Why this matters

FERPA sets the federal floor for student data privacy, but it hasn't stood still and it isn't the whole picture anymore. Heading into 2026, several state privacy laws add stricter requirements on top of FERPA, and COPPA amendments expand what counts as protected student information to include biometric identifiers. Any edtech vendor selling into K-12 or higher ed needs a compliance posture that satisfies the federal baseline and the toughest state law a customer might be in — usually California, Illinois, or New York.

This checklist is for edtech product and engineering teams preparing for a district or university security review, and for schools evaluating a vendor before signing.

Before you start

  • [ ] Inventory every category of student data your product collects (grades, attendance, behavioral, biometric, health, disciplinary)
  • [ ] Map where each category is stored, who can access it internally, and how long it's retained
  • [ ] Identify which state "super laws" (California SOPIPA/CCPA overlap, Illinois SOPPA, New York Ed Law 2-d) apply to your current or target customers
  • [ ] Confirm whether you're acting as a "school official" under FERPA's exception, which determines your legal basis for handling records at all

Contract and documentation requirements

RequirementWhat it coversWhy schools check it
Data Processing Agreement (DPA)Legally binding terms on data use, ownership, deletionRequired before any student data can be shared
Data ownership clauseConfirms the school/district owns the data, not the vendorPrevents vendor lock-in and unauthorized use
No advertising clauseProhibits using student data for targeted ads or profilingStandard requirement in nearly all state student privacy laws
Deletion rightsDefines how and when data is deleted on contract terminationSchools need proof of deletion for their own compliance
Breach notification termsSpecifies notification timeline and method after a breachMany states require notification within 72 hours
Subprocessor disclosureLists any third parties (analytics, hosting, AI models) touching student dataA vendor's subprocessors are in scope too

Technical and security controls

  • [ ] Encryption at rest and in transit for all student records
  • [ ] Role-based access control with audit logging on every record access
  • [ ] SOC 2 Type II report (or equivalent) available to share with prospective school customers
  • [ ] Documented data retention and automated deletion schedule
  • [ ] A tested incident response plan with a defined breach-notification workflow
  • [ ] If using AI features (adaptive learning, chat tutoring, auto-grading): documentation of what student data feeds the model and whether it's used for training

Vendor evaluation criteria (for schools)

  • [ ] Does the vendor sign your district's standard DPA without material redlines?
  • [ ] Can they name every subprocessor with access to student data?
  • [ ] Do they have a named point of contact for data subject requests (access, correction, deletion)?
  • [ ] Is directory information handled separately from protected education records, with clear opt-out support for parents?
  • [ ] Does their AI/ML functionality, if any, comply with your state's emerging AI-in-education guidance?

Red flags to watch for

  • [ ] Vendor treats FERPA as the only applicable law and hasn't addressed state-specific requirements
  • [ ] No clear answer on subprocessors or where data is actually hosted
  • [ ] Data retention policy is "indefinite" or undocumented
  • [ ] AI features trained on student data without an opt-out or anonymization step

How to use this

Walk through the checklist section by section with both your legal and engineering leads before a security review — schools increasingly send their own vendor questionnaires that map directly onto these categories, so having documented answers ready shortens procurement cycles significantly.

How Syslabs helps

Compliance reviews slow down edtech sales cycles when the underlying data architecture wasn't built with access control, retention, and audit logging in mind from the start. Syslabs helps edtech teams design custom software with these controls built in, and works alongside compliance and risk consulting engagements to get products review-ready before they reach a district's procurement desk.