EdTech Privacy Policy: Free FERPA & COPPA Compliant Generator
Educational technology platforms operate in one of the most tightly regulated privacy environments. Student data is protected by federal law (FERPA, COPPA), state student data privacy laws, and increasingly, contractual agreements with school districts. Whether you build learning management systems, assessment tools, tutoring platforms, or classroom communication apps, your privacy policy must address student education records, parent consent, school district obligations, and long-term data stewardship. Here is what every EdTech platform needs — and a free generator that builds a FERPA- and COPPA-ready privacy policy.
FERPA: Student Education Record Requirements
1. What Are Education Records Under FERPA?
The Family Educational Rights and Privacy Act (FERPA) defines education records as records directly related to a student maintained by an educational agency or institution. For EdTech platforms, this includes: grades and transcripts, course enrollment and attendance data, disciplinary records, special education records (IEPs, 504 plans), counselor notes, assessment and test scores, class participation records, and communications about student performance. Your privacy policy must clearly identify what student education records your platform creates, collects, or maintains, and the legal basis for doing so (school official legitimate educational interest, prior written consent, or directory information exception). Under FERPA, your platform, as a school official with a legitimate educational interest, may access education records if the school district has designated you as a school official in its annual FERPA notification and you are under the direct control of the school regarding the use and maintenance of education records.
2. FERPA Parental Rights
FERPA grants parents (and eligible students aged 18 or attending postsecondary institutions) specific rights regarding education records. Your policy must address: right to inspect and review education records within 45 days of request, right to request amendment of records believed to be inaccurate or misleading (with a formal hearing process if the school denies the request), right to consent to disclosures of personally identifiable information (with exceptions for directory information and school officials with legitimate educational interest), and right to file a complaint with the Family Policy Compliance Office at the U.S. Department of Education. For K-12 platforms, rights belong to parents until the student turns 18 or enters postsecondary education, at which point rights transfer to the student. Your system must support both workflows. Disclose in your policy how parents can exercise these rights through your platform, including contact information for your designated FERPA compliance contact.
3. Directory Information vs. Non-Directory Information
FERPA distinguishes between directory information (may be disclosed without consent) and non-directory information (requires prior written consent or a legitimate educational interest exception). Your policy must state what your platform considers directory information if you disclose it. Common directory information includes: student name, address, telephone number, email address, date and place of birth, grade level, enrollment status, dates of attendance, participation in officially recognized activities and sports, weight and height of athletic team members, degrees and awards received, and most recent educational institution attended. However, schools must notify parents annually of what is designated as directory information and allow parents a reasonable time to opt out. If your platform enables disclosure of directory information to third parties (yearbook publishers, scholarship organizations, military recruiters), the school district's directory information opt-out choices must be honored in your system. Non-directory information (grades, discipline records, special education status, assessment results) requires signed and dated written consent with specific disclosures.
COPPA: Children Under 13
1. COPPA Requirements & Verifiable Parental Consent
The Children's Online Privacy Protection Act (COPPA) applies to websites and online services that collect personal information from children under 13. For EdTech platforms used in K-6, COPPA compliance is almost certainly required. Your policy must detail: the types of personal information collected from children (name, email, username and password, persistent identifiers like IP addresses and device IDs, geolocation, photos and videos containing a child's image, audio recordings, and screen names), how information is collected (direct registration, teacher-managed accounts, auto-generated accounts from school district SIS integration, in-app activity tracking), the purpose of collection (educational service delivery, account management, security and safety, service improvement), verifiable parental consent mechanisms (signed consent form via mail/fax/email/scanned upload, electronic signature, video conference verification, or database verification using government ID), and the parent's right to review, delete, or refuse further collection of the child's data at any time. Teacher-managed consent (schools may consent on behalf of parents under COPPA when the tool is used exclusively for educational purposes) is a common approach for EdTech. The FTC has issued guidance clarifying that schools can provide consent for the educational context, but parents retain the right to review and delete their child's data even when the school has provided consent.
2. COPPA Safe Harbor Programs
Many EdTech companies participate in COPPA safe harbor programs that provide FTC-approved self-regulatory guidelines. Common programs include: iKeepSafe (FERPA|COPPA|CIPA compliance certification), PRIVO (COPPA safe harbor certification), the Entertainment Software Rating Board (ESRB) Privacy Certified, and Carnegie Mellon's KidSAFE Seal Program. If your platform participates in a safe harbor program, reference it in your privacy policy. Certification demonstrates a commitment to children's privacy and may reduce enforcement risk. Your policy should also address whether you engage in behavioral advertising to children under 13 (COPPA restricts this), the use of analytics and tracking on child-directed portions of your service, and any sharing of children's data with third parties.
School District Data Agreements
Increasingly, school districts require signed data privacy agreements (DPAs) with EdTech vendors before allowing platform use. These agreements incorporate FERPA obligations and often exceed federal requirements. Your policy should address: contractual obligations to school districts (use student data only for authorized educational purposes, never sell student data, maintain data security, honor data deletion requests), Student Data Privacy Consortium (SDPC) or similar standardized agreements, data inventory requirements (many states require EdTech vendors to file annual data inventory disclosures listing every data element collected), state-specific privacy laws (California AB 1584, New York Education Law Section 2-d, Illinois S.B. 3050, Texas HB 1866, Colorado HB 16-1423, and over 40 other state student data privacy laws), third-party data sharing (any subcontractors that process student data must be disclosed and bound by equivalent privacy obligations), and security incident notification to schools (timelines vary by state from immediate to 72 hours). Your privacy policy should reference your commitment to state student data privacy laws and provide contact information for districts to request your full data privacy agreement.
LMS Integrations & Data Flows
EdTech platforms that integrate with Learning Management Systems (Canvas, Blackboard, Schoology, Google Classroom, Moodle) have specific data privacy considerations. LTI (Learning Tools Interoperability) integrations transmit: student identity data (name, email, user ID through the LTI launch), roles and enrollment data through the LTI Names and Role Provisioning service, and assignment scores and grades through the LTI Advantage Assignment and Grade Services. Disclose: whether your platform reads grades and assignment data from the LMS, whether your platform creates new data within the LMS workflow, the scope of LMS API access (read vs. write, which data objects are accessed), and whether your platform integrates with school district Student Information Systems (PowerSchool, Infinite Campus, Aeries, Skyward) for roster synchronization. SIS integrations often sync: student names, state-assigned student IDs, grade levels, homerooms, schedules, and parent/guardian contact information. Each integration point represents a data sharing arrangement that should be disclosed in your policy.
Proctoring Tools & Assessment Privacy
If your EdTech platform includes remote proctoring or assessment monitoring features (either built-in or through third-party integration with ProctorU, Honorlock, Respondus, Examity, Proctorio, or ExamSoft), heightened privacy disclosures are required. Proctoring tools collect: continuous video and audio recordings of the testing environment, screen captures and screen recordings, webcam feeds showing the student's face and surroundings (often with AI analysis for suspicious behavior), keystroke dynamics and typing patterns, browser activity logs and application detection, room scans (360-degree view of the testing space), and government ID scans for identity verification. Disclose: which proctoring provider is used, whether AI analysis is applied to recordings (including any automated suspicious behavior detection that constitutes automated decision-making under GDPR), recording retention periods, whether recordings are reviewed by humans (and under what circumstances), opt-out mechanisms for students with privacy concerns (alternative assessment arrangements), and data ownership (proctoring recordings are education records under FERPA). The biometric data collected (facial images, voice recordings, keystroke patterns) may trigger additional consent requirements under state biometric privacy laws (Illinois BIPA, Texas, Washington, New York City).
Student Data Retention After Graduation
EdTech platforms must have clear policies for student data retention and deletion when the educational relationship ends. Address: graduation transition (what happens to student accounts and data when a student graduates), account deactivation and data purging timelines, archived records (FERPA permits schools to retain education records indefinitely for archival purposes, but personally identifiable data in your platform should have a defined retention schedule), data export options (export of student portfolios, transcripts, or learning records before account deletion), district choice (whether the school district or the student controls data after graduation), and legal holds (data preservation for litigation, special education records (IDEA requires specific retention periods), and audit requirements). For postsecondary EdTech platforms, FERPA rights transfer to the student at age 18, which changes consent requirements. Your data retention schedule should be specified in months or years for each data category, with justification for each retention period.
Generate Your EdTech Privacy Policy — Free
Create a FERPA- and COPPA-ready privacy policy for your education platform. Select your student data categories, LMS integrations, proctoring tools, and age groups for complete compliance coverage.
Generate EdTech Privacy Policy →