Skip to main content
Skip to main content
Education Compliance

FERPA Vendor Risk Assessment for Schools & Universities

April 17, 2026

FERPA (the Family Educational Rights and Privacy Act) requires schools and universities to protect student education records — and that obligation extends to every EdTech vendor that accesses student data. When a school adopts Canvas for its LMS, PowerSchool for student information, or Google Workspace for student email, it must ensure the vendor handles education records in compliance with FERPA. Unlike HIPAA, FERPA does not require a specific contract type, but the Department of Education has made clear that schools must maintain "direct control" over vendor use of education records. This guide covers what institutions must verify and how to build a defensible vendor assessment process.

FERPA requirements for third-party vendors

FERPA (20 U.S.C. § 1232g) protects education records — any records directly related to a student that are maintained by an educational institution or a party acting for the institution. When schools share education records with vendors, they typically rely on the "school official" exception (§ 99.31(a)(1)), which allows disclosure without parental consent if the vendor: (1) performs a service that the school would otherwise perform itself, (2) is under the direct control of the school regarding the use and maintenance of education records, and (3) uses education records only for the purposes specified in the agreement. The school must also ensure the vendor does not re-disclose education records to other parties without authorization. Critically, the school — not the vendor — is responsible for FERPA compliance. If a vendor mishandles student data, the school faces investigation by the Department of Education's Student Privacy Policy Office (SPPO), potential loss of federal funding eligibility, and reputational damage with parents and the community.

Directory information vs. education records

FERPA distinguishes between education records (protected) and directory information (can be disclosed under certain conditions). Directory information includes names, addresses, phone numbers, dates of attendance, degrees received, and similar general information. Schools can designate what constitutes directory information and must give parents/students the opportunity to opt out of its disclosure.

This distinction matters for vendor assessment because some EdTech tools only access directory information, while others access full education records including grades, disciplinary records, IEP/504 plans, and financial aid data. Your assessment depth should match the data sensitivity. A vendor accessing only directory information (after proper notice and opt-out procedures) presents lower FERPA risk than a vendor accessing grades, attendance records, or special education data. However, many schools over-rely on the directory information exception — if a vendor accesses more than what the school has designated as directory information, the school official exception or written parental consent is required.

Trying to verify a vendor's compliance right now?

ThirdProof runs the investigation in an average of 7 minutes — 27 sources, audit-ready PDF, and 133 security questions auto-filled.

Run a Free Investigation →

What to verify in EdTech vendor assessments

For each vendor that accesses student education records, document your assessment of:

Data use limitations. Does the vendor's terms of service or data privacy agreement restrict use of education records to the contracted purpose only? Watch for broad data licensing terms that allow the vendor to use student data for product improvement, advertising, or analytics beyond the contracted service.

Data retention and deletion. What happens to student data when the contract ends or when a student leaves? FERPA does not prescribe specific retention periods, but schools should ensure vendors delete education records upon contract termination or school request.

Subprocessor and third-party sharing. Does the vendor share student data with subprocessors? Under what conditions? The school must maintain "direct control" over how education records are used — this extends to the vendor's subprocessors.

Security safeguards. What technical and organizational measures protect student data? Encryption, access controls, breach notification procedures, and incident response capabilities. ThirdProof checks these automatically across 27 intelligence sources.

Breach notification. How quickly will the vendor notify the school of a data breach? What information will be provided? Schools need adequate notice to meet their own notification obligations to parents and the Department of Education.

Student data privacy certifications. Does the vendor participate in the Student Data Privacy Consortium's National Data Privacy Agreement (NDPA) or hold relevant certifications? These are not FERPA requirements but indicate vendor maturity around student data protection.

Building a FERPA vendor assessment program

Inventory all EdTech vendors. Create a complete list of every technology vendor that accesses student education records. Include LMS platforms, SIS systems, communication tools, assessment platforms, library systems, and any tool where students log in with school credentials. Many schools discover they have 50-200+ EdTech vendors when they conduct a thorough inventory.

Classify by data access level. Tier vendors based on what student data they access: Tier 1 (full education records including grades, disciplinary, special education), Tier 2 (limited education records like attendance and course enrollment), Tier 3 (directory information only). Assessment depth should match tier.

Review contracts and terms. Ensure every vendor with access to education records has a written agreement establishing the school official relationship. Many schools use the Student Data Privacy Consortium NDPA as a standardized template. Review vendor terms of service for data use provisions that conflict with FERPA requirements.

Conduct independent assessment. Vendor self-attestations about security are insufficient — schools should verify vendor security posture, compliance certifications, breach history, and business legitimacy independently. ThirdProof assessments provide evidence-based verification that supplements vendor-provided documentation.

Document and maintain. Keep records of your vendor assessment process, findings, and decisions. If the SPPO investigates, you need evidence of reasonable oversight — not just signed agreements, but documented due diligence.

Frequently asked questions

Does FERPA require a specific contract with EdTech vendors?+
FERPA does not prescribe a specific contract format like HIPAA's BAA. However, schools using the "school official" exception must ensure the vendor meets the criteria: performing a service for the school, under the school's direct control regarding education records, and using records only for authorized purposes. A written agreement documenting these requirements is essential for compliance evidence.
What happens if an EdTech vendor has a data breach involving student records?+
The school — not the vendor — bears FERPA responsibility. Schools must notify affected parents/students and may face investigation by the Department of Education's SPPO. Repeated violations can result in loss of federal funding eligibility. This is why vendor breach notification terms and incident response capabilities are critical assessment factors.
Can vendors use student data to improve their products?+
Under FERPA's school official exception, vendors can only use education records for the purposes specified in the agreement with the school. Using student data for product development, advertising, or purposes beyond the contracted service likely violates the school official exception and FERPA. Review vendor terms of service carefully for broad data licensing provisions.
How does ThirdProof help with FERPA vendor assessment?+
ThirdProof assesses EdTech vendors across 27 intelligence sources, covering security posture, compliance certifications, breach history, business legitimacy, and sanctions screening. The education industry module provides FERPA-relevant context in assessment findings, helping schools document vendor due diligence beyond signed agreements.

Stop chasing vendors for questionnaires.

ThirdProof delivers a complete vendor risk report and pre-filled security questionnaire in minutes, not months — without contacting the vendor. Try it free with 5 investigations.

Start Free Trial →

No credit card required