Vendor Risk Management for Schools & Universities
April 17, 2026
Every EdTech vendor a school adopts — the LMS, the student information system, the email tenancy, the reading app a single teacher signed up for — becomes part of the institution's risk surface. FERPA is the obligation most people name first, and it is central: the school, not the vendor, answers for education records. But a defensible review has to cover more than the statute. It has to establish whether the vendor is a legitimate business, what its security posture actually looks like, whether it has a breach history, who its subprocessors are, and which compliance claims can be verified rather than merely read off a marketing page. This guide covers both halves.
What school vendor risk management has to cover
FERPA is the obligation schools name first, and it is the right starting point — but it is one of five things a review has to settle, and it is silent on most of the others.
FERPA and the education record. Whether the vendor qualifies under the school official exception, what it may do with education records, and whether the school retains direct control. Covered in detail below.
Student data privacy beyond FERPA. State student-privacy statutes and the Children's Online Privacy Protection Act (COPPA) reach tools FERPA does not, particularly free apps adopted classroom by classroom and anything collecting data from under-13s. The Student Data Privacy Consortium's National Data Privacy Agreement exists because contract terms, not the statute alone, are what bind a vendor.
Cybersecurity posture. FERPA prescribes no technical controls. A vendor can be contractually compliant and still run expired certificates, missing security headers, or infrastructure with known vulnerabilities. Education is a heavily targeted sector, and ransomware against school districts and their suppliers is routine.
Breach and incident history. A vendor that has been breached before is not disqualified, but the school needs to know it, know what was disclosed, and know what changed afterwards — before the vendor is in front of student data rather than after.
Subprocessors. The vendor you contract with is rarely the only company holding the data. Direct control has to survive one layer down.
The practical problem is that most schools have far more EdTech vendors than review capacity. Independent assessment is what makes the long tail reviewable at all: it establishes the verifiable half — legitimacy, security posture, breach history, subprocessors, which certifications hold up — without waiting on the vendor, so limited staff time goes to the contract questions only the vendor can answer.
FERPA requirements for third-party vendors
FERPA (20 U.S.C. § 1232g) protects education records — any records directly related to a student that are maintained by an educational institution or a party acting for the institution. When schools share education records with vendors, they typically rely on the "school official" exception (§ 99.31(a)(1)), which allows disclosure without parental consent if the vendor: (1) performs a service that the school would otherwise perform itself, (2) is under the direct control of the school regarding the use and maintenance of education records, and (3) uses education records only for the purposes specified in the agreement. The school must also ensure the vendor does not re-disclose education records to other parties without authorization. Critically, the school — not the vendor — is responsible for FERPA compliance. If a vendor mishandles student data, the school faces investigation by the Department of Education's Student Privacy Policy Office (SPPO), potential loss of federal funding eligibility, and reputational damage with parents and the community.
Trying to verify a vendor's compliance right now?
ThirdProof runs the investigation in under 10 minutes — 27 sources, a source-cited PDF, and up to 133 security questions auto-filled.
Run a Free Investigation →Directory information vs. education records
FERPA distinguishes between education records (protected) and directory information (can be disclosed under certain conditions). Directory information includes names, addresses, phone numbers, dates of attendance, degrees received, and similar general information. Schools can designate what constitutes directory information and must give parents/students the opportunity to opt out of its disclosure.
This distinction matters for vendor assessment because some EdTech tools only access directory information, while others access full education records including grades, disciplinary records, IEP/504 plans, and financial aid data. Your assessment depth should match the data sensitivity. A vendor accessing only directory information (after proper notice and opt-out procedures) presents lower FERPA risk than a vendor accessing grades, attendance records, or special education data. However, many schools over-rely on the directory information exception — if a vendor accesses more than what the school has designated as directory information, the school official exception or written parental consent is required.
Vetting an EdTech vendor: the checks that matter
Split the review into what the contract has to say and what the evidence has to show. The first half needs the vendor; the second half does not.
Contract terms — ask the vendor. *Data use limitations:* do the terms of service or data privacy agreement restrict use of education records to the contracted purpose only? Watch for broad data licensing that permits product improvement, advertising, or analytics beyond the contracted service, and for AI training clauses, which have appeared quietly in EdTech terms as vendors added assistant features. *Data retention and deletion:* what happens to student data when the contract ends or a student leaves? FERPA prescribes no retention period, so the contract is the only thing setting one. *Breach notification:* how fast, and with what detail? The school's own notification obligations run on that clock.
Evidence — check it yourself. *Business legitimacy:* is the vendor a registered entity of the age and jurisdiction it claims? A district with hundreds of small classroom tools has real exposure here. *Security posture:* TLS configuration, certificate validity, HTTP security headers, known infrastructure vulnerabilities, domain reputation. FERPA prescribes no technical controls, so nothing in the compliance paperwork surfaces any of this. *Breach and incident history:* public breach databases, regulatory enforcement actions and adverse media, which is where an incident the vendor has not volunteered actually shows up. *Certification claims:* SOC 2 and ISO 27001 attestations recorded as registry-verified or vendor-attested rather than accepted at face value. *Subprocessors:* who else holds the data.
ThirdProof runs the second half across 27 intelligence sources without contacting the vendor, so the evidence file exists before the procurement conversation starts.
Student data privacy commitments. Does the vendor sign the Student Data Privacy Consortium's National Data Privacy Agreement (NDPA), or a state-level equivalent? These are not FERPA requirements, but a vendor that has signed one has already accepted terms a school would otherwise have to negotiate.
Subprocessors: the fourth parties behind your EdTech stack
The vendor a school signs with is rarely the only company holding student data. An LMS runs on a cloud provider, sends mail through a delivery service, records sessions with a video platform, and increasingly routes text through a model provider. Each of those is a subprocessor, and each is a place education records can sit.
FERPA's school official exception turns on the school retaining direct control over the use and maintenance of education records. That control has to survive the handoff: a vendor that may not re-disclose records without authorisation cannot solve the problem by passing them to a supplier instead. In practice this means the vendor's subprocessor list is assessment evidence, not a footnote.
Two things are worth establishing for every vendor with real data access. First, whether a subprocessor list is published at all — a vendor that cannot tell you who else touches the data has answered the question. Second, whether the vendor commits to notifying customers before adding one, which is what makes the list durable rather than a snapshot. ThirdProof discovers published subprocessor pages during assessment and runs the same legitimacy and reputation checks against each name it finds, so the fourth-party layer is documented rather than assumed.
Building a school vendor risk program
Inventory all EdTech vendors. Create a complete list of every technology vendor that accesses student education records. Include LMS platforms, SIS systems, communication tools, assessment platforms, library systems, and any tool where students log in with school credentials. Many schools discover they have 50-200+ EdTech vendors when they conduct a thorough inventory.
Classify by data access level. Tier vendors based on what student data they access: Tier 1 (full education records including grades, disciplinary, special education), Tier 2 (limited education records like attendance and course enrollment), Tier 3 (directory information only). Assessment depth should match tier.
Review contracts and terms. Ensure every vendor with access to education records has a written agreement establishing the school official relationship. Many schools use the Student Data Privacy Consortium NDPA as a standardized template. Review vendor terms of service for data use provisions that conflict with FERPA requirements.
Conduct independent assessment. Vendor self-attestations about security are insufficient — schools should verify vendor security posture, compliance certifications, breach history, and business legitimacy independently. ThirdProof assessments provide evidence-based verification that supplements vendor-provided documentation.
Document and maintain. Keep records of your vendor assessment process, findings, and decisions. If the SPPO investigates, you need evidence of reasonable oversight — not just signed agreements, but documented due diligence.
Frequently asked questions
Does FERPA require a specific contract with EdTech vendors?+
What happens if an EdTech vendor has a data breach involving student records?+
Can vendors use student data to improve their products?+
How do schools vet EdTech vendors before adopting them?+
Does FERPA require schools to check an EdTech vendor's cybersecurity?+
How does ThirdProof help with FERPA vendor assessment?+
Vendors assessed by ThirdProof
Stop chasing vendors for questionnaires.
ThirdProof delivers a source-cited vendor risk report and a security questionnaire pre-filled where the evidence supports it — in minutes, not months. Run one vendor free, no account required.
Assess a Vendor Free →No account, no credit card