It is meeting the Family Educational Rights and Privacy Act and 34 CFR Part 99. In practice that means giving parents and eligible students access to education records within 45 days, honoring the right to seek amendment with a hearing if you decline, obtaining written consent before disclosing personally identifiable information from education records unless an exception applies, giving annual notice of these rights, and keeping a record of disclosures. It applies to educational agencies and institutions that receive Department of Education funding.
How long does a school have to respond to a FERPA request?
Forty-five days. Section 99.10 requires an educational agency or institution to comply with a request for access within a reasonable period of time and in no case more than 45 days after it receives the request. Unlike the state consumer privacy laws, there is no extension mechanism, so 45 days is a ceiling rather than a first stage. Time spent locating records inside your own systems counts against that window.
What is considered an education record under FERPA?
A record directly related to a student and maintained by the educational agency or institution or by a party acting for it. Format does not matter, so email, video, and database rows all qualify. The definition specifically excludes records kept in the sole possession of the maker as a personal memory aid and never shared, law enforcement unit records, employee records made in the normal course of business where employment does not result from student status, treatment records for students 18 and over, records created after a person is no longer in attendance, and peer-graded papers before a teacher collects them.
Does FERPA give students the right to delete their data?
No. FERPA creates no right to erasure and no right to data portability. What it gives is the right to seek amendment under 34 CFR 99.20 of a record the parent or eligible student believes is inaccurate, misleading, or in violation of the student's privacy rights. If you decide not to amend, you must inform them of that decision and of their right to a hearing. If the hearing goes against them they may place a statement in the record, which you must keep with the record and disclose alongside it.
Can a school charge a fee for copies of education records?
For the copies, yes, unless the fee effectively prevents a parent or eligible student from exercising the right to inspect and review. For finding the records, no. Section 99.11 states plainly that an educational agency or institution may not charge a fee to search for or to retrieve the education records of a student. Search and retrieval is unrecoverable cost, which is why institutions that handle volume tend to invest in making the search itself faster.
Are schools exempt from state privacy laws?
Not everywhere, and the exceptions are growing. Most comprehensive state privacy laws exempt 501(c) nonprofits, which covers most institutions, and separately carve out FERPA education records at the data level. Seven states break that pattern: California reaches for-profit institutions and edtech vendors because it applies only to businesses, and Colorado, Delaware, Maryland, Minnesota, New Jersey, and Oregon apply to nonprofits with only narrow carve-outs. In those states the non-FERPA data a school holds, including alumni, donors, event attendees, and applicants who never enrolled, carries full consumer rights.
Is an edtech vendor a school official under FERPA?
It can be. Section 99.31(a)(1) lets an institution disclose education records without consent to a school official with a legitimate educational interest, and a contractor or service provider can qualify if it performs a function the institution would otherwise use its own employees for, is under the direct control of the institution with respect to the use and maintenance of education records, and does not redisclose the information. That direct-control requirement is contractual, so the vendor answers to FERPA through your agreement while remaining directly subject to state privacy law in its own right.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.