Most districts around the country are in back-to-school mode, which often includes sending parents various notices regarding school policies. Some of these relate to federal privacy laws like FERPA, which is important to note for those schools using the National Data Privacy Agreement (NDPA). The NDPA is based on using FERPA’s school official exception, which includes a requirement that schools must provide parents annually with a notice of their FERPA rights. This is such an important requirement that it is explicitly called in section 3.2 of NDPA v2.2.
What must the notice include?
The full annual notice requirements can be found in 34 CFR 99.7 of the FERPA rule. The key elements are notifying parents of the four rights they have under FERPA, namely:
– Inspect and review their students’ education records
– Seek to amend records they believe are inaccurate, misleading, or otherwise in violation of their students’ privacy
– Consent to disclosures of their students’ education records (except where an exception like school official applies)
– File a complaint with the US Department of Education if they believe their rights have been violated.
It isn’t enough to simply inform parents that these rights exist, but you also must inform of them of the procedure to request a review or amendment of their records. You also must include a specification of the criteria you use to determine who constitutes a school official with legitimate educational interest.
If you are using the NDPA with edtech providers, you are most likely using the school official exception, so it should be clear that the criteria you use includes these kinds of vendors. A lot of privacy is making sure parents and students don’t experience any surprises with your data sharing practices, so being explicit will often benefit you; that is, you could consider explicitly mentioning the NDPA or linking to your public listing of vendors that have signed the NDPA to make it that much easier for them to understand.
How is this different from the Directory Information notice?
FERPA has another notice requirement that is separate from the annual notice, which is directory information. FERPA defines directory information as a subset of information within a student’s education record that would generally be considered harmless if disclosed. These include many data points that schools have historically made public in yearbooks, honor rolls, and in public events like sports. This notice should explain your policy and provide parents with the ability to opt out of directory information disclosures.
In general, the directory information exception doesn’t work for most edtech since if you combine the limited amount of directory information with non-directory information (which most edtech will do), none of it can be considered directory information anymore. Also, since parents have the right to opt out of directory disclosures, it makes it that much more challenging to implement a new app if some students won’t be able to use it.
What action should I take now?
Since FERPA has been in place since the 1970s, chances are that your district already has versions of these notices on the books, so before undertaking drafting any new notices, you should always see what you already have out there. On the other hand, it’s entirely possible that your district hasn’t updated these notices since edtech started to proliferate in schools, so your notice may not be the clearest on how it relates to edtech.
This also demonstrates how privacy is bigger than just getting NDPAs signed. If your district is interested in getting more comprehensive training on other legal requirements under FERPA, we recommend taking our FERPA 101 course. This course was especially designed for staff involved with decision-making in the district, like approving edtech apps. Seats can be purchased at a bulk discount for this training.
