Written by
Halkwinds Editorial Team
Halkwinds Research & Editorial
Student Data Privacy in EdTech: FERPA, COPPA, and State Student Privacy Laws
How FERPA, COPPA, and a growing patchwork of state student privacy laws shape what EdTech products can collect, share, and retain.

EdTech products sit at the intersection of three overlapping privacy regimes that don't map neatly onto each other: FERPA, which governs education records held by federally funded schools; COPPA, which governs data collection from children under 13 regardless of the education context; and a growing set of state student privacy laws that layer additional, often stricter obligations specifically on top of both. A product can be FERPA-compliant and still violate COPPA, or comply with both federal laws and still fall short of a state's specific student data requirements. This is a practical guide to how these frameworks actually interact.
Table of Contents
- FERPA: Education Records and the School Official Exception
- COPPA: Children's Data Regardless of Education Context
- How FERPA and COPPA Overlap and Diverge
- State Student Privacy Laws: A Growing Patchwork
- Data Minimization and Retention in Practice
- Vendor Contracts and District Responsibility
Key Takeaways
- FERPA applies to education records maintained by federally funded educational institutions, and EdTech vendors typically operate under the "school official" exception, which requires the school to maintain direct control over the vendor's use of student data.
- COPPA applies independently of FERPA whenever a product collects personal information from children under 13, and requires either verifiable parental consent or reliance on the school's consent on parents' behalf under specific conditions.
- A growing number of states have passed student data privacy laws that impose stricter requirements than FERPA and COPPA alone — including limits on using student data for targeted advertising and mandatory data deletion upon contract termination.
- The most common compliance gap is data retention: many EdTech contracts don't clearly specify what happens to student data when a district's contract ends, leaving data in an ambiguous state that neither party is actively managing.
FERPA: Education Records and the School Official Exception
FERPA governs education records maintained by schools and institutions receiving federal funding, giving parents (and eligible students) rights to access and control disclosure of those records. FERPA does not directly regulate EdTech vendors — instead, most EdTech products operate under the "school official" exception, which allows a school to share student data with a vendor performing a service the school would otherwise perform itself, provided the school maintains direct control over the data's use, the vendor uses the data only for the authorized purpose, and the vendor doesn't redisclose it without authorization. This means FERPA compliance for an EdTech vendor is really a question of contract terms with the district, not an independent certification the vendor can claim on its own.
COPPA: Children's Data Regardless of Education Context
COPPA applies whenever a product or service collects personal information from children under 13, regardless of whether the context is educational. This creates an independent compliance obligation on top of FERPA: a product used in elementary schools needs COPPA-compliant consent mechanisms even if it's also operating under FERPA's school official exception. The FTC has recognized a limited exception allowing schools to consent on behalf of parents for products used strictly for educational purposes within the school's direction, but this exception has real boundaries — it doesn't extend to using student data for commercial purposes like targeted advertising or product marketing beyond the educational use the school authorized.
How FERPA and COPPA Overlap and Diverge
The practical distinction that trips up many EdTech products is that FERPA is about who controls disclosure of education records, while COPPA is about consent for collecting data from children in the first place — a product can satisfy FERPA's school-official framework for data sharing and still need independent COPPA compliance for the initial collection and any secondary use of children's data. Products serving both younger children (under 13, triggering COPPA) and older students (13 and up, where COPPA doesn't apply but FERPA and state laws still do) commonly need different consent and data handling flows by age band rather than a single uniform policy.
State Student Privacy Laws: A Growing Patchwork
A significant and growing number of states have passed student data privacy laws — often modeled on frameworks like California's Student Online Personal Information Protection Act (SOPIPA) — that impose obligations beyond FERPA and COPPA specifically for K-12 EdTech: prohibiting the use of student data for targeted advertising, requiring data deletion upon request or contract termination, and restricting the creation of student profiles for non-educational purposes. These laws vary meaningfully by state in scope and specific requirements, and a product operating across multiple states needs a compliance approach flexible enough to apply the most protective applicable standard by default, rather than assuming FERPA and COPPA compliance alone is sufficient nationwide.
Data Minimization and Retention in Practice
Beyond the specific statutory requirements, data minimization — collecting only the student data genuinely necessary for the product's educational function — and clear data retention policies are both practical risk-reduction measures and increasingly explicit legal requirements under state student privacy laws. The most common gap we see in EdTech contracts is a lack of clarity on what happens to student data when a district's contract ends: without an explicit deletion or return-of-data obligation written into the contract, data can persist indefinitely in a vendor's systems long after the relationship that justified collecting it has ended.
Vendor Contracts and District Responsibility
Because FERPA compliance for a vendor operates through the school-official exception rather than independent certification, the data protection agreement between the district and the vendor is where compliance actually gets specified and enforced — covering permitted use, security requirements, subprocessor restrictions, breach notification timelines, and data deletion obligations. Districts increasingly use standardized data privacy agreement templates (several states have developed model agreements) specifically to reduce the negotiation burden of establishing these terms with every individual vendor.
Student data privacy considerations connect directly to the broader personalization and analytics architecture EdTech products are built on — see our related piece on AI in education and personalized learning systems and our LMS integration architecture guide for how data flows across the broader EdTech stack. If your organization is building or evaluating EdTech data privacy compliance, contact our team.
Frequently Asked Questions
Does FERPA compliance automatically mean an EdTech product is COPPA compliant too?
No. FERPA and COPPA address different things — data disclosure control versus collection consent for children under 13 — and a product needs to satisfy both independently when it serves students under 13 in a context FERPA also covers.
Can a school consent to data collection on behalf of parents under COPPA?
Under a limited FTC exception, yes, but only for data used strictly for the educational purpose the school authorized — it doesn't extend to commercial uses like targeted advertising or marketing beyond that scope.
What happens to student data when a district's contract with an EdTech vendor ends?
This depends entirely on what the contract specifies — many state student privacy laws now require deletion or return of data upon termination, but without an explicit contractual obligation, data can persist indefinitely in an ambiguous state.
Do state student privacy laws apply on top of FERPA and COPPA, or instead of them?
On top of — state student privacy laws typically add obligations beyond federal requirements rather than replacing them, which is why multi-state EdTech products need a compliance approach that satisfies the most protective applicable state standard.
Is a standard data privacy agreement enough, or does every district need custom terms?
Many states have developed model data privacy agreement templates that districts and vendors increasingly use as a starting point, which reduces negotiation overhead, though districts may still require modifications for their specific requirements.
Explore Further