Student data privacy (FERPA) for teachers and school staff

For teachers, paraprofessionals, office and support staff: protect student records in email, photos, apps and AI tools, share correctly with parents, and report problems fast.

For: K-12 teachers, paraprofessionals, front office staff, counselors' assistants, coaches and other support staff

  • 2 contact hours
  • 6 modules
  • 8 interactives
  • 4 job aids
  • Updated October 11, 2026

What you will be able to do

  • Identify education records, personally identifiable information and directory information, and apply directory opt-outs.
  • Apply privacy-safe practices to email, messaging, shared drives, grading at home, paper, personal devices, social media and conversations.
  • Determine whether a photo, video, edtech tool or AI tool can be used with student information, applying the school official exception and COPPA basics.
  • Share student information correctly with parents (including noncustodial parents), colleagues and health staff, and route outside, emergency and legal requests to the right person.
  • Recognize a student privacy incident and respond by containing, reporting promptly with facts and supporting prevention.

Learn what the Family Educational Rights and Privacy Act (FERPA) protects and how to apply it in a normal school day: what counts as an education record and personally identifiable information, how directory information and opt-outs work, and how to handle email, shared drives, grading at home, photos, social media, edtech and AI tools safely.

Built for all school staff, not administrators. Scenarios set in real US classrooms and offices walk through divorced-parent requests, health information, photos for the school page and an accidental over-share, and you leave with a staff checklist, a classroom review template, an incident form and a quick-reference card.

Most student privacy problems are small moments, a chart by the door or a click-through app, not dramatic hacks. This course focuses on those moments, explains where FERPA, COPPA and state laws apply, and makes clear when to stop and route a request to the office or privacy officer.

What you’ll be able to do Monday morning

  1. Remove any visible list that pairs student names with grades, levels or services.
  2. Keep group parent messages to logistics and contact families privately about their child.
  3. Check the directory opt-out list before posting any photo or name.
  4. Use only approved apps and keep student details out of AI tools.
  5. Route parent records requests and outside requests to the office.
  6. Save your privacy contact's number and report mistakes within minutes.

Curriculum

6 modules · 24 lessons · about 2 contact hours

01Why does student privacy matter, and what does FERPA protect?Free preview14 min
  1. Why does student privacy matter?
  2. What is FERPA, and whose rights does it protect?
  3. What counts as an education record?
  4. What is personally identifiable information?
  • Sort activity: Education record or not?

Diagram · In practice checklist · 2-question knowledge check

02What is directory information, and how do opt-outs work?13 min
  1. What is directory information?
  2. How do opt-outs work, and why do they matter?
  3. Who can get directory information, and can schools limit it?
  4. What should Ozzie do with the birthday-party request?
  • Ethics dilemma: The science fair photo

Diagram · In practice checklist · 2-question knowledge check

03How do I keep student information safe day to day?14 min
  1. How should I use email and messaging?
  2. What about shared drives, grading at home and printing?
  3. What about personal devices and social media?
  4. What about conversations and visitors?
  • Spot the issue: Spot the privacy problems in a teacher's week

Diagram · In practice checklist · 2-question knowledge check

04Can I use photos, videos, edtech and AI tools?14 min
  1. When are photos and videos education records?
  2. How do edtech tools fit under FERPA?
  3. What about COPPA and children under 13?
  4. How do I use AI tools without exposing student data?
  • Decision tree: Can I use this tool with student data?

Diagram · In practice checklist · 3-question knowledge check

05Who can I share student information with?15 min
  1. What rights do parents have, including noncustodial parents?
  2. When can I share with colleagues and other school officials?
  3. How does health information work: FERPA or HIPAA?
  4. What about emergencies, police and outside requests?
  • Branching scenario: Pickup time request

Diagram · In practice checklist · 2-question knowledge check

06What do I do when something goes wrong?13 min
  1. What counts as a privacy incident?
  2. What should I do first?
  3. What happens after a report, and why does it matter?
  4. How can I prevent the next one?
  • Spot the issue: Spot what went wrong in this incident response
  • State rules selector: Student privacy laws: look up your state
  • Self-assessment: How privacy-safe are my school habits?

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 23 questions, 80% to pass, then your certificate

Try it now, no account needed

Pickup time request

A branching scenario from this course. Your choices are not saved.

Free sample activity

Pickup time request

You teach 4th grade. At pickup, a man you have not met says he is Cordell's father, explains he and Cordell's mom are divorced, and asks to see Cordell's grades and the behavior notes from the fall conference.

Inside the course

Practice activities

  • Sort activity1
  • Ethics dilemma1
  • Spot the issue2
  • Decision tree1
  • Branching scenario1
  • State rules selector1
  • Self-assessment1

Job aids you keep

  • Student Privacy Staff ChecklistChecklist
  • Classroom Privacy Practices Review TemplateTemplate
  • Student Privacy Incident Report FormTemplate
  • FERPA Quick Reference for School StaffPocket card

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 2 contact hours of instruction. It is not approved or accredited by any state education agency, licensing board or continuing education accreditor, and it is not a state-specific training. Some states and districts require privacy training for staff; check with your district or state whether this course is accepted for your professional development or license renewal hours.

Pathways we may pursue include review by state educator professional development approvers and IACET-aligned processes. None of these approvals exists today; the course page will show an approval only after it is granted.

Our full approvals list

State notes

FERPA is the federal floor. Many states add student privacy laws that limit what education technology companies may do with student data, require district contracts, add parent rights or require staff training. Examples include California's Student Online Personal Information Protection Act (Business and Professions Code 22584) and Education Code 49073.1; New York's Education Law 2-d and 8 NYCRR Part 121, which require annual privacy and security training for staff with access to student data; Illinois's Student Online Personal Protection Act (105 ILCS 85); Colorado's Student Data Transparency and Security Act (C.R.S. 22-16-101 and following); Texas Education Code Chapter 32, Subchapter D; and Connecticut General Statutes 10-234aa to 10-234dd.

States also differ on records retention schedules, mandated reporting of abuse, data breach notification, and rules for photos and social media. Your district's policies explain how these apply. Ask your district privacy officer or technology office which state laws apply to you.

Questions about this course

Who should take this course?

Teachers, paraprofessionals, front office staff, coaches, counselors' assistants and other K-12 support staff who see or handle student information. It focuses on everyday practice. Principals, district leaders and privacy officers should also take the separate leader course, which covers annual notices, vendor contracts, consent exceptions and breach response in depth.

Does this course meet my state's student privacy training requirement?

Some states, such as New York, require districts to provide annual privacy training to staff with access to student data. Whether this course counts is up to your district or state. It is a general certificate of completion, not a state edition. Share the course outline with your district privacy officer and ask whether it fits.

Does it cover AI tools?

Yes, from a privacy angle: why student information should never go into unapproved AI tools, how to use AI without identifying students, and how COPPA age rules apply. Broader classroom use of AI, academic integrity and AI policy are covered in a separate course on AI in education for K-12 educators.

How long does it take, and what do I receive?

Plan on about two hours, including six modules, interactive exercises, knowledge checks and a final assessment. You need 80 percent to pass. You receive a certificate of completion for 2 contact hours plus a staff checklist, a classroom privacy review template, an incident report form and a quick-reference card.

Is HIPAA covered?

Yes, briefly. In most K-12 schools, student health records kept by the school, including the school nurse's records, are FERPA education records, not HIPAA records. The course explains this using the 2019 joint FERPA/HIPAA guidance and shows how to share health information on a need-to-know basis.

Is it approved for continuing education or license renewal hours?

Not at this time. It awards a certificate of completion for 2 contact hours and is not approved by any state education agency or accreditor. Check with your district or state licensing office whether they accept it for professional development hours.

This course is general education and training awareness from CE Courses Hub on student data privacy and FERPA for school staff. It is not legal, medical or professional advice and does not replace your district's policies, your licensing board's rules, or advice from a qualified professional or your district's privacy officer or counsel. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.