Responsibilities of Third-Party Service Providers under FERPA
- Document
- 1 August 2015
- Event
- no single event
- Retrieved
- 16 September 2026
The classroom note
A teacher wants to try an AI writing-feedback tool on a class set of essays. Before any privacy policy is read, the more basic question is legal: can the school hand a vendor student work at all, without asking every parent first? FERPA answers that through what is called the school official exception. Where a school contracts with a company to perform a service it would otherwise carry out itself, and keeps that company under its direct control, the company can be treated as a school official and receive personally identifiable information from education records without separate parental consent.
What the evidence says
The Department of Education's Privacy Technical Assistance Center sets out the exception's conditions in guidance written for vendors, dated August 2015: the provider must perform an institutional service the school would otherwise use its own staff for, meet the criteria in the school's annual FERPA notice, remain under the school's direct control, and never redisclose data beyond purposes the school authorised. A companion document for school audiences, last updated February 2014, adds that the exception most plausibly covers apps procured for a school activity, not tools a student finds and uses independently. Neither document is a court ruling; both are the Department's own explanation of a decades-old statute, current as retrieved 16 September 2026 via its student-privacy portal.
The implementation question
Direct control is the mechanism doing the real work, and it is a governance relationship, not a checkbox. A school must say what a vendor may do with student writing, confirm the vendor is not repurposing it to train a separate public model, and retain the ability to require deletion. The guidance's own example is blunt: a contract letting a vendor unilaterally change its terms without notifying the school undermines the school's claim to be exercising that control at all. That makes a contract's change-notice clause as important to review as the AI feature itself.
What holds and what fails
The school official exception holds when a contract names the purpose, limits redisclosure, and gives the school a real ability to audit and terminate. It fails, as a matter of the statute's own logic rather than any accusation against a particular company, wherever a vendor's terms allow reuse of student records for its own product development or model training beyond the school's authorised purpose, because that use is no longer for the school. An AI feature trained on student writing without a clear contractual boundary is exactly the scenario this exception was not built to authorise.
- Does the contract name the specific institutional service the vendor performs, in language a parent could read?
- Can the school actually audit or terminate the vendor's use of student data, or only ask it to comply?
- Does anything in the vendor's terms allow reuse of student work beyond the service the school procured?
FERPA does not ask a school to trust a vendor's privacy page; it asks the school to hold the pen on what the vendor is allowed to do.
Sources & reading trail
PTAC-FAQ-5 (August 2015) sets out the four conditions of FERPA's school official exception for vendors.
Source published: 1 August 2015 · Retrieved: 16 September 2026
Companion school-audience guidance stating the exception is intended for school-procured tools, not independent student use.
Source published: 1 February 2014 · Retrieved: 16 September 2026
Confirms the Department's current student-privacy guidance portal, retrieved 16 September 2026.
Source published: Not established · Retrieved: 16 September 2026
Departments, studies and vendor documents establish the record; the implementation reading and the boundary are School AI Atlas editorial analysis. This retrospective draft does not imply the site published on the event date.