Ask Before You App / Learn / Glossary
Every acronym, clause, and legal term you will run into when reviewing vendor agreements, explained in plain language.
You should not need a law degree to protect your students. Start here.
Showing 7 of 53 terms matching "FERPA"
Specific data elements (like name and address) defined under FERPA that a school may disclose, subject to a parent's right to opt-out.
Districts define their own list of directory information. If a vendor is collecting something your district hasn't designated as directory information, that changes the legal picture.
An optional NDPA exhibit generated by State Alliances to address state-specific data privacy legislative requirements.
Every state has its own privacy laws on top of FERPA. Utah has SB 267 (which directs USBE to study software use in public schools) and Utah Code §53E-9 (Student Privacy and Data Protection). California has SOPIPA. Exhibit G is where state-specific requirements get folded in. For Utah, audit and sub-processor disclosure requirements come from §53E-9, not SB 267.
Records specifically defined and protected under FERPA (20 U.S.C. 1232g(a)(4) and 34 CFR § 99.3).
Not everything a school collects qualifies as an "education record" under FERPA. But if a vendor is processing data that does qualify (grades, behavioral notes, transcripts), FERPA's rules apply whether the vendor realizes it or not.
The foundational U.S. federal law protecting student data privacy. It governs the disclosure of education records and parental access rights.
FERPA is from 1974. It predates the internet by decades. It still applies to every ed-tech vendor touching student data, and it is the legal backbone that everything else (COPPA, state laws, the NDPA) builds on. Parents have the right to inspect and review their child's Education Records, request amendments, and must give consent before records are shared with third parties outside of recognized exceptions.
A recognized cybersecurity framework guiding security and management practices in the education space.
If FERPA tells you what data to protect, GESS tells you how to protect it. It is the security playbook for the education sector.
A companion document to the NDPA utilized for standardizing data-sharing agreements between schools/districts and researchers under FERPA's "Studies Exception."
Research partnerships are valuable but tricky. The NRDPA gives districts a standardized way to share data with researchers without building a custom legal agreement every time.
Under FERPA, a contractor or vendor performing an institutional service or function for which the school would otherwise use employees, operating under the school's direct control regarding PII.
When a vendor is designated as a "school official," they can access education records without parental consent. That is a big legal privilege, and it comes with real obligations. The DPA is what defines those obligations. A vendor that handles the LEA's student information system is a School Official, which allows the LEA to share FERPA-protected data for educational purposes without individual parental consent.
ABYA pulls a district's vendors, agreements, and compliance docs into one public hub, and trains the staff on the terms above. The words on this page are what your hub makes visible and legible to parents and boards.
Free course, 50 minutes
Our NDPA training course walks through every exhibit, every clause, and what to do when a vendor pushes back. You leave with something you can use and cite.