Why this matters
FERPA sets the federal floor for student data privacy, but it hasn't stood still and it isn't the whole picture anymore. Heading into 2026, several state privacy laws add stricter requirements on top of FERPA, and COPPA amendments expand what counts as protected student information to include biometric identifiers. Any edtech vendor selling into K-12 or higher ed needs a compliance posture that satisfies the federal baseline and the toughest state law a customer might be in — usually California, Illinois, or New York.
This checklist is for edtech product and engineering teams preparing for a district or university security review, and for schools evaluating a vendor before signing.
Before you start
- [ ] Inventory every category of student data your product collects (grades, attendance, behavioral, biometric, health, disciplinary)
- [ ] Map where each category is stored, who can access it internally, and how long it's retained
- [ ] Identify which state "super laws" (California SOPIPA/CCPA overlap, Illinois SOPPA, New York Ed Law 2-d) apply to your current or target customers
- [ ] Confirm whether you're acting as a "school official" under FERPA's exception, which determines your legal basis for handling records at all
Contract and documentation requirements
| Requirement | What it covers | Why schools check it |
|---|---|---|
| Data Processing Agreement (DPA) | Legally binding terms on data use, ownership, deletion | Required before any student data can be shared |
| Data ownership clause | Confirms the school/district owns the data, not the vendor | Prevents vendor lock-in and unauthorized use |
| No advertising clause | Prohibits using student data for targeted ads or profiling | Standard requirement in nearly all state student privacy laws |
| Deletion rights | Defines how and when data is deleted on contract termination | Schools need proof of deletion for their own compliance |
| Breach notification terms | Specifies notification timeline and method after a breach | Many states require notification within 72 hours |
| Subprocessor disclosure | Lists any third parties (analytics, hosting, AI models) touching student data | A vendor's subprocessors are in scope too |
Technical and security controls
- [ ] Encryption at rest and in transit for all student records
- [ ] Role-based access control with audit logging on every record access
- [ ] SOC 2 Type II report (or equivalent) available to share with prospective school customers
- [ ] Documented data retention and automated deletion schedule
- [ ] A tested incident response plan with a defined breach-notification workflow
- [ ] If using AI features (adaptive learning, chat tutoring, auto-grading): documentation of what student data feeds the model and whether it's used for training
Vendor evaluation criteria (for schools)
- [ ] Does the vendor sign your district's standard DPA without material redlines?
- [ ] Can they name every subprocessor with access to student data?
- [ ] Do they have a named point of contact for data subject requests (access, correction, deletion)?
- [ ] Is directory information handled separately from protected education records, with clear opt-out support for parents?
- [ ] Does their AI/ML functionality, if any, comply with your state's emerging AI-in-education guidance?
Red flags to watch for
- [ ] Vendor treats FERPA as the only applicable law and hasn't addressed state-specific requirements
- [ ] No clear answer on subprocessors or where data is actually hosted
- [ ] Data retention policy is "indefinite" or undocumented
- [ ] AI features trained on student data without an opt-out or anonymization step
How to use this
Walk through the checklist section by section with both your legal and engineering leads before a security review — schools increasingly send their own vendor questionnaires that map directly onto these categories, so having documented answers ready shortens procurement cycles significantly.
How Syslabs helps
Compliance reviews slow down edtech sales cycles when the underlying data architecture wasn't built with access control, retention, and audit logging in mind from the start. Syslabs helps edtech teams design custom software with these controls built in, and works alongside compliance and risk consulting engagements to get products review-ready before they reach a district's procurement desk.