RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The atlas · 100 retrospective records ↗
School AI Atlas

The atlas / Access & safety

Access & safety / Reference note · Reference note · prepared 16 September 2026

A department office defines when a vendor counts as a school official

FERPA's school-official exception, not a vendor's privacy notice, decides whether an AI tool may hold student records without parental consent.

studentprivacy.ed.govprimary record

Responsibilities of Third-Party Service Providers under FERPA

Document
1 August 2015
Event
no single event
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The classroom note

A teacher wants to try an AI writing-feedback tool on a class set of essays. Before any privacy policy is read, the more basic question is legal: can the school hand a vendor student work at all, without asking every parent first? FERPA answers that through what is called the school official exception. Where a school contracts with a company to perform a service it would otherwise carry out itself, and keeps that company under its direct control, the company can be treated as a school official and receive personally identifiable information from education records without separate parental consent.

What the evidence says

The Department of Education's Privacy Technical Assistance Center sets out the exception's conditions in guidance written for vendors, dated August 2015: the provider must perform an institutional service the school would otherwise use its own staff for, meet the criteria in the school's annual FERPA notice, remain under the school's direct control, and never redisclose data beyond purposes the school authorised. A companion document for school audiences, last updated February 2014, adds that the exception most plausibly covers apps procured for a school activity, not tools a student finds and uses independently. Neither document is a court ruling; both are the Department's own explanation of a decades-old statute, current as retrieved 16 September 2026 via its student-privacy portal.

The implementation question

Direct control is the mechanism doing the real work, and it is a governance relationship, not a checkbox. A school must say what a vendor may do with student writing, confirm the vendor is not repurposing it to train a separate public model, and retain the ability to require deletion. The guidance's own example is blunt: a contract letting a vendor unilaterally change its terms without notifying the school undermines the school's claim to be exercising that control at all. That makes a contract's change-notice clause as important to review as the AI feature itself.

What holds and what fails

The school official exception holds when a contract names the purpose, limits redisclosure, and gives the school a real ability to audit and terminate. It fails, as a matter of the statute's own logic rather than any accusation against a particular company, wherever a vendor's terms allow reuse of student records for its own product development or model training beyond the school's authorised purpose, because that use is no longer for the school. An AI feature trained on student writing without a clear contractual boundary is exactly the scenario this exception was not built to authorise.

  • Does the contract name the specific institutional service the vendor performs, in language a parent could read?
  • Can the school actually audit or terminate the vendor's use of student data, or only ask it to comply?
  • Does anything in the vendor's terms allow reuse of student work beyond the service the school procured?

FERPA does not ask a school to trust a vendor's privacy page; it asks the school to hold the pen on what the vendor is allowed to do.

Sources & reading trail

Responsibilities of Third-Party Service Providers under FERPA ↗

PTAC-FAQ-5 (August 2015) sets out the four conditions of FERPA's school official exception for vendors.

Source published: 1 August 2015 · Retrieved: 16 September 2026

Protecting Student Privacy While Using Online Educational Services: Requirements and Best Practices ↗

Companion school-audience guidance stating the exception is intended for school-procured tools, not independent student use.

Source published: 1 February 2014 · Retrieved: 16 September 2026

Protecting Student Privacy ↗

Confirms the Department's current student-privacy guidance portal, retrieved 16 September 2026.

Source published: Not established · Retrieved: 16 September 2026

Departments, studies and vendor documents establish the record; the implementation reading and the boundary are School AI Atlas editorial analysis. This retrospective draft does not imply the site published on the event date.