Skip to main content
Compliance Guide 11 min read September 2026

FERPA, COPPA, and AI: A Teacher’s Plain-English Compliance Guide

You don’t need a law degree to use AI tools compliantly. You need to know what the laws protect, what the AI-specific risks are, and the six questions to ask before you adopt any tool. Here’s the guide — in teacher language.

Teacher reviewing compliance documents

Answer-First Capsule (AEO Summary)

What are FERPA and COPPA, and how do they apply to AI tools? FERPA protects education records — student work stored by school-adopted tools counts. COPPA requires verifiable parental consent before collecting data from children under 13. The single most important AI-specific question is: is student input data used to train the vendor’s model? If yes, that’s a disclosure of education records for a non-educational purpose, and it requires consent under FERPA (and verifiable parental consent under COPPA for under-13s). Teachers should ask six questions before adopting any AI tool: training data use, retention, sub-processors, deletion, de-identification, and data location. Prefer tools that document compliance in plain English. Secondary AI maintains dedicated FERPA and COPPA compliance pages, answers the training-data question publicly, and provides a full privacy hub for teachers, students, and parents.

Section 1: The Compliance Gap

You’re Already a Compliance Officer — You Just Didn’t Know It

When you bring an AI tool into your classroom, you’re not just adopting a product. You’re making a decision about how student data is handled — and that decision has legal weight. FERPA and COPPA don’t prohibit AI tools. They require that the tools handle student data within boundaries. The problem is that most teachers adopt tools without knowing where the boundaries are.

This isn’t about fear. It’s about professional practice. The same judgment you apply to pedagogy — what’s appropriate, what’s evidence-based, what serves students — applies to data. You don’t need to be a lawyer. You need to know what to ask.

The compliance gap isn’t that teachers are careless. It’s that the tools, the policies, and the training all assume someone else is handling this. But when a tool mishandles student data, the someone else is you.

Section 2: Where the Gaps Are

Four Gaps That Put Student Data at Risk

The compliance risks with AI tools aren’t theoretical. They’re the predictable result of how tools are built, sold, and adopted:

You Adopt the Tool, You Inherit the Liability

When a teacher brings an AI tool into the classroom, the school becomes a “school official” handling student data — and the teacher becomes the one who chose the tool. If the tool mishandles data, the compliance failure doesn’t land on the vendor. It lands on the school, and on you. Most teachers adopt tools without knowing this.

The Policy Is Written for the Vendor, Not You

AI tools post privacy policies designed to protect the company, not to inform the teacher. They’re long, legalistic, and buried. The questions a teacher actually needs answered — Is student data stored? For how long? Used for training? — are answered in language no teacher has time to parse. Compliance becomes something you hope for, not something you verify.

COPPA Turns 13 Into a Cliff Edge

COPPA protects students under 13. FERPA protects all students. But the rules differ on either side of 13 — what you can collect, what consent you need, what the vendor can do. A middle school teacher with 12- and 13-year-olds in the same building is managing two different compliance regimes. Most tools don’t help you tell them apart.

AI Training Is the Hidden Question

The biggest FERPA/COPPA risk with AI tools isn’t storage — it’s training. If student essays are used to train the model, that’s a disclosure of education records to a third party for an unrelated purpose. Most policies don’t clearly say whether this happens. Most teachers don’t know to ask. This is the gap regulators are watching.

Section 3: FERPA in Plain English

What FERPA Actually Says (and What It Means for You)

FERPA is the Family Educational Rights and Privacy Act. It protects education records. Here’s what that means for a teacher using AI:

1

What it protects. FERPA protects “education records” — records that are directly related to a student and maintained by the school. That includes grades, transcripts, disciplinary records, and — critically for AI — student work submitted to and stored by school-adopted tools.

2

Who has access. Schools may disclose education records to “school officials” with “legitimate educational interest” without consent. A teacher using an AI tool on behalf of the school is a school official. The AI vendor, if acting under the school’s direction with a legitimate interest, may be one too — but only if it meets the conditions. If the vendor uses the data for its own purposes (like model training), that’s outside the exception.

3

What requires consent. Disclosure to third parties for purposes unrelated to the educational function requires parental consent (for underage students) or student consent (for adults). Using student essays to improve a vendor’s commercial AI model is not an educational purpose. If it’s happening, it needs consent — and most teachers don’t know to ask whether it’s happening.

4

What you control. You control what tools you bring into the classroom. You control whether you read the data policy. You control whether you ask the vendor the training question. FERPA doesn’t prohibit AI tools — it requires that they’re used in ways that respect the boundaries of education records. Your job is to verify they do.

Section 4: COPPA in Plain English

What COPPA Actually Says (and the Under-13 Rule)

COPPA is the Children’s Online Privacy Protection Act. It adds a layer of protection for the youngest students. Here’s what you need to know:

1

The under-13 rule. COPPA requires verifiable parental consent before collecting personal information from children under 13. “Collecting” includes anything a tool receives from a student — names, work, even identifiers. If your students are under 13 and the tool collects their data, the tool needs verifiable parental consent. Not a checkbox. Not a click-through. Verifiable consent.

2

What counts as personal information. COPPA’s definition is broad: name, address, online contact info, phone, social security number, photographs, audio, persistent identifiers, and — importantly — any information tied to a child’s identity. Student work submitted to an AI tool is personal information if it’s linked to the student. That’s most of what teachers send.

3

The vendor’s obligations. COPPA-compliant tools must post a clear privacy notice, obtain verifiable parental consent, give parents access to and deletion of their child’s data, and not condition participation on data collection beyond what’s reasonably necessary. If a tool can’t show you it does these things, it isn’t COPPA-compliant — and you can’t use it with under-13s without putting the school at risk.

4

The 13-and-over difference. Once students turn 13, COPPA no longer applies — FERPA still does. The consent requirements loosen, but the data-handling obligations don’t. A high school teacher has fewer consent hurdles but the same obligation to ensure student records aren’t repurposed. The age boundary changes the regime, not the responsibility.

Section 5: The AI-Specific Risks

Six Questions FERPA and COPPA Don’t Answer — But AI Raises

FERPA and COPPA were written before AI tools existed. The laws still apply, but they don’t address the specific risks AI introduces. Here are the six questions you need to ask that the laws don’t spell out:

1

The Training Data Question

Does the tool use student inputs to train its model? This is the single most important FERPA/COPPA question for AI. If yes, student records are being disclosed to improve a commercial product — that’s a purpose outside the educational function, and it requires consent. Most policies don’t clearly answer this. You have to ask.

2

The Retention Question

How long does the tool keep student data? FERPA doesn’t mandate a specific retention period, but indefinite retention of education records by a third party raises questions about whether the “school official” exception still applies. A tool that keeps student work forever is a tool that’s building a database, not serving a class.

3

The Sub-Processor Question

Does the tool share student data with sub-processors — cloud providers, model APIs, analytics services? Each sub-processor is another disclosure. FERPA permits disclosures under the school official exception if the terms are “directly controlled” by the school, but most teachers have no visibility into the sub-processor chain. You can’t audit what you can’t see.

4

The Deletion Question

Can you delete student data when the class ends, or when a student leaves? FERPA doesn’t require deletion, but good practice — and some state laws — do. If the tool can’t delete data, it’s holding education records indefinitely for no educational purpose. That’s a compliance question mark and a stewardship failure.

5

The De-identification Question

If the tool claims to “anonymize” data, is the de-identification real? Removing names isn’t enough — essays, writing styles, and contextual details can re-identify students. True de-identification is hard. A tool that claims it without explaining how is a tool that’s asking you to trust a label.

6

The Cross-Border Question

Where is student data stored and processed? If data flows to jurisdictions with weaker privacy protections, the FERPA/COPPA analysis gets harder. You don’t need to be a privacy lawyer, but you deserve to know whether student records stay in a country with comparable protections.

Section 6: What to Do Monday Morning

A Teacher’s Compliance Action Checklist

Six moves to use AI tools compliantly — without becoming a privacy lawyer:

Before you adopt: ask the training question

Email the vendor. Ask: “Is student input data used to train your models?” If the answer is yes, you need consent. If the answer is unclear, treat it as yes. This single question filters out more non-compliant tools than any other.

Check the age of your students

If any student is under 13, COPPA applies — and the tool needs verifiable parental consent. If you don’t know whether the tool has it, don’t use it with under-13s. The risk isn’t worth the convenience.

Read the data policy or ask someone who can

You don’t need to parse every clause. You need to know: what’s collected, how long it’s kept, who it’s shared with, and whether you can delete it. If the policy doesn’t answer these in plain language, ask your admin or IT team to get the answers.

Prefer tools that document compliance in teacher language

Some tools post compliance summaries written for educators — not lawyers. They say what FERPA and COPPA require and how the tool meets it. Prefer those tools. A vendor that explains its compliance to teachers is a vendor that respects your role in the chain.

Connect students and parents to the privacy hub

AI literacy includes data literacy. Students and parents deserve to understand what happens to their data. Point them to resources that explain FERPA, COPPA, and AI data handling in terms they can use — not fine print they can’t.

Document your own adoption decisions

Keep a record of which tools you adopted, when, and what you verified. If a compliance question ever arises, you want to show you acted diligently. A short log — tool, date, what you checked — is the professional equivalent of showing your work.

Section 7: Compliance Built for Teachers

A Platform That Documents Compliance in Teacher Language

Secondary AI treats compliance documentation as a feature, not a legal footnote. The platform is built so you can verify how student data is handled — without reading a 40-page policy:

Compliance pages written for teachers

Secondary AI maintains dedicated FERPA and COPPA compliance pages written in plain English — not legalese. You can read what the law requires, how the platform handles it, and what your responsibilities are, without a law degree.

The training-data question, answered

The platform documents whether student inputs are used for model training — the single most important FERPA/COPPA question for AI. You don’t have to email and ask. The answer is published, and it’s written to be read.

A privacy hub for the whole school community

The AI privacy hub covers data handling, student safety, and compliance frameworks for teachers, students, and parents. It’s a resource you can point people to — so the answer to “what happens to my child’s data?” isn’t “I don’t know.”

Transparency as a built-in feature

The platform treats compliance documentation as a feature, not a legal footnote. Named models, disclosed limitations, clear data handling — because you can’t exercise professional judgment over a tool that hides how it works.

The honest caveat: Compliance documentation doesn’t make a tool compliant — it makes compliance verifiable. You still have to read it, ask questions, and make good adoption decisions. A platform that documents its compliance is one that respects your role in the chain. One that doesn’t is asking you to trust a label.

Section 8: Frequently Asked Questions

The Compliance Question, Answered

FERPA (the Family Educational Rights and Privacy Act) protects education records — records directly related to a student and maintained by the school. When a teacher adopts an AI tool that collects and stores student work, that work can become an education record. FERPA permits disclosure to “school officials” with a “legitimate educational interest,” which can include AI vendors acting under the school’s direction. But if the vendor uses student data for its own purposes — like training its model — that’s outside the exception and requires consent. The key question for AI tools is whether student inputs are used for training; if yes, that’s a disclosure requiring consent.

Continue Reading

Use AI Tools That Document Compliance

You’re responsible for what happens to student data in your classroom. Use tools that respect that responsibility — by documenting it in teacher language, not legalese.